{
  "items": [
    {
      "id": "event--c273ce0c-a618-5ea5-9192-fcc2072243d3",
      "timestamp": "2026-10-08T00:00:13Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "91e2ace35426e99f4a9be60206558ddd4073e74056e2a3633b2983ee6a680820",
        "md5": "a4d420349d6584b39b5576e88e6ff8c1",
        "sha1": "fd65f3747819d278ef7618c76cfdd17c7404dae3",
        "sha256": "91e2ace35426e99f4a9be60206558ddd4073e74056e2a3633b2983ee6a680820",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/91e2ace35426e99f4a9be60206558ddd4073e74056e2a3633b2983ee6a680820"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "obfscred"
      },
      "validity": {
        "first_seen": "2026-10-07T14:50:32Z",
        "last_seen": "2026-10-08T00:00:12Z"
      },
      "tags": [
        "contains-embedded-js",
        "gen2",
        "html",
        "internet",
        "jsfiretruck",
        "obfscred",
        "phishing",
        "trojan",
        "wacatac",
        "windows"
      ]
    },
    {
      "id": "event--8fbc167f-86ee-58ef-8c82-5b66efdcf4b5",
      "timestamp": "2026-10-08T00:00:13Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "f2ff7a813c7c39c6ddaa27605f665a813b0bdf642a7f28ee83cf41be0419c476",
        "md5": "a4a045a2f6d53d79f4adf8000702a445",
        "sha1": "6df6d4a5cf3fd0ed2a47e30e1327dbd5351e9ef2",
        "sha256": "f2ff7a813c7c39c6ddaa27605f665a813b0bdf642a7f28ee83cf41be0419c476",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/f2ff7a813c7c39c6ddaa27605f665a813b0bdf642a7f28ee83cf41be0419c476"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "mirai"
      },
      "validity": {
        "first_seen": "2026-10-07T10:20:20Z",
        "last_seen": "2026-10-08T00:00:10Z"
      },
      "tags": [
        "arm",
        "ddos",
        "dropper",
        "elf",
        "executable",
        "gafgyt",
        "linux",
        "mirai",
        "payload",
        "spreader",
        "trojan"
      ]
    },
    {
      "id": "event--abaa48f2-c03b-58cc-8122-7716eafe2644",
      "timestamp": "2026-10-08T00:00:15Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "4967c7a64422e63f347eefbcbd946cc1fc23a0e0d5082520c2640931e4ae2367",
        "md5": "a4c627db544b379c12ea91b11b5f53dd",
        "sha1": "8fcd2f03a48ea46d1de52a2eff58d625078a67eb",
        "sha256": "4967c7a64422e63f347eefbcbd946cc1fc23a0e0d5082520c2640931e4ae2367",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/4967c7a64422e63f347eefbcbd946cc1fc23a0e0d5082520c2640931e4ae2367"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cryxos"
      },
      "validity": {
        "first_seen": "2026-10-07T18:35:00Z",
        "last_seen": "2026-10-08T00:00:14Z"
      },
      "tags": [
        "contains-embedded-js",
        "cryxos",
        "downloader",
        "gen2",
        "html",
        "internet",
        "jsdldr",
        "spreader",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--411c31fd-829a-5363-a535-b7a0885dfdd9",
      "timestamp": "2026-10-08T00:00:15Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "904c84640dbce64782c509e9052f813ae3308a18d49640920ea1e80ccd900313",
        "md5": "a4add21d4669c35233938571f1bcfe8b",
        "sha1": "07693b45d2f480aebe0b39dd23ffce51cef3d12e",
        "sha256": "904c84640dbce64782c509e9052f813ae3308a18d49640920ea1e80ccd900313",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/904c84640dbce64782c509e9052f813ae3308a18d49640920ea1e80ccd900313"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "msil"
      },
      "validity": {
        "first_seen": "2026-10-07T17:54:15Z",
        "last_seen": "2026-10-08T00:00:13Z"
      },
      "tags": [
        "assembly",
        "asyncrat",
        "exe",
        "executable",
        "loveletter",
        "msil",
        "pe",
        "peexe",
        "trojan",
        "win32",
        "windows",
        "xworm"
      ]
    },
    {
      "id": "event--576e4d84-573c-5a09-9bec-c83449f8a303",
      "timestamp": "2026-10-08T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "75089643812dd530fa41cf1217823912c96898465935de32745ac268037cd9a4",
        "md5": "a50cc06d3a8e8dd29bbd11ca5326364c",
        "sha1": "3716c1a125c6bb41fdf0003d986274d67dcaa2b4",
        "sha256": "75089643812dd530fa41cf1217823912c96898465935de32745ac268037cd9a4",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/75089643812dd530fa41cf1217823912c96898465935de32745ac268037cd9a4"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cryxos"
