{
    "1824082": [
        {
            "ioc_value": "138.128.246.42:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 16:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824080": [
        {
            "ioc_value": "111.229.193.141:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 16:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824081": [
        {
            "ioc_value": "185.88.36.172:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-06 16:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824078": [
        {
            "ioc_value": "154.88.102.59:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 16:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824079": [
        {
            "ioc_value": "119.45.34.167:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 16:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824077": [
        {
            "ioc_value": "arihanp.jamjahani.website",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 15:59:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824076": [
        {
            "ioc_value": "bodegaycocina.com.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-06 15:55:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2966628a54237ac01ae01f1f0d2389dfd2b7d5cb4e9615679fc146a62974a016/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824075": [
        {
            "ioc_value": "66.29.148.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-06 15:50:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "NanoCore,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824074": [
        {
            "ioc_value": "tcc.jp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-06 15:35:40",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/455ed788c575a5270884e4852ef83f5707321817b0054c9aafc6ea9e4cfa86ac/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824073": [
        {
            "ioc_value": "46.33.14.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-06 15:30:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "NanoCore,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824072": [
        {
            "ioc_value": "923nr8dp.chloroquineser.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 15:25:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824071": [
        {
            "ioc_value": "w0vflian.chloroquineser.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 15:24:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1824069": [
        {
            "ioc_value": "urdjsnn.jamjahani.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 15:21:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824066": [
        {
            "ioc_value": "154.88.97.35:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 15:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824067": [
        {
            "ioc_value": "149.104.29.190:18502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 15:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824064": [
        {
            "ioc_value": "139.180.146.76:2379",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 15:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824065": [
        {
            "ioc_value": "154.88.97.38:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 15:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824063": [
        {
            "ioc_value": "rmbvag.jamjahani2026shartbandi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 14:58:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824062": [
        {
            "ioc_value": "jj88.today",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-06 14:45:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d9eaa59d25fd1ada2444f7309b08c27d2a124240834cb0797df01df25ed482ec/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824061": [
        {
            "ioc_value": "caxvhiw.jamjahani.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 14:42:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824060": [
        {
            "ioc_value": "dkrbvhs.jamjahani.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 14:04:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824059": [
        {
            "ioc_value": "po9isauo.bet90boro.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 14:03:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824056": [
        {
            "ioc_value": "103.106.230.190:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-06 14:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824057": [
        {
            "ioc_value": "103.106.230.190:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-06 14:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824058": [
        {
            "ioc_value": "154.88.97.52:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 14:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824055": [
        {
            "ioc_value": "uwxrhkk.mangobetfarsi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 13:58:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824054": [
        {
            "ioc_value": "!k!.mangobetfarsi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 13:57:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1824051": [
        {
            "ioc_value": "v47m17r8.cerocarey.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 13:25:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824050": [
        {
            "ioc_value": "4wuw3u19.cerocarey.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 13:24:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1824049": [
        {
            "ioc_value": "nzfcrki.lolsurpriseball.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 13:20:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824048": [
        {
            "ioc_value": "!k!.lolsurpriseball.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 13:19:11",
            "last_seen_utc": "2026-06-06 13:19:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1824046": [
        {
            "ioc_value": "130.94.33.140:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 13:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824047": [
        {
            "ioc_value": "103.106.230.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-06 13:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824045": [
        {
            "ioc_value": "102.204.223.106:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 13:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824044": [
        {
            "ioc_value": "dlklyo.jamjahani2026.football",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 12:57:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824043": [
        {
            "ioc_value": "vivanuncios.com.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-06 12:45:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8a8b3c255a7ca0f6ef1a6b3756b1f65c8f30225bca8d8d8addc0f581cfc39139/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824042": [
        {
            "ioc_value": "errcxxn.libertabet.tv",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 12:41:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824041": [
        {
            "ioc_value": "libertabet.tv",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 12:41:13",
            "last_seen_utc": "2026-06-06 12:41:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1824040": [
        {
            "ioc_value": "taartendoordetijd.nl",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-06 12:25:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/a33948996e02190a9c902c0547fb9cea700e1dc34061e9ba389323900851857d/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824039": [
        {
            "ioc_value": "mgyhtpm.libertabetgiris.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 12:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824038": [
        {
            "ioc_value": "!k!.libertabetgiris.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 12:02:06",
            "last_seen_utc": "2026-06-06 12:02:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1824037": [
        {
            "ioc_value": "proyectoeleuteria.com.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-06 12:00:56",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/88939ef17d58c79d48d8ee9304d1e911dc13ed4c5647646811e80018f6b84a51/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824034": [
        {
            "ioc_value": "154.219.120.101:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 12:00:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824035": [
        {
            "ioc_value": "154.219.120.101:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 12:00:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824036": [
        {
            "ioc_value": "154.219.120.101:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 12:00:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824033": [
        {
            "ioc_value": "154.219.120.101:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 12:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824032": [
        {
            "ioc_value": "153.75.251.219:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-06 12:00:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824029": [
        {
            "ioc_value": "154.12.86.154:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824030": [
        {
            "ioc_value": "154.12.86.154:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824031": [
        {
            "ioc_value": "154.12.86.154:9004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824028": [
        {
            "ioc_value": "wcrvlfe.kvbel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 11:25:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824027": [
        {
            "ioc_value": "34bbeito.canlibahis1xbet.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 11:25:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824026": [
        {
            "ioc_value": "!k!.kvbel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 11:23:35",
            "last_seen_utc": "2026-06-06 11:23:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1824025": [
        {
            "ioc_value": "wvquvzx.kenzobet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 11:23:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824024": [
        {
            "ioc_value": "!k!.kenzobet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 11:22:45",
            "last_seen_utc": "2026-06-06 11:22:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1824023": [
        {
            "ioc_value": "114.55.167.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-06 11:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824021": [
        {
            "ioc_value": "13.60.184.242:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 11:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824022": [
        {
            "ioc_value": "47.236.136.19:8811",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 11:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824020": [
        {
            "ioc_value": "113.45.226.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824019": [
        {
            "ioc_value": "lfwboc.jamejahani.win",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 10:57:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824018": [
        {
            "ioc_value": "bdyqsrv.kbshavanese.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 10:44:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824017": [
        {
            "ioc_value": "!k!.kbshavanese.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 10:44:16",
            "last_seen_utc": "2026-06-06 10:44:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1824015": [
        {
            "ioc_value": "health.hazelkit.one",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-06 10:41:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/eb03106fc4ffe1d6580fa7a18cde415991d1a3992ce1b5d4bdb25f4906d38e5d/",
            "tags": "DocSaStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824016": [
        {
            "ioc_value": "proxy.willowfleet.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-06 10:41:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/eb03106fc4ffe1d6580fa7a18cde415991d1a3992ce1b5d4bdb25f4906d38e5d/",
            "tags": "DocSaStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823980": [
        {
            "ioc_value": "http://45.205.1.59/ok",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:38:06",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,dropper,infra-rotation,Mirai,nsenter-escape,persistent-operator",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1823981": [
        {
            "ioc_value": "45.205.1.59:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:38:04",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,dropper,infra-rotation,Mirai",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1823982": [
        {
            "ioc_value": "188.54.47.14:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:38:03",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,file-upload-backdoor,php-webshell,ubuntu-container,webshell",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1823983": [
        {
            "ioc_value": "172.104.241.98:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:38:02",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,Linode,multi-pot,postgres,reconnaissance,redis,SOAP",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1823984": [
        {
            "ioc_value": "180.189.174.146:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:38:02",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "dropper,Mirai,web-spread",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1823985": [
        {
            "ioc_value": "83.229.8.197:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:38:01",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "dropper,Mirai,web-spread",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1823986": [
        {
            "ioc_value": "150.241.98.49:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:38:00",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "dropper,Mirai,web-spread",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1823987": [
        {
            "ioc_value": "165.154.46.183:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:37:59",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "dropper,Mirai,web-spread",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1823988": [
        {
            "ioc_value": "185.177.125.71:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:37:58",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,reconnaissance",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1823989": [
        {
            "ioc_value": "143.198.199.73:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 10:37:58",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "DigitalOcean,docker-api,reconnaissance",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1824000": [
        {
            "ioc_value": "voltrix.tv",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 10:37:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "burger"
        }
    ],
    "1824013": [
        {
            "ioc_value": "121.89.81.108:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824014": [
        {
            "ioc_value": "156.245.235.51:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824012": [
        {
            "ioc_value": "47.101.51.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824011": [
        {
            "ioc_value": "39.97.243.199:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824010": [
        {
            "ioc_value": "85.121.4.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-6",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824009": [
        {
            "ioc_value": "101.201.111.98:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824008": [
        {
            "ioc_value": "167.71.233.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824007": [
        {
            "ioc_value": "jjotnoj.jojobetuyelik.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 10:06:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1824006": [
        {
            "ioc_value": "!k!.jojobetuyelik.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 10:05:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1824005": [
        {
            "ioc_value": "jojobetuyelik.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 10:05:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1824004": [
        {
            "ioc_value": "47.108.62.225:58313",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 10:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824002": [
        {
            "ioc_value": "113.45.226.61:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824003": [
        {
            "ioc_value": "180.93.109.34:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 10:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824001": [
        {
            "ioc_value": "91.215.85.121:8849",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 09:44:56",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823999": [
        {
            "ioc_value": "zvxeaqm.jogodobicho.games",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 09:27:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823998": [
        {
            "ioc_value": "6ju7fjjz.bordoo.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 09:23:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823997": [
        {
            "ioc_value": "jdjgvaia.bordoo.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 09:23:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823996": [
        {
            "ioc_value": "i8lvkq19.bordino.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 09:17:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823979": [
        {
            "ioc_value": "4lm4v3bu.bet404.games",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 09:03:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823978": [
        {
            "ioc_value": "113.45.226.61:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 09:00:18",
            "last_seen_utc": "2026-06-06 10:32:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823976": [
        {
            "ioc_value": "38.14.248.138:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 09:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823977": [
        {
            "ioc_value": "38.14.248.138:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 09:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823975": [
        {
            "ioc_value": "38.14.248.138:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 09:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823974": [
        {
            "ioc_value": "188.126.90.12:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 09:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823973": [
        {
            "ioc_value": "jrpzgr.jamejahani.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 08:56:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823972": [
        {
            "ioc_value": "vvxcqgv.jamjahani.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 08:49:06",
            "last_seen_utc": "2026-06-06 08:49:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823971": [
        {
            "ioc_value": "138.124.186.2:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.snappy_client",
            "malware_alias": null,
            "malware_printable": "SnappyClient",
            "first_seen_utc": "2026-06-06 08:21:10",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e3b824d9402d5cc6c295e1f0be9992af4e9b4bb38727e8c70caac664209c852b/",
            "tags": "dropped-by-ACRStealer,SnappyClient",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823970": [
        {
            "ioc_value": "xzz.proxygrid.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-06 08:20:21",
            "last_seen_utc": "2026-06-06 08:20:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e3b824d9402d5cc6c295e1f0be9992af4e9b4bb38727e8c70caac664209c852b/",
            "tags": "ACRStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823969": [
        {
            "ioc_value": "172.245.95.9:7601",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-06-06 08:18:21",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c52755dff77ce635cbfbc96ce0d74519584cef8b9721b3f48210d3a71be4ac2b/",
            "tags": "PureLogsStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823968": [
        {
            "ioc_value": "ubzfosw.jamjahani.win",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 08:11:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823967": [
        {
            "ioc_value": "jamjahani.win",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 08:10:19",
            "last_seen_utc": "2026-06-06 08:10:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1823966": [
        {
            "ioc_value": "38.45.126.242:47788",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-06 08:00:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823964": [
        {
            "ioc_value": "43.224.224.19:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-06 08:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823965": [
        {
            "ioc_value": "43.224.224.17:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-06 08:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823963": [
        {
            "ioc_value": "ofwbhuk.jamjahani.website",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 07:32:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823962": [
        {
            "ioc_value": "!k!.jamjahani.website",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 07:31:42",
            "last_seen_utc": "2026-06-06 15:59:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823961": [
        {
            "ioc_value": "zxuq0oha.bord90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 07:18:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823960": [
        {
            "ioc_value": "6jcq2nrd.bord90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 07:16:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823959": [
        {
            "ioc_value": "bushesbone.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-06-06 07:02:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "OffLoader",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823958": [
        {
            "ioc_value": "184.95.51.11:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.purelogs",
            "malware_alias": null,
            "malware_printable": "PureLogs Stealer",
            "first_seen_utc": "2026-06-06 07:01:15",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8ad8bc3ab40d137a1213b5c6e65d0e1c060b8583ec91520c4b2a8bee96f5b485/",
            "tags": "PureLogsStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823957": [
        {
            "ioc_value": "194.26.192.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-06-06 07:00:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ConnectWise,RMM,ScreenConnect",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823956": [
        {
            "ioc_value": "152.136.38.231:20004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 07:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823954": [
        {
            "ioc_value": "154.88.96.41:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 07:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823955": [
        {
            "ioc_value": "154.88.96.37:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 07:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823952": [
        {
            "ioc_value": "38.47.226.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 07:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823953": [
        {
            "ioc_value": "154.88.96.60:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 07:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823951": [
        {
            "ioc_value": "khndao.x50wheel.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 06:56:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823950": [
        {
            "ioc_value": "posdteu.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-06 06:56:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RemusStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823949": [
        {
            "ioc_value": "mathlah.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-06 06:55:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RemusStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823948": [
        {
            "ioc_value": "piciidq.jamjahani.vip",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 06:54:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823946": [
        {
            "ioc_value": "gauravitechnologies.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-06 06:52:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RemusStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823947": [
        {
            "ioc_value": "onesevenapps.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-06 06:52:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RemusStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823945": [
        {
            "ioc_value": "onefunnydog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:49:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/314dfb2385d84fd279b7e297313da57e3d349711886e152d2a6e82016a657f9f/",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823944": [
        {
            "ioc_value": "lowfoodanddrink.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:48:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f1b785b9f11af50a8c8ca12202676096f4ec8a93957f1aca506f722b0cbf57a2/",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823941": [
        {
            "ioc_value": "u9ppj9u3hfphtv7.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:46:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6619fd64400aa38229a4dc722c9fcb8134cce199f444f766b8ac9ff59dafdfde/",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823942": [
        {
            "ioc_value": "vednb0n9eo7pn6z.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:46:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6619fd64400aa38229a4dc722c9fcb8134cce199f444f766b8ac9ff59dafdfde/",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823943": [
        {
            "ioc_value": "vj2k4sffbxpxhhr.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:46:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6619fd64400aa38229a4dc722c9fcb8134cce199f444f766b8ac9ff59dafdfde/",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823940": [
        {
            "ioc_value": "gm0vmvr1kt1i1n8.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:46:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6619fd64400aa38229a4dc722c9fcb8134cce199f444f766b8ac9ff59dafdfde/",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823939": [
        {
            "ioc_value": "pmpo.cloudvector.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-06 06:42:04",
            "last_seen_utc": "2026-06-06 06:42:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/664f2e71b527adadbe24f929057edf5a270800162dc18dca28ef49ffea5bc00d/",
            "tags": "ACRStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823938": [
        {
            "ioc_value": "gsk.scriptlattice.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-06 06:41:17",
            "last_seen_utc": "2026-06-06 06:41:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d88efdaa4d897576e5e7c8aab16068386ca4b9a4de0a1e4d17a0c4d59b48b25e/",
            "tags": "ACRStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823936": [
        {
            "ioc_value": "95.179.252.135:3334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 06:28:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/eacd44512510f9232e6605e17c4f953454840a99f73b08a204bbc2ad16c6c348/",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823937": [
        {
            "ioc_value": "95.179.252.135:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 06:28:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/eacd44512510f9232e6605e17c4f953454840a99f73b08a204bbc2ad16c6c348/",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823934": [
        {
            "ioc_value": "webfloweu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2026-06-06 06:28:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/eacd44512510f9232e6605e17c4f953454840a99f73b08a204bbc2ad16c6c348/",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823935": [
        {
            "ioc_value": "webupdateflow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2026-06-06 06:28:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/eacd44512510f9232e6605e17c4f953454840a99f73b08a204bbc2ad16c6c348/",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823925": [
        {
            "ioc_value": "mipcepl.jamjahani.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 06:19:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823924": [
        {
            "ioc_value": "!k!.jamjahani.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 06:15:22",
            "last_seen_utc": "2026-06-06 14:04:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822888": [
        {
            "ioc_value": "34.173.83.139:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 06:03:46",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "aws-imds,credential-theft,docker-api,iam-theft,metadata-attack",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822889": [
        {
            "ioc_value": "94.124.119.36:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 06:03:46",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "backdoor-key,container-escape,docker-api,ssh-key-plant,ubuntu-container",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822890": [
        {
            "ioc_value": "177.104.165.104:9443",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-06 06:03:45",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,miner,payload-host,port-9443,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822891": [
        {
            "ioc_value": "http://177.104.165.104:9443/xmrig",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-06 06:03:45",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,miner,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822892": [
        {
            "ioc_value": "116.34.14.135:22",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-06 06:03:45",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "credential-theft,mikrotik-recon,reconnaissance,ssh-bruteforce,telegram-stealer",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822893": [
        {
            "ioc_value": "118.182.166.128:22",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xorddos",
            "malware_alias": "XORDDOS",
            "malware_printable": "XOR DDoS",
            "first_seen_utc": "2026-06-06 06:03:44",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "BillGates,DDoS,ssh-bruteforce,XOR.DDoS",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822894": [
        {
            "ioc_value": "221.234.36.123:22",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-06 06:03:44",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "mdrfckr,mining-toolkit,Outlaw,ssh-bruteforce",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822895": [
        {
            "ioc_value": "167.71.47.6:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 06:03:44",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "DigitalOcean,dropper,Mirai,multi-hash,web-spread",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822896": [
        {
            "ioc_value": "217.79.226.23:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-06 06:03:43",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,dual-role,libredtail-http,Redtail,spreader",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822897": [
        {
            "ioc_value": "47.95.234.23:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-06 06:03:42",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,dual-role,libredtail-http,Redtail,spreader",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822898": [
        {
            "ioc_value": "47.238.121.28:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-06 06:03:42",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,dual-role,libredtail-http,Redtail,spreader",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822899": [
        {
            "ioc_value": "101.36.104.242:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-06 06:03:40",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "CN,docker-api,dual-role,libredtail-http,Redtail,spreader",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822900": [
        {
            "ioc_value": "37.255.239.81:22",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-06 06:03:40",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "reconnaissance,ssh-bruteforce",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822901": [
        {
            "ioc_value": "46.151.182.191:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-06 06:03:39",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "bruteforce,database-enumeration,postgres,reconnaissance",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822902": [
        {
            "ioc_value": "http://45.198.224.5/ok",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-06 06:03:39",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,infra-rotation,Mirai,nsenter-escape,self-hosted",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822903": [
        {
            "ioc_value": "47.103.192.156:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-06 06:03:38",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "h2miner,module-loading,muhstik,redis,slaveof-attack,SYSTEM.EXEC",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822904": [
        {
            "ioc_value": "8.134.122.94:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-06 06:03:38",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "module-loading,muhstik,redis,slaveof-attack,SYSTEM.EXEC",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822916": [
        {
            "ioc_value": "https://loureiru.lol/file.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:03:37",
            "last_seen_utc": "2026-06-06 05:10:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116699073083198092",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822917": [
        {
            "ioc_value": "loureiru.lol",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:03:36",
            "last_seen_utc": "2026-06-06 05:10:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116699073083198092",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822918": [
        {
            "ioc_value": "https://loureiru.lol/api/v1/session",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:03:35",
            "last_seen_utc": "2026-06-06 05:10:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116699073083198092",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822919": [
        {
            "ioc_value": "https://loureiru.lol/api/v1/verify",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:03:35",
            "last_seen_utc": "2026-06-06 05:10:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116699073083198092",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822920": [
        {
            "ioc_value": "https://loureiru.lol/api/v1/status",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:03:34",
            "last_seen_utc": "2026-06-06 02:10:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116699073083198092",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1823742": [
        {
            "ioc_value": "http://2flowers-my.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-06 06:01:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823743": [
        {
            "ioc_value": "http://vipcloud-my.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-06 06:01:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823744": [
        {
            "ioc_value": "http://gstatic-node.io/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-06 06:01:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823745": [
        {
            "ioc_value": "http://solopodvip-my.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-06 06:01:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823746": [
        {
            "ioc_value": "http://winhttp.dll/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-06 06:01:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823739": [
        {
            "ioc_value": "http://82.117.255.80/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-06 06:01:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823740": [
        {
            "ioc_value": "http://195.123.226.91/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-06 06:01:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823741": [
        {
            "ioc_value": "http://195.123.226.167/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-06 06:01:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823650": [
        {
            "ioc_value": "https://openmeadowlab.top/health/session-deploy.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-06 06:01:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116699315834389655",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1823651": [
        {
            "ioc_value": "openmeadowlab.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-06 06:01:15",
            "last_seen_utc": "2026-06-06 05:11:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116699315834389655",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1823652": [
        {
            "ioc_value": "https://openmeadowlab.top/health/public-layout",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-06 06:01:14",
            "last_seen_utc": "2026-06-06 05:11:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116699315834389655",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1823653": [
        {
            "ioc_value": "https://openmeadowlab.top/health/signup-module.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-06 06:01:14",
            "last_seen_utc": "2026-06-06 05:11:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116699315834389655",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1823665": [
        {
            "ioc_value": "linkedmba.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.castleloader",
            "malware_alias": null,
            "malware_printable": "CASTLELOADER",
            "first_seen_utc": "2026-06-06 06:01:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "castleloader,clickfix",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1823666": [
        {
            "ioc_value": "allenjarmon.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.castleloader",
            "malware_alias": null,
            "malware_printable": "CASTLELOADER",
            "first_seen_utc": "2026-06-06 06:01:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "castleloader,clickfix",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1823667": [
        {
            "ioc_value": "writersfm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.castleloader",
            "malware_alias": null,
            "malware_printable": "CASTLELOADER",
            "first_seen_utc": "2026-06-06 06:01:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "castleloader,clickfix",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1823668": [
        {
            "ioc_value": "crewlworkinew.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.castleloader",
            "malware_alias": null,
            "malware_printable": "CASTLELOADER",
            "first_seen_utc": "2026-06-06 06:01:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "castleloader,clickfix",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1823670": [
        {
            "ioc_value": "linkedwiz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.castleloader",
            "malware_alias": null,
            "malware_printable": "CASTLELOADER",
            "first_seen_utc": "2026-06-06 06:01:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "castleloader,clickfix",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1823671": [
        {
            "ioc_value": "amazon-cz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.castleloader",
            "malware_alias": null,
            "malware_printable": "CASTLELOADER",
            "first_seen_utc": "2026-06-06 06:01:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "castleloader,clickfix",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1823697": [
        {
            "ioc_value": "178.128.1.56:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 06:01:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "14061,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1823698": [
        {
            "ioc_value": "44.218.174.67:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 06:01:09",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "14618,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1823699": [
        {
            "ioc_value": "128.90.171.185:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 06:01:08",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "22363,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1823700": [
        {
            "ioc_value": "45.81.17.44:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 06:01:08",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "211056,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1823701": [
        {
            "ioc_value": "196.75.227.199:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.meterpreter",
            "malware_alias": null,
            "malware_printable": "Meterpreter",
            "first_seen_utc": "2026-06-06 06:01:07",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "36903,c2,censys,metasploit",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1823702": [
        {
            "ioc_value": "168.245.203.112:3790",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.meterpreter",
            "malware_alias": null,
            "malware_printable": "Meterpreter",
            "first_seen_utc": "2026-06-06 06:01:07",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "58580,c2,censys,metasploit",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1823827": [
        {
            "ioc_value": "groupewadesecurity.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823828": [
        {
            "ioc_value": "saludmasculina-mx.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823829": [
        {
            "ioc_value": "sihat-alrajul-ar.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823830": [
        {
            "ioc_value": "salud-masculina-mex.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823831": [
        {
            "ioc_value": "sihat-alrajul-bro.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823832": [
        {
            "ioc_value": "sihat-alrajul-bf.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823833": [
        {
            "ioc_value": "salud-masculina-mexic.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823834": [
        {
            "ioc_value": "sihat-alrajul-poc.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823835": [
        {
            "ioc_value": "reclaimremedy.vip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823836": [
        {
            "ioc_value": "insightinnovation.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823837": [
        {
            "ioc_value": "cipherinsight.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823838": [
        {
            "ioc_value": "sihat-alrajul-go.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823839": [
        {
            "ioc_value": "sihat-alrajul-iq.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823840": [
        {
            "ioc_value": "sihat-alrajul-aro.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823841": [
        {
            "ioc_value": "sihat-alrajul-ira.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823843": [
        {
            "ioc_value": "sihat-alrajul-pou.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823845": [
        {
            "ioc_value": "labibsyagakport.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823842": [
        {
            "ioc_value": "sihat-alrajul-qe.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823844": [
        {
            "ioc_value": "refundrescue.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823846": [
        {
            "ioc_value": "koloosdas.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-06-06 06:00:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1823864": [
        {
            "ioc_value": "154.88.96.62:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 06:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823865": [
        {
            "ioc_value": "154.88.96.61:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 06:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823862": [
        {
            "ioc_value": "38.47.226.41:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 06:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823863": [
        {
            "ioc_value": "154.88.97.49:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 06:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822857": [
        {
            "ioc_value": "https://diranda.lol/api/v1/status",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:00:17",
            "last_seen_utc": "2026-06-05 17:08:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116698122012104762",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822866": [
        {
            "ioc_value": "https://captcha-checkpoint.top/o",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:00:17",
            "last_seen_utc": "2026-06-06 02:10:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116698369532004658",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822867": [
        {
            "ioc_value": "captcha-checkpoint.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-06 06:00:17",
            "last_seen_utc": "2026-06-06 02:10:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116698369532004658",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822868": [
        {
            "ioc_value": "https://copperbeacon.top/health/session-deploy.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-06 06:00:16",
            "last_seen_utc": "2026-06-05 21:11:55",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116698370694113067",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822872": [
        {
            "ioc_value": "http://196.251.107.104/Psd8eZaW/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-06 06:00:16",
            "last_seen_utc": "2026-06-06 16:10:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "282234,amadey,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1822873": [
        {
            "ioc_value": "http://196.251.107.104/Psd8eZaW/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-06 06:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "282234,amadey,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1822879": [
        {
            "ioc_value": "secure.therunningink.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2026-06-06 06:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116698601506821123",
            "tags": "SocGholish",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822884": [
        {
            "ioc_value": "a4225ad00fbe2123e27d25bca0988586164e2467762d2d1db304300b2d24d04b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 06:00:15",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/a4225ad00fbe2123e27d25bca0988586164e2467762d2d1db304300b2d24d04b",
            "tags": "clickfix,llvm-mcjit-loader,webdav-rundll32",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1822880": [
        {
            "ioc_value": "temp.logicfrontier.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 06:00:14",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/a4225ad00fbe2123e27d25bca0988586164e2467762d2d1db304300b2d24d04b",
            "tags": "clickfix,llvm-mcjit-loader,webdav-rundll32",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1822885": [
        {
            "ioc_value": "ea2bb5ebd6482e87f25949e792c976dfeaddc1bcb36e2c62476854e4aa22d3a7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 06:00:13",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/a4225ad00fbe2123e27d25bca0988586164e2467762d2d1db304300b2d24d04b",
            "tags": "clickfix,llvm-mcjit-loader,webdav-rundll32",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1822886": [
        {
            "ioc_value": "7340167a765d3d005af93fd10dbd6af48abfd50055fd6b8fca987b7c1363e5d4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 06:00:13",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/a4225ad00fbe2123e27d25bca0988586164e2467762d2d1db304300b2d24d04b",
            "tags": "clickfix,llvm-mcjit-loader,webdav-rundll32",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1823861": [
        {
            "ioc_value": "185.102.115.93:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 05:56:41",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c23f672216fc75e637c1b6dd66ee9753996d9d5dc123da23151fb99ba9814011/",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823859": [
        {
            "ioc_value": "212.34.155.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.snappy_client",
            "malware_alias": null,
            "malware_printable": "SnappyClient",
            "first_seen_utc": "2026-06-06 05:54:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/766bcde5ddd3ae6e2758c749539c5c5d83a1f8a642caeb0bc1bc2c76b5004e7a/",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823860": [
        {
            "ioc_value": "45.150.66.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.snappy_client",
            "malware_alias": null,
            "malware_printable": "SnappyClient",
            "first_seen_utc": "2026-06-06 05:54:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/766bcde5ddd3ae6e2758c749539c5c5d83a1f8a642caeb0bc1bc2c76b5004e7a/",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823858": [
        {
            "ioc_value": "mdprzinwo.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.snappy_client",
            "malware_alias": null,
            "malware_printable": "SnappyClient",
            "first_seen_utc": "2026-06-06 05:54:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/766bcde5ddd3ae6e2758c749539c5c5d83a1f8a642caeb0bc1bc2c76b5004e7a/",
            "tags": "SnappyClient",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823857": [
        {
            "ioc_value": "181.214.48.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-06 05:49:26",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/65e1f57be4a1efe7b1193da12707795493ea98a34d4813be912baf1df8d701d1/",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823856": [
        {
            "ioc_value": "gvrrgvn.jamjahani.promo",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 05:41:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823855": [
        {
            "ioc_value": "jamjahani.promo",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 05:36:33",
            "last_seen_utc": "2026-06-06 05:36:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1823853": [
        {
            "ioc_value": "https://pas.sm188star.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-06-06 15:24:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823854": [
        {
            "ioc_value": "pas.sm188star.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-06-06 15:24:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823852": [
        {
            "ioc_value": "kaxofkea.bizbetslot.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 05:17:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823851": [
        {
            "ioc_value": "33aesmo5.bizbetslot.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 05:16:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823850": [
        {
            "ioc_value": "zwbnyop.jamjahani.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 05:02:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823848": [
        {
            "ioc_value": "45.87.53.6:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 05:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823849": [
        {
            "ioc_value": "175.178.117.214:8083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 05:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823847": [
        {
            "ioc_value": "eizgbh.xenicalby6.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 04:55:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823738": [
        {
            "ioc_value": "rmjjmzw.jamjahani.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 04:19:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823737": [
        {
            "ioc_value": "!k!.jamjahani.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 04:19:17",
            "last_seen_utc": "2026-06-06 04:19:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823736": [
        {
            "ioc_value": "zbc7yta5.taktiik.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 04:03:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823735": [
        {
            "ioc_value": "38.47.226.41:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 04:00:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823734": [
        {
            "ioc_value": "45.118.133.200:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 04:00:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823732": [
        {
            "ioc_value": "154.88.96.42:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 04:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823733": [
        {
            "ioc_value": "45.118.133.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 04:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823731": [
        {
            "ioc_value": "154.88.96.52:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 04:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823730": [
        {
            "ioc_value": "101.43.103.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 03:44:58",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823729": [
        {
            "ioc_value": "mltwwtn.jamjahani.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 03:41:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823728": [
        {
            "ioc_value": "jamjahani.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 03:40:46",
            "last_seen_utc": "2026-06-06 03:40:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1823727": [
        {
            "ioc_value": "e6ce6uwg.bingobet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 03:16:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823726": [
        {
            "ioc_value": "q1wm6mf5.bingobet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 03:15:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823725": [
        {
            "ioc_value": "kyxuncq.jamjahani.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 03:03:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823724": [
        {
            "ioc_value": "!k!.jamjahani.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 03:02:08",
            "last_seen_utc": "2026-06-06 15:21:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823722": [
        {
            "ioc_value": "43.224.224.18:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-06 03:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823723": [
        {
            "ioc_value": "45.118.133.200:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 03:00:15",
            "last_seen_utc": "2026-06-06 10:32:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823721": [
        {
            "ioc_value": "154.88.96.48:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 03:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823720": [
        {
            "ioc_value": "gukxgn.yasbet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 02:59:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823719": [
        {
            "ioc_value": "drlycjl.jamjahani.mobi",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 02:24:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823718": [
        {
            "ioc_value": "pjnmfyn.yekbetiran.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 02:14:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823717": [
        {
            "ioc_value": "!k!.yekbetiran.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 02:13:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823716": [
        {
            "ioc_value": "qffjprx.yektbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 02:04:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823715": [
        {
            "ioc_value": "!k!.yektbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 02:04:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823713": [
        {
            "ioc_value": "154.88.96.54:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 02:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823714": [
        {
            "ioc_value": "154.88.96.53:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 02:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823711": [
        {
            "ioc_value": "154.88.97.41:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 02:00:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823712": [
        {
            "ioc_value": "154.88.97.36:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 02:00:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823710": [
        {
            "ioc_value": "154.88.97.62:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 02:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823709": [
        {
            "ioc_value": "fljmkds.venusbet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 01:55:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823708": [
        {
            "ioc_value": "!k!.venusbet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 01:53:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823707": [
        {
            "ioc_value": "!k!.vezaratshart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 01:50:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823706": [
        {
            "ioc_value": "1822jtv8.betwoonuyelik.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 01:17:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823705": [
        {
            "ioc_value": "hwujtlx.dahdahtoys.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 01:17:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823704": [
        {
            "ioc_value": "p6p6cxqw.betwoonuyelik.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 01:15:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823703": [
        {
            "ioc_value": "!k!.dahdahtoys.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 01:12:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823696": [
        {
            "ioc_value": "154.88.97.34:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 01:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823695": [
        {
            "ioc_value": "154.88.97.57:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-06 01:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823694": [
        {
            "ioc_value": "qyqetw.yasbetapp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 00:55:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823693": [
        {
            "ioc_value": "jbwhmuq.i90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 00:34:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823692": [
        {
            "ioc_value": "!k!.i90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 00:33:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823691": [
        {
            "ioc_value": "aknkoyw.homa.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 00:24:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823690": [
        {
            "ioc_value": "!k!.homa.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-06 00:23:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823689": [
        {
            "ioc_value": "43.230.162.44:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-06 00:00:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823687": [
        {
            "ioc_value": "43.230.162.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-06 00:00:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823688": [
        {
            "ioc_value": "43.230.162.44:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-06 00:00:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823686": [
        {
            "ioc_value": "107.175.149.62:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 00:00:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823685": [
        {
            "ioc_value": "gcwsnip.hokm.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 23:45:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823684": [
        {
            "ioc_value": "wp0ljlux.betwana.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 23:15:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823683": [
        {
            "ioc_value": "gmtzkxm.hit4bet1.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 23:07:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823682": [
        {
            "ioc_value": "6go1tq9f.takbet90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 23:03:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823680": [
        {
            "ioc_value": "39.106.83.18:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 23:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823681": [
        {
            "ioc_value": "154.36.164.157:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 23:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823677": [
        {
            "ioc_value": "154.88.98.50:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 23:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823678": [
        {
            "ioc_value": "149.104.29.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 23:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823679": [
        {
            "ioc_value": "39.106.83.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 23:00:14",
            "last_seen_utc": "2026-06-06 10:32:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823676": [
        {
            "ioc_value": "lulfav.bet404farsi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 22:58:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823675": [
        {
            "ioc_value": "vctiae.bet360pro.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 22:45:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823674": [
        {
            "ioc_value": "nahcjeo.hezarfencrash.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 22:27:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823672": [
        {
            "ioc_value": "149.104.29.125:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 22:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823673": [
        {
            "ioc_value": "39.106.83.18:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 22:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823669": [
        {
            "ioc_value": "korpihy.herz-frank.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 21:49:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823664": [
        {
            "ioc_value": "mjdkxzn7.betvolleyball.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 21:15:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823663": [
        {
            "ioc_value": "w5x39ami.betvolleyball.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 21:14:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1823662": [
        {
            "ioc_value": "tbbhdjx.golfbetpro.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 21:11:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823661": [
        {
            "ioc_value": "149.104.29.125:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 21:00:16",
            "last_seen_utc": "2026-06-06 10:32:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823659": [
        {
            "ioc_value": "154.88.98.51:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 21:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823660": [
        {
            "ioc_value": "85.217.247.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-05 21:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823658": [
        {
            "ioc_value": "154.88.98.55:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 21:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823657": [
        {
            "ioc_value": "nmnntl.bet303casino.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 20:44:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823656": [
        {
            "ioc_value": "zdxibl.bet212.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 20:34:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823655": [
        {
            "ioc_value": "duizlfe.funbet24.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 20:33:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823654": [
        {
            "ioc_value": "ldgssv.bazipoop.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 20:29:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823649": [
        {
            "ioc_value": "154.88.98.52:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 20:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823647": [
        {
            "ioc_value": "154.88.98.54:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 20:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823648": [
        {
            "ioc_value": "154.88.98.53:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 20:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823646": [
        {
            "ioc_value": "154.88.98.61:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 20:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823645": [
        {
            "ioc_value": "bwqzszo.football2026.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 19:53:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823644": [
        {
            "ioc_value": "87.107.191.39:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 19:45:55",
            "last_seen_utc": "2026-06-06 15:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823643": [
        {
            "ioc_value": "wntgjbu.footbalbet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 19:45:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1823642": [
        {
            "ioc_value": "ns2.newchatsits.ir",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 19:45:19",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823641": [
        {
            "ioc_value": "ns1.newchatsits.ir",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 19:45:18",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823640": [
        {
            "ioc_value": "62.109.19.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-05 19:44:53",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823639": [
        {
            "ioc_value": "207.174.2.85:7997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-05 19:43:56",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823638": [
        {
            "ioc_value": "182.23.2.163:12364",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 19:43:38",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823637": [
        {
            "ioc_value": "zttxgpqq.jacksorbetter.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 19:14:24",
            "last_seen_utc": "2026-06-05 19:14:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822921": [
        {
            "ioc_value": "qavsqox.footbal90bet.app",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 19:11:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822915": [
        {
            "ioc_value": "154.88.98.56:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 19:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822913": [
        {
            "ioc_value": "154.88.98.58:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 19:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822914": [
        {
            "ioc_value": "154.88.98.57:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 19:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822912": [
        {
            "ioc_value": "wisvfr.basketballiran.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 18:28:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822911": [
        {
            "ioc_value": "udqmerf.fibi-ireland.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 18:28:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822910": [
        {
            "ioc_value": "wrersk.ar888starz.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 18:17:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822909": [
        {
            "ioc_value": "onoizuz.fibi-ireland.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 18:11:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822908": [
        {
            "ioc_value": "o2w2806g.tagat120art.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 18:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822906": [
        {
            "ioc_value": "154.88.98.60:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 18:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822907": [
        {
            "ioc_value": "154.88.98.59:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 18:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822905": [
        {
            "ioc_value": "154.88.98.62:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 18:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822887": [
        {
            "ioc_value": "ytmjwql.eurothrombosis2018.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 17:28:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822883": [
        {
            "ioc_value": "1v55nk51.irantennis.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 17:13:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822882": [
        {
            "ioc_value": "y7o5phj2.irantennis.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 17:13:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822881": [
        {
            "ioc_value": "irantennis.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 17:13:33",
            "last_seen_utc": "2026-06-05 17:14:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,MacOS",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822878": [
        {
            "ioc_value": "154.88.99.34:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 17:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822876": [
        {
            "ioc_value": "154.88.99.36:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 17:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822877": [
        {
            "ioc_value": "154.88.99.35:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 17:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822875": [
        {
            "ioc_value": "154.88.99.38:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 17:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822874": [
        {
            "ioc_value": "154.88.99.44:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 17:00:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822871": [
        {
            "ioc_value": "xcaejii.enobahis.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 16:50:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822870": [
        {
            "ioc_value": "mmhaqx.sigari.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 16:21:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822869": [
        {
            "ioc_value": "trlclzb.enfejar.game",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 16:11:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822864": [
        {
            "ioc_value": "154.88.99.40:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 16:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822865": [
        {
            "ioc_value": "154.88.99.39:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 16:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822863": [
        {
            "ioc_value": "154.88.99.41:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 16:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822862": [
        {
            "ioc_value": "154.88.99.42:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 16:00:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822861": [
        {
            "ioc_value": "medicosacimadomercado.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.strelastealer",
            "malware_alias": null,
            "malware_printable": "StrelaStealer",
            "first_seen_utc": "2026-06-05 15:39:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "StrelaStealer",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822860": [
        {
            "ioc_value": "dqgfigs.enfejarbazii.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 15:32:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822859": [
        {
            "ioc_value": "1djqvowq.iaap2019.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 15:14:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822858": [
        {
            "ioc_value": "nsz2gpgw.iaap2019.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 15:13:07",
            "last_seen_utc": "2026-06-05 15:13:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822855": [
        {
            "ioc_value": "154.88.99.45:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 15:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822856": [
        {
            "ioc_value": "154.88.99.43:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 15:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822853": [
        {
            "ioc_value": "154.88.99.53:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 15:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822854": [
        {
            "ioc_value": "154.88.99.46:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 15:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822852": [
        {
            "ioc_value": "bdbxwze.electriccrash.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 14:54:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822851": [
        {
            "ioc_value": "!z!.electriccrash.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 14:53:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822850": [
        {
            "ioc_value": "ghuctqf.ef90bet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 14:47:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822849": [
        {
            "ioc_value": "!z!.ef90bet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 14:43:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822848": [
        {
            "ioc_value": "!z!.doobixbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 14:42:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822847": [
        {
            "ioc_value": "huyndo.shirbetfarsi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 14:20:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822846": [
        {
            "ioc_value": "zzvfyei.dahdahtoys.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 14:08:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822845": [
        {
            "ioc_value": "!z!.dahdahtoys.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 14:03:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822842": [
        {
            "ioc_value": "https://pas.evosm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 14:00:31",
            "last_seen_utc": "2026-06-06 04:24:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822843": [
        {
            "ioc_value": "pas.canamrent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 14:00:31",
            "last_seen_utc": "2026-06-06 15:24:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822844": [
        {
            "ioc_value": "https://pas.canamrent.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 14:00:31",
            "last_seen_utc": "2026-06-06 15:24:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822841": [
        {
            "ioc_value": "pas.evosm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 14:00:30",
            "last_seen_utc": "2026-06-06 04:24:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822839": [
        {
            "ioc_value": "154.88.99.48:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 14:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822840": [
        {
            "ioc_value": "154.88.99.47:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 14:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822838": [
        {
            "ioc_value": "154.88.99.49:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 14:00:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822837": [
        {
            "ioc_value": "154.88.99.50:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 14:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822836": [
        {
            "ioc_value": "usetlnl.volleyball.vip",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 13:54:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822835": [
        {
            "ioc_value": "mnejbrs.volleyball.vin",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 13:44:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822834": [
        {
            "ioc_value": "volleyball.vin",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 13:43:51",
            "last_seen_utc": "2026-06-05 13:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822828": [
        {
            "ioc_value": "torh3.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 13:29:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "duckdns,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822829": [
        {
            "ioc_value": "www.torh1.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 13:29:18",
            "last_seen_utc": "2026-06-05 13:19:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "duckdns,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822830": [
        {
            "ioc_value": "book.runds.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 13:29:17",
            "last_seen_utc": "2026-06-05 13:19:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "duckdns,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822831": [
        {
            "ioc_value": "rolex22.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 13:29:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "duckdns,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822832": [
        {
            "ioc_value": "ww6.runds.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 13:29:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "duckdns,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822833": [
        {
            "ioc_value": "mobile.runds.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 13:29:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "duckdns,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822827": [
        {
            "ioc_value": "pacsuhw1.pishbini90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 13:14:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822823": [
        {
            "ioc_value": "1.kurama.ltd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 13:13:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "botnetdomain",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822826": [
        {
            "ioc_value": "xee13c9a.pishbini90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 13:12:49",
            "last_seen_utc": "2026-06-05 13:12:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822825": [
        {
            "ioc_value": "ptrpzfj.volleyball.poker",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 13:10:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822824": [
        {
            "ioc_value": "volleyball.poker",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 13:09:36",
            "last_seen_utc": "2026-06-05 13:09:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822807": [
        {
            "ioc_value": "https://diranda.lol/file.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-05 13:03:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822808": [
        {
            "ioc_value": "diranda.lol",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-05 13:03:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822809": [
        {
            "ioc_value": "https://diranda.lol/api/v1/session",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-05 13:03:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822810": [
        {
            "ioc_value": "https://diranda.lol/api/v1/verify",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-05 13:03:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822811": [
        {
            "ioc_value": "https://copperbeacon.top/health/public-layout",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-05 13:03:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116697421034376921",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822812": [
        {
            "ioc_value": "copperbeacon.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-05 13:03:52",
            "last_seen_utc": "2026-06-05 12:08:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116697421034376921",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822813": [
        {
            "ioc_value": "https://copperbeacon.top/health/signup-module.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-05 13:03:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116697421034376921",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822821": [
        {
            "ioc_value": "cc.etherstress.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 13:03:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cnc,mirai,stresser",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822822": [
        {
            "ioc_value": "owps0tha.staffbulldesign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 13:02:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822819": [
        {
            "ioc_value": "154.88.99.52:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 13:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822820": [
        {
            "ioc_value": "154.88.99.51:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 13:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822818": [
        {
            "ioc_value": "154.88.99.57:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 13:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822817": [
        {
            "ioc_value": "wgzufvo.volleyball.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 12:31:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822816": [
        {
            "ioc_value": "volleyball.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 12:31:20",
            "last_seen_utc": "2026-06-05 12:31:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822815": [
        {
            "ioc_value": "bnhxiy.yasbetapp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 12:16:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822814": [
        {
            "ioc_value": "www.verkeersschoolsociety.nl",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-05 12:10:22",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6e3b544864d8a79ae528b6acd91bbbfc1c90bf7af52174a4c05c464ca32da82e/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822806": [
        {
            "ioc_value": "154.88.99.54:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 12:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822804": [
        {
            "ioc_value": "154.88.99.56:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 12:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822805": [
        {
            "ioc_value": "154.88.99.55:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 12:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822803": [
        {
            "ioc_value": "204.10.160.182:6025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "jar.strrat",
            "malware_alias": null,
            "malware_printable": "STRRAT",
            "first_seen_utc": "2026-06-05 12:00:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "STRRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822802": [
        {
            "ioc_value": "shgaxiz.volleyball.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 11:52:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822801": [
