{
    "id": "1817267",
    "ioc": "f3ef4663e909e2545d25bdd0edc7ba4f88d197760921ca23e7dededf7326aa8e",
    "ioc_type": "sha256_hash",
    "threat_type": "payload",
    "malware": "win.satacom",
    "malware_printable": "Satacom",
    "malware_alias": "CurlyGate,LegionLoader,RobotDropper",
    "confidence_level": "100",
    "first_seen": "2026-05-22 13:32:09 UTC",
    "last_seen": null,
    "reporter": null,
    "reference": "https:\/\/x.com\/AndrewPetrus\/status\/2057813304727552345?s=20",
    "threatfox_link": "https:\/\/threatfox\/ioc\/1817267",
    "tags": [
        "curlygate",
        "LegionLoader",
        "Satacom"
    ]
}