      },
      "validity": {
        "first_seen": "2026-10-07T23:45:51Z",
        "last_seen": "2026-10-08T00:00:16Z"
      },
      "tags": [
        "contains-embedded-js",
        "cryxos",
        "downloader",
        "gen2",
        "html",
        "internet",
        "jsdldr",
        "phishing",
        "spreader",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--412730a0-7a4d-599d-9c45-d752053950fe",
      "timestamp": "2026-10-08T00:00:18Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "609489cf4e8792136c1f5bc9f18d1dc005a41f531667a1c1707c63e34ba23607",
        "md5": "b3a35e6ed43f72670100392d159bb446",
        "sha1": "95467689e3fa69790469564d25022bf2d12b6cb7",
        "sha256": "609489cf4e8792136c1f5bc9f18d1dc005a41f531667a1c1707c63e34ba23607",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/609489cf4e8792136c1f5bc9f18d1dc005a41f531667a1c1707c63e34ba23607"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "zusy"
      },
      "validity": {
        "first_seen": "2026-10-07T20:41:48Z",
        "last_seen": "2026-10-08T00:00:17Z"
      },
      "tags": [
        "apkd",
        "corrupt",
        "exe",
        "executable",
        "pe",
        "peexe",
        "sality",
        "spreader",
        "trojan",
        "upx",
        "virus",
        "win32",
        "windows",
        "zusy"
      ]
    },
    {
      "id": "event--c15b1442-d09a-5acb-8a03-520104dbdd1f",
      "timestamp": "2026-10-08T00:00:19Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "efb20d40f634a00381b5ac0e68a810391ff28ea6e0103749d229d40d5de46eb5",
        "md5": "a4ffeb5297a129dbcaddc172ce79fbf3",
        "sha1": "f0ed1079fc49f824bc5e6c7402e39a39b7480abc",
        "sha256": "efb20d40f634a00381b5ac0e68a810391ff28ea6e0103749d229d40d5de46eb5",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/efb20d40f634a00381b5ac0e68a810391ff28ea6e0103749d229d40d5de46eb5"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "vevi"
      },
      "validity": {
        "first_seen": "2026-10-07T18:41:51Z",
        "last_seen": "2026-10-08T00:00:17Z"
      },
      "tags": [
        "exe",
        "executable",
        "pe",
        "peexe",
        "polyk",
        "ribd",
        "spreader",
        "swisyn",
        "trojan",
        "vevi",
        "virus",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--18f9b339-21dd-550d-985f-4083722c87e1",
      "timestamp": "2026-10-08T00:00:19Z",
      "action": "upsert",
      "reason": "RECUR",
      "indicator": {
        "type": "ip",
        "version": "v4",
        "value": "104.21.2.151",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/ips/104.21.2.151"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "medium",
        "risk_score": 9
      },
      "validity": {
        "first_seen": "2023-10-01T12:29:36Z",
        "last_seen": "2026-10-08T00:00:18Z",
        "expires_at": "2026-11-07T00:00:18Z"
      },
      "tags": [
        "miner"
      ]
    },
    {
      "id": "event--f023fa27-94a7-5cfa-b749-b2d40d782a78",
      "timestamp": "2026-10-08T00:00:19Z",
      "action": "upsert",
      "reason": "RECUR",
      "indicator": {
        "type": "ip",
        "version": "v4",
        "value": "172.67.129.85",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/ips/172.67.129.85"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "medium",
        "risk_score": 9
      },
      "validity": {
        "first_seen": "2023-09-30T07:35:38Z",
        "last_seen": "2026-10-08T00:00:18Z",
        "expires_at": "2026-11-07T00:00:18Z"
      },
      "tags": [
        "miner"
      ]
    },
    {
      "id": "event--5b846888-8370-560f-87f4-efc8701cd03e",
      "timestamp": "2026-10-08T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "da90f828d7617afb6f8cf1149d8f7fd9cfa9155777df884762ebb435ba79defd",
        "md5": "a55eafcd1ebcb1e4a573c72f9f5920d4",
        "sha1": "fc42d5ee930e1c2146c7ce962b4db3c20ccc57aa",
        "sha256": "da90f828d7617afb6f8cf1149d8f7fd9cfa9155777df884762ebb435ba79defd",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/da90f828d7617afb6f8cf1149d8f7fd9cfa9155777df884762ebb435ba79defd"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "obfscred"
