{
    "id": "1783992",
    "ioc": "tridontoq.com",
    "ioc_type": "domain",
    "threat_type": "botnet_cc",
    "malware": "win.castleloader",
    "malware_printable": "CASTLELOADER",
    "malware_alias": null,
    "confidence_level": "90",
    "first_seen": "2026-04-11 07:06:17 UTC",
    "last_seen": null,
    "reporter": null,
    "reference": null,
    "threatfox_link": "https:\/\/threatfox\/ioc\/1783992",
    "tags": [
        "CastleLoader",
        "ClickFix",
        "HijackLoader"
    ]
}