{
    "id": "1831789",
    "ioc": "g4me.flashpopdownloadbutton.monster",
    "ioc_type": "domain",
    "threat_type": "payload_delivery",
    "malware": "win.satacom",
    "malware_printable": "Satacom",
    "malware_alias": "CurlyGate,LegionLoader,RobotDropper",
    "confidence_level": "100",
    "first_seen": "2026-06-14 10:39:45 UTC",
    "last_seen": "2026-06-13 15:38:30 UTC",
    "reporter": null,
    "reference": "",
    "threatfox_link": "https:\/\/threatfox\/ioc\/1831789",
    "tags": [
        "ClickFix",
        "LegionLoader"
    ]
}