      },
      "validity": {
        "first_seen": "2026-10-07T10:06:54Z",
        "last_seen": "2026-10-08T00:00:19Z"
      },
      "tags": [
        "contains-embedded-js",
        "cryxos",
        "gen2",
        "html",
        "internet",
        "obfscred",
        "phishing",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--7aeeb120-e953-51c4-8624-65684e329087",
      "timestamp": "2026-10-08T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "c6b5ad33ea24fc34a4601fa4a9c4bb819fe7b0a57cdc923cd62974c5c3273f21",
        "md5": "a571191464d5ebcb238c29f4c7d6a966",
        "sha1": "b8c82b534624e520fc750e70b83aafbdab6cfb59",
        "sha256": "c6b5ad33ea24fc34a4601fa4a9c4bb819fe7b0a57cdc923cd62974c5c3273f21",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/c6b5ad33ea24fc34a4601fa4a9c4bb819fe7b0a57cdc923cd62974c5c3273f21"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "obfscred"
      },
      "validity": {
        "first_seen": "2026-10-07T17:47:57Z",
        "last_seen": "2026-10-08T00:00:19Z"
      },
      "tags": [
        "contains-embedded-js",
        "cryxos",
        "gen2",
        "html",
        "internet",
        "obfscred",
        "phishing",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--75278703-54cf-5010-9eaa-20d247410e37",
      "timestamp": "2026-10-08T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "84acad9668cccf14aab96df1915c381e4ecf0dc632b23eed36538724386d0f3e",
        "md5": "a52fb2f845ff3f659a5c201f487e09e8",
        "sha1": "c6452dd543255525762368d1464152cfc11489cc",
        "sha256": "84acad9668cccf14aab96df1915c381e4ecf0dc632b23eed36538724386d0f3e",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/84acad9668cccf14aab96df1915c381e4ecf0dc632b23eed36538724386d0f3e"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "padodor"
      },
      "validity": {
        "first_seen": "2026-10-07T18:38:10Z",
        "last_seen": "2026-10-08T00:00:18Z"
      },
      "tags": [
        "berbew",
        "downloader",
        "exe",
        "executable",
        "overlay",
        "padodor",
        "pe",
        "peexe",
        "qukart",
        "spreader",
        "trojan",
        "win32",
        "windows",
        "worm"
      ]
    },
    {
      "id": "event--ec2c5d97-adf3-5ecd-881e-06beb35849f8",
      "timestamp": "2026-10-08T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "db61727412fbb611be3830af87a7bcb89200ce5ffa4d4add9c28cb6c45ed683b",
        "md5": "d46f675d1afeed786e8147ad14862e25",
        "sha1": "90718b8b97058d30a59c534b5bbcd234b1e7cfce",
        "sha256": "db61727412fbb611be3830af87a7bcb89200ce5ffa4d4add9c28cb6c45ed683b",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/db61727412fbb611be3830af87a7bcb89200ce5ffa4d4add9c28cb6c45ed683b"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "padodor"
      },
      "validity": {
        "first_seen": "2026-10-07T22:21:32Z",
        "last_seen": "2026-10-08T00:00:19Z"
      },
      "tags": [
        "berbew",
        "downloader",
        "exe",
        "executable",
        "overlay",
        "padodor",
        "pe",
        "peexe",
        "qukart",
        "spreader",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--52422d00-2142-546f-89f5-9bc0c69335cb",
      "timestamp": "2026-10-08T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "23f87bc856d373938cff1c40a82f3bdc4c0ff3de52043e43691224a9ad187435",
        "md5": "a53ec11f722af771498b36421edfdcc1",
        "sha1": "773a2cae885a070518e61f79d7172659b19204b4",
        "sha256": "23f87bc856d373938cff1c40a82f3bdc4c0ff3de52043e43691224a9ad187435",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/23f87bc856d373938cff1c40a82f3bdc4c0ff3de52043e43691224a9ad187435"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "zusy"
      },
      "validity": {
        "first_seen": "2026-10-07T18:13:15Z",
        "last_seen": "2026-10-08T00:00:20Z"
      },
      "tags": [
        "exe",
        "executable",
        "hackav",
        "hacktool",
        "kiser",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "scar",
        "spreader",
        "trojan",
        "upx",
        "win32",
        "windows",
        "zusy"
      ]
    },
    {
      "id": "event--46e89f9b-e888-5f1c-951b-2bb093bd6ae3",