        {
            "ioc_value": "!z!.volleyball.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 11:52:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822800": [
        {
            "ioc_value": "volleyball.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 11:52:05",
            "last_seen_utc": "2026-06-05 11:52:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822799": [
        {
            "ioc_value": "137.220.133.57:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-05 11:40:49",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e02635368a39ba90646968a41cce5e827e6b88dc4d5c048d26434c1571539135/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822796": [
        {
            "ioc_value": "118.107.9.185:1115",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-05 11:40:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c9460a533e8f214768cbfaa68c486f454083be425e41e0df63777dd41281194c/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822797": [
        {
            "ioc_value": "137.220.133.57:433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-05 11:40:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e02635368a39ba90646968a41cce5e827e6b88dc4d5c048d26434c1571539135/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822798": [
        {
            "ioc_value": "137.220.133.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-05 11:40:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e02635368a39ba90646968a41cce5e827e6b88dc4d5c048d26434c1571539135/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822795": [
        {
            "ioc_value": "118.107.9.185:1113",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-05 11:40:47",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c9460a533e8f214768cbfaa68c486f454083be425e41e0df63777dd41281194c/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822794": [
        {
            "ioc_value": "vvlainw.vip.tennis",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 11:14:46",
            "last_seen_utc": "2026-06-05 11:14:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822793": [
        {
            "ioc_value": "kdk8z7k4.i90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 11:12:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822792": [
        {
            "ioc_value": "gh6fn4zq.i90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 11:12:34",
            "last_seen_utc": "2026-06-06 00:33:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822791": [
        {
            "ioc_value": "mudeurb.vezaratshart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 11:08:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822790": [
        {
            "ioc_value": "!z!.vezaratshart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 11:03:43",
            "last_seen_utc": "2026-06-06 01:51:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822787": [
        {
            "ioc_value": "https://rik.evosm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 11:00:31",
            "last_seen_utc": "2026-06-05 13:24:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822788": [
        {
            "ioc_value": "rik.canamrent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 11:00:31",
            "last_seen_utc": "2026-06-05 13:24:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822789": [
        {
            "ioc_value": "https://rik.canamrent.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 11:00:31",
            "last_seen_utc": "2026-06-05 13:24:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822786": [
        {
            "ioc_value": "rik.evosm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 11:00:30",
            "last_seen_utc": "2026-06-05 13:24:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822785": [
        {
            "ioc_value": "154.88.99.58:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 11:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822784": [
        {
            "ioc_value": "154.88.99.59:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 11:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822783": [
        {
            "ioc_value": "154.88.99.61:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 11:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822782": [
        {
            "ioc_value": "18.176.224.100:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 11:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822781": [
        {
            "ioc_value": "zltxdjx.venusbet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 10:58:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822780": [
        {
            "ioc_value": "!z!.venusbet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 10:57:44",
            "last_seen_utc": "2026-06-06 01:54:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822779": [
        {
            "ioc_value": "ffrpwns.vbetirani.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 10:20:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822778": [
        {
            "ioc_value": "!z!.vbetirani.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 10:19:16",
            "last_seen_utc": "2026-06-05 10:19:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822777": [
        {
            "ioc_value": "ukmcha.yasbet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 10:15:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822776": [
        {
            "ioc_value": "https://devsolutionsfinder.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 10:15:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1822775": [
        {
            "ioc_value": "154.88.99.62:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 10:00:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822774": [
        {
            "ioc_value": "124.222.65.141:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 10:00:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822773": [
        {
            "ioc_value": "159.138.167.119:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 10:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822772": [
        {
            "ioc_value": "119.45.166.6:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 09:46:05",
            "last_seen_utc": "2026-06-06 15:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822771": [
        {
            "ioc_value": "64.94.85.14:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-05 09:45:27",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822770": [
        {
            "ioc_value": "5.249.160.112:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 09:45:20",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822769": [
        {
            "ioc_value": "195.26.86.134:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 09:44:00",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822768": [
        {
            "ioc_value": "193.149.190.156:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 09:43:56",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822767": [
        {
            "ioc_value": "182.23.2.163:58222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 09:43:46",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822765": [
        {
            "ioc_value": "182.23.2.163:10401",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 09:43:44",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822766": [
        {
            "ioc_value": "182.23.2.163:11742",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 09:43:44",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822764": [
        {
            "ioc_value": "158.247.194.144:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-05 09:43:29",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822763": [
        {
            "ioc_value": "nekdncv.usa2026.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 09:41:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822762": [
        {
            "ioc_value": "!z!.usa2026.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 09:40:43",
            "last_seen_utc": "2026-06-05 09:40:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822761": [
        {
            "ioc_value": "edfwndp0.chloroquineser.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 09:12:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822760": [
        {
            "ioc_value": "b25s30n3.chloroquineser.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 09:11:51",
            "last_seen_utc": "2026-06-06 15:24:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822759": [
        {
            "ioc_value": "dnmjqvy.trmegapari.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 09:07:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822758": [
        {
            "ioc_value": "!z!.trmegapari.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 09:02:11",
            "last_seen_utc": "2026-06-05 09:03:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822757": [
        {
            "ioc_value": "101.34.249.170:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 09:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822756": [
        {
            "ioc_value": "118.195.197.228:6651",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 09:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822754": [
        {
            "ioc_value": "192.210.215.182:3308",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 09:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822755": [
        {
            "ioc_value": "154.88.96.38:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 09:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822753": [
        {
            "ioc_value": "3.36.117.91:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 09:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822744": [
        {
            "ioc_value": "giga.miraibotnet.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:27:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822745": [
        {
            "ioc_value": "rep.miraibotnet.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:27:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822746": [
        {
            "ioc_value": "srv.miraibotnet.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:27:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822752": [
        {
            "ioc_value": "bagkqzj.zeppelin.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 08:24:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822751": [
        {
            "ioc_value": "!z!.zeppelin.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 08:23:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822750": [
        {
            "ioc_value": "zeppelin.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 08:23:40",
            "last_seen_utc": "2026-06-05 08:23:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822749": [
        {
            "ioc_value": "kgebll.xenicalby6.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 08:15:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822748": [
        {
            "ioc_value": "tjvdbbc.yektbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 08:14:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822747": [
        {
            "ioc_value": "!z!.yektbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 08:13:43",
            "last_seen_utc": "2026-06-06 02:03:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822739": [
        {
            "ioc_value": "bins.oceanic-node.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:10:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822740": [
        {
            "ioc_value": "meow.oceanic-node.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:10:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822741": [
        {
            "ioc_value": "mewo.oceanic-node.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:10:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822742": [
        {
            "ioc_value": "retard.oceanic-node.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:10:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822743": [
        {
            "ioc_value": "srv.oceanic-node.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:10:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822719": [
        {
            "ioc_value": "https://zadelom.ru/auth/auth",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.berbew",
            "malware_alias": null,
            "malware_printable": "Berbew",
            "first_seen_utc": "2026-06-05 08:06:46",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "berbew",
            "anonymous": "0",
            "reporter": "ninjacatcher"
        }
    ],
    "1822724": [
        {
            "ioc_value": "smart.abuse.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:06:45",
            "last_seen_utc": "2026-06-05 08:04:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "botnetdomain,domain,gorilla,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822730": [
        {
            "ioc_value": "8.145.40.223:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 08:06:45",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "VShell",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1822731": [
        {
            "ioc_value": "130.94.33.140:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 08:06:44",
            "last_seen_utc": "2026-06-06 13:00:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "VShell",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1822733": [
        {
            "ioc_value": "154.36.188.239:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 08:06:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1822734": [
        {
            "ioc_value": "tvt.abuse.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:06:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "botnetdomain,domain,gorilla",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822735": [
        {
            "ioc_value": "boom.abuse.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:06:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "botnetdomain,domain,gorilla",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822736": [
        {
            "ioc_value": "abusing.abuse.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:06:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "botnetdomain,domain,gorilla",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822737": [
        {
            "ioc_value": "fsocietyhackattack.botlesscucks.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:06:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "botnetdomain,cuckbot,domain,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822738": [
        {
            "ioc_value": "hackattackkaboom.botlesscucks.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 08:06:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "botnetdomain,cuckbot,domain,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822732": [
        {
            "ioc_value": "cpteijd.yekbetiran.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 08:04:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822729": [
        {
            "ioc_value": "!z!.yekbetiran.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 08:03:45",
            "last_seen_utc": "2026-06-06 02:14:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822728": [
        {
            "ioc_value": "kazwbt9n.2026.futbol",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 08:02:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822727": [
        {
            "ioc_value": "lgwzmtt.yek1bet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 07:59:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822726": [
        {
            "ioc_value": "!z!.yek1bet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 07:59:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822725": [
        {
            "ioc_value": "yek1bet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 07:59:04",
            "last_seen_utc": "2026-06-05 08:00:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822723": [
        {
            "ioc_value": "afdaqyu.yasbet.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 07:21:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822722": [
        {
            "ioc_value": "yasbet.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 07:21:03",
            "last_seen_utc": "2026-06-05 07:21:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822721": [
        {
            "ioc_value": "xcpvjq6r.cerocarey.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 07:11:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822720": [
        {
            "ioc_value": "wyveypsx.cerocarey.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 07:11:20",
            "last_seen_utc": "2026-06-06 13:24:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822714": [
        {
            "ioc_value": "open-claw.co.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 07:03:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://threatfox.abuse.ch/ioc/1822127/",
            "tags": "clickfix,infostealer,stealer",
            "anonymous": "0",
            "reporter": "ninjacatcher"
        }
    ],
    "1822715": [
        {
            "ioc_value": "clawd-setup.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 07:03:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://urlscan.io/result/019e968d-1b26-752a-a0e0-67e699a45a9e/",
            "tags": "clickfix,infostealer,stealer",
            "anonymous": "0",
            "reporter": "ninjacatcher"
        }
    ],
    "1822718": [
        {
            "ioc_value": "79.133.56.151:18084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 07:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822717": [
        {
            "ioc_value": "204.194.49.142:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 07:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822716": [
        {
            "ioc_value": "204.194.49.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 07:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822713": [
        {
            "ioc_value": "tqdtntx.hotbet90.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 06:43:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822712": [
        {
            "ioc_value": "hotbet90.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 06:42:51",
            "last_seen_utc": "2026-06-05 06:42:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822711": [
        {
            "ioc_value": "xeanui.x50wheel.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 06:34:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822702": [
        {
            "ioc_value": "zyrec2.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 06:11:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822703": [
        {
            "ioc_value": "download.logltech.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 06:11:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822704": [
        {
            "ioc_value": "jaamdesign.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 06:11:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822705": [
        {
            "ioc_value": "stoplooking1.botlesscucks.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 06:11:08",
            "last_seen_utc": "2026-06-05 08:06:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822706": [
        {
            "ioc_value": "stoplooking2.botlesscucks.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 06:11:07",
            "last_seen_utc": "2026-06-05 08:06:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822707": [
        {
            "ioc_value": "dxhook.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 06:11:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822708": [
        {
            "ioc_value": "fer1.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 06:11:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822710": [
        {
            "ioc_value": "dlkcsdq.hotbet90app.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 06:04:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822709": [
        {
            "ioc_value": "!z!.hotbet90app.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 06:03:40",
            "last_seen_utc": "2026-06-05 06:03:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822701": [
        {
            "ioc_value": "31.76.87.101:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-06-05 06:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "stealc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822700": [
        {
            "ioc_value": "111.229.188.75:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 06:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822699": [
        {
            "ioc_value": "eehjqhe.homa.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 05:53:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822698": [
        {
            "ioc_value": "!z!.homa.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 05:53:19",
            "last_seen_utc": "2026-06-06 00:23:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822697": [
        {
            "ioc_value": "185.91.127.173:38014",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-06-05 05:46:40",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "MasonRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822677": [
        {
            "ioc_value": "111.55.74.100:52721",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:46:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822678": [
        {
            "ioc_value": "110.38.254.160:50664",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:46:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822679": [
        {
            "ioc_value": "223.123.42.237:53019",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:46:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822680": [
        {
            "ioc_value": "153.117.37.25:36970",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:46:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822681": [
        {
            "ioc_value": "202.70.139.56:60896",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:46:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822682": [
        {
            "ioc_value": "189.174.142.184:56193",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822683": [
        {
            "ioc_value": "72.255.18.214:36405",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822684": [
        {
            "ioc_value": "124.229.33.220:50854",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822685": [
        {
            "ioc_value": "223.123.35.47:54367",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822686": [
        {
            "ioc_value": "105.186.143.24:59469",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822687": [
        {
            "ioc_value": "103.176.16.78:51683",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822688": [
        {
            "ioc_value": "124.29.194.26:42356",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822689": [
        {
            "ioc_value": "95.82.118.182:44093",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822690": [
        {
            "ioc_value": "58.65.216.9:58090",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822691": [
        {
            "ioc_value": "103.181.160.22:37187",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822692": [
        {
            "ioc_value": "110.38.218.245:48087",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822693": [
        {
            "ioc_value": "119.189.212.129:44218",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822694": [
        {
            "ioc_value": "202.9.122.145:56390",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822695": [
        {
            "ioc_value": "153.117.32.174:49040",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-05 05:45:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "mozi,ngnix,p2p",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822696": [
        {
            "ioc_value": "185.91.127.173:24959",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-06-05 05:45:49",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "XWorm",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822676": [
        {
            "ioc_value": "103.73.161.238:6667",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-05 05:20:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822663": [
        {
            "ioc_value": "anvil-89.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-06-05 05:19:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "tea_not_stirred"
        }
    ],
    "1822664": [
        {
            "ioc_value": "bloomglow9.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-06-05 05:19:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "tea_not_stirred"
        }
    ],
    "1822665": [
        {
            "ioc_value": "alragaa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-06-05 05:19:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "tea_not_stirred"
        }
    ],
    "1822666": [
        {
            "ioc_value": "data-hub-2312.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-06-05 05:19:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "tea_not_stirred"
        }
    ],
    "1822667": [
        {
            "ioc_value": "167.71.70.184:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-06-05 05:19:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "tea_not_stirred"
        }
    ],
    "1822668": [
        {
            "ioc_value": "c2b96ba6140ed15d46a7956ab2e590a39c164197",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-06-05 05:19:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "tea_not_stirred"
        }
    ],
    "1822669": [
        {
            "ioc_value": "8a22239f95067a5a5a9520bfafa4c4b71b7cf828",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-06-05 05:19:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "tea_not_stirred"
        }
    ],
    "1822670": [
        {
            "ioc_value": "85abca56aea793d8a45ddb747c4c4e7cf1ab21aa",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-06-05 05:19:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "tea_not_stirred"
        }
    ],
    "1822519": [
        {
            "ioc_value": "https://shadowcompass.top/public/acl-partial",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-05 05:19:25",
            "last_seen_utc": "2026-06-05 00:10:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116693416680076961",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822520": [
        {
            "ioc_value": "shadowcompass.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-05 05:19:25",
            "last_seen_utc": "2026-06-05 00:10:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116693416680076961",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822521": [
        {
            "ioc_value": "https://shadowcompass.top/public/token-json.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-06-05 05:19:24",
            "last_seen_utc": "2026-06-05 00:10:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116693416680076961",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822533": [
        {
            "ioc_value": "goolge.mobi",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 05:19:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clearfake,clickfix",
            "anonymous": "0",
            "reporter": "tanner"
        }
    ],
    "1822534": [
        {
            "ioc_value": "searggend.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 05:19:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "tanner"
        }
    ],
    "1822537": [
        {
            "ioc_value": "91.92.42.203:5544",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 05:19:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "dropper,nc",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822541": [
        {
            "ioc_value": "youareall.botlesscucks.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 05:19:21",
            "last_seen_utc": "2026-06-05 08:06:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822542": [
        {
            "ioc_value": "musika.botlesscucks.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 05:19:20",
            "last_seen_utc": "2026-06-05 08:06:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822543": [
        {
            "ioc_value": "happytugsmassage.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 05:19:20",
            "last_seen_utc": "2026-06-05 06:03:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822544": [
        {
            "ioc_value": "n058152033245.netvigator.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 05:19:19",
            "last_seen_utc": "2026-06-05 06:03:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822545": [
        {
            "ioc_value": "stoplooking.botlesscucks.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 05:19:19",
            "last_seen_utc": "2026-06-05 08:06:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain,mirai",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822555": [
        {
            "ioc_value": "195.181.245.252:9443",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:19",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "cryptojacking,docker-api,miner,payload-host,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822556": [
        {
            "ioc_value": "http://195.181.245.252:9443/xmrig",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:17",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,miner,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822557": [
        {
            "ioc_value": "57.128.171.186:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:17",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "alpine-container,docker-api,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822558": [
        {
            "ioc_value": "104.236.83.40:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-05 05:19:16",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "DigitalOcean,docker-api,dual-role,libredtail-http,Redtail,spreader",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822559": [
        {
            "ioc_value": "220.162.198.142:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-05 05:19:16",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "CN,docker-api,libredtail-http,Redtail,spreader",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822560": [
        {
            "ioc_value": "110.35.80.116:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 05:19:15",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "dropper,Mirai,web-spread",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822561": [
        {
            "ioc_value": "8.229.68.116:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-05 05:19:15",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,reconnaissance",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822563": [
        {
            "ioc_value": "71.6.239.181:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:15",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "bruteforce,postgres",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822562": [
        {
            "ioc_value": "45.156.87.119:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:13",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "bruteforce,postgres",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822564": [
        {
            "ioc_value": "66.240.223.240:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:12",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "multi-pot,postgres,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822565": [
        {
            "ioc_value": "124.90.54.135:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:12",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "bruteforce,CN,postgres",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822566": [
        {
            "ioc_value": "66.132.224.234:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:12",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "bruteforce,postgres",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822567": [
        {
            "ioc_value": "b0e1ae6d73d656b203514f498b59cbcf29f067edf6fbd3803a3de7d21960848d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:11",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "cryptojacking,docker-api,elf,miner,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822572": [
        {
            "ioc_value": "f38504f53f6a25c405cfa272572eb0ededbbb4b9399b8aec1706d5e2b990f1c9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:10",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "cryptojacking,docker-api,elf,miner,moneroocean,truncated,x86_64,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822573": [
        {
            "ioc_value": "92.60.77.99:8888",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:10",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "cryptojacking,docker-api,miner,moneroocean,payload-host,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822574": [
        {
            "ioc_value": "http://92.60.77.99:8888/xmrig-x86",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:09",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,miner,moneroocean,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822575": [
        {
            "ioc_value": "189.110.239.137:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:09",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "alpine-container,docker-api,miner,moneroocean,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822675": [
        {
            "ioc_value": "pqycltd.hokm.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 05:17:55",
            "last_seen_utc": "2026-06-05 23:45:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822546": [
        {
            "ioc_value": "gstatic-node.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-05 05:16:04",
            "last_seen_utc": "2026-06-06 04:41:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "lumma",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822547": [
        {
            "ioc_value": "colomndead.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-05 05:16:04",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "lumma",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822548": [
        {
            "ioc_value": "cloudsaled.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-05 05:16:03",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "lumma",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822549": [
        {
            "ioc_value": "polandgames.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-05 05:16:03",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "lumma",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822550": [
        {
            "ioc_value": "costexcise.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-05 05:16:03",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "lumma",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822551": [
        {
            "ioc_value": "droppicches.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2026-06-05 05:16:02",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "lumma",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822674": [
        {
            "ioc_value": "dev.useimage.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 05:14:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822673": [
        {
            "ioc_value": "f0rfdtvf.canlibahis1xbet.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 05:11:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822672": [
        {
            "ioc_value": "canlibahis1xbet.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 05:11:44",
            "last_seen_utc": "2026-06-06 11:24:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,MacOS",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822671": [
        {
            "ioc_value": "https://steamcommunity.com/profiles/76561198698223785/g75rit",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 05:10:51",
            "last_seen_utc": "2026-06-05 15:07:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/88f5b6c7f618471993adba7fbb008cb8e2cfc5ef811a5971bc6293ba7b921db3/",
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822662": [
        {
            "ioc_value": "107.150.105.91:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 05:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822660": [
        {
            "ioc_value": "154.83.16.73:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 05:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822661": [
        {
            "ioc_value": "47.92.122.207:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 05:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822659": [
        {
            "ioc_value": "ageqour.hit4bet1.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 04:43:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822658": [
        {
            "ioc_value": "!z!.hit4bet1.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 04:42:14",
            "last_seen_utc": "2026-06-05 23:06:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822657": [
        {
            "ioc_value": "vobyslb.hilo.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 04:10:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822656": [
        {
            "ioc_value": "hilo.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 04:07:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822654": [
        {
            "ioc_value": "119.45.166.6:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 04:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822655": [
        {
            "ioc_value": "154.88.96.34:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 04:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822652": [
        {
            "ioc_value": "myofcdr.hezarfencrash.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 03:31:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822651": [
        {
            "ioc_value": "!z!.hezarfencrash.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 03:31:05",
            "last_seen_utc": "2026-06-05 22:27:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822650": [
        {
            "ioc_value": "4q4880m7.bwin90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 03:12:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822649": [
        {
            "ioc_value": "zoqo6w5l.bwin90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 03:10:35",
            "last_seen_utc": "2026-06-05 03:10:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822648": [
        {
            "ioc_value": "88i.jp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-05 03:05:37",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/972c93d7cec662851b13b110d38fb7f70cd87fd1d2ad22799f5b073dedf3c968/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822647": [
        {
            "ioc_value": "3p1x6btm.1xbet90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 03:02:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822646": [
        {
            "ioc_value": "43.224.224.15:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-05 03:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822645": [
        {
            "ioc_value": "43.224.224.20:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-05 03:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822643": [
        {
            "ioc_value": "186.169.71.201:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 03:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822644": [
        {
            "ioc_value": "61.110.5.174:33061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 03:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822642": [
        {
            "ioc_value": "youykxp.herz-frank.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 02:57:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822641": [
        {
            "ioc_value": "!z!.herz-frank.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 02:55:36",
            "last_seen_utc": "2026-06-05 21:49:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822640": [
        {
            "ioc_value": "89.124.78.101:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-05 02:36:02",
            "last_seen_utc": "2026-06-06 16:12:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=89.124.78.101",
            "tags": "Amadey,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822639": [
        {
            "ioc_value": "emwzmsp.hazaratbetapp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 02:21:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822638": [
        {
            "ioc_value": "!z!.hazaratbetapp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 02:20:06",
            "last_seen_utc": "2026-06-05 02:20:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822636": [
        {
            "ioc_value": "106.12.20.75:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 02:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822637": [
        {
            "ioc_value": "216.128.154.222:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 02:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822634": [
        {
            "ioc_value": "demo212.jnirnportaciones.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 01:50:27",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/cb8e562490eeab0ea9cec1c405f832bafa4e4a3aae0dcf56397b4aa36e5b1ca2/",
            "tags": "remcos",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822635": [
        {
            "ioc_value": "metalioncircle.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-05 01:50:27",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e4aa993ec28ad0b38368b9e29c5f714f1791ea771a504b5f84d73d63a14950f9/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822633": [
        {
            "ioc_value": "branleet.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-05 01:50:26",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ba8d38575e15f2a8a3c819d3f2e189acdf9249c99240236c8be4f96d7284530d/",
            "tags": "quasar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822632": [
        {
            "ioc_value": "gxtryif.hattrickbetapp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 01:49:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822631": [
        {
            "ioc_value": "http://gxfsxs.cn:8880/getinstall64",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-05 01:45:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822630": [
        {
            "ioc_value": "http://89.124.78.101/Lsge63sd3/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-05 01:45:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822629": [
        {
            "ioc_value": "89.125.48.85:15649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sectop_rat",
            "malware_alias": "1xxbot,ArechClient",
            "malware_printable": "SectopRAT",
            "first_seen_utc": "2026-06-05 01:45:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Arechclient2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822628": [
        {
            "ioc_value": "54.37.128.55:3041",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 01:45:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822627": [
        {
            "ioc_value": "37.120.206.165:56687",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 01:45:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822626": [
        {
            "ioc_value": "196.251.107.114:24031",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 01:45:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822625": [
        {
            "ioc_value": "172.111.163.172:29810",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 01:45:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822624": [
        {
            "ioc_value": "95.70.188.185:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-05 01:45:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "QuasarRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822623": [
        {
            "ioc_value": "5.35.87.192:10134",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-05 01:45:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "NanoCore,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822622": [
        {
            "ioc_value": "!z!.hattrickbetapp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 01:44:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822621": [
        {
            "ioc_value": "ennovar.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-05 01:40:14",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/193f74b8b5cb8c3e82bf7e33f4ee083522f2a893c7c1b6959d22188e7a5f9319/",
            "tags": "nanocore",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822620": [
        {
            "ioc_value": "gqjz709j.bordoo.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 01:11:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822619": [
        {
            "ioc_value": "b2eqaaqn.bordoo.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 01:10:05",
            "last_seen_utc": "2026-06-06 09:24:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822618": [
        {
            "ioc_value": "hwfbwco.hamvarzesh90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 01:09:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822617": [
        {
            "ioc_value": "!z!.hamvarzesh90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 01:09:04",
            "last_seen_utc": "2026-06-05 01:09:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822616": [
        {
            "ioc_value": "qcwvat.1kickbet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 01:08:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822615": [
        {
            "ioc_value": "qkqxbb.doobixbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 01:01:09",
            "last_seen_utc": "2026-06-05 14:42:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822614": [
        {
            "ioc_value": "106.12.20.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 01:00:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822613": [
        {
            "ioc_value": "5.230.201.36:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 01:00:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822612": [
        {
            "ioc_value": "zyhhuar.golfbetpro.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 00:33:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822611": [
        {
            "ioc_value": "!z!.golfbetpro.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 00:33:33",
            "last_seen_utc": "2026-06-05 21:10:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822610": [
        {
            "ioc_value": "dybkohl.goldenroulette.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 00:26:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822608": [
        {
            "ioc_value": "https://xmm.evosm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 00:24:41",
            "last_seen_utc": "2026-06-05 10:24:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822609": [
        {
            "ioc_value": "xmm.evosm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-05 00:24:41",
            "last_seen_utc": "2026-06-05 10:24:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822607": [
        {
            "ioc_value": "ttowige.goldenroulette.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 00:21:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822606": [
        {
            "ioc_value": "!z!.goldenroulette.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 00:20:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822605": [
        {
            "ioc_value": "goldenroulette.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-05 00:20:13",
            "last_seen_utc": "2026-06-05 00:25:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822603": [
        {
            "ioc_value": "128.90.171.63:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 00:00:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822604": [
        {
            "ioc_value": "180.93.109.34:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 00:00:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822602": [
        {
            "ioc_value": "185.165.36.162:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 00:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822601": [
        {
            "ioc_value": "154.88.97.56:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-05 00:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822600": [
        {
            "ioc_value": "34.202.161.96:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:28",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822599": [
        {
            "ioc_value": "updates.fisgloval.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:07",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822598": [
        {
            "ioc_value": "sqzzsnr.gardune.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 23:44:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822597": [
        {
            "ioc_value": "!z!.gardune.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 23:44:45",
            "last_seen_utc": "2026-06-04 23:45:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822596": [
        {
            "ioc_value": "jzl98lpw.betbuilder.promo",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 23:10:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822595": [
        {
            "ioc_value": "nienzsq.funbet24.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 23:10:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822594": [
        {
            "ioc_value": "betbuilder.promo",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 23:09:43",
            "last_seen_utc": "2026-06-04 23:09:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4June2026,ClearFake,Commandline,MacOS",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822593": [
        {
            "ioc_value": "!z!.funbet24.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 23:09:13",
            "last_seen_utc": "2026-06-05 20:32:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822592": [
        {
            "ioc_value": "154.88.97.61:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 23:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822591": [
        {
            "ioc_value": "154.88.97.60:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 23:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822590": [
        {
            "ioc_value": "154.88.97.44:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 23:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822589": [
        {
            "ioc_value": "iddmpon.football2026.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 22:37:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822588": [
        {
            "ioc_value": "football2026.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 22:33:39",
            "last_seen_utc": "2026-06-05 19:54:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822587": [
        {
            "ioc_value": "hityspe.footbalbet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 22:33:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822586": [
        {
            "ioc_value": "!z!.footbalbet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 22:32:22",
            "last_seen_utc": "2026-06-05 19:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822585": [
        {
            "ioc_value": "https://xmm.canamrent.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 22:00:32",
            "last_seen_utc": "2026-06-05 10:24:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822582": [
        {
            "ioc_value": "xmm.dvlv88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 22:00:31",
            "last_seen_utc": "2026-06-04 23:24:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822583": [
        {
            "ioc_value": "https://xmm.dvlv88.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 22:00:31",
            "last_seen_utc": "2026-06-04 23:24:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822584": [
        {
            "ioc_value": "xmm.canamrent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 22:00:31",
            "last_seen_utc": "2026-06-05 10:24:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822579": [
        {
            "ioc_value": "154.88.97.43:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 22:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822580": [
        {
            "ioc_value": "154.88.97.50:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 22:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822581": [
        {
            "ioc_value": "154.88.97.53:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 22:00:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822578": [
        {
            "ioc_value": "139.224.3.228:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 22:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822577": [
        {
            "ioc_value": "ne6nzi7r.1shart.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 21:59:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822576": [
        {
            "ioc_value": "thnivbk.footbal90bet.app",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 21:57:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822571": [
        {
            "ioc_value": "mhepihh.footbal90bet.app",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 21:23:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822570": [
        {
            "ioc_value": "footbal90bet.app",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 21:22:53",
            "last_seen_utc": "2026-06-05 19:06:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822569": [
        {
            "ioc_value": "7aaxg4kb.betbatis.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 21:10:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822568": [
        {
            "ioc_value": "8vizuy7n.betbatis.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 21:08:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822553": [
        {
            "ioc_value": "154.88.96.55:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 21:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822554": [
        {
            "ioc_value": "154.88.97.40:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 21:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822552": [
        {
            "ioc_value": "207.154.230.229:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-04 21:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822540": [
        {
            "ioc_value": "syjgiug.fibi-ireland.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 20:48:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822539": [
        {
            "ioc_value": "!z!.fibi-ireland.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 20:46:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822538": [
        {
            "ioc_value": "fibi-ireland.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 20:46:47",
            "last_seen_utc": "2026-06-05 18:27:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822536": [
        {
            "ioc_value": "gbueeqa.eurothrombosis2018.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 20:12:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822535": [
        {
            "ioc_value": "!z!.eurothrombosis2018.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 20:11:22",
            "last_seen_utc": "2026-06-04 20:11:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822532": [
        {
            "ioc_value": "bfdibp.dahdahtoys.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 20:00:30",
            "last_seen_utc": "2026-06-06 01:12:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822531": [
        {
            "ioc_value": "154.88.96.33:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 20:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822529": [
        {
            "ioc_value": "129.150.46.86:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 20:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822530": [
        {
            "ioc_value": "181.215.6.77:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 20:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822528": [
        {
            "ioc_value": "182.23.2.163:2046",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-04 19:43:37",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822526": [
        {
            "ioc_value": "163.172.174.237:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822527": [
        {
            "ioc_value": "163.172.174.237:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822525": [
        {
            "ioc_value": "kihjmjx.enobahis.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 19:37:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822524": [
        {
            "ioc_value": "5ay2qa01.electriccrash.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 19:37:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822523": [
        {
            "ioc_value": "!z!.enobahis.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 19:36:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822522": [
        {
            "ioc_value": "enobahis.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 19:36:24",
            "last_seen_utc": "2026-06-05 16:49:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822518": [
        {
            "ioc_value": "6vk8lpd5.betball90.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 19:09:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822517": [
        {
            "ioc_value": "betball90.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 19:08:40",
            "last_seen_utc": "2026-06-04 19:08:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4June2026,ClearFake,Commandline,MacOS",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822516": [
        {
            "ioc_value": "101.37.210.236:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 19:00:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822514": [
        {
            "ioc_value": "101.126.17.8:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 19:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822515": [
        {
            "ioc_value": "185.165.36.162:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-04 19:00:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822513": [
        {
            "ioc_value": "wvvbpwt.enfejar.game",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 18:58:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822512": [
        {
            "ioc_value": "enfejar.game",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 18:57:51",
            "last_seen_utc": "2026-06-05 16:11:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822511": [
        {
            "ioc_value": "89.124.102.122:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 18:25:12",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7a4ededdbc64263754ab17b3d00d3a22c0361f14caa150332524b3332a0aef5d/",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822510": [
        {
            "ioc_value": "jswnqpn.enfejarbazii.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 18:22:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822509": [
        {
            "ioc_value": "!z!.enfejarbazii.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 18:22:21",
            "last_seen_utc": "2026-06-05 15:32:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822508": [
        {
            "ioc_value": "151.243.109.130:9672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-06-04 18:09:30",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d451229055d8e537fd17aafc7babd3170299b1d84da5e60acb0103a0307b3035/",
            "tags": "RAT,SiriusRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822507": [
        {
            "ioc_value": "207.154.230.229:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-04 18:00:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822506": [
        {
            "ioc_value": "207.154.230.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-04 18:00:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822505": [
        {
            "ioc_value": "154.88.98.33:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 18:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822504": [
        {
            "ioc_value": "154.88.98.35:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 18:00:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822456": [
        {
            "ioc_value": "e0af88c9b1278d91a30f651ba3a0e77419c010de662dd6b5b86c1d8415093bc4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:59:01",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "wshrat",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822457": [
        {
            "ioc_value": "213d841404449d68dd9f50c18f7259074c43df2fd5221f0bbd34d2e89b611b73",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:59:01",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "wshrat",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822458": [
        {
            "ioc_value": "7e160f885fe15d7f5b67e3d321c1bd8240a63bb80c8156f604829f0cbadba313",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:59:00",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "wshrat",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822459": [
        {
            "ioc_value": "85dfef0c1b65ee9eb213ea830e0a78d471872e947e1924e90365d29cdeb64c10",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:59:00",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "wshrat",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822460": [
        {
            "ioc_value": "33e78a25233a88b3ac6fd6fbe4b42b0e047a89736fd9b089628ab60b29c4dd9a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:59",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "wshrat",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822461": [
        {
            "ioc_value": "bed1028badee2ade8a8a8edd25aa4c3e70a6beefafbdffd6426e5e467f24eb01",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:59",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "wshrat",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822462": [
        {
            "ioc_value": "0d81cab9f7ca5ac7c201c4917dfc7beee2ea6ea5fd9f0b23e7b088f084cda92c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "wshrat",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822463": [
        {
            "ioc_value": "f22a7dd6e64dafabcbc35cb9d56abc38392e228d7beef8ed2e71727099c31a80",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "wshrat",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822464": [
        {
            "ioc_value": "3922ac9a1588e0d9d5946e71d95d065cc3cf64e776d792b105981e23220d096f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "wshrat",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822467": [
        {
            "ioc_value": "2c1118dd50e8501345eb3d04cd1e07eda41668e7f4379d9958405d3be6bfc45d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:56",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822469": [
        {
            "ioc_value": "150e66931f7218cc66418cd5f80b412343574a7f8c63ecf20e6eab3efaaee1d1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822468": [
        {
            "ioc_value": "2cd017872d8b04b1b36e832f88cc1976492ccf5e8acea19d82af69b2c3cbe47f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822470": [
        {
            "ioc_value": "ddc089db76d5e0419e1f7d3777d2227df3a5cc4b55ea33f9616863cccad3c89f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822471": [
        {
            "ioc_value": "7f5291e4b0b175d29df2221e56185abf4f8fefc839b8cd71792b4e7b20b529e4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822472": [
        {
            "ioc_value": "274d7502c60c6f91a4e4c083cbdf03df21a7f25079c3f92b9587740a1a274de0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822473": [
        {
            "ioc_value": "28472632ef7c1673383da89b54fb15ac46cb36ca0664f2affc7df4d5449ea590",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822474": [
        {
            "ioc_value": "e58184b737ba26eb64c827eb3ce66a6d715903fa8dea340daca3830688f6817e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822475": [
        {
            "ioc_value": "388244583d42ba76bf6270981ddc7459f5d1a9f54acfda4efc1eed475b50a8b7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:51",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822476": [
        {
            "ioc_value": "4fbd2f5b4625fa46b5706748dbb15d3f58fbeda723fc644d0db9174a78cbade1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:51",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822477": [
        {
            "ioc_value": "e8e0df835a3bedb6457ce71f4b114c01c2f4edf1d6332d224921bad5845755b7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:50",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822478": [
        {
            "ioc_value": "5df07f2b3ddae4b24d05926167a4a5968e2748efe744e4600f968be9abd293a2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:50",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822479": [
        {
            "ioc_value": "74adb88130f4864b40118bc65eaf73dc23c31835254bf25465be7c4a76fa2882",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:49",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822480": [
        {
            "ioc_value": "32b84d2fa205ed7c92f85c45bed6a1607004d3d75f939d343913d19f007d0506",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:49",
            "last_seen_utc": "2026-06-04 16:23:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822481": [
        {
            "ioc_value": "4b7be7782072c15a5f8e8672dee3b24864c913742e1a4b552f03aef2ed3b68c9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:49",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822482": [
        {
            "ioc_value": "73b1bd6d589d5b4c752e380a5c9439d06d53d2b8a192fb20a9464662633b7b09",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822483": [
        {
            "ioc_value": "15cad7d81512892146c840e74150f311907f99d2758eaf3977400b9092255c53",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822484": [
        {
            "ioc_value": "381fcd4c4eef057ea509fa27a645fb7138a92317c3b21f5c5425c4cbdca122b8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:47",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/WSHRAT",
            "tags": "RAT,WSHRAT",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1822494": [
        {
            "ioc_value": "https://fluffynoodle.xyz/ash",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 17:58:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "malwareanalayser"
        }
    ],
    "1822503": [
        {
            "ioc_value": "tiixeira.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-04 17:58:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/3591f7f0f6c977fb1a25ec33abbb79f88833e80573b134c717c1672645630a15/",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822502": [
        {
            "ioc_value": "https://tiixeira.lol/m",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-04 17:58:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/3591f7f0f6c977fb1a25ec33abbb79f88833e80573b134c717c1672645630a15/",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822501": [
        {
            "ioc_value": "ldkrhyp.emshab.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 17:51:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822500": [
        {
            "ioc_value": "!z!.emshab.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 17:46:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822499": [
        {
            "ioc_value": "107.150.105.91:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 17:45:22",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822496": [
        {
            "ioc_value": "https://dot.dvlv88.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 17:30:31",
            "last_seen_utc": "2026-06-04 21:24:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822497": [
        {
            "ioc_value": "dot.canamrent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 17:30:31",
            "last_seen_utc": "2026-06-04 21:24:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822498": [
        {
            "ioc_value": "https://dot.canamrent.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 17:30:31",
            "last_seen_utc": "2026-06-04 21:24:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822495": [
        {
            "ioc_value": "dot.dvlv88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 17:30:30",
            "last_seen_utc": "2026-06-04 21:24:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1822493": [
        {
            "ioc_value": "ex7gv4y7.bet90land.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 17:24:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822492": [
        {
            "ioc_value": "jj5czewc.bet90land.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 17:22:27",
            "last_seen_utc": "2026-06-04 17:23:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822491": [
        {
            "ioc_value": "!z!.emroze.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 17:12:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822490": [
        {
            "ioc_value": "atnvjyj.emroze.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 17:12:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822489": [
        {
            "ioc_value": "emroze.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 17:11:16",
            "last_seen_utc": "2026-06-04 17:11:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4June2026,ClearFake,Commandline,Windows",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1822487": [
        {
            "ioc_value": "154.88.97.55:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-04 17:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822488": [
        {
            "ioc_value": "20.64.242.233:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 17:00:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822486": [
        {
            "ioc_value": "tpvggeb.bordino.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 16:50:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822485": [
        {
            "ioc_value": "!z!.bordino.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 16:50:05",
            "last_seen_utc": "2026-06-06 09:17:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822466": [
        {
            "ioc_value": "amcbvlw.bordbet.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 16:19:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822451": [
        {
            "ioc_value": "124.222.155.113:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 15:45:34",
            "last_seen_utc": "2026-06-06 15:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822449": [
        {
            "ioc_value": "mlcos.baidudns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 15:45:18",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822448": [
        {
            "ioc_value": "api1.haedalcompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 15:45:16",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822447": [
        {
            "ioc_value": "1314180598-04zr21qelt.ap-guangzhou.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 15:45:15",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822445": [
        {
            "ioc_value": "!z!.bord90.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 15:39:07",
            "last_seen_utc": "2026-06-06 07:17:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822422": [
        {
            "ioc_value": "!z!.bingobet90.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 14:57:24",
            "last_seen_utc": "2026-06-06 03:16:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822415": [
        {
            "ioc_value": "120.26.208.96:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 14:50:35",
            "last_seen_utc": "2026-06-06 15:45:05",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1822416": [
        {
            "ioc_value": "106.12.20.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 14:50:33",
            "last_seen_utc": "2026-06-05 01:00:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1822400": [
        {
            "ioc_value": "confirmyouarehuman.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-04 14:37:34",
            "last_seen_utc": "2026-06-04 22:58:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116692236684002982",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1822406": [
        {
            "ioc_value": "3i8e3aty.ef90bet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 14:35:20",
            "last_seen_utc": "2026-06-05 14:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822383": [
        {
            "ioc_value": "!z!.betwoonuyelik.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 13:46:51",
            "last_seen_utc": "2026-06-06 01:15:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822377": [
        {
            "ioc_value": "ptapgsl.betwana.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 13:13:00",
            "last_seen_utc": "2026-06-05 23:15:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1822347": [
        {
            "ioc_value": "!z!.betvolleyball.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-04 11:59:51",
            "last_seen_utc": "2026-06-05 21:14:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1822346": [
        {
            "ioc_value": "154.12.86.154:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 11:46:46",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822341": [
        {
            "ioc_value": "https://elo.canamrent.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 11:25:03",
            "last_seen_utc": "2026-06-04 17:24:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822342": [
        {
            "ioc_value": "elo.canamrent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 11:25:03",
            "last_seen_utc": "2026-06-04 17:24:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822339": [
        {
            "ioc_value": "https://elo.dvlv88.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 11:24:50",
            "last_seen_utc": "2026-06-04 17:24:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822340": [
        {
            "ioc_value": "elo.dvlv88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-04 11:24:50",
            "last_seen_utc": "2026-06-04 17:24:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822302": [
        {
            "ioc_value": "91.92.241.80:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:45:43",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822301": [
        {
            "ioc_value": "82.23.246.160:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:45:35",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822299": [
        {
            "ioc_value": "185.72.9.227:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:56",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822298": [
        {
            "ioc_value": "182.23.2.163:49002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-04 09:43:50",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822297": [
        {
            "ioc_value": "172.238.15.96:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-04 09:43:40",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822296": [
        {
            "ioc_value": "156.247.40.190:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:29",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822295": [
        {
            "ioc_value": "155.103.70.198:13408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-04 09:43:28",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822294": [
        {
            "ioc_value": "140.235.16.223:7203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:22",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822223": [
        {
            "ioc_value": "107.150.105.91:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 06:42:46",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822222": [
        {
            "ioc_value": "204.194.49.142:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 06:42:44",
            "last_seen_utc": "2026-06-06 10:32:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822150": [
        {
            "ioc_value": "nvms.miraibotnet.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-04 05:44:34",
            "last_seen_utc": "2026-06-05 08:12:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mirai,mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822151": [
        {
            "ioc_value": "tvt.miraibotnet.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-04 05:44:34",
            "last_seen_utc": "2026-06-05 08:12:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "mirai,mossad",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1822015": [
        {
            "ioc_value": "20.220.29.224:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-03 19:44:00",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822014": [
        {
            "ioc_value": "194.26.192.57:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 19:43:56",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822013": [
        {
            "ioc_value": "182.23.2.163:47984",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-03 19:43:43",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822012": [
        {
            "ioc_value": "172.81.61.20:7997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 19:43:36",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822011": [
        {
            "ioc_value": "168.144.36.228:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 19:43:33",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822010": [
        {
            "ioc_value": "147.124.210.158:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-03 19:43:21",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821845": [
        {
            "ioc_value": "cabaretcorporation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-03 15:23:52",
            "last_seen_utc": "2026-06-06 06:55:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/0a2b733519d04f2b7539935eaa3ae2199c9cbad748b808637fdfeb020f189f04/",
            "tags": "c2,RemusStealer",
            "anonymous": "0",
            "reporter": "burger"
        }
    ],
    "1821846": [
        {
            "ioc_value": "192.159.99.196:4569",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-03 15:23:51",
            "last_seen_utc": "2026-06-04 20:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "dropper,mirai,netcat",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1821847": [
        {
            "ioc_value": "185.244.182.35:14569",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-03 15:23:51",
            "last_seen_utc": "2026-06-04 20:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "dropper,mirai,netcat",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1821848": [
        {
            "ioc_value": "92.42.100.131:4569",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-03 15:23:50",
            "last_seen_utc": "2026-06-04 20:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "dropper,mirai,netcat",
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1821807": [
        {
            "ioc_value": "209.200.246.194:11544",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 11:46:25",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821716": [
        {
            "ioc_value": "82.23.246.160:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:45:37",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821715": [
        {
            "ioc_value": "204.194.50.173:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 09:44:13",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821714": [
        {
            "ioc_value": "182.23.2.163:10399",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-03 09:43:49",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821713": [
        {
            "ioc_value": "156.247.40.190:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:43:30",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821685": [
        {
            "ioc_value": "124.222.155.113:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 08:01:51",
            "last_seen_utc": "2026-06-06 15:45:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1821697": [
        {
            "ioc_value": "118.89.203.103:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 07:57:06",
            "last_seen_utc": "2026-06-06 10:32:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821695": [
        {
            "ioc_value": "118.89.203.103:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 07:56:52",
            "last_seen_utc": "2026-06-06 15:45:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821534": [
        {
            "ioc_value": "23.95.48.221:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-03 05:56:10",
            "last_seen_utc": "2026-06-06 00:00:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "VShell",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1821542": [
        {
            "ioc_value": "154.88.99.33:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-03 05:56:05",
            "last_seen_utc": "2026-06-05 19:00:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "VShell",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1821525": [
        {
            "ioc_value": "8.163.104.36:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 05:55:36",
            "last_seen_utc": "2026-06-06 15:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1821517": [
        {
            "ioc_value": "45.198.224.19:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-02 19:45:08",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821516": [
        {
            "ioc_value": "195.246.230.99:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 19:44:03",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821514": [
        {
            "ioc_value": "155.103.70.198:13407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-02 19:43:27",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821515": [
        {
            "ioc_value": "155.103.71.115:13408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-02 19:43:27",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821220": [
        {
            "ioc_value": "45.76.203.112:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 14:04:11",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/45.76.203.112#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1820884": [
        {
            "ioc_value": "152.42.132.37:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-02 10:45:52",
            "last_seen_utc": "2026-06-06 15:40:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1820885": [
        {
            "ioc_value": "209.38.33.37:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-02 10:45:52",
            "last_seen_utc": "2026-06-06 15:40:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1820869": [
        {
            "ioc_value": "113.44.136.127:8087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-02 09:46:15",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820868": [
        {
            "ioc_value": "192.159.99.21:5080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-02 09:43:59",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820867": [
        {
            "ioc_value": "182.23.2.163:9060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-02 09:43:50",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820866": [
        {
            "ioc_value": "15.204.255.172:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 09:43:26",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820725": [
        {
            "ioc_value": "45.150.34.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-01 19:45:00",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820724": [
        {
            "ioc_value": "182.23.2.163:11166",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-01 19:43:44",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820723": [
        {
            "ioc_value": "178.16.54.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:43",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820722": [
        {
            "ioc_value": "178.16.52.47:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:42",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820602": [
        {
            "ioc_value": "cnc.reaperc2.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-01 15:11:46",
            "last_seen_utc": "2026-06-05 06:03:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://urlhaus.abuse.ch/host/cnc.reaperc2.xyz/",
            "tags": null,
