{
    "id": "1748992",
    "ioc": "ftp.henfruit.ro",
    "ioc_type": "domain",
    "threat_type": "botnet_cc",
    "malware": "win.phantom_stealer",
    "malware_printable": "Phantom Stealer",
    "malware_alias": null,
    "confidence_level": "100",
    "first_seen": "2026-02-15 23:04:20 UTC",
    "last_seen": null,
    "reporter": null,
    "reference": "https:\/\/www.joesandbox.com\/analysis\/1869082",
    "threatfox_link": "https:\/\/threatfox\/ioc\/1748992",
    "tags": [
        "c2",
        "domain",
        "joesandbox",
        "Phantom",
        "PhantomStealer",
        "stealer"
    ]
}