      "timestamp": "2026-10-08T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "979a67b763ab9d7b646eacb1b246acd9f518d4f2cdf82a0a4fa32228830ed0af",
        "md5": "a5c1c5db7b750e991074f9c0395e6929",
        "sha1": "bea5508d40e5ae3d2854fdf0cc40cdd702c3ae7f",
        "sha256": "979a67b763ab9d7b646eacb1b246acd9f518d4f2cdf82a0a4fa32228830ed0af",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/979a67b763ab9d7b646eacb1b246acd9f518d4f2cdf82a0a4fa32228830ed0af"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cryxos"
      },
      "validity": {
        "first_seen": "2026-10-07T16:52:37Z",
        "last_seen": "2026-10-08T00:00:20Z"
      },
      "tags": [
        "contains-embedded-js",
        "cryxos",
        "downloader",
        "gen2",
        "html",
        "internet",
        "jsdldr",
        "spreader",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--fb9ce76c-fdf2-57ea-8cf4-ae6531dbc3ec",
      "timestamp": "2026-10-08T00:00:21Z",
      "action": "upsert",
      "indicator": {
        "type": "url",
        "value": "http://107.172.206.125/129/seethebestthings.js",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/urls/162f9f53de2a5e5c2746cc0ac3d5030c"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 25,
        "severity": "low",
        "risk_score": 9
      },
      "validity": {
        "first_seen": "2026-10-06T09:22:37Z",
        "last_seen": "2026-10-08T00:00:21Z",
        "expires_at": "2026-11-07T00:00:21Z"
      },
      "tags": [
        "ip"
      ]
    },
    {
      "id": "event--71f57444-95c2-572c-a336-df87c9989d2b",
      "timestamp": "2026-10-08T00:00:21Z",
      "action": "upsert",
      "indicator": {
        "type": "url",
        "value": "http://107.172.206.125/httpswww.siemens-energy.comglobalenhomeproducts-servicessolutions-usecasebiomass-to-power.html.IMG/",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/urls/77e497535fcae63e4b71863d1c879d98"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 25,
        "severity": "low",
        "risk_score": 9
      },
      "validity": {
        "first_seen": "2026-10-06T09:22:37Z",
        "last_seen": "2026-10-08T00:00:21Z",
        "expires_at": "2026-11-07T00:00:21Z"
      },
      "tags": [
        "external-resources",
        "ip"
      ]
    },
    {
      "id": "event--a51efcbb-aa5d-52f9-bc20-8c5158eacd97",
      "timestamp": "2026-10-08T00:00:21Z",
      "action": "upsert",
      "indicator": {
        "type": "url",
        "value": "http://107.172.206.125/129/xcv.htA?picture.Jpg",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/urls/0c7bd3b6f53811f4b1cbcfef097532d2"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 25,
        "severity": "low",
        "risk_score": 9
      },
      "validity": {
        "first_seen": "2026-10-06T09:22:37Z",
        "last_seen": "2026-10-08T00:00:21Z",
        "expires_at": "2026-11-07T00:00:21Z"
      },
      "tags": [
        "ip"
      ]
    },
    {
      "id": "event--d5488804-bbe0-5771-b706-4075f21ab642",
      "timestamp": "2026-10-08T00:00:21Z",
      "action": "upsert",
      "indicator": {
        "type": "url",
        "value": "https://duakale.me/h8wT9M",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/urls/f1f037dcd53c00fc805016f20caccb7d"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "low",
        "risk_score": 5
      },
      "validity": {
        "first_seen": "2026-10-06T09:22:37Z",
        "last_seen": "2026-10-08T00:00:21Z",
        "expires_at": "2026-11-07T00:00:21Z"
      },
      "tags": [
        "external-resources"
      ]
    },
    {
      "id": "event--02b433a1-7159-5c86-b910-23dfe3ff3417",
      "timestamp": "2026-10-08T00:00:21Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "721c27097891dd6aef79b379421acefe105e578b1db69ef0fb5b1546c86378dd",
        "md5": "a5a347a384796edb744196bf229e8b22",
        "sha1": "a31b78d76ca639a854c951017db101de3c74789e",
        "sha256": "721c27097891dd6aef79b379421acefe105e578b1db69ef0fb5b1546c86378dd",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/721c27097891dd6aef79b379421acefe105e578b1db69ef0fb5b1546c86378dd"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "copak"
      },
      "validity": {
        "first_seen": "2026-10-07T19:30:21Z",
        "last_seen": "2026-10-08T00:00:21Z"
      },
      "tags": [
        "bgzj",