            "anonymous": "0",
            "reporter": "burger"
        }
    ],
    "1820615": [
        {
            "ioc_value": "82.156.224.184:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-01 15:11:43",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820574": [
        {
            "ioc_value": "35.75.218.153:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-01 09:45:05",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820573": [
        {
            "ioc_value": "2.58.56.50:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-01 09:44:09",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820572": [
        {
            "ioc_value": "182.23.2.163:11327",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-01 09:43:48",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820571": [
        {
            "ioc_value": "176.65.139.144:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-01 09:43:44",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820529": [
        {
            "ioc_value": "mub.atvrent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-01 07:24:02",
            "last_seen_utc": "2026-06-06 04:48:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1820506": [
        {
            "ioc_value": "165.22.225.218:5443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 06:44:52",
            "last_seen_utc": "2026-06-06 10:32:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820504": [
        {
            "ioc_value": "38.181.42.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 06:44:48",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820414": [
        {
            "ioc_value": "82.157.52.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:49",
            "last_seen_utc": "2026-06-06 15:45:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820364": [
        {
            "ioc_value": "176.65.149.124.ptr.pfcloud.network",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-01 05:44:44",
            "last_seen_utc": "2026-06-05 06:03:06",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": "mirai",
            "anonymous": "0",
            "reporter": "seckle"
        }
    ],
    "1820430": [
        {
            "ioc_value": "49.233.215.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:38",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820432": [
        {
            "ioc_value": "47.116.211.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:37",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820444": [
        {
            "ioc_value": "47.103.95.85:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:35",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820420": [
        {
            "ioc_value": "176.97.124.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 23:46:09",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820399": [
        {
            "ioc_value": "176.97.124.68:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:46:22",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820398": [
        {
            "ioc_value": "154.38.114.115:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:46:19",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820397": [
        {
            "ioc_value": "ds.metric-take-datadqct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:45:54",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820368": [
        {
            "ioc_value": "182.23.2.163:1477",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-31 19:44:04",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820367": [
        {
            "ioc_value": "182.23.2.163:1135",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-31 19:44:03",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820327": [
        {
            "ioc_value": "64.89.160.44:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-31 15:04:22",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820311": [
        {
            "ioc_value": "107.151.246.172:7890",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 11:46:12",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820291": [
        {
            "ioc_value": "64.176.73.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-31 09:45:39",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820290": [
        {
            "ioc_value": "31.57.184.154:2503",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 09:44:59",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820289": [
        {
            "ioc_value": "182.23.2.163:6088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-31 09:43:50",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820288": [
        {
            "ioc_value": "172.81.61.226:5202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-31 09:43:43",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820287": [
        {
            "ioc_value": "155.103.71.115:13407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-31 09:43:29",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820263": [
        {
            "ioc_value": "b.9-9-8.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-05-31 07:05:53",
            "last_seen_utc": "2026-06-05 06:03:06",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,fileless,TeamTNT,vurl",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1820212": [
        {
            "ioc_value": "82.157.52.180:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 06:48:29",
            "last_seen_utc": "2026-06-06 15:45:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1820214": [
        {
            "ioc_value": "64.89.160.44:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 06:48:28",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "205759,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1820174": [
        {
            "ioc_value": "cafebabe.su",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-05-31 06:45:48",
            "last_seen_utc": "2026-06-05 06:03:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1820144": [
        {
            "ioc_value": "84.32.41.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-30 19:45:52",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820143": [
        {
            "ioc_value": "47.236.24.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-30 19:45:28",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820141": [
        {
            "ioc_value": "157.20.182.17:1997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-30 19:43:32",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820072": [
        {
            "ioc_value": "223.26.59.226:32354",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-30 11:47:27",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820044": [
        {
            "ioc_value": "46.225.66.210:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:45:35",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820043": [
        {
            "ioc_value": "38.54.63.135:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:45:23",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820042": [
        {
            "ioc_value": "182.23.2.163:6407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-30 09:43:57",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820041": [
        {
            "ioc_value": "157.20.182.18:1973",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-30 09:43:35",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820040": [
        {
            "ioc_value": "155.103.71.146:776",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-30 09:43:34",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820039": [
        {
            "ioc_value": "114.132.190.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:43:14",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819999": [
        {
            "ioc_value": "113.31.106.210:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-30 06:48:19",
            "last_seen_utc": "2026-06-06 10:32:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819942": [
        {
            "ioc_value": "209.200.246.82:5663",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 23:46:36",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819907": [
        {
            "ioc_value": "49.233.81.84:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:45:46",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819906": [
        {
            "ioc_value": "43.140.219.30:7112",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-29 19:45:33",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819905": [
        {
            "ioc_value": "31.56.209.79:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 19:45:22",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819904": [
        {
            "ioc_value": "27.102.137.139:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 19:45:20",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819903": [
        {
            "ioc_value": "23.235.185.44:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-29 19:45:19",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819902": [
        {
            "ioc_value": "209.99.184.51:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-29 19:44:29",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819901": [
        {
            "ioc_value": "192.162.199.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:44:12",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819900": [
        {
            "ioc_value": "185.212.129.4:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-29 19:44:04",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819899": [
        {
            "ioc_value": "182.23.2.163:4452",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 19:43:57",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819898": [
        {
            "ioc_value": "172.86.109.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-29 19:43:49",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819895": [
        {
            "ioc_value": "162.248.224.236:7492",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819896": [
        {
            "ioc_value": "162.248.225.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819897": [
        {
            "ioc_value": "162.248.225.165:8603",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819894": [
        {
            "ioc_value": "162.248.224.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:41",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819893": [
        {
            "ioc_value": "157.20.182.17:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 19:43:36",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819892": [
        {
            "ioc_value": "146.59.182.123:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-29 19:43:30",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819891": [
        {
            "ioc_value": "134.199.170.120:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-29 19:43:21",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819890": [
        {
            "ioc_value": "13.213.58.233:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-29 19:43:18",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819889": [
        {
            "ioc_value": "111.229.154.250:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:43:14",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819888": [
        {
            "ioc_value": "103.213.251.10:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-29 19:43:06",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819887": [
        {
            "ioc_value": "1.14.172.47:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:43:02",
            "last_seen_utc": "2026-06-06 15:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819866": [
        {
            "ioc_value": "124.220.235.4:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 15:46:36",
            "last_seen_utc": "2026-06-06 15:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819842": [
        {
            "ioc_value": "mub.depansm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-06-06 09:24:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1819843": [
        {
            "ioc_value": "https://mub.depansm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-06-06 09:24:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1819840": [
        {
            "ioc_value": "https://mub.matriculaflix.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:00:50",
            "last_seen_utc": "2026-06-05 14:24:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1819839": [
        {
            "ioc_value": "mub.matriculaflix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:00:49",
            "last_seen_utc": "2026-06-05 14:24:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1819788": [
        {
            "ioc_value": "209.200.246.82:7533",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:49",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819787": [
        {
            "ioc_value": "124.71.141.30:5003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:38",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819786": [
        {
            "ioc_value": "118.89.79.131:6528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:33",
            "last_seen_utc": "2026-06-06 15:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819785": [
        {
            "ioc_value": "103.242.12.143:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:24",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819763": [
        {
            "ioc_value": "119.29.117.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 09:46:58",
            "last_seen_utc": "2026-06-06 15:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819761": [
        {
            "ioc_value": "194.236.215.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-29 09:44:20",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819759": [
        {
            "ioc_value": "192.30.243.28:36812",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 09:44:16",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819760": [
        {
            "ioc_value": "192.30.243.28:8638",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 09:44:16",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819758": [
        {
            "ioc_value": "190.255.90.152:6010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-29 09:44:12",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819757": [
        {
            "ioc_value": "185.212.129.6:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-29 09:44:06",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819756": [
        {
            "ioc_value": "185.212.129.146:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-29 09:44:05",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819755": [
        {
            "ioc_value": "182.23.2.163:2345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 09:43:59",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819754": [
        {
            "ioc_value": "172.82.64.235:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 09:43:50",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819753": [
        {
            "ioc_value": "168.144.36.228:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-29 09:43:47",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819752": [
        {
            "ioc_value": "158.94.208.29:207",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-29 09:43:39",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819751": [
        {
            "ioc_value": "157.254.223.135:2700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 09:43:38",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819750": [
        {
            "ioc_value": "157.20.182.17:1339",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 09:43:37",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819749": [
        {
            "ioc_value": "103.77.246.174:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-05-29 09:43:08",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819748": [
        {
            "ioc_value": "103.213.251.10:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-29 09:43:07",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819713": [
        {
            "ioc_value": "198.44.177.179:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 06:45:14",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819710": [
        {
            "ioc_value": "45.116.78.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 06:44:51",
            "last_seen_utc": "2026-06-06 15:45:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819695": [
        {
            "ioc_value": "15.235.9.17:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 06:26:29",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1819596": [
        {
            "ioc_value": "1364170351-gsw88cee73.ap-guangzhou.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-28 19:45:38",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819595": [
        {
            "ioc_value": "82.197.69.156:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-28 19:45:25",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819594": [
        {
            "ioc_value": "35.158.219.35:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 19:44:47",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819593": [
        {
            "ioc_value": "31.57.184.154:7005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 19:44:44",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819592": [
        {
            "ioc_value": "192.237.187.145:5757",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-28 19:43:54",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819589": [
        {
            "ioc_value": "182.23.2.163:5013",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-28 19:43:44",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819590": [
        {
            "ioc_value": "182.23.2.163:58008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-28 19:43:44",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819591": [
        {
            "ioc_value": "182.23.2.163:7615",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-28 19:43:44",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819588": [
        {
            "ioc_value": "182.23.2.163:13846",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-28 19:43:43",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819587": [
        {
            "ioc_value": "157.20.182.18:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 19:43:28",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819586": [
        {
            "ioc_value": "13.209.95.4:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 19:43:13",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819570": [
        {
            "ioc_value": "xax.cahayasm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-28 18:00:49",
            "last_seen_utc": "2026-06-06 06:07:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1819407": [
        {
            "ioc_value": "91.230.94.235:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:10",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819406": [
        {
            "ioc_value": "91.215.85.212:45423",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:09",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819405": [
        {
            "ioc_value": "85.209.90.132:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:05",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819404": [
        {
            "ioc_value": "83.171.227.230:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:00",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819403": [
        {
            "ioc_value": "81.71.20.107:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:45:58",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819402": [
        {
            "ioc_value": "43.133.165.151:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:23",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819401": [
        {
            "ioc_value": "27.102.138.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:10",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819398": [
        {
            "ioc_value": "206.119.171.212:4333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:20",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819396": [
        {
            "ioc_value": "202.95.8.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819397": [
        {
            "ioc_value": "202.95.8.98:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819394": [
        {
            "ioc_value": "193.5.65.169:4348",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819395": [
        {
            "ioc_value": "193.5.65.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819393": [
        {
            "ioc_value": "172.86.76.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-28 09:43:45",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819392": [
        {
            "ioc_value": "172.236.142.17:6933",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:43:44",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819391": [
        {
            "ioc_value": "165.154.205.4:53341",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:43:40",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819390": [
        {
            "ioc_value": "155.103.71.135:56789",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-28 09:43:33",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819389": [
        {
            "ioc_value": "146.103.106.59:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:43:27",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819388": [
        {
            "ioc_value": "139.59.84.11:2053",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-28 09:43:23",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819387": [
        {
            "ioc_value": "113.31.106.85:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:43:13",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819386": [
        {
            "ioc_value": "103.183.75.134:20443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:43:05",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819351": [
        {
            "ioc_value": "120.48.66.205:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-28 06:56:15",
            "last_seen_utc": "2026-06-06 15:45:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819239": [
        {
            "ioc_value": "138.124.61.65:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 05:33:17",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1819225": [
        {
            "ioc_value": "91.200.84.198:8515",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:55",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819224": [
        {
            "ioc_value": "45.32.236.190:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:18",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819222": [
        {
            "ioc_value": "43.106.14.139:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-27 19:45:12",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819223": [
        {
            "ioc_value": "43.133.149.36:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-27 19:45:12",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819220": [
        {
            "ioc_value": "18.162.155.202:3350",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-27 19:43:47",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819219": [
        {
            "ioc_value": "157.20.182.17:1973",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-27 19:43:30",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819218": [
        {
            "ioc_value": "104.243.248.63:1807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-27 19:43:09",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819217": [
        {
            "ioc_value": "104.225.149.151:54321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:43:08",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819146": [
        {
            "ioc_value": "8.134.70.73:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 15:46:43",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819145": [
        {
            "ioc_value": "47.122.47.221:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 15:46:36",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819106": [
        {
            "ioc_value": "106.52.99.247:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 13:46:11",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819104": [
        {
            "ioc_value": "ns1.deepsekapi.cn",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 13:46:00",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819067": [
        {
            "ioc_value": "47.118.25.45:8451",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 11:48:59",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819047": [
        {
            "ioc_value": "94.23.185.83:9606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-27 09:45:57",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819046": [
        {
            "ioc_value": "89.40.31.128:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-27 09:45:51",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819045": [
        {
            "ioc_value": "82.156.224.203:12618",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-27 09:45:45",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819044": [
        {
            "ioc_value": "35.75.179.211:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-27 09:45:01",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819043": [
        {
            "ioc_value": "2.26.75.242:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-27 09:44:09",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819042": [
        {
            "ioc_value": "164.90.206.5:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-27 09:43:38",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819041": [
        {
            "ioc_value": "157.254.223.135:2500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-27 09:43:32",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819030": [
        {
            "ioc_value": "demale.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-05-27 08:35:12",
            "last_seen_utc": "2026-06-06 06:56:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RemusStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818956": [
        {
            "ioc_value": "8.163.49.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 07:09:22",
            "last_seen_utc": "2026-06-06 15:45:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1818897": [
        {
            "ioc_value": "http://158.94.210.59/25e3868686d747678e3b.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-27 07:09:05",
            "last_seen_utc": "2026-06-06 16:12:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "888,c2,loader,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1819006": [
        {
            "ioc_value": "124.70.184.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 06:54:26",
            "last_seen_utc": "2026-06-06 15:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818936": [
        {
            "ioc_value": "60.205.109.25:51234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 22:46:30",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818935": [
        {
            "ioc_value": "139.196.223.82:2443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 22:46:05",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818934": [
        {
            "ioc_value": "134.122.134.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 22:46:04",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818881": [
        {
            "ioc_value": "50.114.179.165:8043",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 19:45:26",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818880": [
        {
            "ioc_value": "5.101.82.8:48214",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:45:20",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818879": [
        {
            "ioc_value": "207.180.250.181:20600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 19:44:11",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818878": [
        {
            "ioc_value": "190.2.150.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:43:55",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818873": [
        {
            "ioc_value": "182.23.2.163:207",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:43:47",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818874": [
        {
            "ioc_value": "182.23.2.163:2487",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:43:47",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818875": [
        {
            "ioc_value": "182.23.2.163:2822",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:43:47",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818876": [
        {
            "ioc_value": "182.23.2.163:5600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:43:47",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818872": [
        {
            "ioc_value": "155.102.136.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-26 19:43:28",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818871": [
        {
            "ioc_value": "124.198.132.98:5080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 19:43:15",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818870": [
        {
            "ioc_value": "124.198.132.98:2434",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:43:14",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818804": [
        {
            "ioc_value": "47.122.47.221:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 14:46:42",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818786": [
        {
            "ioc_value": "5.252.153.0:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 14:08:57",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818731": [
        {
            "ioc_value": "68.64.178.130:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:46:53",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818730": [
        {
            "ioc_value": "45.227.253.121:35120",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:46:44",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818729": [
        {
            "ioc_value": "36.138.84.183:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:46:38",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818710": [
        {
            "ioc_value": "43.204.108.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:01:24",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818711": [
        {
            "ioc_value": "43.204.108.246:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:01:23",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818704": [
        {
            "ioc_value": "91.92.243.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-26 09:45:51",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818703": [
        {
            "ioc_value": "64.89.161.156:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-26 09:45:36",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818702": [
        {
            "ioc_value": "50.114.179.143:1209",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 09:45:31",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818701": [
        {
            "ioc_value": "46.8.226.70:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-26 09:45:21",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818700": [
        {
            "ioc_value": "34.106.231.199:6932",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 09:44:59",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818699": [
        {
            "ioc_value": "23.27.168.162:2850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-26 09:44:54",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818698": [
        {
            "ioc_value": "209.99.187.22:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-26 09:44:15",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818697": [
        {
            "ioc_value": "202.189.6.77:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 09:44:12",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818696": [
        {
            "ioc_value": "193.24.123.160:45631",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-26 09:44:02",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818695": [
        {
            "ioc_value": "191.93.116.106:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-26 09:43:57",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818694": [
        {
            "ioc_value": "153.75.232.207:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-26 09:43:28",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818692": [
        {
            "ioc_value": "124.198.132.98:2414",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 09:43:14",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818693": [
        {
            "ioc_value": "124.198.132.98:2424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 09:43:14",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818522": [
        {
            "ioc_value": "neuralpulsecore5.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-05-26 04:31:37",
            "last_seen_utc": "2026-06-06 04:45:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/47a2204dd5a0c8e9540373dee70d74dbdb73bac49eb26091c0722589013239a3/",
            "tags": "ACRStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818480": [
        {
            "ioc_value": "47.108.25.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 22:46:18",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818479": [
        {
            "ioc_value": "43.156.42.49:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 22:46:15",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818441": [
        {
            "ioc_value": "91.92.242.64:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 19:45:39",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818440": [
        {
            "ioc_value": "54.196.247.235:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-25 19:45:21",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818439": [
        {
            "ioc_value": "5.101.83.143:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:45:14",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818438": [
        {
            "ioc_value": "5.101.82.98:42859",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:45:13",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818436": [
        {
            "ioc_value": "45.56.162.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-25 19:45:00",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818437": [
        {
            "ioc_value": "45.56.162.61:6031",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-25 19:45:00",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818435": [
        {
            "ioc_value": "45.154.98.254:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:44:58",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818434": [
        {
            "ioc_value": "37.77.150.174:4333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:52",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818433": [
        {
            "ioc_value": "37.77.150.174:4332",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:51",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818432": [
        {
            "ioc_value": "27.102.137.139:1243",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:44:46",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818431": [
        {
            "ioc_value": "202.95.8.92:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-25 19:44:05",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818430": [
        {
            "ioc_value": "188.137.239.44:54298",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 19:43:50",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818429": [
        {
            "ioc_value": "185.122.166.184:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 19:43:44",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818428": [
        {
            "ioc_value": "178.16.54.208:61099",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:43:42",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818427": [
        {
            "ioc_value": "157.20.182.18:1992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 19:43:28",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818425": [
        {
            "ioc_value": "155.103.71.232:15406",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:43:27",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818426": [
        {
            "ioc_value": "157.20.182.17:1998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 19:43:27",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818424": [
        {
            "ioc_value": "138.9.41.208:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:43:18",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818347": [
        {
            "ioc_value": "47.238.154.144:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 14:01:56",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818346": [
        {
            "ioc_value": "45.153.127.224:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-25 14:00:07",
            "last_seen_utc": "2026-06-06 16:12:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=45.153.127.224",
            "tags": "Chaos,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818298": [
        {
            "ioc_value": "83.142.209.64:35630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-25 09:46:05",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818297": [
        {
            "ioc_value": "195.114.193.56:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-25 09:44:13",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818294": [
        {
            "ioc_value": "157.20.182.17:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 09:43:37",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818295": [
        {
            "ioc_value": "157.20.182.18:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 09:43:37",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818293": [
        {
            "ioc_value": "109.110.188.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-25 09:43:15",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818256": [
        {
            "ioc_value": "47.239.20.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 08:45:17",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818266": [
        {
            "ioc_value": "8.210.103.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 08:45:13",
            "last_seen_utc": "2026-06-06 15:45:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818155": [
        {
            "ioc_value": "1.92.95.105:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 07:36:01",
            "last_seen_utc": "2026-06-06 15:44:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "55990,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1818253": [
        {
            "ioc_value": "134.175.78.181:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 06:57:09",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818110": [
        {
            "ioc_value": "82.156.224.203:11641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-24 19:46:20",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818108": [
        {
            "ioc_value": "44.241.110.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-24 19:45:36",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818109": [
        {
            "ioc_value": "44.241.110.100:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-24 19:45:36",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818107": [
        {
            "ioc_value": "31.171.131.118:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:45:21",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818106": [
        {
            "ioc_value": "178.16.55.119:99",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:43:57",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818105": [
        {
            "ioc_value": "178.16.55.108:207",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-24 19:43:56",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818104": [
        {
            "ioc_value": "157.20.182.18:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:43:36",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818103": [
        {
            "ioc_value": "157.20.182.17:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:43:35",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818053": [
        {
            "ioc_value": "45.154.12.150:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:49",
            "last_seen_utc": "2026-06-06 15:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818052": [
        {
            "ioc_value": "103.210.236.87:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:17",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818050": [
        {
            "ioc_value": "wsus.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:12",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818051": [
        {
            "ioc_value": "wsus2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:12",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818049": [
        {
            "ioc_value": "102.220.160.47:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-05-24 14:43:03",
            "last_seen_utc": "2026-06-06 15:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818033": [
        {
            "ioc_value": "156.239.238.117:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:10:22",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818031": [
        {
            "ioc_value": "172.245.126.141:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2026-05-24 14:00:04",
            "last_seen_utc": "2026-06-06 16:12:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=172.245.126.141",
            "tags": "Deimos,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818027": [
        {
            "ioc_value": "45.145.42.80:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.darknexus",
            "malware_alias": null,
            "malware_printable": "Dark Nexus",
            "first_seen_utc": "2026-05-24 13:48:02",
            "last_seen_utc": "2026-06-06 16:12:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=45.145.42.80",
            "tags": "Nexus,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818007": [
        {
            "ioc_value": "menomou.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-05-24 12:25:33",
            "last_seen_utc": "2026-06-06 06:52:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RemusStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817883": [
        {
            "ioc_value": "43.138.192.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 11:08:34",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817856": [
        {
            "ioc_value": "106.13.188.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 11:05:07",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817785": [
        {
            "ioc_value": "39.100.88.189:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 11:04:32",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "37963,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1817715": [
        {
            "ioc_value": "101.43.30.6:888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 11:03:40",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817758": [
        {
            "ioc_value": "https://cyy.turbo88ml.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:09",
            "last_seen_utc": "2026-06-06 15:23:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1817757": [
        {
            "ioc_value": "cyy.turbo88ml.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:08",
            "last_seen_utc": "2026-06-06 15:23:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1817710": [
        {
            "ioc_value": "44.255.242.255:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-23 19:45:50",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817709": [
        {
            "ioc_value": "191.101.131.244:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-23 19:44:12",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817708": [
        {
            "ioc_value": "191.101.131.244:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-23 19:44:11",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817707": [
        {
            "ioc_value": "18.118.196.244:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-23 19:43:58",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817706": [
        {
            "ioc_value": "168.222.97.106:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-23 19:43:47",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817705": [
        {
            "ioc_value": "157.254.223.135:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-23 19:43:39",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817704": [
        {
            "ioc_value": "151.236.20.3:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-23 19:43:35",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817663": [
        {
            "ioc_value": "101.126.10.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:56",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817660": [
        {
            "ioc_value": "68.64.178.130:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:38",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817591": [
        {
            "ioc_value": "68.64.180.15:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:54:15",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817626": [
        {
            "ioc_value": "213.136.74.96:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-23 14:54:05",
            "last_seen_utc": "2026-06-06 16:12:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS51167,chaos,Contabo GmbH",
            "anonymous": "0",
            "reporter": "antiphishorg"
        }
    ],
    "1817651": [
        {
            "ioc_value": "http://170.130.55.223/8a5722931e174543a98d.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-23 14:53:56",
            "last_seen_utc": "2026-06-06 15:36:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,StealC,stealer,tick",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1817655": [
        {
            "ioc_value": "119.29.117.194:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:47:31",
            "last_seen_utc": "2026-06-06 15:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817625": [
        {
            "ioc_value": "91.232.103.163:1604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-23 09:46:49",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817624": [
        {
            "ioc_value": "50.114.179.143:6066",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-23 09:46:22",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817623": [
        {
            "ioc_value": "23.81.118.124:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-23 09:45:41",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817622": [
        {
            "ioc_value": "2.26.75.240:1377",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-23 09:44:28",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817621": [
        {
            "ioc_value": "190.255.82.151:5500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-23 09:44:15",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817620": [
        {
            "ioc_value": "103.13.210.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-23 09:43:04",
            "last_seen_utc": "2026-06-06 15:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817537": [
        {
            "ioc_value": "1.117.77.166:3310",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 08:58:34",
            "last_seen_utc": "2026-06-06 15:44:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1817573": [
        {
            "ioc_value": "47.103.78.72:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 08:58:28",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817427": [
        {
            "ioc_value": "88.119.167.142:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 19:45:35",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817426": [
        {
            "ioc_value": "87.251.76.213:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 19:45:34",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817425": [
        {
            "ioc_value": "5.101.82.98:41843",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-22 19:45:12",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817424": [
        {
            "ioc_value": "46.29.234.94:1298",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-22 19:45:07",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817423": [
        {
            "ioc_value": "46.29.234.94:12639",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-22 19:45:06",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817421": [
        {
            "ioc_value": "45.154.98.84:100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 19:44:58",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817422": [
        {
            "ioc_value": "45.154.98.84:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 19:44:58",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817420": [
        {
            "ioc_value": "2.59.162.106:6698",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-22 19:44:03",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817419": [
        {
            "ioc_value": "2.59.162.106:36125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-22 19:44:02",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817417": [
        {
            "ioc_value": "2.59.162.106:12639",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-22 19:44:01",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817418": [
        {
            "ioc_value": "2.59.162.106:1298",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-22 19:44:01",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817416": [
        {
            "ioc_value": "192.109.200.183:5566",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 19:43:53",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817341": [
        {
            "ioc_value": "184.82.96.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-22 14:45:15",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817205": [
        {
            "ioc_value": "35.220.177.232:4343",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 11:36:04",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1817206": [
        {
            "ioc_value": "46.20.109.225:8999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 11:36:04",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1817248": [
        {
            "ioc_value": "180.131.145.97:9995",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 10:46:24",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817239": [
        {
            "ioc_value": "88.119.167.143:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 09:45:23",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817238": [
        {
            "ioc_value": "54.187.35.128:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 09:45:08",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817237": [
        {
            "ioc_value": "46.224.144.82:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 09:44:54",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817236": [
        {
            "ioc_value": "45.90.120.36:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 09:44:53",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817235": [
        {
            "ioc_value": "31.57.184.154:7006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:40",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817233": [
        {
            "ioc_value": "31.171.131.118:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:39",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817234": [
        {
            "ioc_value": "31.171.131.118:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:39",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817232": [
        {
            "ioc_value": "193.93.194.31:50194",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:43:52",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817231": [
        {
            "ioc_value": "192.169.7.17:27443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 09:43:49",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817230": [
        {
            "ioc_value": "176.119.25.78:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:43:37",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817229": [
        {
            "ioc_value": "172.86.123.119:8679",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 09:43:35",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817228": [
        {
            "ioc_value": "138.9.254.121:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-22 09:43:17",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817226": [
        {
            "ioc_value": "104.37.174.36:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:43:08",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817227": [
        {
            "ioc_value": "104.37.174.36:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:43:08",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817216": [
        {
            "ioc_value": "23.106.135.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:46:27",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817217": [
        {
            "ioc_value": "23.106.135.33:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:46:27",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817215": [
        {
            "ioc_value": "154.201.68.191:14125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:46:18",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817214": [
        {
            "ioc_value": "118.31.114.149:4430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:46:10",
            "last_seen_utc": "2026-06-06 15:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817213": [
        {
            "ioc_value": "106.14.30.169:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:46:02",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817212": [
        {
            "ioc_value": "xulnai.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:45:57",
            "last_seen_utc": "2026-06-06 15:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817211": [
        {
            "ioc_value": "fq3gm5xphax8c.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:45:51",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817210": [
        {
            "ioc_value": "a3tf75e7k596x.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:45:48",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817131": [
        {
            "ioc_value": "59.110.81.93:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:11:42",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "37963,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1817132": [
        {
            "ioc_value": "129.204.14.131:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:11:41",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1817192": [
        {
            "ioc_value": "45.154.98.84:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 08:11:24",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817057": [
        {
            "ioc_value": "62.171.190.148:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-22 08:11:11",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817187": [
        {
            "ioc_value": "47.236.110.1:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 07:55:22",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817116": [
        {
            "ioc_value": "49.232.4.144:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 22:46:51",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817115": [
        {
            "ioc_value": "206.188.197.241:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 22:46:36",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817114": [
        {
            "ioc_value": "193.142.146.30:6555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 22:46:34",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817113": [
        {
            "ioc_value": "linuxkerneldbs.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 22:46:02",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817056": [
        {
            "ioc_value": "46.224.70.245:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-21 19:45:24",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817055": [
        {
            "ioc_value": "42.121.150.29:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-21 19:45:14",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817054": [
        {
            "ioc_value": "34.61.52.162:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-21 19:45:07",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817053": [
        {
            "ioc_value": "193.29.13.23:5758",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-21 19:44:01",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817052": [
        {
            "ioc_value": "158.94.209.7:5022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-21 19:43:33",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817051": [
        {
            "ioc_value": "157.230.125.65:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-21 19:43:30",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816952": [
        {
            "ioc_value": "brownhc.cyou",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.count_loader",
            "malware_alias": null,
            "malware_printable": "CountLoader",
            "first_seen_utc": "2026-05-21 12:02:43",
            "last_seen_utc": "2026-06-06 06:07:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CountLoader",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816915": [
        {
            "ioc_value": "207.154.243.85:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-21 09:44:20",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816914": [
        {
            "ioc_value": "195.63.137.242:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-21 09:44:09",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816875": [
        {
            "ioc_value": "156.225.22.84:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 07:19:52",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816874": [
        {
            "ioc_value": "121.199.27.49:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 07:19:39",
            "last_seen_utc": "2026-06-06 15:45:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816872": [
        {
            "ioc_value": "107.173.38.158:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 07:19:35",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816747": [
        {
            "ioc_value": "154.201.68.191:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 05:01:18",
            "last_seen_utc": "2026-06-06 10:32:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1816801": [
        {
            "ioc_value": "45.154.98.84:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-21 05:01:07",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "210558,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1816739": [
        {
            "ioc_value": "91.92.243.63:35000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-20 19:45:15",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816738": [
        {
            "ioc_value": "41.216.189.163:43210",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:44:41",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816737": [
        {
            "ioc_value": "221.207.101.175:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-20 19:44:32",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816736": [
        {
            "ioc_value": "209.126.80.129:8844",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:43:56",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816735": [
        {
            "ioc_value": "167.17.47.118:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:43:30",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816734": [
        {
            "ioc_value": "144.172.93.140:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:43:20",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816733": [
        {
            "ioc_value": "140.235.17.40:9958",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-20 19:43:18",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816732": [
        {
            "ioc_value": "107.189.25.70:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-20 19:43:09",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816587": [
        {
            "ioc_value": "85.17.244.120:2093",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-20 09:45:20",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816585": [
        {
            "ioc_value": "51.15.8.6:9998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-20 09:45:05",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816584": [
        {
            "ioc_value": "213.209.159.91:2602",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-20 09:44:03",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816583": [
        {
            "ioc_value": "202.1.31.83:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 09:43:56",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816582": [
        {
            "ioc_value": "18.178.185.250:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-20 09:43:40",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816581": [
        {
            "ioc_value": "178.212.13.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 09:43:39",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816580": [
        {
            "ioc_value": "171.22.79.135:3821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 09:43:32",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816553": [
        {
            "ioc_value": "103.149.93.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 07:37:44",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816552": [
        {
            "ioc_value": "121.43.243.13:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 07:37:43",
            "last_seen_utc": "2026-06-06 15:45:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816551": [
        {
            "ioc_value": "45.152.65.240:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 07:37:42",
            "last_seen_utc": "2026-06-06 15:45:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816445": [
        {
            "ioc_value": "43.142.137.169:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 20:46:09",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816431": [
        {
            "ioc_value": "91.202.233.214:44123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-19 19:45:18",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816430": [
        {
            "ioc_value": "83.136.211.194:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 19:45:12",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816428": [
        {
            "ioc_value": "49.232.128.239:6099",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-19 19:44:52",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816429": [
        {
            "ioc_value": "5.101.81.163:47524",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-19 19:44:52",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816427": [
        {
            "ioc_value": "31.57.184.154:2502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 19:44:36",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816426": [
        {
            "ioc_value": "192.159.99.50:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-19 19:43:48",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816425": [
        {
            "ioc_value": "172.111.233.80:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 19:43:33",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816422": [
        {
            "ioc_value": "144.172.94.91:1122",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-19 19:43:20",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816423": [
        {
            "ioc_value": "144.172.94.91:2255",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-19 19:43:20",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816424": [
        {
            "ioc_value": "144.172.94.91:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-19 19:43:20",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816365": [
        {
            "ioc_value": "100.110.56.1:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 14:45:37",
            "last_seen_utc": "2026-06-06 15:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816297": [
        {
            "ioc_value": "178.16.54.248:55380",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-19 09:43:39",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816296": [
        {
            "ioc_value": "176.120.22.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-05-19 09:43:37",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816295": [
        {
            "ioc_value": "167.86.114.91:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-19 09:43:31",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816294": [
        {
            "ioc_value": "142.93.165.129:3334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-19 09:43:19",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816293": [
        {
            "ioc_value": "104.243.248.63:1805",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 09:43:08",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816252": [
        {
            "ioc_value": "45.152.65.240:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 06:46:32",
            "last_seen_utc": "2026-06-06 15:45:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816248": [
        {
            "ioc_value": "111.230.36.144:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 06:46:14",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816173": [
        {
            "ioc_value": "43.143.145.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:16",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1816172": [
        {
            "ioc_value": "47.82.234.12:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:15",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1816164": [
        {
            "ioc_value": "119.91.26.245:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:06",
            "last_seen_utc": "2026-06-06 15:45:05",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1816110": [
        {
            "ioc_value": "43.144.19.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:15:34",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1816142": [
        {
            "ioc_value": "23.236.64.238:8778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 22:47:56",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816141": [
        {
            "ioc_value": "1.117.61.9:12306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 22:47:21",
            "last_seen_utc": "2026-06-06 15:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816106": [
        {
            "ioc_value": "89.125.255.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-18 19:45:01",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816104": [
        {
            "ioc_value": "84.21.189.225:50194",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-18 19:44:59",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816105": [
        {
            "ioc_value": "84.21.189.225:58268",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-18 19:44:59",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816103": [
        {
            "ioc_value": "65.87.7.130:61361",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-18 19:44:52",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816102": [
        {
            "ioc_value": "5.101.81.2:51842",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-18 19:44:41",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816101": [
        {
            "ioc_value": "44.211.251.197:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-18 19:44:34",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816100": [
        {
            "ioc_value": "38.147.189.199:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-18 19:44:31",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816099": [
        {
            "ioc_value": "2.26.75.250:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-18 19:43:47",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816098": [
        {
            "ioc_value": "188.137.181.111:53863",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-18 19:43:39",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816097": [
        {
            "ioc_value": "154.29.72.21:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-18 19:43:21",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816096": [
        {
            "ioc_value": "138.124.90.26:51337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-18 19:43:13",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816095": [
        {
            "ioc_value": "130.49.214.92:53522",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-18 19:43:11",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816094": [
        {
            "ioc_value": "101.99.95.16:2850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-18 19:43:02",
            "last_seen_utc": "2026-06-06 15:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816032": [
        {
            "ioc_value": "118.31.114.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 14:45:47",
            "last_seen_utc": "2026-06-06 15:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815941": [
        {
            "ioc_value": "120.53.15.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 11:28:17",
            "last_seen_utc": "2026-06-06 15:45:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815876": [
        {
            "ioc_value": "175.178.36.137:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 11:28:05",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815946": [
        {
            "ioc_value": "62.234.22.228:51234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 10:46:24",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815934": [
        {
            "ioc_value": "93.82.27.251:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-18 09:45:32",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815932": [
        {
            "ioc_value": "83.136.211.4:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-18 09:45:24",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815933": [
        {
            "ioc_value": "83.136.211.4:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-18 09:45:24",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815930": [
        {
            "ioc_value": "46.8.226.70:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-18 09:44:56",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815931": [
        {
            "ioc_value": "46.8.226.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-18 09:44:56",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815928": [
        {
            "ioc_value": "34.230.7.122:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-18 09:44:44",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815929": [
        {
            "ioc_value": "35.161.127.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-18 09:44:44",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815927": [
        {
            "ioc_value": "163.181.46.56:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-18 09:43:30",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815818": [
        {
            "ioc_value": "47.236.91.172:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:49",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815819": [
        {
            "ioc_value": "35.202.235.112:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-18 07:33:49",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815773": [
        {
            "ioc_value": "194.163.154.86:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-18 07:33:37",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815757": [
        {
            "ioc_value": "124.220.36.247:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:34",
            "last_seen_utc": "2026-06-06 15:45:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815737": [
        {
            "ioc_value": "81.68.216.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:28",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815736": [
        {
            "ioc_value": "81.68.216.220:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:27",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815729": [
        {
            "ioc_value": "89.125.138.217:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-05-18 07:33:25",
            "last_seen_utc": "2026-06-06 16:14:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1815832": [
        {
            "ioc_value": "172.86.76.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:26:30",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815762": [
        {
            "ioc_value": "119.29.112.239:8005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 22:45:31",
            "last_seen_utc": "2026-06-06 15:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815731": [
        {
            "ioc_value": "144.172.65.245:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-17 19:43:19",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815551": [
        {
            "ioc_value": "207.56.229.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 15:53:07",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": "cobalt-strike,erebus-wraith,unattributed",
            "anonymous": "0",
            "reporter": "Erebu"
        }
    ],
    "1815580": [
        {
            "ioc_value": "178.16.53.46:7331",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-17 09:43:36",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815579": [
        {
            "ioc_value": "154.29.72.21:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-17 09:43:23",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815578": [
        {
            "ioc_value": "144.172.100.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-17 09:43:19",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815461": [
        {
            "ioc_value": "81.71.20.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 06:52:36",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815501": [
        {
            "ioc_value": "206.119.173.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 05:46:40",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815500": [
        {
            "ioc_value": "101.126.150.253:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 05:46:19",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815481": [
        {
            "ioc_value": "47.236.91.172:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 03:45:47",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815398": [
        {
            "ioc_value": "91.92.243.63:39850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-16 19:46:20",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815397": [
        {
            "ioc_value": "45.155.69.153:43345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-16 19:45:35",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815396": [
        {
            "ioc_value": "206.81.21.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-16 19:44:19",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815395": [
        {
            "ioc_value": "139.99.131.177:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:23",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815394": [
        {
            "ioc_value": "104.236.230.184:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-16 19:43:08",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815392": [
        {
            "ioc_value": "103.219.153.200:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:06",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815393": [
        {
            "ioc_value": "103.219.153.200:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:06",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815391": [
        {
            "ioc_value": "103.219.153.200:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:05",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815390": [
        {
            "ioc_value": "1.15.221.207:4379",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-16 19:43:03",
            "last_seen_utc": "2026-06-06 15:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815369": [
        {
            "ioc_value": "38.14.248.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-16 18:46:11",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815260": [
        {
            "ioc_value": "38.14.248.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-16 09:46:35",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815259": [
        {
            "ioc_value": "31.57.184.82:7829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 09:44:54",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815258": [
        {
            "ioc_value": "193.169.194.51:6325",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-16 09:43:55",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815257": [
        {
            "ioc_value": "188.126.90.5:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-16 09:43:50",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815256": [
        {
            "ioc_value": "139.99.131.177:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 09:43:20",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815137": [
        {
            "ioc_value": "95.231.168.143:4483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-15 19:44:50",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815135": [
        {
            "ioc_value": "65.21.21.227:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-15 19:44:38",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815136": [
        {
            "ioc_value": "65.21.21.227:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-15 19:44:38",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815134": [
        {
            "ioc_value": "4.235.114.15:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-15 19:44:21",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815133": [
        {
            "ioc_value": "34.69.130.10:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-15 19:44:19",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815132": [
        {
            "ioc_value": "31.57.187.91:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-15 19:44:18",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815131": [
        {
            "ioc_value": "217.30.169.67:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-15 19:44:14",
            "last_seen_utc": "2026-06-06 15:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815130": [
        {
            "ioc_value": "2.26.160.75:4984",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-15 19:43:41",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815129": [
        {
            "ioc_value": "178.236.252.244:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-15 19:43:29",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815128": [
        {
            "ioc_value": "163.245.216.78:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-15 19:43:22",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815127": [
        {
            "ioc_value": "137.184.102.191:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-15 19:43:12",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815126": [
        {
            "ioc_value": "107.175.148.68:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-15 19:43:07",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815125": [
        {
            "ioc_value": "103.147.228.13:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-15 19:43:04",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815073": [
        {
            "ioc_value": "pgo.fatherchrismas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-06-06 15:23:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1815074": [
        {
            "ioc_value": "https://pgo.fatherchrismas.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-06-06 15:23:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1814914": [
        {
            "ioc_value": "207.56.229.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-15 13:48:12",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814909": [
        {
            "ioc_value": "39.108.114.1:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-15 13:47:47",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814910": [
        {
            "ioc_value": "123.57.208.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-15 13:47:47",
            "last_seen_utc": "2026-06-06 15:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812324": [
        {
            "ioc_value": "47.99.93.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-15 13:47:09",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1812358": [
        {
            "ioc_value": "31.207.39.174:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-15 13:35:39",
            "last_seen_utc": "2026-06-06 16:12:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS210403,chaos,Groupe LWS SARL",
            "anonymous": "0",
            "reporter": "antiphishorg"
        }
    ],
    "1812345": [
        {
            "ioc_value": "158.220.127.55:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-15 13:35:37",
            "last_seen_utc": "2026-06-06 16:12:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS51167,chaos,Contabo GmbH",
            "anonymous": "0",
            "reporter": "antiphishorg"
        }
    ],
    "1814531": [
        {
            "ioc_value": "91.124.19.173:6913",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-15 09:45:23",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814529": [
        {
            "ioc_value": "85.11.167.110:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-15 09:45:20",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814530": [
        {
            "ioc_value": "85.11.167.110:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-15 09:45:20",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814528": [
        {
            "ioc_value": "5.101.81.2:63676",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-15 09:44:54",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814527": [
        {
            "ioc_value": "216.250.249.225:2195",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-15 09:44:35",
            "last_seen_utc": "2026-06-06 15:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814525": [
        {
            "ioc_value": "15.236.43.82:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-15 09:43:22",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814523": [
        {
            "ioc_value": "104.243.248.63:1808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-15 09:43:07",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814522": [
        {
            "ioc_value": "103.168.67.140:3031",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-15 09:43:04",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812322": [
        {
            "ioc_value": "1.117.61.9:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 22:45:41",
            "last_seen_utc": "2026-06-06 15:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812320": [
        {
            "ioc_value": "ct.feliz.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 22:45:33",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812283": [
        {
            "ioc_value": "95.141.133.7:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-14 19:47:27",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812282": [
        {
            "ioc_value": "91.215.85.121:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-14 19:47:23",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812281": [
        {
            "ioc_value": "138.9.219.221:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-14 19:43:34",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812280": [
        {
            "ioc_value": "104.243.248.63:1806",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-14 19:43:12",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811874": [
        {
            "ioc_value": "8.218.224.15:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 12:36:52",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1811932": [
