{
    "id": "1518300",
    "ioc": "http:\/\/baleturn.com\/front.php",
    "ioc_type": "url",
    "threat_type": "botnet_cc",
    "malware": "win.satacom",
    "malware_printable": "Satacom",
    "malware_alias": "CurlyGate,LegionLoader,RobotDropper",
    "confidence_level": "100",
    "first_seen": "2025-05-08 05:02:33 UTC",
    "last_seen": null,
    "reporter": "abuse_ch",
    "reference": "https:\/\/bazaar.abuse.ch\/sample\/885268e2da486a7c3473e76c11a1a51595efe389c33af5ece150a44166cee80d\/",
    "threatfox_link": "https:\/\/threatfox\/ioc\/1518300",
    "tags": [
        "LegionLoader",
        "Satacom"
    ]
}