        "copak",
        "exe",
        "executable",
        "lazy",
        "overlay",
        "pe",
        "peexe",
        "ransomware",
        "spreader",
        "teslacrypt",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--3ac9b525-6a30-5a2f-8a4a-65b85d82b287",
      "timestamp": "2026-10-08T00:00:22Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "07c88f6c59c4bdb656ba14584a6620adcf096897c70f8884e74424981ba82612",
        "md5": "a59b439a20eaeb5a65022f15523c2790",
        "sha1": "46905c297a918d56b0b8e978716d4cd17f06732f",
        "sha256": "07c88f6c59c4bdb656ba14584a6620adcf096897c70f8884e74424981ba82612",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/07c88f6c59c4bdb656ba14584a6620adcf096897c70f8884e74424981ba82612"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 99,
        "severity": "high",
        "risk_score": 79,
        "family": "powershell"
      },
      "validity": {
        "first_seen": "2026-10-07T11:33:24Z",
        "last_seen": "2026-10-08T00:00:21Z"
      },
      "tags": [
        "downloader",
        "enyvvnupb0c",
        "powershell",
        "ps",
        "ps1",
        "psagent",
        "source",
        "trojan",
        "url-pattern"
      ]
    },
    {
      "id": "event--b4cf7703-870e-506f-b651-f857ed566a1b",
      "timestamp": "2026-10-08T00:00:23Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "517d0d5a37d34dfc883a7845b1a57df3b23773b44585479450ec33aaf15ac18f",
        "md5": "b5a20d735fd1b6266d22f83ee39e2811",
        "sha1": "a0b5b40176459b02f4b082e302b61f1a48b9d5ad",
        "sha256": "517d0d5a37d34dfc883a7845b1a57df3b23773b44585479450ec33aaf15ac18f",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/517d0d5a37d34dfc883a7845b1a57df3b23773b44585479450ec33aaf15ac18f"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "stop"
      },
      "validity": {
        "first_seen": "2026-10-07T20:41:48Z",
        "last_seen": "2026-10-08T00:00:21Z"
      },
      "tags": [
        "dropper",
        "encoder",
        "exe",
        "executable",
        "johnnie",
        "pe",
        "peexe",
        "ransomware",
        "stop",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--c8ac459a-6bd0-5b18-8619-9cf48cd58fa4",
      "timestamp": "2026-10-08T00:00:24Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "539e2203ae08b4a9001531cf58e248d9ea598beab405db563deb09bd4ba0f93a",
        "md5": "b7f1458779a24eeb430a5a51df433afd",
        "sha1": "31ce9cc4a83c6a5fcb5efed096734aab3631352f",
        "sha256": "539e2203ae08b4a9001531cf58e248d9ea598beab405db563deb09bd4ba0f93a",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/539e2203ae08b4a9001531cf58e248d9ea598beab405db563deb09bd4ba0f93a"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "emotet"
      },
      "validity": {
        "first_seen": "2026-10-07T20:06:14Z",
        "last_seen": "2026-10-08T00:00:22Z"
      },
      "tags": [
        "atraps",
        "cryptdropper",
        "dll",
        "dropper",
        "emotet",
        "executable",
        "pe",
        "pedll",
        "ransomware",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--87b8dde1-bc00-5de5-abed-f0986373cdc8",
      "timestamp": "2026-10-08T00:00:25Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "c1036e6afa0daa70d899a0455d1d45bf149b4267594575a190aafccdd9bc6e98",
        "md5": "a617b7c1453f87cd5cacafb769aff25f",
        "sha1": "ed53f71807130f9ff05d2231f2778c5a19c2330c",
        "sha256": "c1036e6afa0daa70d899a0455d1d45bf149b4267594575a190aafccdd9bc6e98",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/c1036e6afa0daa70d899a0455d1d45bf149b4267594575a190aafccdd9bc6e98"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "obfscred"
      },
      "validity": {
        "first_seen": "2026-10-07T17:10:55Z",
        "last_seen": "2026-10-08T00:00:24Z"
      },
      "tags": [
        "contains-embedded-js",
        "cryxos",
        "gen2",
        "html",
        "internet",
        "jsfiretruck",
        "obfscred",
        "phishing",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--ade471e9-eeec-56fb-ae91-0f4efd425d11",
      "timestamp": "2026-10-08T00:00:26Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "66d1cd9c7b450c9d6ca0dcfd891357c8d66f99f79eb851c8868afb1e136277af",
        "md5": "b9c3402249b5087dc6b207219e8b708d",