        {
            "ioc_value": "80.78.30.62:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-14 12:35:59",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1812137": [
        {
            "ioc_value": "207.56.226.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 12:33:41",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1811674": [
        {
            "ioc_value": "47.102.184.26:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 12:33:30",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "37963,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1811507": [
        {
            "ioc_value": "158.94.209.243:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-14 12:30:56",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1812148": [
        {
            "ioc_value": "147.78.2.110:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 12:14:39",
            "last_seen_utc": "2026-06-06 15:45:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812141": [
        {
            "ioc_value": "113.31.115.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 11:46:11",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812126": [
        {
            "ioc_value": "84.46.251.62:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-14 09:51:34",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812125": [
        {
            "ioc_value": "192.159.99.34:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-14 09:45:53",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811952": [
        {
            "ioc_value": "93.127.160.86:6552",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 19:45:36",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811950": [
        {
            "ioc_value": "85.120.252.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-13 19:45:31",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811951": [
        {
            "ioc_value": "85.17.192.68:2121",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 19:45:31",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811949": [
        {
            "ioc_value": "83.217.215.55:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-13 19:45:29",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811948": [
        {
            "ioc_value": "5.101.83.144:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 19:45:08",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811947": [
        {
            "ioc_value": "5.101.82.216:50044",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 19:45:06",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811946": [
        {
            "ioc_value": "5.101.81.81:6913",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 19:45:05",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811945": [
        {
            "ioc_value": "43.230.162.44:14321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-13 19:44:54",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811944": [
        {
            "ioc_value": "31.13.190.2:6552",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 19:44:46",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811943": [
        {
            "ioc_value": "2.26.96.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-13 19:43:55",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811942": [
        {
            "ioc_value": "194.33.48.221:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-13 19:43:53",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811941": [
        {
            "ioc_value": "139.99.131.177:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-13 19:43:17",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811939": [
        {
            "ioc_value": "103.197.191.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-13 19:43:03",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811940": [
        {
            "ioc_value": "103.197.191.159:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-13 19:43:03",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811775": [
        {
            "ioc_value": "43.139.170.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-13 10:45:56",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811766": [
        {
            "ioc_value": "91.134.139.176:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-13 09:45:26",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811764": [
        {
            "ioc_value": "62.169.31.177:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-05-13 09:45:12",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811763": [
        {
            "ioc_value": "45.92.1.175:5220",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 09:44:52",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811762": [
        {
            "ioc_value": "203.202.232.22:3131",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 09:43:56",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811761": [
        {
            "ioc_value": "194.33.48.221:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-13 09:43:50",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811760": [
        {
            "ioc_value": "147.124.216.58:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-13 09:43:20",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811759": [
        {
            "ioc_value": "101.109.237.93:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-13 09:43:02",
            "last_seen_utc": "2026-06-06 15:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811650": [
        {
            "ioc_value": "168.222.97.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 22:45:18",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811651": [
        {
            "ioc_value": "168.222.97.93:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 22:45:18",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811649": [
        {
            "ioc_value": "161.248.87.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 22:45:17",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811573": [
        {
            "ioc_value": "94.198.51.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-12 19:45:05",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811572": [
        {
            "ioc_value": "37.72.172.58:7077",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-12 19:44:29",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811571": [
        {
            "ioc_value": "2.27.17.179:6644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-12 19:43:45",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811473": [
        {
            "ioc_value": "www.apartuk.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-05-12 15:12:03",
            "last_seen_utc": "2026-06-06 16:12:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=www.apartuk.info",
            "tags": "ViriBack,XLoader",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811472": [
        {
            "ioc_value": "www.axilo.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-05-12 15:12:02",
            "last_seen_utc": "2026-06-06 16:12:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=www.axilo.top",
            "tags": "ViriBack,XLoader",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811234": [
        {
            "ioc_value": "190.255.90.152:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-12 14:50:32",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "3816,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1811440": [
        {
            "ioc_value": "http://cdntestconnect.com/ed54b97a570943999715.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-12 14:48:59",
            "last_seen_utc": "2026-06-06 15:58:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,first,loader,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1811413": [
        {
            "ioc_value": "118.31.62.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 11:45:40",
            "last_seen_utc": "2026-06-06 15:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811412": [
        {
            "ioc_value": "117.72.168.103:50011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 11:45:38",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811410": [
        {
            "ioc_value": "101.132.156.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 11:45:31",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811411": [
        {
            "ioc_value": "101.35.102.87:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 11:45:31",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811401": [
        {
            "ioc_value": "91.92.243.38:35630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-12 09:45:18",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811400": [
        {
            "ioc_value": "91.215.85.121:6466",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-12 09:45:17",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811399": [
        {
            "ioc_value": "85.158.57.247:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-12 09:45:14",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811398": [
        {
            "ioc_value": "67.180.188.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-12 09:45:04",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811397": [
        {
            "ioc_value": "62.84.114.70:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-12 09:45:00",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811396": [
        {
            "ioc_value": "62.171.190.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-12 09:44:59",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811394": [
        {
            "ioc_value": "45.142.107.41:1030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-12 09:44:43",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811395": [
        {
            "ioc_value": "45.142.107.41:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-12 09:44:43",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811392": [
        {
            "ioc_value": "31.57.184.48:7456",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-12 09:44:37",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811393": [
        {
            "ioc_value": "31.57.201.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-12 09:44:37",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811389": [
        {
            "ioc_value": "207.148.2.115:60060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-12 09:43:50",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811390": [
        {
            "ioc_value": "207.148.2.115:60061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-12 09:43:50",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811388": [
        {
            "ioc_value": "2.26.96.209:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-12 09:43:47",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811387": [
        {
            "ioc_value": "155.103.71.115:14549",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-12 09:43:21",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811386": [
        {
            "ioc_value": "146.185.233.71:41254",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-12 09:43:17",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811385": [
        {
            "ioc_value": "104.243.248.63:1803",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-12 09:43:06",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811384": [
        {
            "ioc_value": "103.143.207.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-12 09:43:03",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811187": [
        {
            "ioc_value": "mpd.pegasus-77.biz.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-06-06 15:23:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1811188": [
        {
            "ioc_value": "https://mpd.pegasus-77.biz.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-06-06 15:23:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1811186": [
        {
            "ioc_value": "117.50.184.221:10080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 22:45:16",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811185": [
        {
            "ioc_value": "112.124.71.123:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 22:45:14",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811129": [
        {
            "ioc_value": "64.199.252.59:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 19:45:07",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811128": [
        {
            "ioc_value": "51.77.54.76:6769",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:45:01",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811127": [
        {
            "ioc_value": "46.253.143.52:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:44:51",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811126": [
        {
            "ioc_value": "45.77.89.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:44:49",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811125": [
        {
            "ioc_value": "213.139.77.243:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-11 19:43:58",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811124": [
        {
            "ioc_value": "185.212.128.72:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 19:43:39",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811123": [
        {
            "ioc_value": "185.190.142.66:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:38",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811122": [
        {
            "ioc_value": "155.103.71.115:14548",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-11 19:43:23",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811120": [
        {
            "ioc_value": "139.180.153.57:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:16",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811121": [
        {
            "ioc_value": "139.99.131.177:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 19:43:16",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811119": [
        {
            "ioc_value": "13.60.193.80:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:10",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811118": [
        {
            "ioc_value": "109.73.193.242:10140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:08",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811117": [
        {
            "ioc_value": "103.247.11.53:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-11 19:43:04",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811018": [
        {
            "ioc_value": "38.55.124.41:16571",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 11:45:53",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811017": [
        {
            "ioc_value": "172.245.28.187:4440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 11:45:45",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811016": [
        {
            "ioc_value": "117.72.198.62:9987",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 11:45:33",
            "last_seen_utc": "2026-06-06 15:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810988": [
        {
            "ioc_value": "mpd.loniluekegerman.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 10:26:38",
            "last_seen_utc": "2026-06-06 04:48:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1810966": [
        {
            "ioc_value": "91.92.243.63:35631",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-11 09:45:20",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810967": [
        {
            "ioc_value": "91.92.243.63:35635",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-11 09:45:20",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810965": [
        {
            "ioc_value": "89.42.134.220:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:45:15",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810964": [
        {
            "ioc_value": "78.47.143.18:8053",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-11 09:44:59",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810963": [
        {
            "ioc_value": "5.101.81.81:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-11 09:44:44",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810962": [
        {
            "ioc_value": "45.153.34.51:58001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-11 09:44:38",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810961": [
        {
            "ioc_value": "44.215.161.149:4005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-11 09:44:36",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810960": [
        {
            "ioc_value": "43.133.149.36:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-11 09:44:35",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810959": [
        {
            "ioc_value": "31.57.184.154:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:44:29",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810958": [
        {
            "ioc_value": "20.114.142.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-11 09:43:46",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810957": [
        {
            "ioc_value": "194.163.175.135:8679",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:42",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810956": [
        {
            "ioc_value": "193.169.194.19:8264",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-11 09:43:41",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810955": [
        {
            "ioc_value": "185.242.245.27:44875",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:35",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810954": [
        {
            "ioc_value": "185.212.128.76:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 09:43:34",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810952": [
        {
            "ioc_value": "172.239.57.52:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:26",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810953": [
        {
            "ioc_value": "172.245.97.237:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 09:43:26",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810951": [
        {
            "ioc_value": "168.222.97.106:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:43:24",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810950": [
        {
            "ioc_value": "158.94.210.70:22532",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:43:20",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810949": [
        {
            "ioc_value": "144.91.78.57:9008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-11 09:43:15",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810948": [
        {
            "ioc_value": "137.184.38.192:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:43:11",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810947": [
        {
            "ioc_value": "130.12.182.209:1525",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:43:09",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810462": [
        {
            "ioc_value": "150.158.109.61:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 23:45:17",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810461": [
        {
            "ioc_value": "112.213.106.53:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 23:45:07",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810418": [
        {
            "ioc_value": "64.23.231.32:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-10 19:44:55",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810417": [
        {
            "ioc_value": "5.78.110.145:7989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-10 19:44:52",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810416": [
        {
            "ioc_value": "46.109.239.103:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 19:44:43",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810415": [
        {
            "ioc_value": "44.206.172.239:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-10 19:44:38",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810414": [
        {
            "ioc_value": "31.57.184.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 19:44:31",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810413": [
        {
            "ioc_value": "24.134.4.221:4714",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:44:30",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810412": [
        {
            "ioc_value": "209.99.188.44:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-10 19:43:51",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810410": [
        {
            "ioc_value": "195.123.240.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810411": [
        {
            "ioc_value": "195.123.240.236:8274",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810408": [
        {
            "ioc_value": "189.34.188.6:5406",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810409": [
        {
            "ioc_value": "189.34.188.6:5407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810407": [
        {
            "ioc_value": "178.16.55.171:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-10 19:43:32",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810406": [
        {
            "ioc_value": "178.105.40.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-10 19:43:31",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810405": [
        {
            "ioc_value": "138.9.237.106:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-10 19:43:15",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810404": [
        {
            "ioc_value": "130.49.214.74:50194",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 19:43:11",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809980": [
        {
            "ioc_value": "129.211.2.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 18:42:12",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1809984": [
        {
            "ioc_value": "1.92.101.103:8099",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 18:42:09",
            "last_seen_utc": "2026-06-06 15:44:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "55990,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1810194": [
        {
            "ioc_value": "142.171.172.100:17443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 10:45:37",
            "last_seen_utc": "2026-06-06 15:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810193": [
        {
            "ioc_value": "api.apifox.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 10:45:13",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810170": [
        {
            "ioc_value": "57.158.27.132:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-10 09:44:56",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810169": [
        {
            "ioc_value": "43.133.149.36:18080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-10 09:44:39",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810168": [
        {
            "ioc_value": "207.56.2.25:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-10 09:43:50",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810167": [
        {
            "ioc_value": "198.23.185.234:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 09:43:47",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810166": [
        {
            "ioc_value": "194.26.192.229:50",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 09:43:45",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810165": [
        {
            "ioc_value": "192.159.99.183:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-10 09:43:41",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810164": [
        {
            "ioc_value": "179.43.134.189:9968",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-10 09:43:33",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810163": [
        {
            "ioc_value": "175.27.164.136:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-10 09:43:31",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810162": [
        {
            "ioc_value": "172.245.152.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-10 09:43:27",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809787": [
        {
            "ioc_value": "39nasm720z98q.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-09 20:44:40",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809758": [
        {
            "ioc_value": "82.25.35.113:2177",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-09 19:44:46",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809756": [
        {
            "ioc_value": "5.180.46.180:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-09 19:44:38",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809754": [
        {
            "ioc_value": "213.130.25.141:44333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-09 19:43:46",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809753": [
        {
            "ioc_value": "198.167.212.165:73",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-09 19:43:41",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809751": [
        {
            "ioc_value": "194.26.192.229:100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-09 19:43:40",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809752": [
        {
            "ioc_value": "194.26.192.229:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-09 19:43:40",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809750": [
        {
            "ioc_value": "168.144.89.48:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-09 19:43:24",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809749": [
        {
            "ioc_value": "167.99.151.149:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-09 19:43:23",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809747": [
        {
            "ioc_value": "138.9.223.13:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-09 19:43:13",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809748": [
        {
            "ioc_value": "138.9.41.254:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-09 19:43:13",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809219": [
        {
            "ioc_value": "139.196.50.117:9930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 23:44:52",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809218": [
        {
            "ioc_value": "106.53.82.117:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 23:44:44",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809059": [
        {
            "ioc_value": "202.95.18.30:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 19:45:15",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809058": [
        {
            "ioc_value": "ns1.cacheflow.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 19:44:47",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809056": [
        {
            "ioc_value": "93.127.160.86:6553",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:44:41",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809057": [
        {
            "ioc_value": "93.127.160.86:6554",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:44:41",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809054": [
        {
            "ioc_value": "91.92.241.142:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 19:44:40",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809055": [
        {
            "ioc_value": "91.92.241.142:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 19:44:40",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809053": [
        {
            "ioc_value": "89.208.113.158:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 19:44:39",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809051": [
        {
            "ioc_value": "83.142.209.146:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 19:44:36",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809052": [
        {
            "ioc_value": "83.142.209.60:8795",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:44:36",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809050": [
        {
            "ioc_value": "80.211.196.157:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 19:44:34",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809048": [
        {
            "ioc_value": "75.119.154.8:2700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 19:44:33",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809049": [
        {
            "ioc_value": "75.119.154.8:3500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 19:44:33",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809046": [
        {
            "ioc_value": "64.90.19.46:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:44:32",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809047": [
        {
            "ioc_value": "66.163.112.213:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:44:32",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809045": [
        {
            "ioc_value": "61.7.18.194:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:44:30",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809044": [
        {
            "ioc_value": "5.101.86.70:9843",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:44:27",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809043": [
        {
            "ioc_value": "5.101.86.105:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:44:25",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809042": [
        {
            "ioc_value": "31.57.216.56:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:44:13",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809041": [
        {
            "ioc_value": "23.227.203.172:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 19:44:11",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809039": [
        {
            "ioc_value": "209.38.100.109:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 19:43:41",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809040": [
        {
            "ioc_value": "209.54.101.159:1414",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:41",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809038": [
        {
            "ioc_value": "193.42.24.165:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:43:36",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809037": [
        {
            "ioc_value": "193.169.194.24:2509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:35",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809036": [
        {
            "ioc_value": "185.220.205.80:3535",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:31",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809034": [
        {
            "ioc_value": "185.212.128.15:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 19:43:29",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809035": [
        {
            "ioc_value": "185.212.128.24:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 19:43:29",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809033": [
        {
            "ioc_value": "180.97.214.70:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-08 19:43:28",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809032": [
        {
            "ioc_value": "177.67.105.14:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 19:43:26",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809031": [
        {
            "ioc_value": "172.94.3.201:5816",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:25",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809029": [
        {
            "ioc_value": "160.25.82.142:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:19",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809030": [
        {
            "ioc_value": "160.30.231.100:553",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-08 19:43:19",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809028": [
        {
            "ioc_value": "154.7.228.167:2443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-08 19:43:17",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809026": [
        {
            "ioc_value": "146.185.233.76:7227",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:15",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809027": [
        {
            "ioc_value": "146.185.239.61:9702",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:15",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809024": [
        {
            "ioc_value": "138.9.231.141:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:13",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809025": [
        {
            "ioc_value": "138.9.234.119:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:13",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809020": [
        {
            "ioc_value": "138.9.0.156:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:12",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809021": [
        {
            "ioc_value": "138.9.114.126:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:12",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809022": [
        {
            "ioc_value": "138.9.116.98:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:12",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809023": [
        {
            "ioc_value": "138.9.216.8:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:12",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809019": [
        {
            "ioc_value": "129.212.254.59:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 19:43:09",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809018": [
        {
            "ioc_value": "107.174.234.194:7755",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:06",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808921": [
        {
            "ioc_value": "mpd.hidayahnetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-08 16:30:38",
            "last_seen_utc": "2026-06-06 04:48:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1808743": [
        {
            "ioc_value": "47.94.168.149:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 10:44:30",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808742": [
        {
            "ioc_value": "47.83.254.175:1102",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 10:44:29",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808741": [
        {
            "ioc_value": "1364170351-kld29tgkc1.ap-guangzhou.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 10:43:48",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808671": [
        {
            "ioc_value": "89.203.129.126:9997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-08 08:43:59",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808667": [
        {
            "ioc_value": "81.17.101.139:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 08:43:57",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808668": [
        {
            "ioc_value": "82.38.148.254:5902",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:57",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808669": [
        {
            "ioc_value": "82.38.148.254:5903",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:57",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808670": [
        {
            "ioc_value": "83.143.58.253:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:57",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808666": [
        {
            "ioc_value": "69.197.150.245:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:56",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808665": [
        {
            "ioc_value": "62.169.25.116:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:55",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808664": [
        {
            "ioc_value": "5.252.179.132:1616",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:54",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808661": [
        {
            "ioc_value": "5.101.86.95:4034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:53",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808662": [
        {
            "ioc_value": "5.101.86.99:7192",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:53",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808663": [
        {
            "ioc_value": "5.252.153.0:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:53",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808660": [
        {
            "ioc_value": "5.101.86.70:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:52",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808659": [
        {
            "ioc_value": "5.101.86.41:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:51",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808658": [
        {
            "ioc_value": "5.101.86.103:8834",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:50",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808655": [
        {
            "ioc_value": "5.101.83.117:8374",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:49",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808656": [
        {
            "ioc_value": "5.101.86.103:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:49",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808657": [
        {
            "ioc_value": "5.101.86.103:6913",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:49",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808654": [
        {
            "ioc_value": "5.101.82.226:3581",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:48",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808653": [
        {
            "ioc_value": "5.101.81.23:4315",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:47",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808652": [
        {
            "ioc_value": "45.79.163.107:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:46",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808649": [
        {
            "ioc_value": "45.23.73.4:5645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:45",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808650": [
        {
            "ioc_value": "45.56.91.55:2005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:45",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808648": [
        {
            "ioc_value": "31.57.216.62:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:42",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808647": [
        {
            "ioc_value": "23.249.29.138:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-08 08:43:41",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808643": [
        {
            "ioc_value": "209.38.110.161:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:21",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808644": [
        {
            "ioc_value": "209.99.186.98:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:21",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808645": [
        {
            "ioc_value": "209.99.190.172:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-08 08:43:21",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808646": [
        {
            "ioc_value": "209.99.190.53:666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-08 08:43:21",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808641": [
        {
            "ioc_value": "195.250.25.214:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 08:43:19",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808642": [
        {
            "ioc_value": "198.46.173.6:2208",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:19",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808640": [
        {
            "ioc_value": "194.37.80.126:7543",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-08 08:43:18",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808639": [
        {
            "ioc_value": "185.212.129.114:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 08:43:15",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808638": [
        {
            "ioc_value": "179.0.178.240:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:14",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808637": [
        {
            "ioc_value": "178.104.186.90:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:13",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808635": [
        {
            "ioc_value": "170.168.103.124:5342",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:12",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808636": [
        {
            "ioc_value": "172.245.209.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:12",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808634": [
        {
            "ioc_value": "167.114.129.165:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:11",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808633": [
        {
            "ioc_value": "146.185.239.55:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:08",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808629": [
        {
            "ioc_value": "138.9.118.8:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:07",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808630": [
        {
            "ioc_value": "138.9.216.212:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:07",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808631": [
        {
            "ioc_value": "138.9.226.206:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:07",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808632": [
        {
            "ioc_value": "138.9.41.75:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:07",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808627": [
        {
            "ioc_value": "108.61.193.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:05",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808628": [
        {
            "ioc_value": "113.31.118.180:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:05",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808623": [
        {
            "ioc_value": "104.243.248.63:1802",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 08:43:04",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808624": [
        {
            "ioc_value": "106.55.186.190:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:04",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808625": [
        {
            "ioc_value": "107.161.50.202:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:04",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808626": [
        {
            "ioc_value": "107.172.235.68:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:04",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808621": [
        {
            "ioc_value": "103.83.87.7:2492",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:03",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808622": [
        {
            "ioc_value": "103.83.87.81:4141",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:03",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808423": [
        {
            "ioc_value": "http://secure.controlpanel.asia/330311481fe14ab99814.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-08 08:00:21",
            "last_seen_utc": "2026-06-05 08:25:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,CDCDCDC,loader,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1808600": [
        {
            "ioc_value": "45.202.249.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 07:49:28",
            "last_seen_utc": "2026-06-06 15:45:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808598": [
        {
            "ioc_value": "45.202.249.88:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 07:49:24",
            "last_seen_utc": "2026-06-06 15:45:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808288": [
        {
            "ioc_value": "49.7.54.204:8901",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-07 20:45:06",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808287": [
        {
            "ioc_value": "106.14.116.17:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-07 20:44:34",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808286": [
        {
            "ioc_value": "101.33.225.32:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-07 20:44:32",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808282": [
        {
            "ioc_value": "158.94.211.95:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.lokipws",
            "malware_alias": "Burkina,Loki,LokiBot,LokiPWS",
            "malware_printable": "Loki Password Stealer (PWS)",
            "first_seen_utc": "2026-05-07 20:36:02",
            "last_seen_utc": "2026-06-05 23:48:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=158.94.211.95",
            "tags": "Lokibot,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808259": [
        {
            "ioc_value": "5.101.86.106:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-07 18:44:06",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808258": [
        {
            "ioc_value": "5.101.83.114:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-07 18:44:05",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808257": [
        {
            "ioc_value": "217.145.72.202:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-07 18:43:51",
            "last_seen_utc": "2026-06-06 15:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808256": [
        {
            "ioc_value": "186.169.76.228:5010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-07 18:43:25",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808255": [
        {
            "ioc_value": "168.144.36.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-07 18:43:18",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808254": [
        {
            "ioc_value": "155.103.71.115:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-07 18:43:14",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808253": [
        {
            "ioc_value": "146.185.233.41:5382",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-07 18:43:11",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808252": [
        {
            "ioc_value": "138.197.21.32:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-07 18:43:09",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808143": [
        {
            "ioc_value": "94.154.35.160:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-07 10:44:22",
            "last_seen_utc": "2026-06-06 08:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808142": [
        {
            "ioc_value": "83.147.38.94:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-07 10:44:18",
            "last_seen_utc": "2026-06-06 15:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808141": [
        {
            "ioc_value": "66.85.27.30:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-07 10:44:15",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808140": [
        {
            "ioc_value": "5.101.81.81:9323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-07 10:44:07",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808139": [
        {
            "ioc_value": "203.159.90.139:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-07 10:43:34",
            "last_seen_utc": "2026-06-06 08:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808138": [
        {
            "ioc_value": "104.167.199.243:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-07 10:43:04",
            "last_seen_utc": "2026-06-06 08:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807882": [
        {
            "ioc_value": "http://178.16.55.25/bcbb13c7c8984290857b.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-06 20:53:25",
            "last_seen_utc": "2026-06-06 16:12:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,FFF0506,loader,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1807868": [
        {
            "ioc_value": "27.102.137.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 20:53:22",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Remcos,RemcosRAT,Remvio,Socmer",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1807906": [
        {
            "ioc_value": "45.207.192.190:30078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:39",
            "last_seen_utc": "2026-06-06 15:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807905": [
        {
            "ioc_value": "207.56.226.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:29",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807904": [
        {
            "ioc_value": "117.72.168.103:16337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:09",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807903": [
        {
            "ioc_value": "static.slbc7890.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:44:56",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807846": [
        {
            "ioc_value": "5.101.86.102:2501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 18:44:01",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807847": [
        {
            "ioc_value": "5.101.86.107:4934",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 18:44:01",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807845": [
        {
            "ioc_value": "31.57.216.62:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 18:43:51",
            "last_seen_utc": "2026-06-05 18:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807844": [
        {
            "ioc_value": "192.109.200.143:2345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-06 18:43:26",
            "last_seen_utc": "2026-06-05 18:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807843": [
        {
            "ioc_value": "178.16.52.203:1889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-06 18:43:21",
            "last_seen_utc": "2026-06-05 18:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807842": [
        {
            "ioc_value": "154.18.238.18:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-06 18:43:14",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807841": [
        {
            "ioc_value": "104.194.157.45:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-06 18:43:05",
            "last_seen_utc": "2026-06-06 08:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807793": [
        {
            "ioc_value": "68.64.178.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:54",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807792": [
        {
            "ioc_value": "39.101.78.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:44",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807791": [
        {
            "ioc_value": "124.223.90.150:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:32",
            "last_seen_utc": "2026-06-06 15:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807789": [
        {
            "ioc_value": "103.53.81.232:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:24",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807790": [
        {
            "ioc_value": "103.53.81.232:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:24",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807788": [
        {
            "ioc_value": "1.15.100.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:22",
            "last_seen_utc": "2026-06-06 15:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807787": [
        {
            "ioc_value": "www.pronhub.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:21",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807786": [
        {
            "ioc_value": "update.javashell.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:20",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807783": [
        {
            "ioc_value": "1325813086-kvn4jlpgeu.ap-shanghai.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:13",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807784": [
        {
            "ioc_value": "1364170351-ivarm6apjz.ap-guangzhou.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:13",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807785": [
        {
            "ioc_value": "4176rbz8vepn6.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:13",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807540": [
        {
            "ioc_value": "5.101.86.41:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 08:44:09",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807541": [
        {
            "ioc_value": "5.101.86.41:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 08:44:09",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807539": [
        {
            "ioc_value": "5.101.86.104:1334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 08:44:08",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807538": [
        {
            "ioc_value": "31.57.184.154:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-06 08:43:54",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807364": [
        {
            "ioc_value": "77.93.152.138:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-06 06:01:23",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "401479,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1807365": [
        {
            "ioc_value": "192.109.200.143:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-06 06:01:22",
            "last_seen_utc": "2026-06-05 18:43:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "51396,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1807261": [
        {
            "ioc_value": "www.cement-chemistry.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-05 20:44:19",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807238": [
        {
            "ioc_value": "mne.hidayahnetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-05 20:00:38",
            "last_seen_utc": "2026-06-06 06:07:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1807206": [
        {
            "ioc_value": "5.101.86.98:4126",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 18:49:30",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807204": [
        {
            "ioc_value": "5.101.82.228:9362",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 18:49:12",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807205": [
        {
            "ioc_value": "5.101.82.229:3039",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 18:49:12",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807203": [
        {
            "ioc_value": "5.101.81.81:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 18:49:05",
            "last_seen_utc": "2026-06-04 18:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807201": [
        {
            "ioc_value": "38.190.224.70:4338",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 18:48:26",
            "last_seen_utc": "2026-06-04 18:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807073": [
        {
            "ioc_value": "http://5.252.177.67/bb7f17919d0a4d0aaf22.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-05 17:17:43",
            "last_seen_utc": "2026-06-06 15:10:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,StealC,stealer,win20",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1807037": [
        {
            "ioc_value": "http://213.165.47.49/480bee37986b4097bc20.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-05 13:58:25",
            "last_seen_utc": "2026-06-06 16:14:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,StealC,stealer,test",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1807043": [
        {
            "ioc_value": "candipoker.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-05 13:58:21",
            "last_seen_utc": "2026-06-05 21:26:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,fingerfix",
            "anonymous": "0",
            "reporter": "Lenny_3BO"
        }
    ],
    "1807059": [
        {
            "ioc_value": "http://89.46.38.100/c0b30d15260a4d8888dc.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-05 13:58:14",
            "last_seen_utc": "2026-06-06 15:45:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,M1,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1806983": [
        {
            "ioc_value": "http://196.251.107.130/16b022998f754137b60a.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-05 12:59:27",
            "last_seen_utc": "2026-06-06 16:12:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,RUN,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1806998": [
        {
            "ioc_value": "http://213.165.47.174/0cddd9346bd3479aab11.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-05 12:59:20",
            "last_seen_utc": "2026-06-06 16:06:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,steal,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1807013": [
        {
            "ioc_value": "http://193.111.117.51/94a5dbd165044e85b88e.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-05 12:59:16",
            "last_seen_utc": "2026-06-06 15:59:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,neverhigh,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1806956": [
        {
            "ioc_value": "5.180.82.239:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 10:47:56",
            "last_seen_utc": "2026-06-04 18:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806955": [
        {
            "ioc_value": "5.101.86.97:6913",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 10:47:55",
            "last_seen_utc": "2026-06-05 08:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806953": [
        {
            "ioc_value": "5.101.82.99:6031",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 10:47:42",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806952": [
        {
            "ioc_value": "5.101.82.227:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 10:47:38",
            "last_seen_utc": "2026-06-05 18:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806951": [
        {
            "ioc_value": "46.151.182.33:9545",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 10:47:27",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806901": [
        {
            "ioc_value": "172.245.156.179:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-05 08:44:56",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806900": [
        {
            "ioc_value": "webshareclouds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-05 08:44:35",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806899": [
        {
            "ioc_value": "perfectgo.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-05 08:44:34",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806698": [
        {
            "ioc_value": "woodfez.biz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-05-05 06:12:25",
            "last_seen_utc": "2026-06-06 04:48:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RemusStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806444": [
        {
            "ioc_value": "104.168.5.25:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 00:05:43",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ee0e4e3198fd8942c1241f276857745823901fbbdd73b6827517998e17f91e09/",
            "tags": "remcos",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806229": [
        {
            "ioc_value": "8.130.80.145:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:45:07",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806228": [
        {
            "ioc_value": "154.219.115.123:61443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:43",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806227": [
        {
            "ioc_value": "119.29.198.193:8555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:36",
            "last_seen_utc": "2026-06-06 15:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806112": [
        {
            "ioc_value": "5.101.86.101:1398",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-04 18:44:06",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805878": [
        {
            "ioc_value": "77.74.201.243:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 12:45:16",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805876": [
        {
            "ioc_value": "t.shakesnap.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 12:44:30",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805877": [
        {
            "ioc_value": "t2.shakesnap.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 12:44:30",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805817": [
        {
            "ioc_value": "93.127.134.156:3389",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-04 10:44:16",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805813": [
        {
            "ioc_value": "178.16.54.192:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-04 10:43:21",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805769": [
        {
            "ioc_value": "8.130.173.155:30006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 08:45:10",
            "last_seen_utc": "2026-06-05 12:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805768": [
        {
            "ioc_value": "31.7.62.178:14443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 08:44:52",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805766": [
        {
            "ioc_value": "82.165.79.60:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:13",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805765": [
        {
            "ioc_value": "82.165.79.60:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:12",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805762": [
        {
            "ioc_value": "5.101.86.73:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-04 08:44:06",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805763": [
        {
            "ioc_value": "5.101.86.73:8371",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-04 08:44:06",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805761": [
        {
            "ioc_value": "5.101.86.4:3841",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-04 08:44:05",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805757": [
        {
            "ioc_value": "163.181.45.55:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-04 08:43:16",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805413": [
        {
            "ioc_value": "190.255.86.67:5469",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-03 18:43:37",
            "last_seen_utc": "2026-06-06 08:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805272": [
        {
            "ioc_value": "80.78.22.41:783",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:50",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805271": [
        {
            "ioc_value": "49.232.90.5:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:46",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805269": [
        {
            "ioc_value": "38.165.21.163:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:37",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805268": [
        {
            "ioc_value": "151.245.90.45:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:29",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805267": [
        {
            "ioc_value": "ap.johamp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:08",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805202": [
        {
            "ioc_value": "46.151.182.148:25608",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-03 08:43:54",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805200": [
        {
            "ioc_value": "217.145.226.192:7747",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-03 08:43:44",
            "last_seen_utc": "2026-06-05 18:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805198": [
        {
            "ioc_value": "159.69.90.48:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-03 08:43:14",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804969": [
        {
            "ioc_value": "34.124.142.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:32",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804970": [
        {
            "ioc_value": "34.124.142.136:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:32",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804968": [
        {
            "ioc_value": "203.160.54.22:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:31",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804967": [
        {
            "ioc_value": "195.123.220.237:2053",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:30",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804966": [
        {
            "ioc_value": "165.154.22.163:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:27",
            "last_seen_utc": "2026-06-05 12:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804965": [
        {
            "ioc_value": "h67as5d5x.m6p3wca1.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:06",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804928": [
        {
            "ioc_value": "38.147.173.24:8562",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-02 18:43:44",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804922": [
        {
            "ioc_value": "157.230.26.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-02 18:43:13",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804919": [
        {
            "ioc_value": "134.122.99.247:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-02 18:43:07",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804853": [
        {
            "ioc_value": "47.101.172.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 14:44:30",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804732": [
        {
            "ioc_value": "8.160.216.91:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:53",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804728": [
        {
            "ioc_value": "31.57.184.161:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-02 08:43:40",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804729": [
        {
            "ioc_value": "31.57.184.161:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-02 08:43:40",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804727": [
        {
            "ioc_value": "31.57.184.161:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-02 08:43:39",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804719": [
        {
            "ioc_value": "124.95.172.200:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:06",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804652": [
        {
            "ioc_value": "38.55.177.51:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 07:06:20",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804643": [
        {
            "ioc_value": "firewai.biz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-05-02 06:55:05",
            "last_seen_utc": "2026-06-06 04:48:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/5eb440933efc934628399697e2bca83ac41cefbb7c653dae1b91113596c4755e/",
            "tags": "RemusStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803956": [
        {
            "ioc_value": "https://arsimonopa.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:17",
            "last_seen_utc": "2026-06-06 15:56:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1803960": [
        {
            "ioc_value": "https://lemonimonakio.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:15",
            "last_seen_utc": "2026-06-06 16:09:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1804005": [
        {
            "ioc_value": "47.239.222.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 05:24:07",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "AS45102,Cobalt Strike,cobeacon",
            "anonymous": "1",
            "reporter": "xcyber901"
        }
    ],
    "1803898": [
        {
            "ioc_value": "91.92.242.228:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:44:00",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803899": [
        {
            "ioc_value": "93.71.143.3:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-01 18:44:00",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803896": [
        {
            "ioc_value": "89.114.115.200:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 18:43:58",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803894": [
        {
            "ioc_value": "59.152.212.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 18:43:53",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803892": [
        {
            "ioc_value": "5.101.86.65:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:52",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803893": [
        {
            "ioc_value": "5.101.86.65:8643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:52",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803889": [
        {
            "ioc_value": "5.101.86.15:6798",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:51",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803890": [
        {
            "ioc_value": "5.101.86.15:9267",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:51",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803891": [
        {
            "ioc_value": "5.101.86.34:5749",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:51",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803887": [
        {
            "ioc_value": "5.101.82.190:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:50",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803888": [
        {
            "ioc_value": "5.101.86.15:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:50",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803884": [
        {
            "ioc_value": "45.9.168.220:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:48",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803881": [
        {
            "ioc_value": "45.10.164.177:45123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 18:43:45",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803880": [
        {
            "ioc_value": "39.101.82.73:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-01 18:43:44",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803874": [
        {
            "ioc_value": "31.57.184.154:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 18:43:41",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803875": [
        {
            "ioc_value": "31.57.184.187:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:41",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803866": [
        {
            "ioc_value": "195.88.191.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803867": [
        {
            "ioc_value": "195.88.191.41:7666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803863": [
        {
            "ioc_value": "192.227.232.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 18:43:22",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803860": [
        {
            "ioc_value": "190.255.86.67:5011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 18:43:20",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803858": [
        {
            "ioc_value": "185.212.128.80:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 18:43:19",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803859": [
        {
            "ioc_value": "185.212.128.85:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 18:43:19",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803856": [
        {
            "ioc_value": "173.211.106.231:21320",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 18:43:16",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803853": [
        {
            "ioc_value": "169.40.135.17:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:14",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803849": [
        {
            "ioc_value": "146.185.233.71:35412",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:09",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803848": [
        {
            "ioc_value": "134.122.162.29:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 18:43:07",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803845": [
        {
            "ioc_value": "109.227.59.160:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 18:43:05",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803846": [
        {
            "ioc_value": "114.132.29.20:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 18:43:05",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803842": [
        {
            "ioc_value": "104.168.5.25:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:04",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803843": [
        {
            "ioc_value": "107.175.113.106:55",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-01 18:43:04",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803841": [
        {
            "ioc_value": "103.79.79.105:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-01 18:43:03",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803840": [
        {
            "ioc_value": "103.110.65.166:52223",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-01 18:43:02",
            "last_seen_utc": "2026-06-06 15:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803693": [
        {
            "ioc_value": "8.222.192.153:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:50",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803692": [
        {
            "ioc_value": "64.83.42.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:47",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803689": [
        {
            "ioc_value": "47.236.91.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:44",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803687": [
        {
            "ioc_value": "118.25.178.35:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:20",
            "last_seen_utc": "2026-06-06 15:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803685": [
        {
            "ioc_value": "secure-server.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:09",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803670": [
        {
            "ioc_value": "frr.ambil-disini.web.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-06-06 15:22:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1803671": [
        {
            "ioc_value": "https://frr.ambil-disini.web.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-06-06 15:22:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1803520": [
        {
            "ioc_value": "84.201.14.11:2177",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 08:43:51",
            "last_seen_utc": "2026-06-04 18:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803514": [
        {
            "ioc_value": "72.56.246.58:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 08:43:49",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803512": [
        {
            "ioc_value": "62.60.226.63:6856",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:48",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803513": [
        {
            "ioc_value": "64.89.163.114:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 08:43:48",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803506": [
        {
            "ioc_value": "5.101.86.57:1984",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803507": [
        {
            "ioc_value": "5.101.86.60:6798",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803508": [
        {
            "ioc_value": "5.101.86.76:1338",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803509": [
        {
            "ioc_value": "5.101.86.76:9323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803510": [
        {
            "ioc_value": "5.101.86.76:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803511": [
        {
            "ioc_value": "5.101.86.78:9323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803502": [
        {
            "ioc_value": "5.101.81.81:4315",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:45",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803503": [
        {
            "ioc_value": "5.101.86.34:6913",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:45",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803504": [
        {
            "ioc_value": "5.101.86.4:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:45",
            "last_seen_utc": "2026-06-06 15:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803505": [
        {
            "ioc_value": "5.101.86.4:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:45",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803499": [
        {
            "ioc_value": "46.151.182.71:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803500": [
        {
            "ioc_value": "47.103.106.26:2333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803501": [
        {
            "ioc_value": "47.83.254.175:6321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803498": [
        {
            "ioc_value": "46.151.182.33:4747",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:43",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803493": [
        {
            "ioc_value": "4.236.165.30:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:40",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803491": [
        {
            "ioc_value": "31.58.58.168:51272",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:38",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803490": [
        {
            "ioc_value": "3.19.238.211:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-01 08:43:37",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803486": [
        {
            "ioc_value": "20.2.83.254:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 08:43:23",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803483": [
        {
            "ioc_value": "194.116.236.110:6161",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:21",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803478": [
        {
            "ioc_value": "190.2.150.52:853",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:20",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803479": [
        {
            "ioc_value": "192.159.99.131:1458",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:20",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803476": [
        {
            "ioc_value": "178.16.53.63:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:17",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803473": [
        {
            "ioc_value": "178.128.252.142:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 08:43:16",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803475": [
        {
            "ioc_value": "178.16.53.183:111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:16",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803470": [
        {
            "ioc_value": "169.40.135.35:6158",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:14",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803466": [
        {
            "ioc_value": "163.5.102.110:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:13",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803467": [
        {
            "ioc_value": "163.5.102.110:2407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:13",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803468": [
        {
            "ioc_value": "163.5.102.99:6325",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:13",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803464": [
        {
            "ioc_value": "158.94.209.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-01 08:43:12",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803465": [
        {
            "ioc_value": "158.94.209.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-01 08:43:12",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803460": [
        {
            "ioc_value": "155.103.70.100:50030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:11",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803461": [
        {
            "ioc_value": "155.103.70.100:50033",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:11",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803462": [
        {
            "ioc_value": "155.103.70.68:2323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:11",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803457": [
        {
            "ioc_value": "151.243.109.10:9323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:10",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803458": [
        {
            "ioc_value": "151.243.109.213:6325",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:10",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803456": [
        {
            "ioc_value": "146.190.133.216:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 08:43:09",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803455": [
        {
            "ioc_value": "143.202.105.137:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 08:43:08",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803452": [
        {
            "ioc_value": "136.0.41.76:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 08:43:07",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803448": [
        {
            "ioc_value": "111.229.144.163:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 08:43:05",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803442": [
        {
            "ioc_value": "103.140.238.45:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-01 08:43:03",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803443": [
        {
            "ioc_value": "103.140.238.45:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-01 08:43:03",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803389": [
        {
            "ioc_value": "165.154.24.229:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 07:08:50",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803387": [
        {
            "ioc_value": "203.160.54.22:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 07:08:49",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803385": [
        {
            "ioc_value": "106.75.31.247:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 07:08:46",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803386": [
        {
            "ioc_value": "146.19.125.9:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 07:08:46",
            "last_seen_utc": "2026-06-06 15:45:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803286": [
        {
            "ioc_value": "94.176.3.228:48765",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:32",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803290": [
        {
            "ioc_value": "98.81.111.167:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:32",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803291": [
        {
            "ioc_value": "98.97.125.70:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:32",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803279": [
        {
            "ioc_value": "91.202.233.153:43555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803280": [
        {
            "ioc_value": "91.215.85.151:47653",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803284": [
        {
            "ioc_value": "94.154.35.160:6466",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803285": [
        {
            "ioc_value": "94.154.35.73:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803275": [
        {
            "ioc_value": "85.121.5.202:5689",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:30",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803276": [
        {
            "ioc_value": "85.155.186.2:3821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:30",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803269": [
        {
            "ioc_value": "83.97.20.133:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:29",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803271": [
        {
            "ioc_value": "83.98.39.53:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:29",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803272": [
        {
            "ioc_value": "83.98.39.54:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:29",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803262": [
        {
            "ioc_value": "79.135.160.20:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:28",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803264": [