        "sha1": "8d6c72514a7c3e26d18a8cb9cf95e45e15120061",
        "sha256": "66d1cd9c7b450c9d6ca0dcfd891357c8d66f99f79eb851c8868afb1e136277af",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/66d1cd9c7b450c9d6ca0dcfd891357c8d66f99f79eb851c8868afb1e136277af"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "sality"
      },
      "validity": {
        "first_seen": "2026-10-07T20:17:05Z",
        "last_seen": "2026-10-08T00:00:25Z"
      },
      "tags": [
        "adware",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "sality",
        "salitystub",
        "salload",
        "spreader",
        "trojan",
        "virus",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--6da27573-a648-5f4b-9169-de40aec83751",
      "timestamp": "2026-10-08T00:00:26Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "47222097f3f9c89467b0dc4d1c12e7152e2e012ae4f94c84fb772e2bee8fb668",
        "md5": "a68603dd8c01984074b2215b545fb9fc",
        "sha1": "8df872d50c3ff22a2890c616a4c563d18d3f9b6a",
        "sha256": "47222097f3f9c89467b0dc4d1c12e7152e2e012ae4f94c84fb772e2bee8fb668",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/47222097f3f9c89467b0dc4d1c12e7152e2e012ae4f94c84fb772e2bee8fb668"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "blackmoon"
      },
      "validity": {
        "first_seen": "2026-10-07T05:04:31Z",
        "last_seen": "2026-10-08T00:00:26Z"
      },
      "tags": [
        "bbmw",
        "blackmoon",
        "dropper",
        "exe",
        "executable",
        "ganelp",
        "overlay",
        "pe",
        "peexe",
        "petite",
        "pua",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--e3847c5f-1948-5b09-9528-009f9d5502a8",
      "timestamp": "2026-10-08T00:00:26Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "06f624550ac51fbde1d3da97ec348b42eba5186237a21c5b8820924c3a53e305",
        "md5": "a69f7bc008af785bb93d8590d7da0eeb",
        "sha1": "72581a3f7b88717097a2d91e25dbb427125aefb4",
        "sha256": "06f624550ac51fbde1d3da97ec348b42eba5186237a21c5b8820924c3a53e305",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/06f624550ac51fbde1d3da97ec348b42eba5186237a21c5b8820924c3a53e305"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 98,
        "severity": "high",
        "risk_score": 79,
        "family": "powershell"
      },
      "validity": {
        "first_seen": "2026-10-07T05:51:02Z",
        "last_seen": "2026-10-08T00:00:25Z"
      },
      "tags": [
        "downloader",
        "jsceal",
        "powershell",
        "ps",
        "ps1",
        "psagent",
        "source",
        "trojan",
        "url-pattern"
      ]
    },
    {
      "id": "event--54f7b976-17a4-500f-a8e4-9f16bfebfc7e",
      "timestamp": "2026-10-08T00:00:27Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "18ab16e9c40bfb8e7c54acf251055eb2517110329e6be4ca1f3e475da0d7bea8",
        "md5": "b9c4663d0d48f7fe9b407f16e9aa41ff",
        "sha1": "219b325adaa4ae09d727d1620f0e6dec312da0af",
        "sha256": "18ab16e9c40bfb8e7c54acf251055eb2517110329e6be4ca1f3e475da0d7bea8",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/18ab16e9c40bfb8e7c54acf251055eb2517110329e6be4ca1f3e475da0d7bea8"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cerbu"
      },
      "validity": {
        "first_seen": "2026-10-07T19:47:22Z",
        "last_seen": "2026-10-08T00:00:25Z"
      },
      "tags": [
        "cerbu",
        "cryp",
        "exe",
        "executable",
        "pe",
        "peexe",
        "pqdvyq2wovnjxm96yixhcq",
        "spreader",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--f10aeb54-6ae9-55e4-8d08-7e32f94a97c7",
      "timestamp": "2026-10-08T00:00:27Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "8d45294ec57a27ab2cdd0afae1b9235ccd740d6ad7628c9cdd563538702506bb",
        "md5": "a6778862c1299d2099622ac61221ff6a",
        "sha1": "caf55697536b3bcfff4efdb7a821441379acef73",
        "sha256": "8d45294ec57a27ab2cdd0afae1b9235ccd740d6ad7628c9cdd563538702506bb",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/8d45294ec57a27ab2cdd0afae1b9235ccd740d6ad7628c9cdd563538702506bb"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "zusy"
      },
      "validity": {
        "first_seen": "2026-10-07T18:28:59Z",
        "last_seen": "2026-10-08T00:00:26Z"