        {
            "ioc_value": "80.96.113.212:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:28",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803265": [
        {
            "ioc_value": "81.229.251.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:28",
            "last_seen_utc": "2026-06-05 18:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803257": [
        {
            "ioc_value": "66.163.115.78:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803259": [
        {
            "ioc_value": "68.64.178.130:9900",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803260": [
        {
            "ioc_value": "72.56.246.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803261": [
        {
            "ioc_value": "72.56.246.58:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803251": [
        {
            "ioc_value": "52.198.162.251:16000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803254": [
        {
            "ioc_value": "62.81.188.1:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803255": [
        {
            "ioc_value": "66.163.115.78:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803256": [
        {
            "ioc_value": "66.163.115.78:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803245": [
        {
            "ioc_value": "45.95.232.195:54655",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:25",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803246": [
        {
            "ioc_value": "46.101.77.223:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:25",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803249": [
        {
            "ioc_value": "5.42.221.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:25",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803239": [
        {
            "ioc_value": "45.155.69.175:42455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803240": [
        {
            "ioc_value": "45.56.91.55:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803244": [
        {
            "ioc_value": "45.81.243.52:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803235": [
        {
            "ioc_value": "45.125.67.171:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803236": [
        {
            "ioc_value": "45.144.137.216:38271",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803238": [
        {
            "ioc_value": "45.155.69.106:42211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-06-06 15:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803230": [
        {
            "ioc_value": "38.76.217.23:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803231": [
        {
            "ioc_value": "43.134.133.177:8445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803232": [
        {
            "ioc_value": "43.142.77.170:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803233": [
        {
            "ioc_value": "43.142.77.170:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803234": [
        {
            "ioc_value": "43.160.225.40:39001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803224": [
        {
            "ioc_value": "31.57.184.48:6523",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:21",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803225": [
        {
            "ioc_value": "37.72.140.15:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:21",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803228": [
        {
            "ioc_value": "38.54.119.24:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:21",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803229": [
        {
            "ioc_value": "38.60.134.130:62858",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:21",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803218": [
        {
            "ioc_value": "222.255.100.119:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803219": [
        {
            "ioc_value": "23.227.203.6:42235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803222": [
        {
            "ioc_value": "31.57.184.154:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-06-06 15:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803211": [
        {
            "ioc_value": "216.107.208.250:10444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-06-06 15:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803214": [
        {
            "ioc_value": "217.60.38.14:14421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803215": [
        {
            "ioc_value": "219.142.15.101:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803216": [
        {
            "ioc_value": "220.231.47.163:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803217": [
        {
            "ioc_value": "221.130.42.19:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803204": [
        {
            "ioc_value": "207.107.147.42:4438",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803205": [
        {
            "ioc_value": "208.249.244.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803206": [
        {
            "ioc_value": "209.151.145.164:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803208": [
        {
            "ioc_value": "212.227.93.107:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803210": [
        {
            "ioc_value": "213.199.35.149:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803199": [
        {
            "ioc_value": "2.27.29.65:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803200": [
        {
            "ioc_value": "202.171.43.176:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803201": [
        {
            "ioc_value": "202.181.24.236:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803202": [
        {
            "ioc_value": "202.95.17.188:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803203": [
        {
            "ioc_value": "206.189.40.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803190": [
        {
            "ioc_value": "193.112.115.127:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:15",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803191": [
        {
            "ioc_value": "193.112.169.214:30892",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:15",
            "last_seen_utc": "2026-06-05 18:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803192": [
        {
            "ioc_value": "193.23.137.40:3334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:15",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803180": [
        {
            "ioc_value": "185.242.3.83:9909",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:14",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803181": [
        {
            "ioc_value": "185.247.224.40:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:14",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803173": [
        {
            "ioc_value": "185.212.128.81:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803174": [
        {
            "ioc_value": "185.212.129.23:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803175": [
        {
            "ioc_value": "185.212.129.24:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803176": [
        {
            "ioc_value": "185.212.129.29:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803177": [
        {
            "ioc_value": "185.212.129.30:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803178": [
        {
            "ioc_value": "185.213.20.250:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803179": [
        {
            "ioc_value": "185.242.245.120:42534",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803166": [
        {
            "ioc_value": "180.184.29.135:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-06 15:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803167": [
        {
            "ioc_value": "182.255.45.114:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803168": [
        {
            "ioc_value": "185.122.171.4:44355",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803171": [
        {
            "ioc_value": "185.212.128.25:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803172": [
        {
            "ioc_value": "185.212.128.48:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-06 15:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803161": [
        {
            "ioc_value": "178.16.52.105:207",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:11",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803162": [
        {
            "ioc_value": "178.16.52.22:8396",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:11",
            "last_seen_utc": "2026-06-06 15:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803158": [
        {
            "ioc_value": "173.211.106.231:21321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:10",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803159": [
        {
            "ioc_value": "173.242.59.199:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:10",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803148": [
        {
            "ioc_value": "162.243.100.39:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803149": [
        {
            "ioc_value": "162.243.64.101:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803152": [
        {
            "ioc_value": "172.111.162.252:3030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803153": [
        {
            "ioc_value": "172.9.165.216:8096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803154": [
        {
            "ioc_value": "172.93.144.164:8580",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803140": [
        {
            "ioc_value": "153.75.224.159:5400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803141": [
        {
            "ioc_value": "154.219.115.123:60001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803142": [
        {
            "ioc_value": "156.238.236.249:7930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803145": [
        {
            "ioc_value": "161.248.179.92:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803146": [
        {
            "ioc_value": "161.248.179.92:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803147": [
        {
            "ioc_value": "162.14.124.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803134": [
        {
            "ioc_value": "149.104.28.204:3656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:07",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803139": [
        {
            "ioc_value": "151.236.4.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:07",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803127": [
        {
            "ioc_value": "142.93.88.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:06",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803121": [
        {
            "ioc_value": "134.175.253.242:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803124": [
        {
            "ioc_value": "138.124.113.131:4211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803125": [
        {
            "ioc_value": "138.197.119.51:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803126": [
        {
            "ioc_value": "139.64.164.72:63337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803114": [
        {
            "ioc_value": "115.42.60.122:5440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803115": [
        {
            "ioc_value": "117.72.101.55:9520",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803116": [
        {
            "ioc_value": "119.91.247.247:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-06-05 08:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803119": [
        {
            "ioc_value": "130.94.23.39:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803107": [
        {
            "ioc_value": "103.151.52.35:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803108": [
        {
            "ioc_value": "103.57.250.99:41895",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803109": [
        {
            "ioc_value": "103.75.190.47:54630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803110": [
        {
            "ioc_value": "104.234.174.93:57712",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803111": [
        {
            "ioc_value": "106.55.71.62:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803112": [
        {
            "ioc_value": "114.132.133.191:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803113": [
        {
            "ioc_value": "115.190.247.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802897": [
        {
            "ioc_value": "82.156.219.31:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:45",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802895": [
        {
            "ioc_value": "39.105.74.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:33",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802896": [
        {
            "ioc_value": "39.105.74.52:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:33",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802894": [
        {
            "ioc_value": "193.53.127.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:30",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802893": [
        {
            "ioc_value": "149.88.73.40:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:25",
            "last_seen_utc": "2026-06-05 12:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802892": [
        {
            "ioc_value": "www.microsslcheck.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:10",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802891": [
        {
            "ioc_value": "releases-export-finishing-phillips.trycloudflare.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:09",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802724": [
        {
            "ioc_value": "101.43.29.69:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 12:55:24",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802153": [
        {
            "ioc_value": "103.140.238.45:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-04-29 15:18:41",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Sliver",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1802141": [
        {
            "ioc_value": "82.156.62.131:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-29 14:43:42",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802139": [
        {
            "ioc_value": "217.154.212.25:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-29 14:43:28",
            "last_seen_utc": "2026-06-06 15:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802138": [
        {
            "ioc_value": "156.245.147.98:9010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-29 14:43:24",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802137": [
        {
            "ioc_value": "100.113.210.8:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-29 14:43:11",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802063": [
        {
            "ioc_value": "47.109.20.107:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-29 10:43:33",
            "last_seen_utc": "2026-06-05 12:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1801960": [
        {
            "ioc_value": "156.245.147.101:9010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-29 07:49:06",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1801679": [
        {
            "ioc_value": "1318289497-6hwi9hel8e.ap-beijing.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-28 14:43:02",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800975": [
        {
            "ioc_value": "45.43.59.179:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 11:02:18",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800972": [
        {
            "ioc_value": "ns1.twnic.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 10:46:10",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800970": [
        {
            "ioc_value": "cc.twnic.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 10:43:32",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800903": [
        {
            "ioc_value": "107.172.252.244:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 08:25:23",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800899": [
        {
            "ioc_value": "147.78.2.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 08:23:19",
            "last_seen_utc": "2026-06-06 15:45:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800898": [
        {
            "ioc_value": "45.130.148.102:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 08:22:39",
            "last_seen_utc": "2026-06-06 15:45:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-305419896",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800672": [
        {
            "ioc_value": "82.165.179.9:1604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-04-27 04:47:42",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/dc7926a343bf4a612ebd57924bd5e3a6df997164b090c662855f2f3e6e91c930/",
            "tags": "asyncrat",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800528": [
        {
            "ioc_value": "http://pillow.riverbridge.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 19:14:08",
            "last_seen_utc": "2026-06-06 15:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ipocalur,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800509": [
        {
            "ioc_value": "pillow.riverbridge.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 18:19:19",
            "last_seen_utc": "2026-06-06 15:22:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2199baf11d50dd10555f8aec122178e03b62570fc0d4614a8e928978dc547154/",
            "tags": "ipocalur,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800411": [
        {
            "ioc_value": "http://91.92.242.236/oPvjr94jfe/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-26 18:11:00",
            "last_seen_utc": "2026-06-06 15:50:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "54e64e,amadey,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1800496": [
        {
            "ioc_value": "2.26.133.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-26 18:08:56",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800301": [
        {
            "ioc_value": "156.245.147.98:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-26 08:48:33",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800299": [
        {
            "ioc_value": "dd.googleos-js.vip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-26 08:43:33",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800298": [
        {
            "ioc_value": "d2.googleos-js.vip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-26 08:43:30",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1799966": [
        {
            "ioc_value": "91.92.242.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-04-25 14:39:53",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1800020": [
        {
            "ioc_value": "8.136.97.98:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-25 14:21:21",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800017": [
        {
            "ioc_value": "124.222.75.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-25 14:17:33",
            "last_seen_utc": "2026-06-06 15:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1797248": [
        {
            "ioc_value": "psy.flise-mesteren.dk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:06",
            "last_seen_utc": "2026-06-06 15:22:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1797247": [
        {
            "ioc_value": "https://psy.flise-mesteren.dk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:01",
            "last_seen_utc": "2026-06-06 15:22:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1797062": [
        {
            "ioc_value": "31.56.209.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-04-24 08:14:10",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Remcos,RemcosRAT,Remvio,Socmer",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1796426": [
        {
            "ioc_value": "http://196.251.107.248/kont2rt/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-23 04:45:34",
            "last_seen_utc": "2026-06-06 15:45:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796313": [
        {
            "ioc_value": "192.210.174.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 20:53:22",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796311": [
        {
            "ioc_value": "141.227.135.62:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 20:50:52",
            "last_seen_utc": "2026-06-06 15:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796097": [
        {
            "ioc_value": "47.94.162.43:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 14:30:19",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1796068": [
        {
            "ioc_value": "wrath.bottlevacuum.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:13",
            "last_seen_utc": "2026-06-06 15:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796067": [
        {
            "ioc_value": "http://wrath.bottlevacuum.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:09",
            "last_seen_utc": "2026-06-06 15:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796009": [
        {
            "ioc_value": "82.156.62.131:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 10:36:10",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1795599": [
        {
            "ioc_value": "43.225.158.58:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-21 14:54:03",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1795596": [
        {
            "ioc_value": "ws1.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-21 14:46:24",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1795595": [
        {
            "ioc_value": "ws.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-21 14:46:21",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1795513": [
        {
            "ioc_value": "103.97.176.69:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-21 11:31:32",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1794638": [
        {
            "ioc_value": "http://213.5.130.87",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-19 18:25:29",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1794558": [
        {
            "ioc_value": "82.156.90.136:9180",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-19 15:48:58",
            "last_seen_utc": "2026-06-06 15:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1794452": [
        {
            "ioc_value": "152.136.159.25:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-19 11:09:55",
            "last_seen_utc": "2026-06-05 12:46:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793918": [
        {
            "ioc_value": "121.4.92.72:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-18 02:46:54",
            "last_seen_utc": "2026-06-06 15:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793739": [
        {
            "ioc_value": "43.230.200.254:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-17 20:50:11",
            "last_seen_utc": "2026-06-06 15:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793738": [
        {
            "ioc_value": "ns2.jane2010.filegear-sg.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-17 20:44:37",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793737": [
        {
            "ioc_value": "ns1.jane2010.filegear-sg.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-17 20:44:14",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793645": [
        {
            "ioc_value": "http://213.5.130.147",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-17 18:15:06",
            "last_seen_utc": "2026-06-06 06:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1793617": [
        {
            "ioc_value": "ask.shurimaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:27",
            "last_seen_utc": "2026-06-06 15:21:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793616": [
        {
            "ioc_value": "https://ask.shurimaster.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:25",
            "last_seen_utc": "2026-06-06 15:21:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793584": [
        {
            "ioc_value": "155.103.71.232:15407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-04-17 15:17:52",
            "last_seen_utc": "2026-06-06 15:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/K_N1kolenko/status/2045099146856599584",
            "tags": "RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792850": [
        {
            "ioc_value": "pir.rapidphonebuyer.co.uk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:58",
            "last_seen_utc": "2026-06-06 15:19:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792849": [
        {
            "ioc_value": "https://pir.rapidphonebuyer.co.uk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:56",
            "last_seen_utc": "2026-06-06 15:19:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792719": [
        {
            "ioc_value": "gusto.brothbridge.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:20",
            "last_seen_utc": "2026-06-06 15:21:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792718": [
        {
            "ioc_value": "http://gusto.brothbridge.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:17",
            "last_seen_utc": "2026-06-06 15:21:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792708": [
        {
            "ioc_value": "47.109.23.77:4567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 10:57:49",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792707": [
        {
            "ioc_value": "43.167.177.224:7778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 10:56:58",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792532": [
        {
            "ioc_value": "bxx2rghe05kng.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 02:43:39",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1791747": [
        {
            "ioc_value": "http://107.189.24.190:80",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 11:43:19",
            "last_seen_utc": "2026-06-06 15:16:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gr00n1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1791738": [
        {
            "ioc_value": "139.224.23.63:8866",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-15 11:39:45",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1791688": [
        {
            "ioc_value": "venom.summertunnel.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:17",
            "last_seen_utc": "2026-06-06 15:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1791687": [
        {
            "ioc_value": "http://venom.summertunnel.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:13",
            "last_seen_utc": "2026-06-06 15:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1790897": [
        {
            "ioc_value": "http://185.183.35.120",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-14 18:35:26",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1790859": [
        {
            "ioc_value": "lts.cloudvaly.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 16:03:14",
            "last_seen_utc": "2026-06-06 16:13:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ho0r1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1790857": [
        {
            "ioc_value": "https://lts.cloudvaly.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 16:03:10",
            "last_seen_utc": "2026-06-06 16:13:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ho0r1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1790171": [
        {
            "ioc_value": "dzodu.sparklingideas.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:23",
            "last_seen_utc": "2026-06-06 15:20:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1790170": [
        {
            "ioc_value": "http://dzodu.sparklingideas.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:18",
            "last_seen_utc": "2026-06-06 15:20:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1790169": [
        {
            "ioc_value": "http://kdije.weirdthings.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:10:11",
            "last_seen_utc": "2026-06-06 15:18:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "okfueh,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1787027": [
        {
            "ioc_value": "https://cannabis-dna.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 11:32:51",
            "last_seen_utc": "2026-06-06 16:15:02",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1785529": [
        {
            "ioc_value": "http://185.183.35.206",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-14 06:06:10",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1785317": [
        {
            "ioc_value": "140.143.207.166:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-14 05:10:44",
            "last_seen_utc": "2026-06-06 15:43:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mythic",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1785064": [
        {
            "ioc_value": "pre.hifive.net.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:47:21",
            "last_seen_utc": "2026-06-06 15:20:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1785049": [
        {
            "ioc_value": "https://pre.hifive.net.au/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:46:34",
            "last_seen_utc": "2026-06-06 15:20:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1784575": [
        {
            "ioc_value": "156.239.47.94:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-12 07:02:44",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1784558": [
        {
            "ioc_value": "47.104.248.7:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-12 06:34:43",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1784256": [
        {
            "ioc_value": "45.74.244.142:18433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-04-11 12:10:14",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1783725": [
        {
            "ioc_value": "120.48.18.226:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-11 07:06:58",
            "last_seen_utc": "2026-06-06 15:45:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1783849": [
        {
            "ioc_value": "https://cdn.mensualgeneratr.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.smokeloader",
            "malware_alias": "Dofoil,Sharik,Smoke,Smoke Loader",
            "malware_printable": "SmokeLoader",
            "first_seen_utc": "2026-04-11 07:06:31",
            "last_seen_utc": "2026-06-06 15:30:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,SmokeLoader",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1784155": [
        {
            "ioc_value": "101.35.214.58:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-11 06:36:58",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-305419896",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1783375": [
        {
            "ioc_value": "39.102.125.11:4435",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-09 14:48:47",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1782524": [
        {
            "ioc_value": "82.165.179.9:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-04-07 23:06:40",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/4c3b97c157d08ee298edb5d30fa86a3b90b04fedfbe517e7e0307b6013eacbf0/",
            "tags": "asyncrat",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1782182": [
        {
            "ioc_value": "dzdi.serendipityhub.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:46:05",
            "last_seen_utc": "2026-06-06 15:20:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1782152": [
        {
            "ioc_value": "http://dzdi.serendipityhub.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:43:55",
            "last_seen_utc": "2026-06-06 15:20:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1781907": [
        {
            "ioc_value": "43.139.108.161:8192",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-06 18:49:49",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1781593": [
        {
            "ioc_value": "47.76.96.68:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-06 02:47:20",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1781225": [
        {
            "ioc_value": "111.230.217.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:05",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1781224": [
        {
            "ioc_value": "109.244.130.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:01",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1780720": [
        {
            "ioc_value": "hor.kaitorinihon.jp",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:13:22",
            "last_seen_utc": "2026-06-06 15:19:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1780716": [
        {
            "ioc_value": "https://hor.kaitorinihon.jp/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:12:59",
            "last_seen_utc": "2026-06-06 15:19:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1780145": [
        {
            "ioc_value": "solstice-line-drift.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.deerstealer",
            "malware_alias": null,
            "malware_printable": "DeerStealer",
            "first_seen_utc": "2026-04-01 15:29:27",
            "last_seen_utc": "2026-06-06 04:44:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/97b9baa6e486c6515f4eff4e625dcec79907d785255c40c070a53cb98f13fa35/",
            "tags": "DeerStealer",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1780037": [
        {
            "ioc_value": "164.92.67.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-04-01 10:45:34",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/164.92.67.70#443",
            "tags": "c2,havoc,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1777986": [
        {
            "ioc_value": "47.122.47.221:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-28 14:56:18",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1777607": [
        {
            "ioc_value": "pn2.skfilmsint.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-06-06 15:18:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777609": [
        {
            "ioc_value": "gre.syslicense.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-06-06 15:17:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777611": [
        {
            "ioc_value": "fefeo.iknowthat.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-06-06 15:18:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777601": [
        {
            "ioc_value": "https://pn2.skfilmsint.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-06-06 15:18:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777603": [
        {
            "ioc_value": "https://gre.syslicense.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-06-06 15:17:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777605": [
        {
            "ioc_value": "http://fefeo.iknowthat.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-06-06 15:18:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777296": [
        {
            "ioc_value": "185.242.3.83:2202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-27 12:01:30",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.242.3.83",
            "tags": "AS60223,AsyncRAT,C2,censys,NETIFACE-AS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1777022": [
        {
            "ioc_value": "161.248.179.38:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-27 00:01:49",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.248.179.38",
            "tags": "AS150895,AsyncRAT,C2,censys,EZTECH-VN,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1777014": [
        {
            "ioc_value": "49.234.199.152:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-27 00:00:31",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/49.234.199.152",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1776672": [
        {
            "ioc_value": "158.94.209.95:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-03-26 14:59:36",
            "last_seen_utc": "2026-06-06 16:04:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "GCleaner,loader",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1776411": [
        {
            "ioc_value": "83.229.127.46:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-25 20:00:39",
            "last_seen_utc": "2026-06-06 15:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.127.46",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-666666666,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1775338": [
        {
            "ioc_value": "47.120.20.86:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-25 07:08:19",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1774903": [
        {
            "ioc_value": "37.72.172.58:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-24 12:01:13",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1774898": [
        {
            "ioc_value": "47.92.208.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-24 12:00:35",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.92.208.27",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1774595": [
        {
            "ioc_value": "154.83.12.132:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-23 21:06:09",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1774355": [
        {
            "ioc_value": "kdije.weirdthings.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 13:42:00",
            "last_seen_utc": "2026-06-06 15:18:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1774216": [
        {
            "ioc_value": "msi.swadeshcomputer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:02:27",
            "last_seen_utc": "2026-06-06 15:17:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1774200": [
        {
            "ioc_value": "https://msi.swadeshcomputer.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:01:55",
            "last_seen_utc": "2026-06-06 15:17:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1774191": [
        {
            "ioc_value": "45.77.22.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-03-23 08:01:13",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.77.22.230",
            "tags": "AS-VULTR,AS20473,C2,censys,Posh",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1774142": [
        {
            "ioc_value": "115.191.25.159:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-23 06:56:52",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1773942": [
        {
            "ioc_value": "100.52.66.182:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-03-22 20:01:13",
            "last_seen_utc": "2026-06-06 15:43:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/100.52.66.182",
            "tags": "AMAZON-AES,AS14618,C2,censys,Havoc",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1773536": [
        {
            "ioc_value": "156.239.252.191:448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-22 18:02:20",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BEACON,C2,CobaltStrike,Shodan",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1773754": [
        {
            "ioc_value": "138.226.236.52:13212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-22 12:01:29",
            "last_seen_utc": "2026-06-06 15:43:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/138.226.236.52",
            "tags": "AdaptixC2,AS205775,C2,censys,NEONCORENETWORKS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1773380": [
        {
            "ioc_value": "47.76.96.68:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-21 20:00:25",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.76.96.68",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1772653": [
        {
            "ioc_value": "5.101.86.72:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-20 16:00:44",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.86.72",
            "tags": "AS-GLOBALTELEHOST,AS62563,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1772652": [
        {
            "ioc_value": "101.35.95.103:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 16:00:21",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.35.95.103",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-0,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1772372": [
        {
            "ioc_value": "pr2.codetohaven.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:59",
            "last_seen_utc": "2026-06-06 15:16:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1772370": [
        {
            "ioc_value": "https://pr2.codetohaven.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:49",
            "last_seen_utc": "2026-06-06 15:16:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1771875": [
        {
            "ioc_value": "182.255.44.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 06:42:00",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1771791": [
        {
            "ioc_value": "8.136.13.87:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-20 00:02:12",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.136.13.87",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1771714": [
        {
            "ioc_value": "45.136.13.247:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-19 20:02:51",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.136.13.247",
            "tags": "AdaptixC2,AS139659,C2,censys,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1771713": [
        {
            "ioc_value": "167.17.47.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-19 20:02:47",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.17.47.121",
            "tags": "AdaptixC2,AS43180,C2,censys,TRUNKNETWORKS-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1771456": [
        {
            "ioc_value": "dhzuadd.hellothere.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:25",
            "last_seen_utc": "2026-06-06 15:17:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1771455": [
        {
            "ioc_value": "https://dhzuadd.hellothere.sbs",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:20",
            "last_seen_utc": "2026-06-06 15:17:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1771235": [
        {
            "ioc_value": "85.206.168.238:888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-19 04:00:37",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.206.168.238",
            "tags": "AS61272,C2,censys,IST-AS,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1771152": [
        {
            "ioc_value": "165.154.244.77:2562",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-19 00:00:22",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/165.154.244.77",
            "tags": "AS142002,C2,censys,CobaltStrike,cs-watermark-987654321,SCLOUDPTELTD-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1769955": [
        {
            "ioc_value": "43.138.39.212:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-18 04:00:18",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.138.39.212",
            "tags": "AS45090,C2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1769709": [
        {
            "ioc_value": "172.86.107.196:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-03-17 20:03:22",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.86.107.196",
            "tags": "AS14956,C2,censys,Pupy,RAT,ROUTERHOSTING",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1769012": [
        {
            "ioc_value": "88.218.60.191:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-17 04:01:23",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/88.218.60.191",
            "tags": "AdaptixC2,AS48282,C2,censys,VDSINA-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1768984": [
        {
            "ioc_value": "156.245.144.203:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-17 02:48:23",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1768940": [
        {
            "ioc_value": "20.29.10.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-17 00:01:17",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.29.10.79",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1767951": [
        {
            "ioc_value": "http://82.38.71.155/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.smokeloader",
            "malware_alias": "Dofoil,Sharik,Smoke,Smoke Loader",
            "malware_printable": "SmokeLoader",
            "first_seen_utc": "2026-03-16 10:41:19",
            "last_seen_utc": "2026-06-06 15:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,SmokeLoader",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1767077": [
        {
            "ioc_value": "185.242.3.83:5505",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-15 16:00:41",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.242.3.83",
            "tags": "AS60223,AsyncRAT,C2,censys,NETIFACE-AS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1767015": [
        {
            "ioc_value": "156.245.144.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-15 14:49:59",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1767016": [
        {
            "ioc_value": "156.245.144.203:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-15 14:49:59",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1766813": [
        {
            "ioc_value": "119.29.117.194:801",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-15 06:51:25",
            "last_seen_utc": "2026-06-06 15:45:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1766764": [
        {
            "ioc_value": "202.191.67.71:50003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-15 04:01:14",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/202.191.67.71",
            "tags": "AdaptixC2,AS131262,C2,censys,KELNET-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1765787": [
        {
            "ioc_value": "5.101.82.60:2509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-14 08:00:55",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.60",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1765444": [
        {
            "ioc_value": "pan.paihost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:06:16",
            "last_seen_utc": "2026-06-06 15:16:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1765442": [
        {
            "ioc_value": "https://pan.paihost.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:05:58",
            "last_seen_utc": "2026-06-06 15:16:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1764276": [
        {
            "ioc_value": "46.151.182.205:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-13 04:01:11",
            "last_seen_utc": "2026-06-06 15:44:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.151.182.205",
            "tags": "AS205759,AsyncRAT,C2,censys,GHOSTYNETWORKS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1763830": [
        {
            "ioc_value": "20.104.107.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-03-12 00:02:50",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.104.107.19",
            "tags": "AS8075,C2,censys,Havoc,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1763737": [
        {
            "ioc_value": "130.12.182.209:9456",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-03-11 23:00:21",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/260311-zw3w6adw5k",
            "tags": "quasar",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1763543": [
        {
            "ioc_value": "159.138.31.252:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-11 16:01:48",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/159.138.31.252",
            "tags": "AS136907,C2,censys,HWCLOUDS-AS-AP,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1763331": [
        {
            "ioc_value": "77.237.245.173:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-11 12:01:42",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.237.245.173",
            "tags": "AS51167,C2,censys,CONTABO,Covenant",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1763170": [
        {
            "ioc_value": "60.247.206.23:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-11 07:03:38",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1762854": [
        {
            "ioc_value": "85.206.168.238:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-10 16:00:58",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.206.168.238",
            "tags": "AS61272,C2,censys,IST-AS,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1762492": [
        {
            "ioc_value": "107.172.3.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-10 00:01:13",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.3.15",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1762462": [
        {
            "ioc_value": "38.147.170.252:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-09 21:47:27",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1762153": [
        {
            "ioc_value": "ooe.myserver.com.bd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:37",
            "last_seen_utc": "2026-06-06 15:16:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1762131": [
        {
            "ioc_value": "https://ooe.myserver.com.bd/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:17",
            "last_seen_utc": "2026-06-06 15:16:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1762086": [
        {
            "ioc_value": "mullenpalimpseststudio.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2026-03-09 08:43:24",
            "last_seen_utc": "2026-06-06 04:44:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/260306-g134lsgs2p",
            "tags": "c2,domain,HijackLoader,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1760833": [
        {
            "ioc_value": "20.100.168.21:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-07 08:01:02",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.100.168.21",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1759331": [
        {
            "ioc_value": "194.36.178.53:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-06 00:01:40",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/194.36.178.53",
            "tags": "AdaptixC2,AS200740,C2,censys,FIRST-SERVER-EU-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1758456": [
        {
            "ioc_value": "http://213.5.130.197",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:58",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758457": [
        {
            "ioc_value": "http://213.5.130.154",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:57",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758458": [
        {
            "ioc_value": "http://213.5.130.200",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:56",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758459": [
        {
            "ioc_value": "http://213.5.130.131",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:55",
            "last_seen_utc": "2026-06-06 06:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758460": [
        {
            "ioc_value": "http://213.5.130.179",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758461": [
        {
            "ioc_value": "http://213.5.130.189",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-06-06 06:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758006": [
        {
            "ioc_value": "70.153.18.45:10002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-04 04:01:12",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/70.153.18.45",
            "tags": "AS8075,censys,EvilGoPhish,MICROSOFT-CORP-MSN-AS-BLOCK,panel,Phishing",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1757096": [
        {
            "ioc_value": "77.90.185.21:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-03 00:00:51",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.90.185.21",
            "tags": "AS213790,C2,censys,LIMITEDNETWORK-AS,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1757045": [
        {
            "ioc_value": "luxcocinas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.strelastealer",
            "malware_alias": null,
            "malware_printable": "StrelaStealer",
            "first_seen_utc": "2026-03-02 22:36:33",
            "last_seen_utc": "2026-06-06 07:17:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "StrelaStealer",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1756955": [
        {
            "ioc_value": "104.243.248.63:1801",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-02 15:30:09",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1756664": [
        {
            "ioc_value": "ctl.it-bd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-02 09:31:49",
            "last_seen_utc": "2026-06-06 15:15:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1756622": [
        {
            "ioc_value": "https://ctl.it-bd.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-02 09:30:33",
            "last_seen_utc": "2026-06-06 15:15:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1756333": [
        {
            "ioc_value": "171.22.181.114:38990",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.pink",
            "malware_alias": null,
            "malware_printable": "Pink",
            "first_seen_utc": "2026-03-01 14:27:15",
            "last_seen_utc": "2026-06-06 16:13:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Pink",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1755728": [
        {
            "ioc_value": "188.227.14.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-28 11:00:05",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/188.227.14.105",
            "tags": "AS35000,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1754986": [
        {
            "ioc_value": "47.84.183.211:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-26 07:04:33",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.84.183.211",
            "tags": "AS45102,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1754813": [
        {
            "ioc_value": "47.120.20.86:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 20:02:24",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.20.86",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1754717": [
        {
            "ioc_value": "103.39.79.102:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 19:02:08",
            "last_seen_utc": "2026-06-05 12:45:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.39.79.102",
            "tags": "AS932,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1754671": [
        {
            "ioc_value": "115.190.250.28:5521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 19:01:08",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.250.28",
            "tags": "AS137718,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1754439": [
        {
            "ioc_value": "185.72.8.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-25 09:05:20",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1754438": [
        {
            "ioc_value": "185.72.8.121:1032",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-25 09:05:18",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1753846": [
        {
            "ioc_value": "64.89.161.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-23 23:00:07",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.89.161.183",
            "tags": "AS205759,C2,censys,GHOSTYNETWORKS",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1753479": [
        {
            "ioc_value": "glo.gadgetwalabd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-23 10:07:22",
            "last_seen_utc": "2026-06-06 16:15:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1753432": [
        {
            "ioc_value": "https://glo.gadgetwalabd.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-23 10:06:47",
            "last_seen_utc": "2026-06-06 16:15:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1751483": [
        {
            "ioc_value": "45.116.104.104:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-21 08:01:40",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.116.104.104",
            "tags": "AS215481,C2,censys,FLEXYNODE-AS,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1751453": [
        {
            "ioc_value": "47.104.159.246:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-21 03:00:07",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.104.159.246",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1751104": [
        {
            "ioc_value": "107.172.217.220:12096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-20 11:00:06",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.217.220",
            "tags": "AS36352,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1751083": [
        {
            "ioc_value": "185.180.198.3:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1751084": [
        {
            "ioc_value": "185.180.198.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1751056": [
        {
            "ioc_value": "81.68.89.216:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-20 07:09:34",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1749217": [
        {
            "ioc_value": "111.228.4.54:4455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-16 09:05:30",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/111.228.4.54#4455",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1749089": [
        {
            "ioc_value": "lockbit7z57mkicfkuq44j6yrpu5finwvjllczkkp2uvdedsdonjztyd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:16",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1749095": [
        {
            "ioc_value": "lockbit7z6f3gu6rjvrysn5gjbsqj3hk3bvsg64ns6pjldqr2xhvhsyd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:16",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1749096": [
        {
            "ioc_value": "lockbit7z6qinyhhmibvycu5kwmcvgrbpvtztkvvmdce5zwtucaeyrqd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:16",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1749076": [
        {
            "ioc_value": "lockbit7z2mmiz3ryxafn5kapbvbbiywsxwovasfkgf5dqqp5kxlajad.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:15",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1749077": [
        {
            "ioc_value": "lockbit7z2og4jlsmdy7dzty3g42eu3gh2sx2b6ywtvhrjtss7li4fyd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:15",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1749080": [
        {
            "ioc_value": "lockbit7z37ntefjdbjextn6tmdkry4j546ejnru5cejeguitiopvhad.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:15",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1749082": [
        {
            "ioc_value": "lockbit7z3ddvg5vuez2vznt73ljqgwx5tnuqaa2ye7lns742yiv2zyd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:15",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1749083": [
        {
            "ioc_value": "lockbit7z3hv7ev5knxbrhsvv2mmu2rddwqizdz4vwfvxt5izrq6zqqd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:15",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1749084": [
        {
            "ioc_value": "lockbit7z3ujnkhxwahhjduh5me2updvzxewhhc5qvk2snxezoi5drad.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:15",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1749085": [
        {
            "ioc_value": "lockbit7z4bsm63m3dagp5xglyacr4z4bwytkvkkwtn6enmuo5fi5iyd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2026-02-16 05:12:15",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/LockBit%205.0%20Ransomware",
            "tags": "lockbit,lockbit5,ransomware",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1748314": [
        {
            "ioc_value": "27.221.15.199:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-02-14 18:46:07",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1747540": [
        {
            "ioc_value": "gor.emiraride.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:35",
            "last_seen_utc": "2026-06-06 16:14:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1747538": [
        {
            "ioc_value": "https://gor.emiraride.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:02",
            "last_seen_utc": "2026-06-06 16:14:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1747433": [
        {
            "ioc_value": "83.229.127.46:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-13 08:01:04",
            "last_seen_utc": "2026-06-06 15:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.127.46",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-666666666,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1747139": [
        {
            "ioc_value": "45.66.164.17:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-13 07:00:24",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.66.164.17",
            "tags": "AS63023,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1747121": [
        {
            "ioc_value": "117.72.191.140:8028",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-13 06:59:13",
            "last_seen_utc": "2026-06-06 15:45:01",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.191.140#8028",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1747002": [
        {
            "ioc_value": "118.107.0.254:2002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-12 20:00:41",
            "last_seen_utc": "2026-06-06 15:45:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.107.0.254",
            "tags": "AS152194,C2,censys,CobaltStrike,cs-watermark-987654321,CTGSERVERLIMITED-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1746911": [
        {
            "ioc_value": "175.192.75.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-02-12 16:01:27",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/175.192.75.105",
            "tags": "AS4766,C2,censys,KIXS-AS-KR,Netsupport,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1744175": [
        {
            "ioc_value": "118.107.0.254:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-10 03:00:13",
            "last_seen_utc": "2026-06-06 15:45:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.107.0.254",
            "tags": "AS152194,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1743719": [
        {
            "ioc_value": "opa.dokantrack.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-09 11:14:08",
            "last_seen_utc": "2026-06-06 16:14:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1743622": [
        {
            "ioc_value": "https://opa.dokantrack.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-09 11:13:23",
            "last_seen_utc": "2026-06-06 16:14:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1743594": [
        {
            "ioc_value": "15.204.14.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-09 11:00:33",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.14.143",
            "tags": "AS16276,C2,censys,OVH",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1743398": [
        {
            "ioc_value": "192.3.233.166:59850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 16:00:16",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/192.3.233.166",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1743395": [
        {
            "ioc_value": "1.15.25.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:41",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743391": [
        {
            "ioc_value": "106.52.208.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-06-06 16:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743392": [
        {
            "ioc_value": "106.13.137.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-06-06 16:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743393": [
        {
            "ioc_value": "101.43.2.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-06-06 16:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743394": [
        {
            "ioc_value": "101.133.148.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-06-06 16:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743388": [
        {
            "ioc_value": "115.190.178.249:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-06-06 16:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743389": [
        {
            "ioc_value": "114.132.150.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-06-06 16:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743390": [
        {
            "ioc_value": "110.40.176.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-06-06 16:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743386": [
        {
            "ioc_value": "120.48.50.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743387": [
        {
            "ioc_value": "117.72.214.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743381": [
        {
            "ioc_value": "124.223.199.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-06 16:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743382": [
        {
            "ioc_value": "124.221.32.87:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-06 16:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743383": [
        {
            "ioc_value": "124.220.48.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743384": [
        {
            "ioc_value": "124.220.164.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743385": [
        {
            "ioc_value": "121.41.167.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743378": [
        {
            "ioc_value": "152.136.139.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-06-06 16:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743379": [
        {
            "ioc_value": "129.204.103.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-06-06 16:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743380": [
        {
            "ioc_value": "124.223.47.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-06-06 16:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743374": [
        {
            "ioc_value": "172.245.215.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-06-06 16:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743375": [
        {
            "ioc_value": "165.154.125.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-06-06 16:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743376": [
        {
            "ioc_value": "156.233.233.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-06-06 16:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743377": [
        {
            "ioc_value": "154.201.91.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-06-06 16:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743370": [
        {
            "ioc_value": "38.190.224.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-06-06 16:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743371": [
        {
            "ioc_value": "222.255.214.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-06-06 16:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743372": [
        {
            "ioc_value": "192.252.187.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-06-06 16:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743373": [
        {
            "ioc_value": "178.16.52.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-06-06 16:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743365": [
        {
            "ioc_value": "43.139.146.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-06 16:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743366": [
        {
            "ioc_value": "43.133.41.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-06 16:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743367": [
        {
            "ioc_value": "42.192.49.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-06 16:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743368": [
        {
            "ioc_value": "39.107.85.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-06 16:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743369": [
        {
            "ioc_value": "39.106.144.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-06 16:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743363": [
        {
            "ioc_value": "47.100.168.4:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-06-06 16:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743364": [
        {
            "ioc_value": "43.139.169.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-06-06 16:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743362": [
        {
            "ioc_value": "47.111.146.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:30",
            "last_seen_utc": "2026-06-06 16:00:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743358": [
        {
            "ioc_value": "47.243.175.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-06-06 16:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743359": [
        {
            "ioc_value": "47.239.188.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-06-06 16:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743360": [
        {
            "ioc_value": "47.122.30.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-06-06 16:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743361": [
        {
            "ioc_value": "47.122.1.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-06-06 16:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743356": [
        {
            "ioc_value": "61.166.154.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-06-06 16:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743357": [
        {
            "ioc_value": "49.235.177.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-06-06 16:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743353": [
        {
            "ioc_value": "81.70.255.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-06-06 16:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743354": [
        {
            "ioc_value": "81.69.98.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-06-06 16:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743355": [
        {
            "ioc_value": "8.210.78.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-06-06 16:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743351": [
        {
            "ioc_value": "83.229.126.65:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-06-06 16:00:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743352": [
        {
            "ioc_value": "81.71.159.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-06-06 16:00:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743349": [
        {
            "ioc_value": "83.229.123.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-06-06 16:00:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743350": [
        {
            "ioc_value": "83.229.126.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-06-06 16:00:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743348": [
        {
            "ioc_value": "8.153.205.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:14",
            "last_seen_utc": "2026-06-06 16:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743347": [
        {
            "ioc_value": "8.137.149.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:13",
            "last_seen_utc": "2026-06-06 16:00:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743344": [
        {
            "ioc_value": "47.93.28.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-06-06 16:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743345": [
        {
            "ioc_value": "60.205.139.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-06-06 16:00:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743346": [
        {
            "ioc_value": "lcowpowerlite.italynorth.cloudapp.azure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-06-06 16:00:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743340": [
        {
            "ioc_value": "47.109.198.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-06-06 16:00:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743341": [
        {
            "ioc_value": "47.120.70.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-06-06 16:00:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743342": [
        {
            "ioc_value": "47.121.137.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-06-06 16:00:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743343": [
        {
            "ioc_value": "47.121.29.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-06-06 16:00:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743336": [
        {
            "ioc_value": "45.115.236.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-06-06 16:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743338": [
        {
            "ioc_value": "47.107.136.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-06-06 16:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743339": [
        {
            "ioc_value": "47.109.145.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-06-06 16:00:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743333": [
        {
            "ioc_value": "192.140.176.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-06-06 16:00:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743334": [
        {
            "ioc_value": "36.140.162.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-06-06 16:00:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743335": [
        {
            "ioc_value": "39.105.165.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-06-06 16:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743330": [
        {
            "ioc_value": "152.32.251.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-06-06 16:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743331": [
        {
            "ioc_value": "154.201.74.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-06-06 16:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743332": [
        {
            "ioc_value": "179.43.186.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-06-06 16:00:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743326": [
        {
            "ioc_value": "139.196.41.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-06-06 16:00:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743327": [
        {
            "ioc_value": "139.224.16.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-06-06 16:00:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743328": [
        {
            "ioc_value": "14.103.175.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-06-06 16:00:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743329": [
        {
            "ioc_value": "150.187.25.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-06-06 16:00:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743322": [
        {
            "ioc_value": "120.48.168.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-06-06 16:00:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743323": [
        {
            "ioc_value": "121.40.18.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743324": [
        {
            "ioc_value": "122.51.93.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-06-06 16:00:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743325": [
        {
            "ioc_value": "134.122.140.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-06-06 16:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743320": [
        {
            "ioc_value": "117.72.102.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-06-06 16:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743321": [
        {
            "ioc_value": "117.72.242.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-06-06 16:00:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743318": [
        {
            "ioc_value": "113.44.67.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-06-06 16:00:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743319": [
        {
            "ioc_value": "115.190.161.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-06-06 16:00:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743314": [
        {
            "ioc_value": "106.38.201.95:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-06-06 16:00:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743315": [
        {
            "ioc_value": "106.75.162.108:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-06-06 16:00:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743316": [
        {
            "ioc_value": "106.75.215.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-06-06 16:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743317": [
        {
            "ioc_value": "106.75.224.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-06-06 16:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743312": [
        {
            "ioc_value": "106.12.219.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-06-06 16:00:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743313": [
        {
            "ioc_value": "106.13.29.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-06-06 16:00:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743267": [
        {
            "ioc_value": "15.204.14.143:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-08 11:00:25",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.14.143",
            "tags": "AS16276,C2,censys,OVH",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1743209": [
        {
            "ioc_value": "15.204.95.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-08 04:00:55",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1742595": [
        {
            "ioc_value": "174.138.86.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-07 03:00:18",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/174.138.86.141",
            "tags": "AS14061,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1741652": [
        {
            "ioc_value": "192.159.99.249:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-05 13:04:12",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/192.159.99.249#5555",
            "tags": "c2,evilginx,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1741587": [
        {
            "ioc_value": "57.158.27.132:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-02-05 13:01:59",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/57.158.27.132#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1741476": [
        {
            "ioc_value": "94.74.0.253:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-05 11:00:23",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/94.74.0.253",
            "tags": "AS39636,ASN-AEMNET,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1741375": [
        {
            "ioc_value": "37.72.172.58:6066",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-02-05 06:34:37",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AS29802,asyncrat,c2,fofa,RAT",
            "anonymous": "0",
            "reporter": "oxygen28"
        }
    ],
    "1741247": [
        {
            "ioc_value": "mezcalpro.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-02-05 06:34:08",
            "last_seen_utc": "2026-06-05 20:10:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116013228581960779",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1741246": [
        {
            "ioc_value": "https://mezcalpro.com/scq",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-02-05 06:34:07",
            "last_seen_utc": "2026-06-05 20:10:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116013228581960779",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1741132": [
        {
            "ioc_value": "172.174.234.34:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-04 11:00:54",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.174.234.34",
            "tags": "AS8075,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1740953": [
        {
            "ioc_value": "188.166.244.201:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-04 00:02:27",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/188.166.244.201",
            "tags": "AdaptixC2,AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1740216": [
        {
            "ioc_value": "47.115.175.62:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-03 00:02:43",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.115.175.62",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1739255": [
        {
            "ioc_value": "98.85.71.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-31 00:05:33",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/98.85.71.175",
            "tags": "AMAZON-AES,AS14618,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1739209": [
        {
            "ioc_value": "47.115.193.52:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-01-30 18:54:11",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1739169": [
        {
            "ioc_value": "167.99.208.145:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-30 16:05:29",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.208.145",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1739163": [
        {
            "ioc_value": "107.150.105.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 16:04:48",
            "last_seen_utc": "2026-06-06 16:00:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.150.105.91",
            "tags": "AS135377,C2,censys,CobaltStrike,cs-watermark-666666666,UCLOUD-HK-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1739009": [
        {
            "ioc_value": "111.92.243.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 08:04:49",
            "last_seen_utc": "2026-06-06 16:00:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.92.243.40",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1738909": [
        {
            "ioc_value": "68.64.178.201:54321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-30 00:06:02",
            "last_seen_utc": "2026-06-06 15:44:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.178.201",
            "tags": "AdaptixC2,AS139659,C2,censys,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1737790": [
        {
            "ioc_value": "47.120.46.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-26 23:00:09",
            "last_seen_utc": "2026-06-06 16:00:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.46.230",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1737664": [
        {
            "ioc_value": "https://fluraresto.me/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-06-06 16:08:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1737665": [
        {
            "ioc_value": "https://mastralakkot.live/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-06-06 15:59:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1737569": [
        {
            "ioc_value": "27.223.85.234:58001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-26 08:05:39",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/27.223.85.234",
            "tags": "AdaptixC2,AS4837,C2,censys,CHINA169-BACKBONE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1737455": [
        {
            "ioc_value": "167.179.76.179:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-25 22:49:35",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1737454": [
        {
            "ioc_value": "ns1.ns-apache.jo3.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-25 22:48:35",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1736696": [
        {
            "ioc_value": "80.87.206.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.rhysida",
            "malware_alias": null,
            "malware_printable": "Rhysida",
            "first_seen_utc": "2026-01-24 18:47:55",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Rhysida",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1736697": [
        {
            "ioc_value": "80.87.206.64:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.rhysida",
            "malware_alias": null,
            "malware_printable": "Rhysida",
            "first_seen_utc": "2026-01-24 18:47:55",
            "last_seen_utc": "2026-06-06 15:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Rhysida",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1736055": [
        {
            "ioc_value": "lat.sodstreams.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-23 09:14:44",
            "last_seen_utc": "2026-06-06 16:14:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1736049": [
        {
            "ioc_value": "https://lat.sodstreams.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-23 09:14:26",
            "last_seen_utc": "2026-06-06 16:14:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1736034": [