      },
      "tags": [
        "dropper",
        "exe",
        "executable",
        "hackav",
        "kiser",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "scar",
        "spreader",
        "trojan",
        "upx",
        "win32",
        "windows",
        "zusy"
      ]
    },
    {
      "id": "event--1ade172c-59c9-51a2-9fa8-d0e849918817",
      "timestamp": "2026-10-08T00:00:27Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "75427bc71371b8664323df034278815ee38b6d6800ec58bbe7f738f43ce5aa9a",
        "md5": "a6af9a775105b2a3e1610ca4d6cbbe96",
        "sha1": "70633f191626e706a2f1ba220324fc0eeab250ce",
        "sha256": "75427bc71371b8664323df034278815ee38b6d6800ec58bbe7f738f43ce5aa9a",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/75427bc71371b8664323df034278815ee38b6d6800ec58bbe7f738f43ce5aa9a"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "vilsel"
      },
      "validity": {
        "first_seen": "2026-10-07T18:10:14Z",
        "last_seen": "2026-10-08T00:00:26Z"
      },
      "tags": [
        "chir",
        "cqkyek",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "spyware",
        "trojan",
        "upx",
        "vilsel",
        "win32",
        "windows",
        "worm"
      ]
    },
    {
      "id": "event--eb469214-a2f7-58b0-b7bb-776bfca00946",
      "timestamp": "2026-10-08T00:00:28Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "8b4241ae48a604ddef1775815ba9c2efcf148dfbf2b2ee45ae3ec223491103b2",
        "md5": "a6d4764f842882905e79919800efd725",
        "sha1": "4c46a89b785c0a9b586b221db2ee31dfecf6691f",
        "sha256": "8b4241ae48a604ddef1775815ba9c2efcf148dfbf2b2ee45ae3ec223491103b2",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/8b4241ae48a604ddef1775815ba9c2efcf148dfbf2b2ee45ae3ec223491103b2"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 91,
        "severity": "high",
        "risk_score": 74,
        "family": "acsogenixx"
      },
      "validity": {
        "first_seen": "2026-10-07T20:25:59Z",
        "last_seen": "2026-10-08T00:00:27Z"
      },
      "tags": [
        "acsogenixx",
        "javascript",
        "js",
        "obfuse",
        "source",
        "trojan"
      ]
    },
    {
      "id": "event--5d19e882-9aa6-53f0-9110-c7ee5ba8c75e",
      "timestamp": "2026-10-08T00:00:28Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "56a5e3b16b201f61093d63da463eb838d4057cac815a704190b084607f0596fd",
        "md5": "a7116140c33e0e8c3aaf8a56e87afe8a",
        "sha1": "9b9230d41ec1e008bb6189fd91301553667630c7",
        "sha256": "56a5e3b16b201f61093d63da463eb838d4057cac815a704190b084607f0596fd",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/56a5e3b16b201f61093d63da463eb838d4057cac815a704190b084607f0596fd"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 98,
        "severity": "high",
        "risk_score": 79,
        "family": "powershell"
      },
      "validity": {
        "first_seen": "2026-10-07T05:02:37Z",
        "last_seen": "2026-10-08T00:00:27Z"
      },
      "tags": [
        "downloader",
        "jsceal",
        "powershell",
        "ps",
        "ps1",
        "psagent",
        "source",
        "trojan",
        "url-pattern"
      ]
    },
    {
      "id": "event--d68ea343-6514-5e9c-8355-dc368b515127",
      "timestamp": "2026-10-08T00:00:28Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "68cf2c6ae25b0785e75add3cce95eb290b9ff65c941ed099055822e725f72378",
        "md5": "8b0dd8c83438ace92f8fb58c684c163f",
        "sha1": "fb5b929618f31333cbe7b49bf196579fae489793",
        "sha256": "68cf2c6ae25b0785e75add3cce95eb290b9ff65c941ed099055822e725f72378",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/68cf2c6ae25b0785e75add3cce95eb290b9ff65c941ed099055822e725f72378"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "comet"
      },
      "validity": {
        "first_seen": "2026-04-22T07:23:34Z",
        "last_seen": "2026-04-22T07:23:34Z"
      },
      "tags": [
        "bobsoft",
        "comet",
        "darkkomet",
        "dropper",
        "exe",
        "executable",
        "pe",
        "peexe",
        "spreader",
        "synaptics",
        "trojan",
        "virus",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--96af5d59-935f-53f6-8cee-92c67224fb6e",