        {
            "ioc_value": "158.158.8.193:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-01-23 08:45:57",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1736014": [
        {
            "ioc_value": "47.120.32.72:8075",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-23 08:04:06",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.32.72",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1735678": [
        {
            "ioc_value": "fusionjanicepalimpsest.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2026-01-22 17:23:40",
            "last_seen_utc": "2026-06-06 04:44:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.joesandbox.com/analysis/1855760/0/html",
            "tags": "c2,domain,HijackLoader,joesandbox",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1735522": [
        {
            "ioc_value": "176.31.71.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 12:04:28",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/176.31.71.168",
            "tags": "AS16276,C2,censys,OVH,Pupy,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1735412": [
        {
            "ioc_value": "34.64.98.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 04:04:19",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/34.64.98.201",
            "tags": "AS396982,C2,censys,GOOGLE-CLOUD-PLATFORM,Pupy,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1735342": [
        {
            "ioc_value": "54.145.56.188:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-21 20:04:36",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.145.56.188",
            "tags": "AMAZON-AES,AS14618,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1735337": [
        {
            "ioc_value": "121.4.92.72:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-21 20:03:53",
            "last_seen_utc": "2026-06-06 15:45:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/121.4.92.72",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1734893": [
        {
            "ioc_value": "136.24.173.249:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-20 16:04:24",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/136.24.173.249",
            "tags": "AS19165,C2,censys,Mythic,WEBPASS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1734081": [
        {
            "ioc_value": "103.79.79.105:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-18 00:03:59",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.79.79.105",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Pupy,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1733763": [
        {
            "ioc_value": "113.250.188.15:8078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-17 11:00:10",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.250.188.15",
            "tags": "AS134420,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1733589": [
        {
            "ioc_value": "poc.sekershuk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-16 15:03:06",
            "last_seen_utc": "2026-06-06 16:12:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1733587": [
        {
            "ioc_value": "https://poc.sekershuk.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-16 15:02:50",
            "last_seen_utc": "2026-06-06 16:12:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1732736": [
        {
            "ioc_value": "64.23.231.32:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-01-16 11:05:53",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/64.23.231.32#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1732709": [
        {
            "ioc_value": "117.72.178.246:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-16 11:03:46",
            "last_seen_utc": "2026-06-06 15:45:01",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.178.246#4848",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1732012": [
        {
            "ioc_value": "212.103.26.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-01-13 20:03:58",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/212.103.26.10",
            "tags": "AS15557,C2,censys,Havoc,LDCOMNET",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1732009": [
        {
            "ioc_value": "47.84.83.56:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-01-13 20:03:34",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.84.83.56",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1731532": [
        {
            "ioc_value": "54.38.94.225:8881",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-01-13 08:52:00",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1701407": [
        {
            "ioc_value": "64.23.248.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-01-12 23:00:32",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.23.248.252",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1701312": [
        {
            "ioc_value": "130.12.181.93:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-01-12 16:03:19",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/130.12.181.93",
            "tags": "AS36680,C2,censys,NETIFACELLC,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1700297": [
        {
            "ioc_value": "139.224.16.185:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-10 06:45:16",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1700191": [
        {
            "ioc_value": "115.190.237.175:35555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-09 20:02:46",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.237.175",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-666666666,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1693493": [
        {
            "ioc_value": "137.184.93.131:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-09 11:01:05",
            "last_seen_utc": "2026-06-06 15:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/137.184.93.131",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1693407": [
        {
            "ioc_value": "8.148.184.136:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-09 04:02:43",
            "last_seen_utc": "2026-06-06 15:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.148.184.136",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1693365": [
        {
            "ioc_value": "117.72.178.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-08 23:00:12",
            "last_seen_utc": "2026-06-06 16:00:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.178.246",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1693357": [
        {
            "ioc_value": "172.94.18.103:191",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-08 22:50:04",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1692743": [
        {
            "ioc_value": "38.49.57.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-07 20:02:36",
            "last_seen_utc": "2026-06-06 16:00:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.49.57.15",
            "tags": "AS8796,C2,censys,CobaltStrike,cs-watermark-666666666,FD-298-8796",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1691952": [
        {
            "ioc_value": "115.190.233.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-06 08:02:23",
            "last_seen_utc": "2026-06-06 16:00:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.233.79",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1691605": [
        {
            "ioc_value": "http://213.5.130.122",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:42",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691603": [
        {
            "ioc_value": "http://213.5.130.151",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:41",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691604": [
        {
            "ioc_value": "http://213.5.130.124",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691606": [
        {
            "ioc_value": "http://213.5.130.187",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691533": [
        {
            "ioc_value": "hov.multiatend.com.br",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-05 10:07:27",
            "last_seen_utc": "2026-06-06 16:12:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1691482": [
        {
            "ioc_value": "https://hov.multiatend.com.br/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-05 10:06:49",
            "last_seen_utc": "2026-06-06 16:12:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1691375": [
        {
            "ioc_value": "124.198.131.115:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 08:35:25",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/124.198.131.115#5555",
            "tags": "c2,evilginx,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1688739": [
        {
            "ioc_value": "101.34.205.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:16",
            "last_seen_utc": "2026-06-06 16:00:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688738": [
        {
            "ioc_value": "103.171.35.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:15",
            "last_seen_utc": "2026-06-06 16:00:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688737": [
        {
            "ioc_value": "107.149.192.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:14",
            "last_seen_utc": "2026-06-06 16:00:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688734": [
        {
            "ioc_value": "124.222.218.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-06-06 16:00:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688735": [
        {
            "ioc_value": "124.221.255.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-06-06 16:00:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688736": [
        {
            "ioc_value": "123.56.78.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-06-06 16:00:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688732": [
        {
            "ioc_value": "152.32.202.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-06-06 16:00:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688733": [
        {
            "ioc_value": "150.158.119.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-06-06 16:00:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688730": [
        {
            "ioc_value": "165.154.244.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-06-06 16:00:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688731": [
        {
            "ioc_value": "156.225.20.77:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-06-06 16:00:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688729": [
        {
            "ioc_value": "182.92.239.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:10",
            "last_seen_utc": "2026-06-06 16:00:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688726": [
        {
            "ioc_value": "39.105.160.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-06-06 16:00:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688727": [
        {
            "ioc_value": "38.38.250.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-06-06 16:00:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688728": [
        {
            "ioc_value": "211.184.175.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-06-06 16:00:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688725": [
        {
            "ioc_value": "45.58.56.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:07",
            "last_seen_utc": "2026-06-06 16:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688723": [
        {
            "ioc_value": "8.130.80.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-06-06 16:00:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688724": [
        {
            "ioc_value": "8.130.26.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-06-06 16:00:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688721": [
        {
            "ioc_value": "94.74.164.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-06-06 16:00:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688722": [
        {
            "ioc_value": "87.251.67.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-06-06 16:00:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688694": [
        {
            "ioc_value": "16.171.13.191:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-30 16:04:05",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/16.171.13.191",
            "tags": "AMAZON-02,AS16509,C2,censys,Covenant",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1687817": [
        {
            "ioc_value": "118.89.88.183:56781",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-28 20:01:34",
            "last_seen_utc": "2026-06-06 15:45:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.89.88.183",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1687327": [
        {
            "ioc_value": "37.72.172.58:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-28 07:41:32",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,C2,censys,HVC-AS,RAT",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1687170": [
        {
            "ioc_value": "37.72.172.58:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-27 16:02:33",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1686405": [
        {
            "ioc_value": "155.102.62.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-25 18:44:15",
            "last_seen_utc": "2026-06-06 15:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1686010": [
        {
            "ioc_value": "139.196.223.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-25 07:52:31",
            "last_seen_utc": "2026-06-06 16:00:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.196.223.82",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1685948": [
        {
            "ioc_value": "ghost4senator.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2025-12-24 18:08:41",
            "last_seen_utc": "2026-06-06 06:05:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/251224-vvmrbshs2b",
            "tags": "C2,domain,netwire,rat,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1685856": [
        {
            "ioc_value": "helpremote.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-24 12:48:51",
            "last_seen_utc": "2026-06-06 16:00:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1685596": [
        {
            "ioc_value": "172.94.18.103:190",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 22:45:05",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1685256": [
        {
            "ioc_value": "115.190.160.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 20:01:06",
            "last_seen_utc": "2026-06-06 16:00:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.160.206",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1685210": [
        {
            "ioc_value": "196.251.107.104:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 18:07:43",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/251223-qezczazpcx",
            "tags": "AS9304,asyncrat,C2,rat,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1685209": [
        {
            "ioc_value": "196.251.107.104:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 18:07:42",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/251223-qezczazpcx",
            "tags": "AS9304,asyncrat,C2,rat,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1684938": [
        {
            "ioc_value": "8.159.146.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 03:00:34",
            "last_seen_utc": "2026-06-06 16:00:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1684936": [
        {
            "ioc_value": "missmovie.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 02:54:49",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1684826": [
        {
            "ioc_value": "179.43.186.214:7889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-22 20:01:00",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/179.43.186.214",
            "tags": "AS51852,C2,censys,CobaltStrike,cs-watermark-987654321,PLI-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1684794": [
        {
            "ioc_value": "45.133.180.162:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-22 18:02:02",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/251222-d45vtstqc1",
            "tags": "AS9009,asyncrat,C2,rat,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1684679": [
        {
            "ioc_value": "193.142.146.30:9433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-22 13:24:27",
            "last_seen_utc": "2026-06-06 15:45:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.142.146.30",
            "tags": "AS213438,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1684543": [
        {
            "ioc_value": "64.190.113.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-12-22 00:01:20",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.190.113.161",
            "tags": "AS399629,BLNWX,C2,censys,Pupy,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1682522": [
        {
            "ioc_value": "155.102.133.61:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-18 18:44:36",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1681582": [
        {
            "ioc_value": "fortwaynejubileebrontide.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2025-12-17 17:02:48",
            "last_seen_utc": "2026-06-06 04:44:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "proxylife"
        }
    ],
    "1681468": [
        {
            "ioc_value": "chi.botick.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-12-17 13:31:59",
            "last_seen_utc": "2026-06-06 16:11:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1681466": [
        {
            "ioc_value": "https://chi.botick.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-12-17 13:31:48",
            "last_seen_utc": "2026-06-06 16:11:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1680306": [
        {
            "ioc_value": "43.161.245.186:79",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-16 02:49:55",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1677537": [
        {
            "ioc_value": "effinghampodiatriclore.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2025-12-13 08:00:47",
            "last_seen_utc": "2026-06-06 04:44:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "DeerStealer,DonutLoader,HijackLoader",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1676363": [
        {
            "ioc_value": "67.219.102.244:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-12 02:50:28",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1673804": [
        {
            "ioc_value": "47.246.29.99:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-09 18:49:53",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1673343": [
        {
            "ioc_value": "https://91.124.149.73/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-12-09 08:05:46",
            "last_seen_utc": "2026-06-06 16:11:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1670887": [
        {
            "ioc_value": "20.157.116.151:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-08 14:58:40",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.157.116.151",
            "tags": "AdaptixC2,AS8069,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1668967": [
        {
            "ioc_value": "180.76.141.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-07 16:01:37",
            "last_seen_utc": "2026-06-06 16:00:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/180.76.141.175",
            "tags": "AS38365,BAIDU,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1667182": [
        {
            "ioc_value": "216.238.89.173:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-04 00:03:19",
            "last_seen_utc": "2026-06-06 15:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/216.238.89.173",
            "tags": "AdaptixC2,AS-VULTR,AS20473,C2,censys",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1667105": [
        {
            "ioc_value": "115.190.161.178:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-03 20:01:15",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.161.178",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1666902": [
        {
            "ioc_value": "122.114.10.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-03 12:31:15",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.114.10.199",
            "tags": "AS4837,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1666137": [
        {
            "ioc_value": "8.137.149.67:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-02 12:51:03",
            "last_seen_utc": "2026-06-06 15:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1665523": [
        {
            "ioc_value": "http://213.5.130.104",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665524": [
        {
            "ioc_value": "http://213.5.130.180",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665525": [
        {
            "ioc_value": "http://213.5.130.106",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:50",
            "last_seen_utc": "2026-06-06 06:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665526": [
        {
            "ioc_value": "http://213.5.130.102",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665527": [
        {
            "ioc_value": "http://213.5.130.152",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-06-06 06:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665528": [
        {
            "ioc_value": "http://213.5.130.107",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665529": [
        {
            "ioc_value": "http://213.5.130.153",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665530": [
        {
            "ioc_value": "http://213.5.130.100",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665531": [
        {
            "ioc_value": "http://213.5.130.182",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665532": [
        {
            "ioc_value": "http://213.5.130.181",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:47",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665454": [
        {
            "ioc_value": "122.114.10.199:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-01 12:36:20",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.114.10.199",
            "tags": "AS4837,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1665331": [
        {
            "ioc_value": "47.84.83.56:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-01 06:57:39",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.84.83.56#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1663611": [
        {
            "ioc_value": "103.110.65.166:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-30 20:01:55",
            "last_seen_utc": "2026-06-06 15:43:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.110.65.166",
            "tags": "AS26383,ASNET,C2,censys,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1663223": [
        {
            "ioc_value": "106.13.29.104:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-29 20:00:50",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/106.13.29.104",
            "tags": "AS38365,BAIDU,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1663012": [
        {
            "ioc_value": "47.236.56.15:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-29 12:00:52",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.56.15",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,CobaltStrike,cs-watermark-0",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1660878": [
        {
            "ioc_value": "43.162.121.116:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-29 04:01:42",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.121.116",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1660370": [
        {
            "ioc_value": "85.130.116.122:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-11-28 12:03:50",
            "last_seen_utc": "2026-06-06 16:12:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.130.116.122",
            "tags": "A1BG_RSD,AS13124,censys,Chaos,panel",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1660317": [
        {
            "ioc_value": "148.135.120.162:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-28 10:51:31",
            "last_seen_utc": "2026-06-06 15:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1660316": [
        {
            "ioc_value": "ns2.googleclouds.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-28 10:50:17",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1660315": [
        {
            "ioc_value": "ns1.googleclouds.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-28 10:50:14",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1651951": [
        {
            "ioc_value": "5.101.82.51:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-28 04:01:01",
            "last_seen_utc": "2026-06-06 15:44:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.51",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1651813": [
        {
            "ioc_value": "47.103.143.60:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-27 18:47:59",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1650889": [
        {
            "ioc_value": "job.itechno.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-26 12:50:54",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1650040": [
        {
            "ioc_value": "156.245.248.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-25 10:49:55",
            "last_seen_utc": "2026-06-06 16:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1649775": [
        {
            "ioc_value": "http://213.5.130.84",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:37",
            "last_seen_utc": "2026-06-06 06:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649776": [
        {
            "ioc_value": "http://213.5.130.96",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-06-06 06:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649777": [
        {
            "ioc_value": "http://213.5.130.98",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-06-06 06:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649778": [
        {
            "ioc_value": "http://213.5.130.160",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:35",
            "last_seen_utc": "2026-06-06 06:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649164": [
        {
            "ioc_value": "5.101.86.44:61288",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-23 08:00:29",
            "last_seen_utc": "2026-06-06 15:44:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.86.44",
            "tags": "AS-GLOBALTELEHOST,AS62563,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1647756": [
        {
            "ioc_value": "1.13.247.208:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-21 10:49:27",
            "last_seen_utc": "2026-06-06 15:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1647446": [
        {
            "ioc_value": "193.233.245.114:38990",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.pink",
            "malware_alias": null,
            "malware_printable": "Pink",
            "first_seen_utc": "2025-11-21 06:30:46",
            "last_seen_utc": "2026-06-05 14:00:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Pink",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1647575": [
        {
            "ioc_value": "123.58.64.57:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-21 00:02:05",
            "last_seen_utc": "2026-06-06 15:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/123.58.64.57",
            "tags": "AS17623,C2,censys,CNCGROUP-SZ,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1646839": [
        {
            "ioc_value": "43.156.63.124:64494",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-19 23:00:16",
            "last_seen_utc": "2026-06-06 10:32:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.156.63.124",
            "tags": "AS132203,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1645785": [
        {
            "ioc_value": "47.236.149.142:46832",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-17 23:00:18",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.149.142",
            "tags": "AS45102,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1645505": [
        {
            "ioc_value": "194.233.73.173:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-11-17 12:04:03",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/194.233.73.173",
            "tags": "AdaptixC2,AS141995,C2,CAPL-AS-AP,censys",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1641582": [
        {
            "ioc_value": "62.4.0.66:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-15 08:48:18",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1639703": [
        {
            "ioc_value": "62.60.226.183:483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2025-11-13 04:54:17",
            "last_seen_utc": "2026-06-06 15:45:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Tofsee",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1639448": [
        {
            "ioc_value": "adeyqa.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2025-11-12 16:36:02",
            "last_seen_utc": "2026-06-06 06:07:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=adeyqa.net",
            "tags": "Amadey,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1638854": [
        {
            "ioc_value": "54.165.230.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 04:02:31",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.165.230.182",
            "tags": "AMAZON-AES,AS14618,C2,censys,Covenant",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1638274": [
        {
            "ioc_value": "38.242.212.5:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-11-10 18:47:41",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1638236": [
        {
            "ioc_value": "154.205.145.109:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-11-10 16:02:55",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.205.145.109",
            "tags": "AS138915,C2,censys,Havoc,KAOPU-HK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1637255": [
        {
            "ioc_value": "62.60.226.65:43155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-09 08:02:17",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.60.226.65",
            "tags": "AS214351,C2,censys,FEMOIT,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1636099": [
        {
            "ioc_value": "111.228.55.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 23:00:12",
            "last_seen_utc": "2026-06-06 16:00:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.228.55.96",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1636044": [
        {
            "ioc_value": "193.143.1.216:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-11-07 18:48:21",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1634744": [
        {
            "ioc_value": "165.154.225.239:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 02:49:37",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1633709": [
        {
            "ioc_value": "156.225.20.77:5006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-05 08:00:35",
            "last_seen_utc": "2026-06-06 15:45:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/156.225.20.77",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1633464": [
        {
            "ioc_value": "https://cpajoliette.com/d.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-11-05 07:37:04",
            "last_seen_utc": "2026-06-05 16:10:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "SmartApeSG",
            "anonymous": "0",
            "reporter": "HuntYethHounds"
        }
    ],
    "1633501": [
        {
            "ioc_value": "59.110.28.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 20:01:04",
            "last_seen_utc": "2026-06-06 16:00:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/59.110.28.230",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1633194": [
        {
            "ioc_value": "51.15.8.6:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-04 08:00:54",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.8.6",
            "tags": "AS12876,C2,censys,Online,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1633063": [
        {
            "ioc_value": "192.253.227.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:22",
            "last_seen_utc": "2026-06-06 16:00:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1633061": [
        {
            "ioc_value": "167.88.168.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:14",
            "last_seen_utc": "2026-06-06 16:00:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1632776": [
        {
            "ioc_value": "83.229.126.183:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 20:00:26",
            "last_seen_utc": "2026-06-06 15:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.126.183",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-987654321,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1631753": [
        {
            "ioc_value": "117.72.175.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2025-11-03 12:08:57",
            "last_seen_utc": "2026-06-06 16:00:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.nviso.eu/blog",
            "tags": "C2,NVISO,VShell",
            "anonymous": "0",
            "reporter": "0xThiebaut"
        }
    ],
    "1631367": [
        {
            "ioc_value": "117.72.242.9:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 09:03:04",
            "last_seen_utc": "2026-06-06 15:45:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.242.9",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1631471": [
        {
            "ioc_value": "119.42.148.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 07:01:12",
            "last_seen_utc": "2026-06-06 16:00:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.42.148.186#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1630767": [
        {
            "ioc_value": "159.223.0.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-01 12:33:11",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/159.223.0.103#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1630704": [
        {
            "ioc_value": "117.72.175.125:8087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-01 12:31:38",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.175.125#8087",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1630391": [
        {
            "ioc_value": "85.215.57.133:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-10-31 16:01:24",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.215.57.133",
            "tags": "AdaptixC2,AS8560,C2,censys,IONOS-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1629384": [
        {
            "ioc_value": "103.149.93.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-30 04:00:42",
            "last_seen_utc": "2026-06-06 16:00:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.149.93.146",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1628837": [
        {
            "ioc_value": "112.3.31.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 10:49:29",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1628814": [
        {
            "ioc_value": "179.43.186.214:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 09:23:45",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1628768": [
        {
            "ioc_value": "gestcular.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2025-10-29 07:22:28",
            "last_seen_utc": "2026-06-06 04:44:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,hijackloader",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1628725": [
        {
            "ioc_value": "94.154.35.114:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-10-29 04:01:19",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/94.154.35.114",
            "tags": "AS214943,C2,censys,DcRAT,RAILNET,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1628691": [
        {
            "ioc_value": "8.17.56.128:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 02:49:59",
            "last_seen_utc": "2026-06-06 15:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1628195": [
        {
            "ioc_value": "ns1.servicedata.services",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 20:48:37",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1628076": [
        {
            "ioc_value": "8.137.149.67:8060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 12:28:01",
            "last_seen_utc": "2026-06-06 15:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1627925": [
        {
            "ioc_value": "182.254.155.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 04:00:27",
            "last_seen_utc": "2026-06-06 16:00:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/182.254.155.23",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1627719": [
        {
            "ioc_value": "182.16.98.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 02:49:21",
            "last_seen_utc": "2026-06-06 16:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1627659": [
        {
            "ioc_value": "182.16.98.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-27 20:50:01",
            "last_seen_utc": "2026-06-06 16:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1626705": [
        {
            "ioc_value": "196.251.83.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-26 07:39:14",
            "last_seen_utc": "2026-06-06 16:00:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/196.251.83.89",
            "tags": "AS401120,C2,censys,CHEAPY-HOST",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1626837": [
        {
            "ioc_value": "1.94.136.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-26 07:07:52",
            "last_seen_utc": "2026-06-06 10:32:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1626312": [
        {
            "ioc_value": "173.212.216.226:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-10-25 04:02:07",
            "last_seen_utc": "2026-06-06 15:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/173.212.216.226",
            "tags": "AS51167,censys,Chaos,CONTABO,panel",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1626300": [
        {
            "ioc_value": "47.121.135.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-25 04:00:11",
            "last_seen_utc": "2026-06-06 16:00:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.121.135.201",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1626112": [
        {
            "ioc_value": "140.143.194.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-24 16:00:08",
            "last_seen_utc": "2026-06-06 16:00:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/140.143.194.253",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1625642": [
        {
            "ioc_value": "maelootp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 16:48:58",
            "last_seen_utc": "2026-06-06 16:00:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1625564": [
        {
            "ioc_value": "evil.ritademo.io.vn",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 12:50:22",
            "last_seen_utc": "2026-06-06 16:00:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1625393": [
        {
            "ioc_value": "40.66.42.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-10-23 08:02:52",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/40.66.42.246",
            "tags": "AS8075,C2,censys,Havoc,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1625174": [
        {
            "ioc_value": "40.66.42.246:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-10-22 22:00:43",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/40.66.42.246",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1625107": [
        {
            "ioc_value": "185.72.8.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-10-22 18:45:52",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1625108": [
        {
            "ioc_value": "185.72.8.137:7882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-10-22 18:45:52",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1624905": [
        {
            "ioc_value": "116.62.226.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-22 15:43:44",
            "last_seen_utc": "2026-06-06 16:00:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1624664": [
        {
            "ioc_value": "115.190.140.220:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-22 08:02:02",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.140.220",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1624300": [
        {
            "ioc_value": "47.110.67.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 20:01:59",
            "last_seen_utc": "2026-06-06 16:00:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.110.67.64",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1624166": [
        {
            "ioc_value": "http://213.5.130.75",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:24",
            "last_seen_utc": "2026-06-06 06:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624167": [
        {
            "ioc_value": "http://213.5.130.10",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:23",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624169": [
        {
            "ioc_value": "http://213.5.130.90",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624170": [
        {
            "ioc_value": "http://213.5.130.89",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-06-06 06:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1618876": [
        {
            "ioc_value": "www.salesf0rce.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 02:49:37",
            "last_seen_utc": "2026-06-06 16:00:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1617732": [
        {
            "ioc_value": "157.20.182.18:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-10-19 06:39:17",
            "last_seen_utc": "2026-06-06 15:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/157.20.182.18",
            "tags": "AS152485,C2,censys,RAT",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1617577": [
        {
            "ioc_value": "143.92.43.246:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-18 12:49:25",
            "last_seen_utc": "2026-06-06 15:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1617285": [
        {
            "ioc_value": "5.152.16.189:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-10-17 12:02:17",
            "last_seen_utc": "2026-06-06 15:44:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.152.16.189",
            "tags": "AS35805,C2,censys,Netsupport,RAT,SILKNET-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1617002": [
        {
            "ioc_value": "3.143.55.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-17 08:02:43",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.143.55.137",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1616729": [
        {
            "ioc_value": "47.129.2.130:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:50:54",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1616728": [
        {
            "ioc_value": "ns1.gygiuh.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:49:04",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1616141": [
        {
            "ioc_value": "23.94.44.214:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-15 18:47:32",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1615761": [
        {
            "ioc_value": "89.58.30.49:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-14 20:02:48",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.58.30.49",
            "tags": "AS197540,C2,censys,Covenant,NETCUP-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1614712": [
        {
            "ioc_value": "5.101.82.60:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-10-14 08:01:33",
            "last_seen_utc": "2026-06-06 15:44:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.60",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1611540": [
        {
            "ioc_value": "windowsedgeupdater.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2025-10-10 18:36:02",
            "last_seen_utc": "2026-06-06 06:07:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=windowsedgeupdater.com",
            "tags": "Amadey,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1608986": [
        {
            "ioc_value": "45.138.16.162:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-10-07 20:02:30",
            "last_seen_utc": "2026-06-06 15:44:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.138.16.162",
            "tags": "AdaptixC2,AS210558,C2,censys,SERVICES-1337-GMBH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1608605": [
        {
            "ioc_value": "143.92.43.153:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-07 02:49:11",
            "last_seen_utc": "2026-06-06 15:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1608606": [
        {
            "ioc_value": "143.92.43.231:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-07 02:49:11",
            "last_seen_utc": "2026-06-06 15:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1604499": [
        {
            "ioc_value": "149.50.135.215:49152",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-30 00:02:15",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.50.135.215",
            "tags": "AdaptixC2,AS27823,C2,censys,Dattatec.com",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1603281": [
        {
            "ioc_value": "154.92.15.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-28 15:48:32",
            "last_seen_utc": "2026-06-06 16:00:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1602818": [
        {
            "ioc_value": "84.27.86.226:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-09-27 16:02:13",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/84.27.86.226",
            "tags": "AS33915,C2,censys,Netsupport,RAT,TNF-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1601556": [
        {
            "ioc_value": "115.120.245.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 20:00:39",
            "last_seen_utc": "2026-06-06 16:00:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.120.245.134",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-987654321,HWCSNET",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1601359": [
        {
            "ioc_value": "196.251.69.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 12:51:01",
            "last_seen_utc": "2026-06-06 16:00:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1599651": [
        {
            "ioc_value": "47.113.186.138:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-24 20:00:10",
            "last_seen_utc": "2026-06-06 16:00:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.113.186.138",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1599442": [
        {
            "ioc_value": "43.162.114.240:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-24 08:02:13",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.240",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1598336": [
        {
            "ioc_value": "43.139.170.200:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-23 06:06:58",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1598300": [
        {
            "ioc_value": "43.162.114.107:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-23 04:00:59",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.107",
            "tags": "AS132203,censys,EvilGinx,Phishing",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1598102": [
        {
            "ioc_value": "159.75.211.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:51:05",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1598100": [
        {
            "ioc_value": "cstest.mucfc.store",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:49:30",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1597898": [
        {
            "ioc_value": "ns2.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:38",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1597894": [
        {
            "ioc_value": "ns1.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:35",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1596535": [
        {
            "ioc_value": "43.162.108.133:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-21 16:01:22",
            "last_seen_utc": "2026-06-06 15:44:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.108.133",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1589781": [
        {
            "ioc_value": "91.92.241.142:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-09-14 04:00:25",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.92.241.142",
            "tags": "AS209800,C2,censys,METASPINNER-ASN,RAT",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1589687": [
        {
            "ioc_value": "213.252.247.119:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-09-13 20:02:04",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/213.252.247.119",
            "tags": "AS61272,C2,censys,IST-AS,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1589068": [
        {
            "ioc_value": "18.167.174.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-09-13 04:01:58",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.167.174.198",
            "tags": "AMAZON-02,AS16509,C2,censys,Pupy,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1588133": [
        {
            "ioc_value": "195.178.110.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:36",
            "last_seen_utc": "2026-06-06 16:00:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.178.110.135",
            "tags": "AS48090,C2,censys,CobaltStrike,cs-watermark-426352781,DMZHOST",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1588128": [
        {
            "ioc_value": "150.158.170.241:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:30",
            "last_seen_utc": "2026-06-06 16:00:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.158.170.241",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1587773": [
        {
            "ioc_value": "106.12.111.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 06:43:14",
            "last_seen_utc": "2026-06-06 16:00:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1587441": [
        {
            "ioc_value": "101.32.109.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-10 20:01:24",
            "last_seen_utc": "2026-06-06 16:00:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.32.109.112",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1587229": [
        {
            "ioc_value": "142.93.86.246:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-10 16:02:07",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/142.93.86.246",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1582910": [
        {
            "ioc_value": "8.138.222.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-06 20:01:18",
            "last_seen_utc": "2026-06-06 16:00:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.138.222.215",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1582784": [
        {
            "ioc_value": "103.236.70.158:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-09-06 12:01:48",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.236.70.158",
            "tags": "AS134768,C2,censys,CHINANET-SHAANXI-CLOUD-BASE,DcRAT,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1581557": [
        {
            "ioc_value": "8.148.194.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-04 07:40:17",
            "last_seen_utc": "2026-06-06 16:00:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.148.194.157#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1580723": [
        {
            "ioc_value": "47.236.159.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:52:55",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1580721": [
        {
            "ioc_value": "ns2.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:45",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1580720": [
        {
            "ioc_value": "ns1.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:42",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1580257": [
        {
            "ioc_value": "47.121.137.8:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 05:43:42",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.121.137.8#80",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1580237": [
        {
            "ioc_value": "47.99.196.178:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-02 04:01:38",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.99.196.178",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1578899": [
        {
            "ioc_value": "103.73.66.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-31 20:50:07",
            "last_seen_utc": "2026-06-06 16:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577783": [
        {
            "ioc_value": "43.199.78.142:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:50:45",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577775": [
        {
            "ioc_value": "n1.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577776": [
        {
            "ioc_value": "n2.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577777": [
        {
            "ioc_value": "n3.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577774": [
        {
            "ioc_value": "lab.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:01",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1574437": [
        {
            "ioc_value": "183.63.173.29:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-25 16:50:36",
            "last_seen_utc": "2026-06-06 15:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1574099": [
        {
            "ioc_value": "89.216.98.17:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-08-25 08:14:17",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/89.216.98.17#3085",
            "tags": "c2,netsupport,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1573705": [
        {
            "ioc_value": "43.163.112.217:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-25 00:00:27",
            "last_seen_utc": "2026-06-06 16:00:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.163.112.217",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1573120": [
        {
            "ioc_value": "62.60.226.133:61287",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-08-23 18:00:42",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/250823-wglgsaxsdv",
            "tags": "AS214351,C2,rat,remcos,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1572312": [
        {
            "ioc_value": "dakk5rnsax46s.cfc-execute.su.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-21 12:49:30",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1571607": [
        {
            "ioc_value": "178.16.55.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-20 08:02:12",
            "last_seen_utc": "2026-06-06 16:00:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.16.55.53",
            "tags": "C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1570775": [
        {
            "ioc_value": "116.203.31.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-18 20:01:59",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.203.31.207",
            "tags": "AS24940,C2,censys,CobaltStrike,cs-watermark-987654321,HETZNER-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1570558": [
        {
            "ioc_value": "150.187.25.242:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-17 20:01:54",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.187.25.242",
            "tags": "AS20312,C2,censys,CobaltStrike,cs-watermark-987654321,Fundacion",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1569825": [
        {
            "ioc_value": "8.138.167.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 15:22:26",
            "last_seen_utc": "2026-06-06 16:00:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.138.167.123#443",
            "tags": "c2,cobaltstrike,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1569794": [
        {
            "ioc_value": "118.31.2.114:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 08:18:04",
            "last_seen_utc": "2026-06-06 08:00:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1569780": [
        {
            "ioc_value": "119.29.231.118:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 08:01:47",
            "last_seen_utc": "2026-06-06 16:00:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.29.231.118",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1569167": [
        {
            "ioc_value": "116.198.233.179:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 21:57:45",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/116.198.233.179#6666",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1568713": [
        {
            "ioc_value": "117.72.184.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 06:21:34",
            "last_seen_utc": "2026-06-06 16:00:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.184.172",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1567756": [
        {
            "ioc_value": "116.198.233.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 20:01:25",
            "last_seen_utc": "2026-06-06 16:00:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.198.233.179",
            "tags": "AS137699,C2,censys,CHINATELECOM-JIANGSU-SUQIAN-IDC,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1567668": [
        {
            "ioc_value": "62.117.98.115:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-12 12:01:59",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.117.98.115",
            "tags": "AS8732,C2,censys,COMCOR-AS,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1567648": [
        {
            "ioc_value": "107.174.115.43:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 10:50:19",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1567234": [
        {
            "ioc_value": "45.204.216.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-11 08:01:15",
            "last_seen_utc": "2026-06-06 16:00:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.204.216.24",
            "tags": "AS62468,C2,censys,CobaltStrike,cs-watermark-987654321,HKCLOUDX",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1565164": [
        {
            "ioc_value": "8.219.76.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-06 12:54:26",
            "last_seen_utc": "2026-06-06 16:00:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1564496": [
        {
            "ioc_value": "47.105.36.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-05 08:53:36",
            "last_seen_utc": "2026-06-06 16:00:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1564345": [
        {
            "ioc_value": "185.233.166.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1564346": [
        {
            "ioc_value": "185.233.166.124:9702",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1563211": [
        {
            "ioc_value": "89.197.168.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-01 20:01:06",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.197.168.150",
            "tags": "AS47474,C2,censys,Mythic,VIRTUAL1",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1561533": [
        {
            "ioc_value": "217.154.212.25:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-28 05:29:47",
            "last_seen_utc": "2026-06-06 15:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1561181": [
        {
            "ioc_value": "117.72.181.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-27 16:00:55",
            "last_seen_utc": "2026-06-06 16:00:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.181.104",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1560617": [
        {
            "ioc_value": "47.236.130.154:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-25 10:51:18",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1558329": [
        {
            "ioc_value": "103.125.248.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-19 12:49:30",
            "last_seen_utc": "2026-06-06 16:00:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1558180": [
        {
            "ioc_value": "104.167.16.88:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-07-19 00:01:30",
            "last_seen_utc": "2026-06-06 15:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/104.167.16.88",
            "tags": "AdaptixC2,AS16276,C2,censys,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1558066": [
        {
            "ioc_value": "193.112.84.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-18 12:51:20",
            "last_seen_utc": "2026-06-06 16:00:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1558027": [
        {
            "ioc_value": "206.189.227.148:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-07-18 08:01:12",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.189.227.148",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1557619": [
        {
            "ioc_value": "ns3.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:04",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1557618": [
        {
            "ioc_value": "ns2.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:03",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1557617": [
        {
            "ioc_value": "ns1.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:02",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1556099": [
        {
            "ioc_value": "51.81.171.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-07-12 00:01:36",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1555914": [
        {
            "ioc_value": "38.207.178.172:8002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-07-11 12:05:09",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS139659,chaos,LUCIDACLOUD LIMITED",
            "anonymous": "0",
            "reporter": "antiphishorg"
        }
    ],
    "1554642": [
        {
            "ioc_value": "88.129.151.109:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-07-08 20:56:28",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1554340": [
        {
            "ioc_value": "88.129.147.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-07-07 20:54:20",
            "last_seen_utc": "2026-06-06 15:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1554064": [
        {
            "ioc_value": "8.152.99.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-06 20:00:32",
            "last_seen_utc": "2026-06-06 16:00:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.152.99.85",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1553070": [
        {
            "ioc_value": "112.125.19.107:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-03 20:00:15",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/112.125.19.107",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-1234567890",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1550284": [
        {
            "ioc_value": "54.38.94.225:8886",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-28 08:51:18",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1549901": [
        {
            "ioc_value": "217.154.212.25:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-27 06:58:55",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/217.154.212.25#80",
            "tags": "c2,cobaltstrike,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1549030": [
        {
            "ioc_value": "156.227.233.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-25 04:00:19",
            "last_seen_utc": "2026-06-06 16:00:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/156.227.233.153",
            "tags": "AS138152,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1548335": [
        {
            "ioc_value": "107.173.122.193:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-21 18:56:08",
            "last_seen_utc": "2026-06-06 15:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1548333": [
        {
            "ioc_value": "ns3.admlistdel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-21 18:55:13",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1548330": [
        {
            "ioc_value": "ns2.admlistdel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-21 18:55:10",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1547925": [
        {
            "ioc_value": "82.156.156.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-20 06:01:32",
            "last_seen_utc": "2026-06-06 16:00:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1546246": [
        {
            "ioc_value": "191.93.118.254:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-06-18 08:02:37",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9265a6e0b26a240f1f8bffddf3b36d0e533919d0c894bd66839a90e351961464/",
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1546232": [
        {
            "ioc_value": "191.93.118.254:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-06-18 07:58:54",
            "last_seen_utc": "2026-06-06 15:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6ecbf71d231e9b9e7459b97c97d94aed467481b5b4f22af288bbaea5945c1af4/",
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1546074": [
        {
            "ioc_value": "exclusionremcoss.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-06-17 18:52:20",
            "last_seen_utc": "2026-06-05 13:19:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/domain/exclusionremcoss.duckdns.org",
            "tags": "c2,domain,remcos,virustotal",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1545615": [
        {
            "ioc_value": "8.147.128.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-17 03:12:25",
            "last_seen_utc": "2026-06-06 16:00:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1545597": [
        {
            "ioc_value": "47.107.136.106:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-16 23:10:50",
            "last_seen_utc": "2026-06-06 15:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1545348": [
        {
            "ioc_value": "8.137.149.67:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-16 12:01:46",
            "last_seen_utc": "2026-06-06 15:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.137.149.67",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1544612": [
        {
            "ioc_value": "47.109.48.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-13 20:01:30",
            "last_seen_utc": "2026-06-06 16:00:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.48.57",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1544039": [
        {
            "ioc_value": "39.104.78.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-12 08:56:19",
            "last_seen_utc": "2026-06-06 16:00:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.104.78.25",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1543390": [
        {
            "ioc_value": "8.155.0.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-10 16:01:13",
            "last_seen_utc": "2026-06-06 16:00:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.155.0.238",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1542759": [
        {
            "ioc_value": "119.45.29.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-08 20:01:01",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.45.29.172",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1542057": [
        {
            "ioc_value": "172.81.131.230:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-06 20:01:59",
            "last_seen_utc": "2026-06-06 15:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.81.131.230",
            "tags": "AS27176,C2,censys,DATAWAGON,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1541666": [
        {
            "ioc_value": "3.19.238.211:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-06-06 16:01:21",
            "last_seen_utc": "2026-06-06 15:44:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.19.238.211",
            "tags": "AMAZON-02,AS16509,C2,censys,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1541652": [
        {
            "ioc_value": "68.64.176.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 16:00:50",
            "last_seen_utc": "2026-06-06 16:00:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.176.42",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-391144938,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1541446": [
        {
            "ioc_value": "ns1.admlistdel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 02:53:59",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1541358": [
        {
            "ioc_value": "blindbut.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2025-06-05 14:00:08",
            "last_seen_utc": "2026-06-06 06:07:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=blindbut.icu",
            "tags": "Amadey,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1538881": [
        {
            "ioc_value": "193.239.85.15:2083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-06-02 12:01:04",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.239.85.15",
            "tags": "AS9009,C2,censys,Havoc,M247",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1538799": [
        {
            "ioc_value": "47.109.198.8:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-02 05:47:28",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.109.198.8#6000",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1538358": [
        {
            "ioc_value": "54.38.94.225:8885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-01 08:52:56",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1537676": [
        {
            "ioc_value": "101.43.91.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:39",
            "last_seen_utc": "2026-06-06 16:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1537678": [
        {
            "ioc_value": "59.110.7.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:38",
            "last_seen_utc": "2026-06-06 16:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1536850": [
        {
            "ioc_value": "99.112.198.249:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-05-30 08:53:21",
            "last_seen_utc": "2026-06-06 15:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1536831": [
        {
            "ioc_value": "129.28.85.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 08:00:11",
            "last_seen_utc": "2026-06-06 16:00:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/129.28.85.210",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1536730": [
        {
            "ioc_value": "111.229.4.108:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 02:55:17",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1536683": [
        {
            "ioc_value": "161.35.176.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-05-29 22:26:34",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.176.231",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Havoc",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1535962": [
        {
            "ioc_value": "217.154.212.25:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-28 08:01:49",
            "last_seen_utc": "2026-06-06 15:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/217.154.212.25",
            "tags": "AS8560,C2,censys,IONOS-AS,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1535963": [
        {
            "ioc_value": "159.89.36.127:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-28 08:01:49",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/159.89.36.127",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1534920": [
        {
            "ioc_value": "8.216.80.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-26 20:01:30",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.216.80.229",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1533613": [
        {
            "ioc_value": "221.132.29.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-24 20:01:31",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/221.132.29.137",
            "tags": "AS45899,C2,censys,Mythic,VNPT-AS-VN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1533071": [
        {
            "ioc_value": "1.15.174.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-24 11:13:44",
            "last_seen_utc": "2026-06-06 16:00:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1532332": [
        {
            "ioc_value": "8.140.239.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-23 05:34:51",
            "last_seen_utc": "2026-06-06 16:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1532341": [
        {
            "ioc_value": "msg.msdegeup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-22 23:55:29",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1532306": [
        {
            "ioc_value": "178.217.98.23:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-05-22 20:01:48",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.217.98.23",
            "tags": "AS48282,censys,Chaos,panel,VDSINA-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1527752": [
        {
            "ioc_value": "117.72.206.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 08:00:35",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.206.39",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1526357": [
        {
            "ioc_value": "106.54.61.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-20 06:37:42",
            "last_seen_utc": "2026-06-06 16:00:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1525628": [
        {
            "ioc_value": "118.26.39.237:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-19 12:00:22",
            "last_seen_utc": "2026-06-06 15:45:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.26.39.237",
            "tags": "AS135377,C2,censys,CobaltStrike,cs-watermark-666666666,UCLOUD-HK-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1525250": [
        {
            "ioc_value": "124.223.114.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-18 15:34:22",
            "last_seen_utc": "2026-06-06 16:00:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://intelinsights.substack.com/p/from-939-to-85-hunting-cobalt-strike",
            "tags": "censys,cobaltstrike",
            "anonymous": "0",
            "reporter": "orlof_v"
        }
    ],
    "1525138": [
        {
            "ioc_value": "47.108.139.103:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-18 08:05:45",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.108.139.103",
            "tags": "AS37963,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1524773": [
        {
            "ioc_value": "167.99.51.2:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 14:42:08",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.99.51.2#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1524641": [
        {
            "ioc_value": "167.99.51.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 08:00:32",
            "last_seen_utc": "2026-06-06 15:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.51.2",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1524331": [
        {
            "ioc_value": "8.216.80.229:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 06:27:29",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.216.80.229#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1524319": [
        {
            "ioc_value": "101.35.109.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-17 06:26:23",
            "last_seen_utc": "2026-06-06 16:00:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/101.35.109.246#443",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1523466": [
        {
            "ioc_value": "103.171.35.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:57",
            "last_seen_utc": "2026-06-06 16:00:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1523462": [
        {
            "ioc_value": "60.204.169.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:47",
            "last_seen_utc": "2026-06-06 16:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1523434": [
        {
            "ioc_value": "179.43.186.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:13:56",
            "last_seen_utc": "2026-06-06 16:00:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1523246": [
        {
            "ioc_value": "8.134.70.73:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 05:25:01",
            "last_seen_utc": "2026-06-06 10:32:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1521639": [
        {
            "ioc_value": "8.134.70.73:88",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-13 14:08:42",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "beacon,c2,Cobalt Strike,CobaltStrike",
            "anonymous": "0",
            "reporter": "pancak3lullz"
        }
    ],
    "1520343": [
        {
            "ioc_value": "38.54.112.234:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:58:42",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1520342": [
        {
            "ioc_value": "asusupdateserver.asuscomm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:55:40",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1519438": [
        {
            "ioc_value": "47.109.190.151:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-11 06:11:06",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.190.151",
            "tags": "AS37963,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1519450": [
        {
            "ioc_value": "https://topguningit.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-05-11 05:00:17",
            "last_seen_utc": "2026-06-06 16:11:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Rony"
        }
    ],
    "1518529": [
        {
            "ioc_value": "47.108.140.10:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-09 05:36:03",
            "last_seen_utc": "2026-06-06 15:44:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.108.140.10",
            "tags": "AS37963,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1518023": [
        {
            "ioc_value": "106.52.207.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-07 13:00:19",
            "last_seen_utc": "2026-06-06 15:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1516147": [
        {
            "ioc_value": "41.216.189.77:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-05-05 12:00:58",
            "last_seen_utc": "2026-06-06 15:44:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/41.216.189.77",
            "tags": "AS211138,C2,censys,Havoc,PRIVATEHOSTING-NET",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1513590": [
        {
            "ioc_value": "54.38.94.225:8882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-04-29 08:53:29",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1513585": [
        {
            "ioc_value": "107.143.144.154:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-04-29 08:43:42",
            "last_seen_utc": "2026-06-06 15:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1509966": [
        {
            "ioc_value": "167.71.13.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-22 12:21:47",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.71.13.103#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1492577": [
        {
            "ioc_value": "118.31.114.149:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-17 00:01:32",
            "last_seen_utc": "2026-06-06 15:45:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.31.114.149",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1492480": [
        {
            "ioc_value": "113.45.253.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-16 16:01:35",
            "last_seen_utc": "2026-06-06 15:45:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.45.253.80",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-666666666,HWCSNET",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1492218": [
        {
            "ioc_value": "112.126.68.61:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-16 08:01:30",
            "last_seen_utc": "2026-06-06 15:44:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/112.126.68.61",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-100000",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1492012": [
        {
            "ioc_value": "47.83.134.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-04-15 16:02:30",
            "last_seen_utc": "2026-06-06 15:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.83.134.97",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Havoc",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1491748": [
        {
            "ioc_value": "193.142.146.70:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-04-15 04:01:37",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.142.146.70",
            "tags": "AS213438,C2,censys,COLOCATEL-INC,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1486437": [
        {
            "ioc_value": "167.71.13.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-10 05:55:49",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.71.13.103",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1485438": [
        {
            "ioc_value": "3.146.93.253:55502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-07 13:47:33",
            "last_seen_utc": "2026-06-06 09:56:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "redirector,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1485428": [
        {
            "ioc_value": "3.146.93.253:55501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-07 12:47:32",
            "last_seen_utc": "2026-06-06 14:50:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "redirector,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1485431": [
        {
            "ioc_value": "3.146.93.253:55590",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-07 12:47:31",
            "last_seen_utc": "2026-06-06 15:54:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "redirector,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1485432": [
        {
            "ioc_value": "3.146.93.253:55500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-07 12:47:30",
            "last_seen_utc": "2026-06-06 11:35:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "redirector,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1485433": [
        {
            "ioc_value": "52.15.213.182:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-07 12:47:28",
            "last_seen_utc": "2026-06-06 11:36:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "bot,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1485407": [
        {
            "ioc_value": "3.146.93.253:55600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-07 11:09:30",
            "last_seen_utc": "2026-06-06 15:23:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "redirector,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1485408": [
        {
            "ioc_value": "gecsge4e1e5427f8.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-07 11:09:30",
            "last_seen_utc": "2026-06-06 15:54:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "redirector,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1484906": [
        {
            "ioc_value": "52.14.24.94:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-05 05:50:37",
            "last_seen_utc": "2026-06-06 15:54:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "bot,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1463173": [
        {
            "ioc_value": "38.46.218.36:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:14",
            "last_seen_utc": "2026-06-06 16:12:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1463174": [
        {
            "ioc_value": "38.46.218.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:13",
            "last_seen_utc": "2026-06-06 15:12:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1463176": [
        {
            "ioc_value": "38.46.218.39:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:12",
            "last_seen_utc": "2026-06-06 14:12:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1463152": [
        {
            "ioc_value": "200.107.126.227:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-04-02 08:01:26",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/200.107.126.227",
            "tags": "AS14754,C2,censys,Netsupport,RAT,TELECOMUNICACIONES",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1462468": [
        {
            "ioc_value": "43.143.229.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-01 10:24:30",
            "last_seen_utc": "2026-06-06 16:00:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1459722": [
        {
            "ioc_value": "193.142.146.70:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-03-28 04:00:35",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.142.146.70",
            "tags": "AS213438,C2,censys,COLOCATEL-INC,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1458716": [
        {
            "ioc_value": "ehchq7m7rpvdr.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-25 22:53:24",
            "last_seen_utc": "2026-06-06 16:00:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1457513": [
        {
            "ioc_value": "103.142.147.17:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-24 06:29:33",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.142.147.17",
            "tags": "AS135581,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1454148": [
        {
            "ioc_value": "103.142.147.18:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1454149": [
        {
            "ioc_value": "103.142.147.19:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-06-06 15:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1452404": [
        {
            "ioc_value": "47.116.208.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-20 12:01:27",
            "last_seen_utc": "2026-06-06 16:00:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.116.208.81",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1446559": [
        {
            "ioc_value": "www.dyshop.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-12 02:47:28",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1446149": [
        {
            "ioc_value": "210.2.169.213:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-11 12:01:13",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.2.169.213",
            "tags": "AS23966,C2,censys,Havoc,LDN-AS-PK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1441769": [
        {
            "ioc_value": "51.81.171.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-06 04:01:35",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1440611": [
        {
            "ioc_value": "43.153.2.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-04 00:00:37",
            "last_seen_utc": "2026-06-06 15:45:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.153.2.113",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-100000,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1440087": [
        {
            "ioc_value": "15.204.95.228:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-03 12:01:16",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1439776": [
        {
            "ioc_value": "150.5.174.231:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-02 20:01:03",
            "last_seen_utc": "2026-06-06 15:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.5.174.231",
            "tags": "AS150436,BYTEPLUS-AS-AP,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1439368": [
        {
            "ioc_value": "54.38.94.225:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-03-02 08:46:23",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1439168": [
        {
            "ioc_value": "47.129.171.26:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:47:46",
            "last_seen_utc": "2026-06-06 15:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1439166": [
        {
            "ioc_value": "ns.1.3.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1439167": [
        {
            "ioc_value": "ns.1.4.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1414086": [
        {
            "ioc_value": "169.239.129.45:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-17 10:47:48",
            "last_seen_utc": "2026-06-06 15:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1411885": [
        {
            "ioc_value": "192.52.167.140:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-02-14 00:01:07",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/192.52.167.140",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Netsupport,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1409420": [
        {
            "ioc_value": "103.215.81.156:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-02-10 20:43:10",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1404178": [
        {
            "ioc_value": "20.74.209.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-05 22:51:06",
            "last_seen_utc": "2026-06-06 16:00:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1402495": [
        {
            "ioc_value": "62.60.226.42:43155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-02-02 16:00:48",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.60.226.42",
            "tags": "AS214351,C2,censys,FEMOIT,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1402480": [
        {
            "ioc_value": "service-rchqbzvz-1301033415.sh.tencentapigw.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-02 12:49:35",
            "last_seen_utc": "2026-06-06 16:00:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1399002": [
        {
            "ioc_value": "173.44.141.226:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-02-01 08:44:50",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1398921": [
        {
            "ioc_value": "62.60.226.6:43155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-02-01 04:00:38",
            "last_seen_utc": "2026-06-06 15:44:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.60.226.6",
            "tags": "AS214351,C2,censys,FEMOIT,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1398820": [
        {
            "ioc_value": "162.252.173.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 13:44:30",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1398810": [
        {
            "ioc_value": "162.252.173.12:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 12:01:38",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/162.252.173.12",
            "tags": "AS9009,backdoor,C2,censys,M247,Ransomhub",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1398803": [
        {
            "ioc_value": "213.252.247.119:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-01-31 12:00:35",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/213.252.247.119",
            "tags": "AS61272,C2,censys,IST-AS,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1398748": [
        {
            "ioc_value": "193.203.49.90:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 08:45:58",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1398657": [
        {
            "ioc_value": "8.134.108.73:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-31 07:01:30",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.134.108.73",
            "tags": "AS37963,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1396136": [
        {
            "ioc_value": "38.146.28.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:47:19",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1396135": [
        {
            "ioc_value": "185.33.86.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:45:48",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1396130": [
        {
            "ioc_value": "38.146.28.93:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:01:38",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.146.28.93",
            "tags": "AS174,backdoor,C2,censys,COGENT-174,Ransomhub",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1396129": [
        {
            "ioc_value": "193.203.49.90:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:01:37",
            "last_seen_utc": "2026-06-06 15:43:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.203.49.90",
            "tags": "AS204957,backdoor,C2,censys,GREENFLOID-AS,Ransomhub",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1396102": [
        {
            "ioc_value": "185.33.86.15:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 04:01:31",
            "last_seen_utc": "2026-06-06 15:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.33.86.15",
            "tags": "AS202015,backdoor,C2,censys,HZ-US-AS,Ransomhub",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1394408": [
        {
            "ioc_value": "54.38.94.225:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-26 08:46:00",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1394158": [
        {
            "ioc_value": "54.38.94.225:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-25 20:47:04",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1391935": [
        {
            "ioc_value": "173.44.141.226:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-23 07:00:09",
            "last_seen_utc": "2026-06-06 15:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/173.44.141.226",
            "tags": "AS62904,backdoor,C2,censys,Ransomhub",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1390969": [
        {
            "ioc_value": "1brainfix.ddns.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2025-01-21 20:45:43",
            "last_seen_utc": "2026-06-06 06:05:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "anyrun,c2,njrat",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1386236": [
        {
            "ioc_value": "https://135.181.31.18",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-01-18 16:10:00",
            "last_seen_utc": "2026-06-06 16:10:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1384954": [
        {
            "ioc_value": "92.118.112.208:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:16:20",
            "last_seen_utc": "2026-06-06 15:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384953": [
        {
            "ioc_value": "92.118.112.208:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:16:19",
            "last_seen_utc": "2026-06-06 15:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384933": [
        {
            "ioc_value": "38.180.81.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:15:21",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384934": [
        {
            "ioc_value": "38.180.81.153:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:15:21",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384921": [
        {
            "ioc_value": "167.99.139.231:8004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-17 09:14:13",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384912": [
        {
            "ioc_value": "185.174.101.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384913": [
        {
            "ioc_value": "185.174.101.240:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384914": [
        {
            "ioc_value": "185.174.101.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384915": [
        {
            "ioc_value": "185.174.101.69:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-06-06 15:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384908": [
        {
            "ioc_value": "108.181.115.171:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384909": [
        {
            "ioc_value": "108.181.115.171:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384910": [
        {
            "ioc_value": "108.181.182.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384911": [
        {
            "ioc_value": "108.181.182.143:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384790": [
        {
            "ioc_value": "at1.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384791": [
        {
            "ioc_value": "at2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384792": [
        {
            "ioc_value": "at3.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-06-06 15:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1383739": [
        {
            "ioc_value": "ns3177629.ip-51-195-60.eu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-15 00:03:52",
            "last_seen_utc": "2026-06-05 06:03:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.195.60.102+ns3177629.ip-51-195-60.eu",
            "tags": "AS16276,C2,censys,Nosviak,OVH,Panel",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1382512": [
        {
            "ioc_value": "drrugs.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-12 12:03:45",
            "last_seen_utc": "2026-06-05 06:03:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.195.60.102+drrugs.xyz",
            "tags": "AS16276,C2,censys,Nosviak,OVH,Panel",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1381420": [
        {
            "ioc_value": "77.238.236.123:18300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:55:47",
            "last_seen_utc": "2026-06-06 15:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1381067": [
        {
            "ioc_value": "112.5.58.181:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:43:51",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380875": [
        {
            "ioc_value": "update.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380878": [
        {
            "ioc_value": "upgrade.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380837": [
        {
            "ioc_value": "ns3.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380841": [
        {
            "ioc_value": "ns3.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380833": [
        {
            "ioc_value": "ns2.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:29",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380818": [
        {
            "ioc_value": "ns2.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:27",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380815": [
        {
            "ioc_value": "ns2.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:26",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380811": [
        {
            "ioc_value": "ns1.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:25",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380783": [
        {
            "ioc_value": "ns1.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-06-06 15:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380787": [
        {
            "ioc_value": "ns1.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-06-06 15:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380635": [
        {
            "ioc_value": "8.219.78.159:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:57",
            "last_seen_utc": "2026-06-06 15:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380629": [
        {
            "ioc_value": "70.34.196.238:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:43",
            "last_seen_utc": "2026-06-06 15:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380607": [
        {
            "ioc_value": "47.98.134.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:28",
            "last_seen_utc": "2026-06-06 16:00:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380569": [
        {
            "ioc_value": "38.54.115.233:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:17:37",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380533": [
        {
            "ioc_value": "207.148.68.118:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:17:20",
            "last_seen_utc": "2026-06-06 15:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380446": [
        {
            "ioc_value": "139.180.189.95:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:16:21",
            "last_seen_utc": "2026-06-06 15:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380421": [
        {
            "ioc_value": "118.25.91.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:44",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380420": [
        {
            "ioc_value": "117.72.39.83:43872",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:43",
            "last_seen_utc": "2026-06-06 15:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380232": [
        {
            "ioc_value": "38.207.179.146:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-10 04:04:28",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.207.179.146",
            "tags": "AS139659,C2,censys,LUCID-AS-AP,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1377164": [
        {
            "ioc_value": "47.99.93.43:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-02 07:44:34",
            "last_seen_utc": "2026-06-06 15:45:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.99.93.43",
            "tags": "as37963,c2,CobaltStrike,cs-watermark-100000,shodan",
            "anonymous": "0",
            "reporter": "skocherhan"
        }
    ],
    "1376919": [
        {
            "ioc_value": "86.124.168.255:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2025-01-01 04:03:19",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.124.168.255",
            "tags": "AS8708,c2,censys,RCS-RDS,SocGholish",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1369624": [
        {
            "ioc_value": "kurama.ltd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-30 04:04:10",
            "last_seen_utc": "2026-06-05 06:03:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.195.60.102+kurama.ltd",
            "tags": "AS16276,C2,censys,Nosviak,OVH,Panel",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1359401": [
        {
            "ioc_value": "8.153.97.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-24 08:00:43",
            "last_seen_utc": "2026-06-06 16:00:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.153.97.202",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1359309": [
        {
            "ioc_value": "91.199.154.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-12-24 04:01:34",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "AS62212,C2,censys,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1358812": [
        {
            "ioc_value": "47.93.240.197:65433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-20 09:04:31",
            "last_seen_utc": "2026-06-06 15:45:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1357389": [
        {
            "ioc_value": "45.56.69.210:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-16 16:01:41",
            "last_seen_utc": "2026-06-06 15:44:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.56.69.210",
            "tags": "AKAMAI-LINODE-AP,AS63949,censys,EvilGoPhish,panel,Phishing",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1356002": [
        {
            "ioc_value": "113.44.90.0:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-12 06:21:40",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.44.90.0",
            "tags": "AS55990,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1352876": [
        {
            "ioc_value": "139.196.126.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-06 07:36:52",
            "last_seen_utc": "2026-06-06 16:00:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1350210": [
        {
            "ioc_value": "117.72.39.83:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-02 21:01:15",
            "last_seen_utc": "2026-06-06 15:45:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1349957": [
        {
            "ioc_value": "117.72.39.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-01 07:43:42",
            "last_seen_utc": "2026-06-06 15:45:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1349567": [
        {
            "ioc_value": "216.118.101.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:19",
            "last_seen_utc": "2026-06-06 15:44:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1349531": [
        {
            "ioc_value": "216.118.101.132:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:11",
            "last_seen_utc": "2026-06-06 15:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1349510": [
        {
            "ioc_value": "216.118.101.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:08",
            "last_seen_utc": "2026-06-06 15:43:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1349492": [
        {
            "ioc_value": "216.118.101.216:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:04",
            "last_seen_utc": "2026-06-06 15:44:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1349438": [
        {
            "ioc_value": "216.118.101.54:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:05:51",
            "last_seen_utc": "2026-06-06 15:44:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1348902": [
        {
            "ioc_value": "216.118.101.108:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-29 13:56:30",
            "last_seen_utc": "2026-06-06 15:43:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1348295": [
        {
            "ioc_value": "47.90.142.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:54",
            "last_seen_utc": "2026-06-06 16:00:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1348026": [
        {
            "ioc_value": "8.137.114.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:07",
            "last_seen_utc": "2026-06-06 16:00:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1346058": [
        {
            "ioc_value": "servicioremotoempresas.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-19 18:00:05",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1342672": [
        {
            "ioc_value": "gapi-node.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2024-11-07 11:11:05",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "domain,lummastealer",
            "anonymous": "0",
            "reporter": "abus3reports"
        }
    ],
    "1340201": [
        {
            "ioc_value": "146.70.158.198:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-10-30 17:53:55",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Sliver%20C2",
            "tags": "c2,sliver,sliverc2",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1339913": [
        {
            "ioc_value": "39.107.242.125:666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-10-29 08:02:00",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-426352781",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1338675": [
        {
            "ioc_value": "https://stripplasst.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:41",
            "last_seen_utc": "2026-06-06 15:56:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1338673": [
        {
            "ioc_value": "https://skinnyjeanso.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:39",
            "last_seen_utc": "2026-06-06 16:03:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1338670": [
        {
            "ioc_value": "https://coolarition.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:34",
            "last_seen_utc": "2026-06-06 16:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1336210": [
        {
            "ioc_value": "exitlife.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2024-10-13 13:18:10",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1334295": [
        {
            "ioc_value": "47.116.17.233:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-10-06 12:01:50",
            "last_seen_utc": "2026-06-06 15:45:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.116.17.233",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1332624": [
        {
            "ioc_value": "154.221.17.44:2888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-10-02 06:31:45",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1332328": [
        {
            "ioc_value": "195.100.198.220:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-10-01 16:02:09",
            "last_seen_utc": "2026-06-06 15:43:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.100.198.220",
            "tags": "AS5400,BT,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1329042": [
        {
            "ioc_value": "118.25.148.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-09-25 08:00:47",
            "last_seen_utc": "2026-06-06 16:00:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.148.25",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1326604": [
        {
            "ioc_value": "206.210.123.104:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-09-20 08:01:06",
            "last_seen_utc": "2026-06-06 15:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "AS33130,C2,censys,IASL,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1326366": [
        {
            "ioc_value": "189.115.194.189:9990",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-09-19 16:01:20",
            "last_seen_utc": "2026-06-06 15:43:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/189.115.194.189",
            "tags": "AS18881,C2,censys,RAT,TELEFONICA",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1326051": [
        {
            "ioc_value": "https://isomicrotich.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:51",
            "last_seen_utc": "2026-06-06 16:12:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": "0",
            "reporter": "spamhaus"
        }
    ],
    "1326052": [
        {
            "ioc_value": "https://rilomenifis.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:50",
            "last_seen_utc": "2026-06-06 16:03:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": "0",
            "reporter": "spamhaus"
        }
    ],
    "1321901": [
        {
            "ioc_value": "64.23.213.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-09-07 16:01:45",
            "last_seen_utc": "2026-06-06 15:44:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.23.213.61",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1319266": [
        {
            "ioc_value": "154.221.17.44:2666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-09-01 12:00:42",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.221.17.44",
            "tags": "AS142403,C2,censys,CobaltStrike,cs-watermark-666666666,YISUCLOUDLTD-HK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1317376": [
        {
            "ioc_value": "https://pikchestop.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-06-06 15:54:59",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": "0",
            "reporter": "johannes"
        }
    ],
    "1317377": [
        {
            "ioc_value": "https://indepahote.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-06-06 16:09:40",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": "0",
            "reporter": "johannes"
        }
    ],
    "1317070": [
        {
            "ioc_value": "86.53.241.21:447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-29 00:01:11",
            "last_seen_utc": "2026-06-06 15:44:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.53.241.21",
            "tags": "AS3257,C2,censys,GTT-BACKBONE,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1316706": [
        {
            "ioc_value": "213.252.247.119:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2024-08-28 04:01:10",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/213.252.247.119",
            "tags": "AS61272,C2,censys,IST-AS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1316522": [
        {
            "ioc_value": "107.22.165.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-27 04:00:34",
            "last_seen_utc": "2026-06-06 15:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.22.165.49",
            "tags": "AMAZON-AES,AS14618,C2,censys,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1314694": [
        {
            "ioc_value": "83.229.120.73:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-08-22 10:04:33",
            "last_seen_utc": "2026-06-06 15:44:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.120.73",
            "tags": "AS139659,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1313657": [
        {
            "ioc_value": "193.19.242.55:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-19 19:55:59",
            "last_seen_utc": "2026-06-06 15:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.19.242.55",
            "tags": "AS35319,AS48964,C2,censys,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1313194": [
        {
            "ioc_value": "110.13.35.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-18 14:04:40",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/110.13.35.37",
            "tags": "AS9318,C2,censys,RAT,SKB-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1312402": [
        {
            "ioc_value": "20.188.119.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-17 14:04:20",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1312338": [
        {
            "ioc_value": "210.249.114.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-17 02:04:24",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "AS2516,C2,censys,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1312117": [
        {
            "ioc_value": "20.188.119.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-16 14:02:33",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1311619": [
        {
            "ioc_value": "23.24.178.35:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-15 22:40:43",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.35",
            "tags": "AS20214,C2,censys,COMCAST-20214,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1311614": [
        {
            "ioc_value": "120.25.239.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-15 22:40:39",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/120.25.239.36",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1309755": [
        {
            "ioc_value": "146.70.158.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-08-11 21:50:57",
            "last_seen_utc": "2026-06-06 15:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.158.198",
            "tags": "AS9009,C2,censys,M247",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1296480": [
        {
            "ioc_value": "43.138.0.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-07-09 19:05:36",
            "last_seen_utc": "2026-06-06 16:00:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1296006": [
        {
            "ioc_value": "213.149.181.121:469",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:58",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/213.149.181.121",
            "tags": "CYTA-NETWORK Internet Services,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1296003": [
        {
            "ioc_value": "20.105.139.205:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:48",
            "last_seen_utc": "2026-06-06 15:43:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.105.139.205",
            "tags": "MICROSOFT-CORP-MSN-AS-BLOCK,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1295752": [
        {
            "ioc_value": "210.249.114.153:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-08 06:51:14",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1295405": [
        {
            "ioc_value": "23.24.178.33:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-07 03:48:38",
            "last_seen_utc": "2026-06-06 15:44:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.33",
            "tags": "COMCAST-7922,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1292877": [
        {
            "ioc_value": "210.249.114.154:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-03 06:52:14",
            "last_seen_utc": "2026-06-06 15:43:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291417": [
        {
            "ioc_value": "198.244.197.118:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:40",
            "last_seen_utc": "2026-06-06 15:43:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/198.244.197.118",
            "tags": "NetSupportRAT,OVH",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291414": [
        {
            "ioc_value": "206.210.123.104:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:30",
            "last_seen_utc": "2026-06-06 15:43:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "IASL,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291411": [
        {
            "ioc_value": "61.96.204.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:19",
            "last_seen_utc": "2026-06-06 15:44:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/61.96.204.117",
            "tags": "DREAMX-AS DREAMLINE CO.,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291410": [
        {
            "ioc_value": "185.23.192.33:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:15",
            "last_seen_utc": "2026-06-06 15:43:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.23.192.33",
            "tags": "NetSupportRAT,WINET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291409": [
        {
            "ioc_value": "2.136.235.200:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:10",
            "last_seen_utc": "2026-06-06 15:43:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/2.136.235.200",
            "tags": "NetSupportRAT,TELEFONICA_DE_ESPANA",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291397": [
        {
            "ioc_value": "210.249.114.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:04:31",
            "last_seen_utc": "2026-06-06 15:43:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291297": [
        {
            "ioc_value": "londopas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:04",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1291296": [
        {
            "ioc_value": "berjimek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:03",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1291010": [
        {
            "ioc_value": "www.qianxinnbplus.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 10:13:19",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HKLNIL Landui Cloud ComputingHK Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1289464": [
        {
            "ioc_value": "50.116.12.237:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-26 17:08:27",
            "last_seen_utc": "2026-06-06 10:32:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-426352781",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1289423": [
        {
            "ioc_value": "152.32.202.240:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-26 17:07:43",
            "last_seen_utc": "2026-06-06 15:45:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1287670": [
        {
            "ioc_value": "91.199.154.103:34211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-06-22 06:45:48",
            "last_seen_utc": "2026-06-06 15:44:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "Sliver",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1285430": [
        {
            "ioc_value": "ieee-ecce.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1285431": [
        {
            "ioc_value": "kauzalvip.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1285432": [
        {
            "ioc_value": "nakit-yok.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1285433": [
        {
            "ioc_value": "nathanhr.services",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1283657": [
        {
            "ioc_value": "support.whatsappsignup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-10 09:26:05",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,PEG TECH INC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1278385": [
        {
            "ioc_value": "static.nvidiadrives.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 19:42:15",
            "last_seen_utc": "2026-06-06 16:00:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1278172": [
        {
            "ioc_value": "119.91.208.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 08:38:33",
            "last_seen_utc": "2026-06-06 16:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1277937": [
        {
            "ioc_value": "47.109.69.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-01 13:08:25",
            "last_seen_utc": "2026-06-06 16:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1277588": [
        {
            "ioc_value": "101.43.32.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-31 12:57:33",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1276810": [
        {
            "ioc_value": "asterchildrenshoes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:53:46",
            "last_seen_utc": "2026-06-06 16:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BL Networks,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1276802": [
        {
            "ioc_value": "124.223.41.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:52:55",
            "last_seen_utc": "2026-06-06 16:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1276786": [
        {
            "ioc_value": "8.210.9.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 10:17:04",
            "last_seen_utc": "2026-06-06 16:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,CobaltStrike,cs-watermark-0",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1276244": [
        {
            "ioc_value": "https://65.108.55.55:9000/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-05-27 16:13:21",
            "last_seen_utc": "2026-06-06 16:10:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1275630": [
        {
            "ioc_value": "pt-security.ru",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-25 22:18:29",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MTW-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1274726": [
        {
            "ioc_value": "47.92.127.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-24 13:15:35",
            "last_seen_utc": "2026-06-06 16:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1273973": [
        {
            "ioc_value": "119.28.83.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-22 11:06:58",
            "last_seen_utc": "2026-06-06 16:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1273882": [
        {
            "ioc_value": "51.15.16.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2024-05-21 18:51:48",
            "last_seen_utc": "2026-06-06 15:44:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.16.116",
            "tags": "Online SAS,SocGholish",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1273456": [
        {
            "ioc_value": "139.159.203.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-21 12:53:29",
            "last_seen_utc": "2026-06-06 16:00:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,HWCSNET Huawei Cloud Service data center",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1272788": [
        {
            "ioc_value": "123.58.198.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-19 07:56:13",
            "last_seen_utc": "2026-06-06 16:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1271699": [
        {
            "ioc_value": "vip8806.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-16 07:53:43",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS LLC,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1271605": [
        {
            "ioc_value": "blmdiscount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-06-06 16:00:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1271606": [
        {
            "ioc_value": "91.238.181.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-06-06 16:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1271347": [
        {
            "ioc_value": "118.25.85.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 15:33:07",
            "last_seen_utc": "2026-06-06 16:00:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.85.198",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-305419896,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1270684": [
        {
            "ioc_value": "64.7.198.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-14 10:14:21",
            "last_seen_utc": "2026-06-06 16:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BLNWX,CobaltStrike,cs-watermark-426352781",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1269727": [
        {
            "ioc_value": "113.31.105.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:31",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "China Telecom (Group),CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1269724": [
        {
            "ioc_value": "185.196.8.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:10",
            "last_seen_utc": "2026-06-06 16:00:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1269723": [
        {
            "ioc_value": "action-winds.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:09",
            "last_seen_utc": "2026-06-06 16:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1269721": [
        {
            "ioc_value": "microstar.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:08",
            "last_seen_utc": "2026-06-06 16:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1267565": [
        {
            "ioc_value": "113.31.106.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 10:14:57",
            "last_seen_utc": "2026-06-06 16:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHINANET-SHANGHAI-MAN China Telecom Group,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1267486": [
        {
            "ioc_value": "111.230.12.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 07:48:08",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.230.12.238",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1266959": [
        {
            "ioc_value": "134.122.130.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-06 12:49:25",
            "last_seen_utc": "2026-06-06 16:00:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1263972": [
        {
            "ioc_value": "134.122.130.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-29 12:51:26",
            "last_seen_utc": "2026-06-06 16:00:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1263319": [
        {
            "ioc_value": "124.71.106.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-28 17:59:06",
            "last_seen_utc": "2026-06-06 16:00:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Huawei Cloud Service data center",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1262666": [
        {
            "ioc_value": "118.31.116.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-26 12:59:31",
            "last_seen_utc": "2026-06-06 16:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1262568": [
        {
            "ioc_value": "8.134.11.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-25 22:12:56",
            "last_seen_utc": "2026-06-06 16:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1261845": [
        {
            "ioc_value": "165.227.108.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-24 13:08:20",
            "last_seen_utc": "2026-06-06 16:00:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-970865301,DigitalOcean LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1260893": [
        {
            "ioc_value": "80.66.75.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:49",
            "last_seen_utc": "2026-06-06 16:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GRIZ-INET-SERVICE",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1260890": [
        {
            "ioc_value": "101.201.54.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:43",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1259796": [
        {
            "ioc_value": "62.204.41.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-21 15:09:17",
            "last_seen_utc": "2026-06-06 16:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.204.41.11",
            "tags": "AS59425,c2,censys,CobaltStrike,cs-watermark-1580103824,HORIZONMSK-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1255726": [
        {
            "ioc_value": "124.220.6.158:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-11 10:15:16",
            "last_seen_utc": "2026-06-06 15:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&virtual_hosts=EXCLUDE&q=%28services.software.uniform_resource_identifier%3A+%60cpe%3A2.3%3Aa%3Afortra%3Acobalt_strike%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%60%29+and+autonomous_system.name%3D%60TENCENT-NET-AP+Shenzhen+Tencent+Computer+Systems+Company+Limited%60",
            "tags": "AS45090,c2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1255727": [
        {
            "ioc_value": "124.220.6.158:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-11 10:15:15",
            "last_seen_utc": "2026-06-06 15:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&virtual_hosts=EXCLUDE&q=%28services.software.uniform_resource_identifier%3A+%60cpe%3A2.3%3Aa%3Afortra%3Acobalt_strike%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%60%29+and+autonomous_system.name%3D%60TENCENT-NET-AP+Shenzhen+Tencent+Computer+Systems+Company+Limited%60",
            "tags": "AS45090,c2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1255012": [
        {
            "ioc_value": "159.223.0.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-04-09 06:47:29",
            "last_seen_utc": "2026-06-06 15:43:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/159.223.0.103",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1252542": [
        {
            "ioc_value": "185.196.10.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-02 10:17:26",
            "last_seen_utc": "2026-06-06 16:00:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,SIMPLECARRIER",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1250157": [
        {
            "ioc_value": "soneypaly.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 14:42:02",
            "last_seen_utc": "2026-06-06 16:00:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1249815": [
        {
            "ioc_value": "47.105.69.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 07:57:29",
            "last_seen_utc": "2026-06-06 16:00:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1248363": [
        {
            "ioc_value": "https://titnovacrion.top/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.unidentified_111",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Unidentified 111 (Latrodectus)",
            "first_seen_utc": "2024-03-22 19:47:18",
            "last_seen_utc": "2026-06-06 16:11:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "1245476": [
        {
            "ioc_value": "47.100.87.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-09 20:54:40",
            "last_seen_utc": "2026-06-06 16:00:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1244781": [
        {
            "ioc_value": "194.165.16.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 20:55:37",
            "last_seen_utc": "2026-06-06 16:00:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FLYSERVERS-ENDCLIENTS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1244726": [
        {
            "ioc_value": "googlesupportacc.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 10:12:56",
            "last_seen_utc": "2026-06-06 16:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASSEFLOW,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1241656": [
        {
            "ioc_value": "121.43.55.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-21 22:13:19",
            "last_seen_utc": "2026-06-06 16:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1237621": [
        {
            "ioc_value": "qw.regcssv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-07 10:12:21",
            "last_seen_utc": "2026-06-06 16:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,FLYSERVERS-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1236577": [
        {
            "ioc_value": "ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-03 19:38:15",
            "last_seen_utc": "2026-06-06 16:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.22.66.152+ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "tags": "AMAZON-02,AS16509,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1236276": [
        {
            "ioc_value": "20.56.70.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-02 06:00:13",
            "last_seen_utc": "2026-06-06 16:00:49",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "malpulse"
        }
    ],
    "1235332": [
        {
            "ioc_value": "www.louangelwolf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-30 06:20:34",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1551089073",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1234854": [
        {
            "ioc_value": "kkudndkwatnfevcaqeefytqnh.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:18",
            "last_seen_utc": "2026-06-06 16:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1234859": [
        {
            "ioc_value": "whxzqkbbtzvdyxdeseoiyujzs.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1234860": [
        {
            "ioc_value": "uohhunkmnfhbimtagizqgwpmv.to",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1234928": [
        {
            "ioc_value": "114.55.133.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:40",
            "last_seen_utc": "2026-06-06 16:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/114.55.133.151",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1234909": [
        {
            "ioc_value": "117.72.39.83:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:20",
            "last_seen_utc": "2026-06-06 15:45:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1234304": [
        {
            "ioc_value": "38.147.189.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2024-01-24 18:49:24",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.147.189.199",
            "tags": "Pupy RAT,XNNET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1233919": [
        {
            "ioc_value": "www.idn15r69vh3fwhzclfoeuaoy.today",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-23 13:53:21",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.219.229.99+www.idn15r69vh3fwhzclfoeuaoy.today",
            "tags": "AS45102,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1231802": [
        {
            "ioc_value": "164-90-169-184.cprapid.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-18 13:44:13",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.169.184+164-90-169-184.cprapid.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1230963": [
        {
            "ioc_value": "https://65.21.187.53/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-01-16 08:13:32",
            "last_seen_utc": "2026-06-06 16:10:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1230909": [
        {
            "ioc_value": "lz4.tiktok123.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-15 16:27:00",
            "last_seen_utc": "2026-06-06 16:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230478": [
        {
            "ioc_value": "164.92.79.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-13 06:47:25",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.79.49",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1230429": [
        {
            "ioc_value": "site.dev.hutechweb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-12 18:36:24",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230076": [
        {
            "ioc_value": "ns1.fiducaire.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-06-06 16:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230077": [
        {
            "ioc_value": "ns1.asurances.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-06-06 16:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230078": [
        {
            "ioc_value": "sagsblog.telinduslab.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230079": [
        {
            "ioc_value": "ns1.jocelynhealth.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1590258876",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1229840": [
        {
            "ioc_value": "ns.emaratalyoum.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-10 10:50:13",
            "last_seen_utc": "2026-06-06 16:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1727139162",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1229817": [
        {
            "ioc_value": "161.35.239.147:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-10 06:48:20",
            "last_seen_utc": "2026-06-06 15:43:22",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.239.147",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1229694": [
        {
            "ioc_value": "emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:19",
            "last_seen_utc": "2026-06-06 16:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1229695": [
        {
            "ioc_value": "ns1.emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:17",
            "last_seen_utc": "2026-06-06 16:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1229661": [
        {
            "ioc_value": "111.92.243.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 08:45:29",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HFTCL-AS-AP High Family Technology Co. Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1228458": [
        {
            "ioc_value": "139.9.62.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 21:31:13",
            "last_seen_utc": "2026-06-06 16:00:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.9.62.19",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1228181": [
        {
            "ioc_value": "101.133.225.51:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 14:48:41",
            "last_seen_utc": "2026-06-06 15:44:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.133.225.51",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1228033": [
        {
            "ioc_value": "143.110.151.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-01-05 06:45:36",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/143.110.151.209",
            "tags": "DIGITALOCEAN-ASN,Sliver",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1227297": [
        {
            "ioc_value": "106.54.209.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-02 14:31:12",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/106.54.209.36",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1226488": [
        {
            "ioc_value": "astra4512.startdedicated.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-30 11:33:25",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GD-EMEA-DC-SXB1",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1224105": [
        {
            "ioc_value": "cs.xcb.one",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-27 22:15:29",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1223678": [
        {
            "ioc_value": "8.140.203.92:7817",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-12-26 06:46:27",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.140.203.92",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1221451": [
        {
            "ioc_value": "62.234.27.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-18 05:00:11",
            "last_seen_utc": "2026-06-06 16:00:50",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "malpulse"
        }
    ],
    "1213636": [
        {
            "ioc_value": "MicrosoftSyst3m.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-16 22:12:14",
            "last_seen_utc": "2026-06-06 16:00:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,GLOBALLAYER",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1213211": [
        {
            "ioc_value": "117.72.39.83:33333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-15 18:59:31",
            "last_seen_utc": "2026-06-06 15:45:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1209246": [
        {
            "ioc_value": "unzip2.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-04 08:45:50",
            "last_seen_utc": "2026-06-06 16:00:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1205166": [
        {
            "ioc_value": "techsyscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-06-06 16:00:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1205167": [
        {
            "ioc_value": "yify88.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-06-06 16:00:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1205164": [
        {
            "ioc_value": "americcorp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:02",
            "last_seen_utc": "2026-06-06 16:00:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1204685": [
        {
            "ioc_value": "tech-guard.vguard.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-22 20:04:09",
            "last_seen_utc": "2026-06-06 16:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/44.204.120.159+tech-guard.vguard.tech",
            "tags": "AMAZON-AES,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1203913": [
        {
            "ioc_value": "shohetrc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2023-11-21 12:36:02",
            "last_seen_utc": "2026-06-06 06:07:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=shohetrc.com",
            "tags": "Amadey,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1202628": [
        {
            "ioc_value": "ns.manager.moonlighter.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-15 20:24:37",
            "last_seen_utc": "2026-06-06 16:00:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1893164628,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1201144": [
        {
            "ioc_value": "101.34.222.38:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.viper_rat",
            "malware_alias": null,
            "malware_printable": "Viper RAT",
            "first_seen_utc": "2023-11-09 17:50:07",
            "last_seen_utc": "2026-06-06 15:43:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.34.222.38",
            "tags": "C2,censys,RAT",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1200343": [
        {
            "ioc_value": "dev.theokanegroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-09 04:06:44",
            "last_seen_utc": "2026-06-06 16:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/134.209.164.110+dev.theokanegroup.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1199545": [
        {
            "ioc_value": "38.54.115.233:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-06 21:04:29",
            "last_seen_utc": "2026-06-06 15:45:18",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "malpulse"
        }
    ],
    "1199506": [
        {
            "ioc_value": "bwyb.love",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-06 18:07:30",
            "last_seen_utc": "2026-06-06 16:00:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.242.158.114+bwyb.love",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1199160": [
        {
            "ioc_value": "www.sunwu.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-05 15:00:42",
            "last_seen_utc": "2026-06-06 16:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.157.149.194+www.sunwu.world",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1192255": [
        {
            "ioc_value": "139.155.148.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-24 10:39:59",
            "last_seen_utc": "2026-06-06 16:00:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.155.148.131",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1191379": [
        {
            "ioc_value": "www.goocoinorg.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-20 21:57:56",
            "last_seen_utc": "2026-06-06 16:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+www.goocoinorg.com&ref=threatfox",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1189545": [
        {
            "ioc_value": "airlinesapp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-16 08:49:32",
            "last_seen_utc": "2026-06-06 16:00:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,DigitalOcean LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1188605": [
        {
            "ioc_value": "lectricelfuel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-13 19:49:34",
            "last_seen_utc": "2026-06-06 16:00:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+lectricelfuel.com&ref=threatfox",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1187879": [
        {
            "ioc_value": "143.110.151.209:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2023-10-12 01:35:38",
            "last_seen_utc": "2026-06-06 15:43:14",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/143.110.151.209",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1187462": [
        {
            "ioc_value": "117.72.8.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-11 12:59:56",
            "last_seen_utc": "2026-06-06 16:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.8.192",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1180378": [
        {
            "ioc_value": "111.229.187.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-30 16:12:13",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "malpulse"
        }
    ],
    "1177540": [
        {
            "ioc_value": "wcbradley.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2023-09-27 18:41:09",
            "last_seen_utc": "2026-06-06 06:05:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,historicalandnew,NanoCore,rat",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1165497": [
        {
            "ioc_value": "igo0gle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-21 09:29:08",
            "last_seen_utc": "2026-06-06 16:00:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-ALVIVA,CobaltStrike,cs-watermark-674054486",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1165172": [
        {
            "ioc_value": "8.217.217.243:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-09-20 18:47:20",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.217.217.243",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1162850": [
        {
            "ioc_value": "quotamoney.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:02",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162852": [
        {
            "ioc_value": "fisholl.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:02",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162853": [
        {
            "ioc_value": "programmbox.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:02",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162855": [
        {
            "ioc_value": "woodcat.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:02",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162862": [
        {
            "ioc_value": "doorblu.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:02",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162849": [
        {
            "ioc_value": "buyerbrand.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:01",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162829": [
        {
            "ioc_value": "coolworks.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:00",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162831": [
        {
            "ioc_value": "gitarlessonfinger.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:00",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162837": [
        {
            "ioc_value": "coursenote.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:00",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162839": [
        {
            "ioc_value": "balancelag.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:00",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1162841": [
        {
            "ioc_value": "singlesfree.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-09-11 17:51:00",
            "last_seen_utc": "2026-06-06 04:41:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "1ZRR4H"
        }
    ],
    "1160369": [
        {
            "ioc_value": "blazeblaze.ddns.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2023-09-10 22:34:52",
            "last_seen_utc": "2026-06-06 06:05:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,historicalandnew,remcos",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1155921": [
        {
            "ioc_value": "csxv.sec.cm",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-09 20:06:55",
            "last_seen_utc": "2026-06-06 16:00:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHANGWAY-AS,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1155319": [
        {
            "ioc_value": "43.136.38.59:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-05 21:52:59",
            "last_seen_utc": "2026-06-06 16:00:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1152278": [
        {
            "ioc_value": "withoutedge.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:05",
            "last_seen_utc": "2026-06-06 16:01:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152277": [
        {
            "ioc_value": "thconnewfoot.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:04",
            "last_seen_utc": "2026-06-06 16:01:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152274": [
        {
            "ioc_value": "caixas.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-06-06 16:00:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152275": [
        {
            "ioc_value": "ddllsearch.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-06-06 16:00:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152276": [
        {
            "ioc_value": "gepcash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-06-06 16:01:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152272": [
        {
            "ioc_value": "amazonclouds.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-06-06 16:00:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152273": [
        {
            "ioc_value": "amur-city.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-06-06 16:00:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1151693": [
        {
            "ioc_value": "43.153.222.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-23 11:56:21",
            "last_seen_utc": "2026-06-06 16:00:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1149951": [
        {
            "ioc_value": "164.92.145.128:7810",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2023-08-14 18:46:43",
            "last_seen_utc": "2026-06-06 15:43:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.145.128",
            "tags": "Brute Ratel C4,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1149946": [
        {
            "ioc_value": "pctor.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:05",
            "last_seen_utc": "2026-06-06 16:01:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1149945": [
        {
            "ioc_value": "tehomics.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:04",
            "last_seen_utc": "2026-06-06 16:01:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1149944": [
        {
            "ioc_value": "instant-healthonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:03",
            "last_seen_utc": "2026-06-06 16:01:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1148731": [
        {
            "ioc_value": "stratpringl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-05 14:38:23",
            "last_seen_utc": "2026-06-06 16:01:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,PINDC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1148487": [
        {
            "ioc_value": "onlinetechdesk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-04 11:01:52",
            "last_seen_utc": "2026-06-06 16:01:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike,cs-watermark-587247372",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1146843": [
        {
            "ioc_value": "harmonyshoused.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:25:44",
            "last_seen_utc": "2026-06-06 16:01:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1146834": [
        {
            "ioc_value": "api.office-updates.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:24:41",
            "last_seen_utc": "2026-06-06 16:00:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-494165167,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1146619": [
        {
            "ioc_value": "mkbkygbgwcdc.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-02 10:24:58",
            "last_seen_utc": "2026-06-06 16:01:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,KAOPU-HK Kaopu Cloud HK Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1144026": [
        {
            "ioc_value": "ekostroy33.ru",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-31 11:01:39",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-SUISSE,CobaltStrike,cs-watermark-0",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1140114": [
        {
            "ioc_value": "tcessolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-25 10:17:22",
            "last_seen_utc": "2026-06-06 16:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS202973,CobaltStrike,cs-watermark-587247372",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1138741": [
        {
            "ioc_value": "http://aloowforest.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-07-18 17:57:56",
            "last_seen_utc": "2026-06-06 04:41:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/c4d44b15-e208-4db2-b119-351ceef1f068",
            "tags": "Lumma,Stealer",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1138601": [
        {
            "ioc_value": "http://speedtestip.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-07-18 05:35:24",
            "last_seen_utc": "2026-06-06 04:41:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/05cd0861-68b0-4b15-8ad4-6179430d986d",
            "tags": "Lumma,stealer",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1138390": [
        {
            "ioc_value": "http://many-verses.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-07-16 18:51:47",
            "last_seen_utc": "2026-06-06 04:41:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/16736490-2916-42c4-9a6a-e2d2ea841ce3",
            "tags": "KjGtqi,Lumma,Stealer",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1138361": [
        {
            "ioc_value": "http://worldofpoetry.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-07-16 15:56:48",
            "last_seen_utc": "2026-06-06 04:41:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/9f4ac06d-5c74-4405-be6c-86be69bf66e0",
            "tags": "Lumma,Stealer",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1138204": [
        {
            "ioc_value": "http://crazypictures.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-07-15 15:27:17",
            "last_seen_utc": "2026-06-06 04:41:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/1f182b9d-da31-498f-8e04-c26d6f999d35",
            "tags": "Lumma,Stealer",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1138196": [
        {
            "ioc_value": "rw1.sentrysource.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-15 12:48:31",
            "last_seen_utc": "2026-06-06 16:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-93937751,ROGERS-COMMUNICATIONS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1137213": [
        {
            "ioc_value": "http://clonecloud-my.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-07-11 05:33:00",
            "last_seen_utc": "2026-06-06 04:41:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/2162c485-a4a5-45d4-a304-cc6e812b3577",
            "tags": "Lumma,Stealer,YT6gHy",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1135804": [
        {
            "ioc_value": "pedagogists.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:02",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1135803": [
        {
            "ioc_value": "cdnsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:01",
            "last_seen_utc": "2026-06-06 16:01:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1135691": [
        {
            "ioc_value": "http://agustfreeday-my.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-07-03 07:07:02",
            "last_seen_utc": "2026-06-06 04:41:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/bbe7d580-0a5e-4ec6-9658-c4821455d624",
            "tags": "iOqpIq,Lumma,Stealer",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1134732": [
        {
            "ioc_value": "http://flowers-my.xyz/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-06-29 06:30:24",
            "last_seen_utc": "2026-06-06 04:41:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/88e5e14b-87b8-4df1-a647-8889c32b68d2",
            "tags": "Lumma,Stealer",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1134787": [
        {
            "ioc_value": "1.15.248.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-28 22:51:22",
            "last_seen_utc": "2026-06-06 16:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1134128": [
        {
            "ioc_value": "check1.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:12:17",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1134127": [
        {
            "ioc_value": "check.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:11:33",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1133505": [
        {
            "ioc_value": "usadevgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-22 17:12:29",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,WAICORE-TRANSIT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1132563": [
        {
            "ioc_value": "103.27.186.185:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-06-20 18:49:40",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.27.186.185",
            "tags": "Pupy RAT,SNL-HK Starry Network Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1131885": [
        {
            "ioc_value": "http://gservice-node.io/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-06-19 19:49:43",
            "last_seen_utc": "2026-06-06 04:41:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/crep1x/status/1670881176364408833",
            "tags": "Lumma,stealer",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1131883": [
        {
            "ioc_value": "gservice-node.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-06-19 19:49:06",
            "last_seen_utc": "2026-06-06 04:41:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Lumma,stealer",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1131330": [
        {
            "ioc_value": "http://217.12.206.230/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-06-16 22:15:55",
            "last_seen_utc": "2026-06-06 04:41:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/4e682046-d702-46c7-91c5-6f2a6c9a0909/",
            "tags": "Lumma,Stealer",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1128165": [
        {
            "ioc_value": "heastings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-11 22:26:06",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,M247",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1128099": [
        {
            "ioc_value": "45.135.118.251:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-11 17:23:14",
            "last_seen_utc": "2026-06-05 12:46:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1127715": [
        {
            "ioc_value": "unitechdb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:05",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1127713": [
        {
            "ioc_value": "cornptia.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1127714": [
        {
            "ioc_value": "eyefinancemonitor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1127447": [
        {
            "ioc_value": "surplusofer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-08 16:27:41",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1126526": [
        {
            "ioc_value": "http://185.99.133.246/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-06-04 19:33:16",
            "last_seen_utc": "2026-06-06 04:41:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Lumma,stealer",
            "anonymous": "0",
            "reporter": "0xw4ifu"
        }
    ],
    "1122048": [
        {
            "ioc_value": "dianqi2.dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:42:02",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1122047": [
        {
            "ioc_value": "dianqi1.dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:46",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1122046": [
        {
            "ioc_value": "dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:31",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1122045": [
        {
            "ioc_value": "dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:10",
            "last_seen_utc": "2026-06-06 15:44:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1121462": [
        {
            "ioc_value": "skynet-i.asuscomm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:36:26",
            "last_seen_utc": "2026-06-06 15:44:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,STC-AS PJSC Rostelecom Krasnodar",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1121460": [
        {
            "ioc_value": "update.microsoftapply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:35:48",
            "last_seen_utc": "2026-06-06 15:44:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-Not Found,DediPath",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1120772": [
        {
            "ioc_value": "australiansuper.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-23 12:37:36",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike,cs-watermark-348901740",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1116637": [
        {
            "ioc_value": "sheersdesigns.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:03",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1116636": [
        {
            "ioc_value": "artmicrodesign.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:02",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1115696": [
        {
            "ioc_value": "http://195.123.227.138/c2sock",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2023-05-14 08:10:28",
            "last_seen_utc": "2026-06-06 04:41:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/c31fecf8-b6fc-4d4a-a212-64b3d852e449",
            "tags": "Lumma,Stealer",
            "anonymous": "0",
            "reporter": "g0njxa"
        }
    ],
    "1114522": [
        {
            "ioc_value": "103.27.186.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-05-10 18:49:37",
            "last_seen_utc": "2026-06-06 15:43:04",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.27.186.185",
            "tags": "Pupy RAT,SNL-HK Starry Network Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1112839": [
        {
            "ioc_value": "situotech.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-06 16:13:31",
            "last_seen_utc": "2026-06-06 16:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,HARMONYHOSTING-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1111457": [
        {
            "ioc_value": "35.201.196.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-05-05 12:41:05",
            "last_seen_utc": "2026-06-06 15:44:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/35.201.196.246",
            "tags": "GOOGLE-CLOUD-PLATFORM,Pupy RAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1110863": [
        {
            "ioc_value": "39.106.36.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:43",
            "last_seen_utc": "2026-06-06 15:44:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.106.36.96",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1110862": [
        {
            "ioc_value": "36.95.131.171:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:41",
            "last_seen_utc": "2026-06-06 15:44:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/36.95.131.171",
            "tags": "Deimos,TELKOMNET-AS-AP PT Telekomunikasi Indonesia",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1110860": [
        {
            "ioc_value": "18.162.155.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:35",
            "last_seen_utc": "2026-06-06 15:43:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.162.155.202",
            "tags": "AMAZON-02,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1110859": [
        {
            "ioc_value": "8.218.26.114:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:33",
            "last_seen_utc": "2026-06-06 15:44:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.218.26.114",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1110858": [
        {
            "ioc_value": "3.209.12.178:3060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:30",
            "last_seen_utc": "2026-06-06 15:44:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.209.12.178",
            "tags": "AMAZON-AES,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1108307": [
        {
            "ioc_value": "feralhendown.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2023-04-26 18:30:06",
            "last_seen_utc": "2026-06-06 06:07:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "amadey,currentandold,triage",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1106335": [
        {
            "ioc_value": "maboloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1106336": [
        {
            "ioc_value": "matong.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1105988": [
        {
            "ioc_value": "qw.sveexec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-21 10:20:17",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,GLOBALLAYER",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1103771": [
        {
            "ioc_value": "77.242.250.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-15 12:28:52",
            "last_seen_utc": "2026-06-06 16:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1416875320",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1102558": [
        {
            "ioc_value": "lls-rs.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-12 09:02:56",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,PROSPERO-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1096685": [
        {
            "ioc_value": "iony.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1096686": [
        {
            "ioc_value": "office36o.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1096683": [
        {
            "ioc_value": "feyrijavac.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1096684": [
        {
            "ioc_value": "fidelyus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1095276": [
        {
            "ioc_value": "jacketsupport.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 22:27:30",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,GLOBALLAYER",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1095042": [
        {
            "ioc_value": "duckducklive.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 04:51:21",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b5da1db6d69f2f872e603beb0f121c68f3320ed33a0c9835bfc1a931d177c947",
            "tags": "391144938,Beacon,Cobalt Strike,CobaltStrike",
            "anonymous": "0",
            "reporter": "AndreGironda"
        }
    ],
    "1094484": [
        {
            "ioc_value": "louvree.abudhabe.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-28 15:52:23",
            "last_seen_utc": "2026-06-06 16:01:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1826426664,EMIRATES-INTERNET Emirates Internet",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1092077": [
        {
            "ioc_value": "jquerymaingame.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092078": [
        {
            "ioc_value": "mail-my-account.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092079": [
        {
            "ioc_value": "my-accounts-gooogle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092080": [
        {
            "ioc_value": "pegistrationads.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092075": [
        {
            "ioc_value": "eaglehardwares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092076": [
        {
            "ioc_value": "information.baby",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092009": [
        {
            "ioc_value": "moviegallerys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 13:36:29",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1091575": [
        {
            "ioc_value": "acroserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 22:40:17",
            "last_seen_utc": "2026-06-06 16:01:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1091535": [
        {
            "ioc_value": "atechniques.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 19:45:49",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1091454": [
        {
            "ioc_value": "winsatoom.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 13:33:15",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-668694132",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1087542": [
        {
            "ioc_value": "devoinnanote.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-13 04:47:12",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-2130772225,SHARKTECH",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1082976": [
        {
            "ioc_value": "ponzinivek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082977": [
        {
            "ioc_value": "ruplearben.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082978": [
        {
            "ioc_value": "talonbilling.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082979": [
        {
            "ioc_value": "gorillagaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082980": [
        {
            "ioc_value": "chanimoblie.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082871": [
        {
            "ioc_value": "kbnexc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:02",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082870": [
        {
            "ioc_value": "jquerysslx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:01",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082838": [
        {
            "ioc_value": "e-servicesolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 13:15:07",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA GROUP Ltd,CobaltStrike,cs-watermark-674054486",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1082591": [
        {
            "ioc_value": "devsecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-24 02:30:56",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1082417": [
        {
            "ioc_value": "www.vmware.rest",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-23 13:06:07",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-1234567890",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1081602": [
        {
            "ioc_value": "777palm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2023-02-21 12:57:12",
            "last_seen_utc": "2026-06-06 04:48:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1/",
            "tags": "Stealc,stealer",
            "anonymous": "0",
            "reporter": "sekoia_io"
        }
    ],
    "1081018": [
        {
            "ioc_value": "galspost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-17 18:25:01",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1101991775,Microsoft Corporation",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1080735": [
        {
            "ioc_value": "imvcatool.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-16 14:54:22",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1078198": [
        {
            "ioc_value": "aspnetcenter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 19:39:46",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Web Gostaran Bandar Company PJS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1078172": [
        {
            "ioc_value": "audelr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1078173": [
        {
            "ioc_value": "csou.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1078174": [
        {
            "ioc_value": "integrated-security.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1078175": [
        {
            "ioc_value": "uranustechsolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1078062": [
        {
            "ioc_value": "getsafeblog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-03 17:24:39",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1077913": [
        {
            "ioc_value": "39.107.242.125:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-03 00:16:03",
            "last_seen_utc": "2026-06-06 15:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.redpacketsecurity.com/cobalt-stike-beacon-detected-39-107-242-125-port-80/",
            "tags": "CobaltStrike,RedPacketSecurity",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1076907": [
        {
            "ioc_value": "qw.svcshosvt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:40:26",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1076896": [
        {
            "ioc_value": "nxsimdevelop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:39:18",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1075651": [
        {
            "ioc_value": "appdevtechnology.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-01 02:21:19",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1075540": [
        {
            "ioc_value": "dbx.formsift.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-31 15:09:13",
            "last_seen_utc": "2026-06-06 16:01:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1075020": [
        {
            "ioc_value": "devcloudpro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-29 11:29:55",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1074894": [
        {
            "ioc_value": "164.90.158.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:40:24",
            "last_seen_utc": "2026-06-06 15:43:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.158.199",
            "tags": "DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1074890": [
        {
            "ioc_value": "145.131.8.169:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:40:10",
            "last_seen_utc": "2026-06-06 15:43:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/145.131.8.169",
            "tags": "Mythic,SENTIA",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1074833": [
        {
            "ioc_value": "130.61.124.23:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:26:29",
            "last_seen_utc": "2026-06-06 15:43:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/130.61.124.23",
            "tags": "Covenant,ORACLE-BMC-31898",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1074144": [
        {
            "ioc_value": "support-wellsfargovis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:03",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1074141": [
        {
            "ioc_value": "recoverporta1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1074142": [
        {
            "ioc_value": "recoverportal2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1074143": [
        {
            "ioc_value": "recoveryweb2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1073670": [
        {
            "ioc_value": "vd-ntds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-23 20:33:42",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PROSPERO-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1070164": [
        {
            "ioc_value": "hnsxpharm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1070165": [
        {
            "ioc_value": "myjqueryss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1070167": [
        {
            "ioc_value": "telusmobility-billed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1070168": [
        {
            "ioc_value": "thenbkgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1070137": [
        {
            "ioc_value": "avdev.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 11:23:14",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Flyservers S.A.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1069980": [
        {
            "ioc_value": "qw.execsvct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 19:53:20",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1069895": [
        {
            "ioc_value": "azurecloudfire.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 14:15:53",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ITRESHENIYA-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1069868": [
        {
            "ioc_value": "goupdatemic.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 11:23:42",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GOOGLE",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1069579": [
        {
            "ioc_value": "mwg-update.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-18 02:29:29",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1068206": [
        {
            "ioc_value": "goodsport2023.win",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-13 17:37:32",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,VOM",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1068079": [
        {
            "ioc_value": "blackandwhiteshoose.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 21:56:23",
            "last_seen_utc": "2026-06-06 16:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1068045": [
        {
            "ioc_value": "qw.svcrencst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 20:55:06",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1067954": [
        {
            "ioc_value": "realsecuritystore.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 14:45:18",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1067924": [
        {
            "ioc_value": "fixx.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 13:04:56",
            "last_seen_utc": "2026-06-06 16:01:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SNEL",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1067646": [
        {
            "ioc_value": "allowedcloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-11 10:59:45",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HIVELOCITY Inc.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1064196": [
        {
            "ioc_value": "freegaysnews.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 19:48:39",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1064176": [
        {
            "ioc_value": "topgamenetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 18:58:09",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1064173": [
        {
            "ioc_value": "zfuxwvouqvnttpsrxe.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 16:21:02",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064075": [
        {
            "ioc_value": "cloudyspaces.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064076": [
        {
            "ioc_value": "666621.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-06-06 16:01:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064069": [
        {
            "ioc_value": "144.217.207.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064070": [
        {
            "ioc_value": "allsdone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064071": [
        {
            "ioc_value": "ipsandwich.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064072": [
        {
            "ioc_value": "cookieholder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064073": [
        {
            "ioc_value": "pingcheker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064074": [
        {
            "ioc_value": "wagonovk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064062": [
        {
            "ioc_value": "microsoftupdateassist.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064063": [
        {
            "ioc_value": "qvibova.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064064": [
        {
            "ioc_value": "cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064065": [
        {
            "ioc_value": "metalkost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064066": [
        {
            "ioc_value": "m7r4r2i2.stackpathcdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064067": [
        {
            "ioc_value": "online.cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064057": [
        {
            "ioc_value": "bartiba.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064058": [
        {
            "ioc_value": "varnart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064059": [
        {
            "ioc_value": "nsfdfdfdf.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064060": [
        {
            "ioc_value": "micorsoft.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064061": [
        {
            "ioc_value": "aigouing.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064046": [
        {
            "ioc_value": "ksplsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064047": [
        {
            "ioc_value": "lastinsuranceteam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064048": [
        {
            "ioc_value": "msdnsservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064049": [
        {
            "ioc_value": "securequoteme.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064050": [
        {
            "ioc_value": "techdevcorp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064051": [
        {
            "ioc_value": "syncorporation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064052": [
        {
            "ioc_value": "visualstudioapp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064053": [
        {
            "ioc_value": "altreeservicellc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064054": [
        {
            "ioc_value": "discountshadesdirect.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064055": [
        {
            "ioc_value": "setechnowork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064056": [
        {
            "ioc_value": "technicollit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064038": [
        {
            "ioc_value": "shiyicaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064039": [
        {
            "ioc_value": "cdn-top.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064040": [
        {
            "ioc_value": "onesecondservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064041": [
        {
            "ioc_value": "vpnupdaters.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064042": [
        {
            "ioc_value": "rodinscoldly.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064043": [
        {
            "ioc_value": "antariscapital.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064044": [
        {
            "ioc_value": "ftwealthmgt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064045": [
        {
            "ioc_value": "iconiq-capitel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064031": [
        {
            "ioc_value": "asset-trades.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064032": [
        {
            "ioc_value": "telemetrin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064033": [
        {
            "ioc_value": "secupdate4win.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064034": [
        {
            "ioc_value": "cdn-start.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064035": [
        {
            "ioc_value": "capitalmanagementdata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064036": [
        {
            "ioc_value": "lawsolutions.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064024": [
        {
            "ioc_value": "diegomaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064025": [
        {
            "ioc_value": "dp-test1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064026": [
        {
            "ioc_value": "cloudkey.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064027": [
        {
            "ioc_value": "updatevpncitrix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064028": [
        {
            "ioc_value": "classgum.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064029": [
        {
            "ioc_value": "edgeupdater.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064030": [
        {
            "ioc_value": "gfcbm.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064016": [
        {
            "ioc_value": "barmnava.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064017": [
        {
            "ioc_value": "firewallwithadvancedserurity.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064018": [
        {
            "ioc_value": "lgbtqplusfriendlydomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064019": [
        {
            "ioc_value": "market-stats.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064020": [
        {
            "ioc_value": "apabfs.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064021": [
        {
            "ioc_value": "fziomerof.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064022": [
        {
            "ioc_value": "fserd.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064023": [
        {
            "ioc_value": "verofes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064015": [
        {
            "ioc_value": "postofficeltdc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:43",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064006": [
        {
            "ioc_value": "jarvcza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064007": [
        {
            "ioc_value": "teystyjeem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064008": [
        {
            "ioc_value": "faceupfinder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064009": [
        {
            "ioc_value": "costacancordia.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064010": [
        {
            "ioc_value": "lapsusareskids.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064011": [
        {
            "ioc_value": "msupdater.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064012": [
        {
            "ioc_value": "dwordname.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064013": [
        {
            "ioc_value": "trademot.finance",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064014": [
        {
            "ioc_value": "agreminj.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063998": [
        {
            "ioc_value": "exchangeallltd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063999": [
        {
            "ioc_value": "guggenheimpartners-survey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064000": [
        {
            "ioc_value": "caresalonservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064001": [
        {
            "ioc_value": "just-findncall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064002": [
        {
            "ioc_value": "fluoxi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064003": [
        {
            "ioc_value": "buynet.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064004": [
        {
            "ioc_value": "everythingchecker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064005": [
        {
            "ioc_value": "dezword.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063995": [
        {
            "ioc_value": "goksearch.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063996": [
        {
            "ioc_value": "polyhaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063997": [
        {
            "ioc_value": "data-protection-test.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063992": [
        {
            "ioc_value": "update04.microsoft-essentials.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:39",
            "last_seen_utc": "2026-06-06 16:01:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063991": [
        {
            "ioc_value": "akaluij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:38",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063989": [
        {
            "ioc_value": "43.129.7.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-06-06 16:01:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063990": [
        {
            "ioc_value": "82.156.241.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-06-06 16:01:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063985": [
        {
            "ioc_value": "donormix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-06-06 16:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063986": [
        {
            "ioc_value": "hardicki.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063987": [
        {
            "ioc_value": "stfconnect.onthewifi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063988": [
        {
            "ioc_value": "agsdef.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-06-06 16:01:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063978": [
        {
            "ioc_value": "observerinfo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-06 16:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063979": [
        {
            "ioc_value": "dehikz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-06 16:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063980": [
        {
            "ioc_value": "cocanewline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-06 16:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063981": [
        {
            "ioc_value": "rainqor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-06 16:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063982": [
        {
            "ioc_value": "axelkim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063983": [
        {
            "ioc_value": "azimurs.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063984": [
        {
            "ioc_value": "innovativesitecreations.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-06 16:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063972": [
        {
            "ioc_value": "creditscore.usbankcreditcards.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063975": [
        {
            "ioc_value": "megumin.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063976": [
        {
            "ioc_value": "loanhelp.support",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063977": [
        {
            "ioc_value": "volsecure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-06-06 16:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063966": [
        {
            "ioc_value": "domtern.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-06-06 16:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063968": [
        {
            "ioc_value": "drakr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-06-06 16:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063969": [
        {
            "ioc_value": "devcisco.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063971": [
        {
            "ioc_value": "web-news-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063963": [
        {
            "ioc_value": "bankafrika.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063964": [
        {
            "ioc_value": "mssfr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063965": [
        {
            "ioc_value": "edgekey.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-06-06 16:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063955": [
        {
            "ioc_value": "webyoutubeshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063956": [
        {
            "ioc_value": "extic.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063957": [
        {
            "ioc_value": "reykh.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063959": [
        {
            "ioc_value": "propertynewsclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063960": [
        {
            "ioc_value": "afindisc.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063961": [
        {
            "ioc_value": "propertyinfogroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063962": [
        {
            "ioc_value": "topnewscompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063950": [
        {
            "ioc_value": "baidenfree.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063951": [
        {
            "ioc_value": "directoryupdate.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063952": [
        {
            "ioc_value": "azmnetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063953": [
        {
            "ioc_value": "onevisioncommunications.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063954": [
        {
            "ioc_value": "campioni-imam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063943": [
        {
            "ioc_value": "serviceapp1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063944": [
        {
            "ioc_value": "softcloud.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063945": [
        {
            "ioc_value": "appmind.center",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063946": [
        {
            "ioc_value": "ms-data.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063947": [
        {
            "ioc_value": "oracleup.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063948": [
        {
            "ioc_value": "topinfocompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063949": [
        {
            "ioc_value": "blockchainstartups-crypto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063934": [
        {
            "ioc_value": "expresssmash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063935": [
        {
            "ioc_value": "vgroz.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063936": [
        {
            "ioc_value": "baidengop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063937": [
        {
            "ioc_value": "ofilopex.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063938": [
        {
            "ioc_value": "aabancaa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063939": [
        {
            "ioc_value": "shermango.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063940": [
        {
            "ioc_value": "nongxinyin.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063941": [
        {
            "ioc_value": "a6m1n.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063942": [
        {
            "ioc_value": "emailbox.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063926": [
        {
            "ioc_value": "wxtencent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063927": [
        {
            "ioc_value": "emergeno.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063928": [
        {
            "ioc_value": "browngreeer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063929": [
        {
            "ioc_value": "processdec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063931": [
        {
            "ioc_value": "sndm-sndm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063932": [
        {
            "ioc_value": "sinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063933": [
        {
            "ioc_value": "vinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063918": [
        {
            "ioc_value": "westtherr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063919": [
        {
            "ioc_value": "quickaccestwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063920": [
        {
            "ioc_value": "usgrim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063921": [
        {
            "ioc_value": "onelivemusicshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063922": [
        {
            "ioc_value": "zomerax.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063923": [
        {
            "ioc_value": "fsamon.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063924": [
        {
            "ioc_value": "sscimails.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063925": [
        {
            "ioc_value": "agentrecovery.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063909": [
        {
            "ioc_value": "entertainok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063910": [
        {
            "ioc_value": "jatafatuna.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063911": [
        {
            "ioc_value": "pluyk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063912": [
        {
            "ioc_value": "affinm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063913": [
        {
            "ioc_value": "gijoxupe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063914": [
        {
            "ioc_value": "vangshares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063915": [
        {
            "ioc_value": "fudupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063917": [
        {
            "ioc_value": "contemporaryto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063902": [
        {
            "ioc_value": "ziono.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063903": [
        {
            "ioc_value": "lolutow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063904": [
        {
            "ioc_value": "niht12.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063905": [
        {
            "ioc_value": "slfcorporate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063906": [
        {
            "ioc_value": "baidu-cdn-10.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063907": [
        {
            "ioc_value": "jandoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063908": [
        {
            "ioc_value": "casevor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063897": [
        {
            "ioc_value": "gotroops.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063898": [
        {
            "ioc_value": "wtxservice.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063899": [
        {
            "ioc_value": "xevayuhace.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063900": [
        {
            "ioc_value": "suppcat.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063901": [
        {
            "ioc_value": "softloadup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063889": [
        {
            "ioc_value": "asbetysh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063890": [
        {
            "ioc_value": "ascagliarinish.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063891": [
        {
            "ioc_value": "ascasdsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063892": [
        {
            "ioc_value": "aschamp79sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063893": [
        {
            "ioc_value": "aschnurmansh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063894": [
        {
            "ioc_value": "aseleeeksh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063895": [
        {
            "ioc_value": "asensvsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063880": [
        {
            "ioc_value": "artist2actresssh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063881": [
        {
            "ioc_value": "arturprikhodkosh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063882": [
        {
            "ioc_value": "arvin78sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063883": [
        {
            "ioc_value": "arvind567shahsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063884": [
        {
            "ioc_value": "arvindkkumsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063885": [
        {
            "ioc_value": "arvosash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063886": [
        {
            "ioc_value": "arwalsersh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063887": [
        {
            "ioc_value": "aryaarieash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063888": [
        {
            "ioc_value": "aryalalexsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063870": [
        {
            "ioc_value": "dovaxanil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063871": [
        {
            "ioc_value": "hehegahu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063872": [
        {
            "ioc_value": "agriculturemachineries.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063873": [
        {
            "ioc_value": "arhipenkolenagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063874": [
        {
            "ioc_value": "aritmiagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063875": [
        {
            "ioc_value": "artes911sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063876": [
        {
            "ioc_value": "arthas89sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063877": [
        {
            "ioc_value": "arthurstevens62sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063878": [
        {
            "ioc_value": "arthurtaylor13sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063879": [
        {
            "ioc_value": "artis214sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-06 16:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063864": [
        {
            "ioc_value": "zipo-cons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063865": [
        {
            "ioc_value": "fazehotafa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063866": [
        {
            "ioc_value": "zendriol.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063867": [
        {
            "ioc_value": "sezezapa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063868": [
        {
            "ioc_value": "sorekipe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063869": [
        {
            "ioc_value": "zezinuwe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063858": [
        {
            "ioc_value": "shrekf.art",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063859": [
        {
            "ioc_value": "amaniza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063860": [
        {
            "ioc_value": "microcloud.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063861": [
        {
            "ioc_value": "anexuss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063862": [
        {
            "ioc_value": "edictsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063863": [
        {
            "ioc_value": "out1etshops.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063851": [
        {
            "ioc_value": "stepnbayac.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063852": [
        {
            "ioc_value": "chickenpoken.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063853": [
        {
            "ioc_value": "hockeysmall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063854": [
        {
            "ioc_value": "orthodoxok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063855": [
        {
            "ioc_value": "cocesovo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063856": [
        {
            "ioc_value": "familyinsurancepartner.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063857": [
        {
            "ioc_value": "senebuvuyi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063848": [
        {
            "ioc_value": "fincheck.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063849": [
        {
            "ioc_value": "svchosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063850": [
        {
            "ioc_value": "conhosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063843": [
        {
            "ioc_value": "maximumservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063844": [
        {
            "ioc_value": "conferencedesk.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063845": [
        {
            "ioc_value": "bluetechsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063846": [
        {
            "ioc_value": "allgroupservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063847": [
        {
            "ioc_value": "acitopram.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-06 16:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063838": [
        {
            "ioc_value": "businessservicesolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063839": [
        {
            "ioc_value": "gravyblicus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063840": [
        {
            "ioc_value": "firmwarekey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063841": [
        {
            "ioc_value": "updateraccount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063842": [
        {
            "ioc_value": "mvnetworking.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063832": [
        {
            "ioc_value": "avasecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063833": [
        {
            "ioc_value": "extranetserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063834": [
        {
            "ioc_value": "clacem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-06 16:01:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063835": [
        {
            "ioc_value": "eonline-cdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-06 16:01:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063836": [
        {
            "ioc_value": "cagohufe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-06 16:01:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063837": [
        {
            "ioc_value": "vezawahoy.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-06 16:01:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063826": [
        {
            "ioc_value": "tetafup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063827": [
        {
            "ioc_value": "api-trend-micro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-06 16:01:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063828": [
        {
            "ioc_value": "digital-hardware.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063829": [
        {
            "ioc_value": "aboutdatabasesoftware.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063830": [
        {
            "ioc_value": "high-control.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063831": [
        {
            "ioc_value": "soft-base.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063821": [
        {
            "ioc_value": "iptvr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063823": [
        {
            "ioc_value": "mingw.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063824": [
        {
            "ioc_value": "transfercloud.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063825": [
        {
            "ioc_value": "flashcom.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063818": [
        {
            "ioc_value": "sciencelifedata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063819": [
        {
            "ioc_value": "bookingsupport.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063820": [
        {
            "ioc_value": "ateyakima.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063813": [
        {
            "ioc_value": "buy1walmart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063816": [
        {
            "ioc_value": "drbeat.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063817": [
        {
            "ioc_value": "aialadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063810": [
        {
            "ioc_value": "hhkj222.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063811": [
        {
            "ioc_value": "yw2204.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063812": [
        {
            "ioc_value": "nordicqlobal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063806": [
        {
            "ioc_value": "favls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063807": [
        {
            "ioc_value": "linkkedin.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063808": [
        {
            "ioc_value": "magellanfit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063805": [
        {
            "ioc_value": "afspd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:03",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063804": [
        {
            "ioc_value": "164.92.70.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:46:51",
            "last_seen_utc": "2026-06-06 16:01:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063802": [
        {
            "ioc_value": "abritrum-bridges.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:44:07",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063208": [
        {
            "ioc_value": "a.wv2022.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 19:56:09",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1063123": [
        {
            "ioc_value": "apacheorg.wiki",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 02:22:09",
            "last_seen_utc": "2026-06-06 16:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDIE-AS-AP Cloudie Limited,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1062406": [
        {
            "ioc_value": "updatemicrotok.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-24 19:00:50",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-SERVERION,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1053949": [
        {
            "ioc_value": "eserverx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 21:43:42",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1050306": [
        {
            "ioc_value": "cmdatabase.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 11:41:44",
            "last_seen_utc": "2026-06-06 16:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ADM Service Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1050198": [
        {
            "ioc_value": "cloudmane.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-17 12:12:59",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1036758": [
        {
            "ioc_value": "8.212.49.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-13 11:43:38",
            "last_seen_utc": "2026-06-06 16:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Alibaba (US) Technology Co. Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1036111": [
        {
            "ioc_value": "qw.conhoosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-12 01:38:31",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1035723": [
        {
            "ioc_value": "expoglobalservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-08 20:45:56",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TIER-NET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1035558": [
        {
            "ioc_value": "www.microsofer.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-07 20:05:59",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1031731": [
        {
            "ioc_value": "googlecontentuser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 20:03:53",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/TheDFIRReport/status/1599780643222654976",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1031726": [
        {
            "ioc_value": "test.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 19:27:32",
            "last_seen_utc": "2026-06-06 16:01:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YISUCLOUDLTD-HK YISU CLOUD LTD",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1029025": [
        {
            "ioc_value": "palalto.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 11:42:38",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028963": [
        {
            "ioc_value": "esoftwareupdates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-04 20:18:27",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASGHOSTNET,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028767": [
        {
            "ioc_value": "globalplayservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 21:28:11",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028737": [
        {
            "ioc_value": "rapidfinact.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:50:52",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SHINJIRU-MY-AS-AP Shinjiru Technology Sdn Bhd",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028720": [
        {
            "ioc_value": "globalsteamclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:38:18",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028501": [
        {
            "ioc_value": "get-music-online.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-01 20:32:20",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1024554": [
        {
            "ioc_value": "msndla.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-27 16:10:54",
            "last_seen_utc": "2026-06-06 16:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1023854": [
        {
            "ioc_value": "childhealthresources.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:54:46",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1023821": [
        {
            "ioc_value": "360safeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:50:52",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1021044": [
        {
            "ioc_value": "aksaholdings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-20 10:32:06",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1012628": [
        {
            "ioc_value": "msisfx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-15 06:56:25",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/malware_traffic/status/1592262598195646464",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1009773": [
        {
            "ioc_value": "get-smartbuyer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-12 17:46:46",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1000509": [
        {
            "ioc_value": "qw.stakcl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-10 11:51:33",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "991420": [
        {
            "ioc_value": "sogouupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-08 20:20:30",
            "last_seen_utc": "2026-06-06 16:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "985010": [
        {
            "ioc_value": "dnsupdatecheck.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-07 20:10:29",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "973832": [
        {
            "ioc_value": "ipulsecloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-04 11:23:08",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "964538": [
        {
            "ioc_value": "zadiguser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-06 16:01:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964540": [
        {
            "ioc_value": "wasazokiwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964541": [
        {
            "ioc_value": "yuwajeni.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-06 16:01:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964542": [
        {
            "ioc_value": "yavahiyil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-06 16:01:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964543": [
        {
            "ioc_value": "rabihino.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964545": [
        {
            "ioc_value": "nokevohoh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964546": [
        {
            "ioc_value": "rawocav.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964548": [
        {
            "ioc_value": "deyikurihe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "952862": [
        {
            "ioc_value": "freshuper.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-30 19:51:44",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,tzulo inc.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952596": [
        {
            "ioc_value": "reebons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:32:13",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952587": [
        {
            "ioc_value": "gaswert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:23:49",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952582": [
        {
            "ioc_value": "sajij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 11:54:42",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952555": [
        {
            "ioc_value": "asasyz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:14:36",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952552": [
        {
            "ioc_value": "agazud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:12:26",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LLC Baxet",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952534": [
        {
            "ioc_value": "tuuik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:57:36",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952528": [
        {
            "ioc_value": "alfuhin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:56:46",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "950974": [
        {
            "ioc_value": "amaladin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-27 23:43:27",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "949937": [
        {
            "ioc_value": "aualadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-26 10:09:11",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "916136": [
        {
            "ioc_value": "bthserv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:42:10",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Internet Solutions & Innovations LTD.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "916115": [
        {
            "ioc_value": "nuesro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:37:35",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "916100": [
        {
            "ioc_value": "pasadonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:36:50",
            "last_seen_utc": "2026-06-06 16:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "915911": [
        {
            "ioc_value": "worldsgates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:40:40",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LUCIDACLOUD LIMITED",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "915908": [
        {
            "ioc_value": "protramal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:39:30",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "915846": [
        {
            "ioc_value": "spltst.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 01:11:02",
            "last_seen_utc": "2026-06-06 16:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,combahton GmbH",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "891477": [
        {
            "ioc_value": "cehocihit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 13:10:54",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "891461": [
        {
            "ioc_value": "cloudmicro.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 12:38:04",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "887212": [
        {
            "ioc_value": "keycloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:41:28",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PARTNER-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "886703": [
        {
            "ioc_value": "activeservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:13:41",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amati Foundation,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "886693": [
        {
            "ioc_value": "newyearbalance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:12:51",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "886516": [
        {
            "ioc_value": "xamayojir.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:02:36",
            "last_seen_utc": "2026-06-06 16:01:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "886499": [
        {
            "ioc_value": "xicefoga.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 20:58:25",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-WDC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "884091": [
        {
            "ioc_value": "ams-prd-cob.nl",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:51:56",
            "last_seen_utc": "2026-06-06 16:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "883488": [
        {
            "ioc_value": "tagujog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:35:22",
            "last_seen_utc": "2026-06-06 16:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "883412": [
        {
            "ioc_value": "mysqlserver.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:32:23",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ICME",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "883142": [
        {
            "ioc_value": "xuluxetas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:23:44",
            "last_seen_utc": "2026-06-06 16:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-NYC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "880419": [
        {
            "ioc_value": "hadujaza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-12 17:16:11",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "871733": [
        {
            "ioc_value": "softsupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "871734": [
        {
            "ioc_value": "anushl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "870515": [
        {
            "ioc_value": "tinneatonenessnabobical.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.lockbit",
            "malware_alias": "ABCD Ransomware",
            "malware_printable": "LockBit",
            "first_seen_utc": "2022-10-04 11:15:06",
            "last_seen_utc": "2026-06-06 04:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "lockbit,ransomware",
            "anonymous": "0",
            "reporter": "ankit_anubhav"
        }
    ],
    "858399": [
        {
            "ioc_value": "anbush.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-06-06 16:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "858402": [
        {
            "ioc_value": "get-topservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-06-06 16:01:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "858403": [
        {
            "ioc_value": "msoftupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "858404": [
        {
            "ioc_value": "pregabas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-06-06 16:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "851096": [
        {
            "ioc_value": "34.92.131.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-22 11:26:18",
            "last_seen_utc": "2026-06-06 16:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Google LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "850706": [
        {
            "ioc_value": "87.246.7.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:58:14",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "850701": [
        {
            "ioc_value": "cloudmicro.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-06-06 16:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "850702": [
        {
            "ioc_value": "fregiyu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-06-06 16:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "850704": [
        {
            "ioc_value": "microcloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-06-06 16:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "850260": [
        {
            "ioc_value": "154.22.117.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-17 21:24:41",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Cogent Communications",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "849761": [
        {
            "ioc_value": "198.98.53.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-14 22:07:14",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "847988": [
        {
            "ioc_value": "globallookclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:52",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847986": [
        {
            "ioc_value": "realfunsolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:50",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847972": [
        {
            "ioc_value": "www.service1app.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847975": [
        {
            "ioc_value": "youronlinesports.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847976": [
        {
            "ioc_value": "yourinfosolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847978": [
        {
            "ioc_value": "login.onemusic24.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847981": [
        {
            "ioc_value": "zx.jacollans.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847942": [
        {
            "ioc_value": "satorkar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847943": [
        {
            "ioc_value": "er.theinfoinc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847957": [
        {
            "ioc_value": "realmacnow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847958": [
        {
            "ioc_value": "onemusicllc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847959": [
        {
            "ioc_value": "ateliernow.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847960": [
        {
            "ioc_value": "er.dropklant.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847929": [
        {
            "ioc_value": "sprinthunter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847930": [
        {
            "ioc_value": "newstamagavk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847934": [
        {
            "ioc_value": "www.onestepstar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847124": [
        {
            "ioc_value": "115.75.66.68:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:17",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847123": [
        {
            "ioc_value": "115.75.66.68:6821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:16",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847122": [
        {
            "ioc_value": "115.75.66.68:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:14",
            "last_seen_utc": "2026-06-06 15:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847121": [
        {
            "ioc_value": "115.75.66.68:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:40:24",
            "last_seen_utc": "2026-06-06 15:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847028": [
        {
            "ioc_value": "barabezo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 18:29:19",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/08ec3f13e8637a08dd763af6ccb46ff8516bc46efaacb1e5f052ada634a90c0e/",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847018": [
        {
            "ioc_value": "alojun.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847019": [
        {
            "ioc_value": "asdder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-06-06 16:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847020": [
        {
            "ioc_value": "www.zominoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-06-06 16:01:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "846483": [
        {
            "ioc_value": "asorock0011.ddns.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2022-08-30 14:06:50",
            "last_seen_utc": "2026-06-06 06:05:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://medium.com/@the_abjuri5t/nanocore-rat-hunting-guide-cb185473c1e0",
            "tags": "NanoCore,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "846258": [
        {
            "ioc_value": "jevomukif.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-30 06:22:11",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-29-IOCs-for-Monster-Libra-TA551-IcedID-with-Cobalt-Stike.txt",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "844214": [
        {
            "ioc_value": "msdnupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-06-06 16:01:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "844215": [
        {
            "ioc_value": "msdupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-06-06 16:01:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "843958": [
        {
            "ioc_value": "caxoxc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-18 12:15:06",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "843546": [
        {
            "ioc_value": "47.108.180.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-16 11:38:21",
            "last_seen_utc": "2026-06-06 16:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "842464": [
        {
            "ioc_value": "jahojahi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-11 06:03:19",
            "last_seen_utc": "2026-06-06 16:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-10-IOCs-for-IcedID-and-Cobalt-Strike.txt",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "841613": [
        {
            "ioc_value": "zambeziz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-06 07:00:06",
            "last_seen_utc": "2026-06-06 16:01:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltSrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "839793": [
        {
            "ioc_value": "zuyonijobo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-27 08:49:04",
            "last_seen_utc": "2026-06-06 16:01:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://isc.sans.edu/diary/28884",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "802793": [
        {
            "ioc_value": "digerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-06 05:36:04",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "796822": [
        {
            "ioc_value": "chitozx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-05 05:12:06",
            "last_seen_utc": "2026-06-06 16:01:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "750750": [
        {
            "ioc_value": "42.192.21.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-02 13:06:49",
            "last_seen_utc": "2026-06-06 16:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "730561": [
        {
            "ioc_value": "18.117.254.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-28 08:57:21",
            "last_seen_utc": "2026-06-06 16:01:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "729038": [
        {
            "ioc_value": "blinkinuf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:33",
            "last_seen_utc": "2026-06-06 16:01:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "729037": [
        {
            "ioc_value": "malrok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:32",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720823": [
        {
            "ioc_value": "trumpiko.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720824": [
        {
            "ioc_value": "freygor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720826": [
        {
            "ioc_value": "sinjoan.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720827": [
        {
            "ioc_value": "afluix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720273": [
        {
            "ioc_value": "www.edge-chrome.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720276": [
        {
            "ioc_value": "www.hellomrsone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720260": [
        {
            "ioc_value": "we.topsmartservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-06-06 16:01:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720263": [
        {
            "ioc_value": "wpsserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-06-06 16:01:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720248": [
        {
            "ioc_value": "thedaily-news.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:18",
            "last_seen_utc": "2026-06-06 16:01:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720239": [
        {
            "ioc_value": "sevenhungredbucks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720241": [
        {
            "ioc_value": "snccoupr-int.cf",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720247": [
        {
            "ioc_value": "telembank.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720230": [
        {
            "ioc_value": "ppew.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-06-06 16:01:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720231": [
        {
            "ioc_value": "pretunz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-06-06 16:01:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720236": [
        {
            "ioc_value": "rss.top-business-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720237": [
        {
            "ioc_value": "scarfaceserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720226": [
        {
            "ioc_value": "outlet-studio.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:15",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720208": [
        {
            "ioc_value": "js.msedgeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:14",
            "last_seen_utc": "2026-06-06 16:00:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720198": [
        {
            "ioc_value": "harborfreight.delivery",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-06 16:01:53",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720201": [
        {
            "ioc_value": "hityok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-06 16:01:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720203": [
        {
            "ioc_value": "jiguz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720204": [
        {
            "ioc_value": "jijuanjo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720206": [
        {
            "ioc_value": "jqueryupdatenow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720207": [
        {
            "ioc_value": "jqueryupneed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-06 16:01:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720188": [
        {
            "ioc_value": "fifacud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720189": [
        {
            "ioc_value": "filaspo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720193": [
        {
            "ioc_value": "gasienda.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720185": [
        {
            "ioc_value": "dreamkoks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:11",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720176": [
        {
            "ioc_value": "democrazzy.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:10",
            "last_seen_utc": "2026-06-06 16:01:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720156": [
        {
            "ioc_value": "cloud.sovarermscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:31",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720136": [
        {
            "ioc_value": "backupcreds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-06-06 16:01:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720140": [
        {
            "ioc_value": "biohazzzard.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-06-06 16:01:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720141": [
        {
            "ioc_value": "bksfinance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720143": [
        {
            "ioc_value": "boronab.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-06-06 16:01:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720132": [
        {
            "ioc_value": "araizx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-06-06 16:01:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720133": [
        {
            "ioc_value": "arminext.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "719898": [
        {
            "ioc_value": "aginij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-22 18:35:13",
            "last_seen_utc": "2026-06-06 16:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "710534": [
        {
            "ioc_value": "85.175.101.203:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-15 20:53:40",
            "last_seen_utc": "2026-06-06 15:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,STC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "606362": [
        {
            "ioc_value": "criobob.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-06-06 16:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "606363": [
        {
            "ioc_value": "prozakx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "606364": [
        {
            "ioc_value": "terroklo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "606360": [
        {
            "ioc_value": "microdozz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:57",
            "last_seen_utc": "2026-06-06 16:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "549372": [
        {
            "ioc_value": "us189-hpgsgae5dva9fzch.z01.azurefd.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-10 18:53:07",
            "last_seen_utc": "2026-06-06 16:01:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,threatview.io",
            "anonymous": "0",
            "reporter": "Malwar3Ninja"
        }
    ],
    "548951": [
        {
            "ioc_value": "artidomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-08 16:20:03",
            "last_seen_utc": "2026-06-06 16:01:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/ian_kenefick/status/1523288477559062529",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "544836": [
        {
            "ioc_value": "116.62.185.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-30 19:45:18",
            "last_seen_utc": "2026-06-06 16:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "540702": [
        {
            "ioc_value": "165.227.180.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-29 19:30:18",
            "last_seen_utc": "2026-06-06 16:01:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "532916": [
        {
            "ioc_value": "120.26.240.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-25 12:31:07",
            "last_seen_utc": "2026-06-06 16:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "530098": [
        {
            "ioc_value": "193.29.13.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-23 16:42:50",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "***************************************,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "523516": [
        {
            "ioc_value": "45.8.158.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-21 16:54:57",
            "last_seen_utc": "2026-06-06 16:01:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASBAXETN,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "521565": [
        {
            "ioc_value": "115.29.171.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-19 13:44:33",
            "last_seen_utc": "2026-06-06 16:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "521083": [
        {
            "ioc_value": "84.32.188.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-18 18:01:52",
            "last_seen_utc": "2026-06-06 16:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "520317": [
        {
            "ioc_value": "137.184.42.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-15 22:57:51",
            "last_seen_utc": "2026-06-06 16:01:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "519914": [
        {
            "ioc_value": "84.32.188.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 16:59:25",
            "last_seen_utc": "2026-06-06 16:01:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "519792": [
        {
            "ioc_value": "furfen.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 10:30:57",
            "last_seen_utc": "2026-06-06 16:01:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BumbleBee,Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "519116": [
        {
            "ioc_value": "175.41.21.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-13 16:57:52",
            "last_seen_utc": "2026-06-06 16:01:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "518853": [
        {
            "ioc_value": "175.41.16.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-12 16:50:58",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "518404": [
        {
            "ioc_value": "138.68.110.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-10 17:05:31",
            "last_seen_utc": "2026-06-06 16:01:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "516676": [
        {
            "ioc_value": "13.55.118.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-06 22:59:35",
            "last_seen_utc": "2026-06-06 16:01:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "493695": [
        {
            "ioc_value": "185.186.143.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 22:55:20",
            "last_seen_utc": "2026-06-06 16:01:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASKONTEL,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "492845": [
        {
            "ioc_value": "194.37.97.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 16:53:16",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247 Ltd",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "466600": [
        {
            "ioc_value": "blopik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-30 09:51:36",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "461231": [
        {
            "ioc_value": "borizhog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-29 08:36:59",
            "last_seen_utc": "2026-06-06 16:01:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "448027": [
        {
            "ioc_value": "37.72.172.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 22:55:12",
            "last_seen_utc": "2026-06-06 16:01:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "446029": [
        {
            "ioc_value": "1.14.76.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 10:56:07",
            "last_seen_utc": "2026-06-06 16:01:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "443786": [
        {
            "ioc_value": "139.60.160.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 20:44:05",
            "last_seen_utc": "2026-06-06 16:01:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "443190": [
        {
            "ioc_value": "apeduze.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 16:44:21",
            "last_seen_utc": "2026-06-06 16:01:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "438442": [
        {
            "ioc_value": "drimzis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "438443": [
        {
            "ioc_value": "blinkij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "398650": [
        {
            "ioc_value": "152.136.178.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 22:47:07",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "396104": [
        {
            "ioc_value": "dunclikf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 12:19:46",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393426": [
        {
            "ioc_value": "sifgu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393427": [
        {
            "ioc_value": "gfsert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393429": [
        {
            "ioc_value": "shizij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393430": [
        {
            "ioc_value": "zxerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393431": [
        {
            "ioc_value": "korunder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393424": [
        {
            "ioc_value": "chesft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393425": [
        {
            "ioc_value": "uktyl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-06-06 16:01:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393312": [
        {
            "ioc_value": "defenr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393313": [
        {
            "ioc_value": "fedij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393314": [
        {
            "ioc_value": "kejimn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393311": [
        {
            "ioc_value": "brikeb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:34",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393046": [
        {
            "ioc_value": "kapuleti.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-08 17:09:32",
            "last_seen_utc": "2026-06-06 16:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "392705": [
        {
            "ioc_value": "45.12.1.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-06 16:43:33",
            "last_seen_utc": "2026-06-06 16:01:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "392630": [
        {
            "ioc_value": "45.12.1.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:45:53",
            "last_seen_utc": "2026-06-06 16:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "392595": [
        {
            "ioc_value": "45.12.1.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:43:28",
            "last_seen_utc": "2026-06-06 16:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDNETWORKS-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "391528": [
        {
            "ioc_value": "defegh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "391530": [
        {
            "ioc_value": "klycnmik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "391531": [
        {
            "ioc_value": "ngrety.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "391111": [
        {
            "ioc_value": "lifegothistory.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-27 06:03:58",
            "last_seen_utc": "2026-06-06 16:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1497771037718724612",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "390123": [
        {
            "ioc_value": "192.241.133.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:44:41",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "390104": [
        {
            "ioc_value": "159.65.246.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:42:29",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389873": [
        {
            "ioc_value": "68.183.200.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:58:18",
            "last_seen_utc": "2026-06-06 16:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389866": [
        {
            "ioc_value": "138.68.227.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:57:13",
            "last_seen_utc": "2026-06-06 16:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389865": [
        {
            "ioc_value": "165.227.219.211:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:56:32",
            "last_seen_utc": "2026-06-06 16:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389864": [
        {
            "ioc_value": "165.232.154.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:55:44",
            "last_seen_utc": "2026-06-06 16:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389861": [
        {
            "ioc_value": "143.198.110.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:53",
            "last_seen_utc": "2026-06-06 16:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389860": [
        {
            "ioc_value": "178.128.171.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:15",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389853": [
        {
            "ioc_value": "165.227.23.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:53:10",
            "last_seen_utc": "2026-06-06 16:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389850": [
        {
            "ioc_value": "161.35.137.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:52:19",
            "last_seen_utc": "2026-06-06 16:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389847": [
        {
            "ioc_value": "64.227.0.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:51:26",
            "last_seen_utc": "2026-06-06 16:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389656": [
        {
            "ioc_value": "45.55.36.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-20 16:42:59",
            "last_seen_utc": "2026-06-06 16:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "384626": [
        {
            "ioc_value": "168.61.180.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-09 22:36:37",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "373668": [
        {
            "ioc_value": "bornometa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "373671": [
        {
            "ioc_value": "jenevabaiden.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "373673": [
        {
            "ioc_value": "sbronm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "362296": [
        {
            "ioc_value": "101.34.182.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-29 22:33:30",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "332687": [
        {
            "ioc_value": "192.227.155.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:30:16",
            "last_seen_utc": "2026-06-06 16:01:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "332653": [
        {
            "ioc_value": "146.70.29.233:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:29:00",
            "last_seen_utc": "2026-06-06 16:01:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "313943": [
        {
            "ioc_value": "107.172.219.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-22 22:25:42",
            "last_seen_utc": "2026-06-06 16:01:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "299262": [
        {
            "ioc_value": "193.201.9.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 22:32:52",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SELECTEL",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "298501": [
        {
            "ioc_value": "citrixseruritys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-06-06 16:01:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "298505": [
        {
            "ioc_value": "milanvar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "295525": [
        {
            "ioc_value": "23.227.198.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 22:26:20",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "295436": [
        {
            "ioc_value": "217.79.243.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 10:32:22",
            "last_seen_utc": "2026-06-06 16:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "295353": [
        {
            "ioc_value": "149.255.35.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-14 22:28:25",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "294999": [
        {
            "ioc_value": "81.68.225.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-13 22:28:33",
            "last_seen_utc": "2026-06-06 16:01:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "292303": [
        {
            "ioc_value": "39.98.48.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-10 16:24:49",
            "last_seen_utc": "2026-06-06 16:00:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "291740": [
        {
            "ioc_value": "39.104.25.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-07 10:30:52",
            "last_seen_utc": "2026-06-06 16:01:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "276593": [
        {
            "ioc_value": "77.83.36.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-16 10:42:30",
            "last_seen_utc": "2026-06-06 16:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ISI-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "275144": [
        {
            "ioc_value": "101.32.204.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-13 10:06:28",
            "last_seen_utc": "2026-06-06 16:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "252110": [
        {
            "ioc_value": "62.113.255.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-22 16:01:01",
            "last_seen_utc": "2026-06-06 16:01:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TTM",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "242948": [
        {
            "ioc_value": "107.173.89.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-04 17:48:48",
            "last_seen_utc": "2026-06-06 16:01:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "240983": [
        {
            "ioc_value": "104.128.92.144:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-31 17:43:37",
            "last_seen_utc": "2026-06-06 16:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,IT7NET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "238207": [
        {
            "ioc_value": "fivepointschiro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-27 09:58:20",
            "last_seen_utc": "2026-06-06 16:01:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/mojoesec/status/1453040284686770185",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "236436": [
        {
            "ioc_value": "111.230.196.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-22 12:07:15",
            "last_seen_utc": "2026-06-06 16:01:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "233476": [
        {
            "ioc_value": "23.224.152.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-13 17:43:22",
            "last_seen_utc": "2026-06-06 16:01:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "232821": [
        {
            "ioc_value": "139.198.183.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-11 23:27:10",
            "last_seen_utc": "2026-06-06 16:01:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YUNIFY-NET Yunify Technologies Inc.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "232263": [
        {
            "ioc_value": "121.37.255.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-09 23:36:53",
            "last_seen_utc": "2026-06-06 16:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HWCSNET Huawei Cloud Service data center",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "223357": [
        {
            "ioc_value": "47.95.207.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-09-18 17:39:24",
            "last_seen_utc": "2026-06-06 16:01:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ]
}