      "timestamp": "2026-10-08T00:00:28Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "f79081af699355a6f370e643a16eb0c1de3521be4ab05eb26f8604bd54b126c5",
        "md5": "f49f25bc1367fb364ca57b94d65dab9c",
        "sha1": "ec20fc578fcc0f2b7c1049537189beb4abacc84e",
        "sha256": "f79081af699355a6f370e643a16eb0c1de3521be4ab05eb26f8604bd54b126c5",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/f79081af699355a6f370e643a16eb0c1de3521be4ab05eb26f8604bd54b126c5"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "comet"
      },
      "validity": {
        "first_seen": "2026-07-31T05:29:46Z",
        "last_seen": "2026-07-31T05:29:46Z"
      },
      "tags": [
        "bobsoft",
        "comet",
        "darkkomet",
        "exe",
        "executable",
        "pe",
        "peexe",
        "persistence",
        "pua",
        "spreader",
        "trojan",
        "virus",
        "win32",
        "windows",
        "zorex"
      ]
    },
    {
      "id": "event--b35fdbd5-5493-53e2-a18a-fa1bd9c36152",
      "timestamp": "2026-10-08T00:00:29Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "2c9bf3cc17668f3428595c15cac6419d64bcae4d60d455a10f00183e78032299",
        "md5": "a6f95ecea67803c4a35ebc0b98f3bf2a",
        "sha1": "0277c9fb909d4bddf1c1dd710de36fc997e12c40",
        "sha256": "2c9bf3cc17668f3428595c15cac6419d64bcae4d60d455a10f00183e78032299",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/2c9bf3cc17668f3428595c15cac6419d64bcae4d60d455a10f00183e78032299"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "zusy"
      },
      "validity": {
        "first_seen": "2026-10-07T18:57:22Z",
        "last_seen": "2026-10-08T00:00:28Z"
      },
      "tags": [
        "exe",
        "executable",
        "hackav",
        "hacktool",
        "kiser",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "scar",
        "spreader",
        "trojan",
        "upx",
        "win32",
        "windows",
        "zusy"
      ]
    },
    {
      "id": "event--ffec9a3f-3e15-5404-8222-199e85a7a94d",
      "timestamp": "2026-10-08T00:00:29Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "5ecb11ff2789e06e8b3c814e7d08216164934c2df95be93256042415c85598dc",
        "md5": "a674bb6856e44ecbbe1d4acbfd482cdd",
        "sha1": "cec107773b40db4ac25f78974fd96c4c791d9207",
        "sha256": "5ecb11ff2789e06e8b3c814e7d08216164934c2df95be93256042415c85598dc",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/5ecb11ff2789e06e8b3c814e7d08216164934c2df95be93256042415c85598dc"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "popuper"
      },
      "validity": {
        "first_seen": "2026-10-07T20:39:43Z",
        "last_seen": "2026-10-08T00:00:27Z"
      },
      "tags": [
        "dgbgn",
        "downloader",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "popuper",
        "spreader",
        "trojan",
        "virus",
        "win32",
        "windows",
        "zusy"
      ]
    },
    {
      "id": "event--dde9555f-e2a1-572a-a697-43db6743c71e",
      "timestamp": "2026-10-08T00:00:29Z",
      "action": "upsert",
      "indicator": {
        "type": "url",
        "value": "http://best-targeted-traffic.com/install.php?unq=20i72663937xgujyuj&version=0&pais=Unknown",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/urls/c698b02f92d9d4f20d076ba097d8b26a"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 96,
        "severity": "high",
        "risk_score": 75
      },
      "validity": {
        "first_seen": "2026-10-07T23:26:08Z",
        "last_seen": "2026-10-08T00:00:28Z",
        "expires_at": "2027-01-06T00:00:28Z"
      },
      "tags": [
        "phishing"
      ]
    },
    {
      "id": "event--96ddf20d-9a93-5a28-8e86-2647a9a30bde",
      "timestamp": "2026-10-08T00:00:30Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "47fa138348a519c96b0786cce7fa92d803d3b37bf05075e36b2eb6fb75566ccd",
        "md5": "bf6c89b2abccb3b5b39088138bf7c9e5",
        "sha1": "8a0ebcf1f8523f98d8c335fe1c2f69b3db7215dc",
        "sha256": "47fa138348a519c96b0786cce7fa92d803d3b37bf05075e36b2eb6fb75566ccd",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/47fa138348a519c96b0786cce7fa92d803d3b37bf05075e36b2eb6fb75566ccd"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "zusy"
      },
      "validity": {
        "first_seen": "2026-10-07T22:09:01Z",
        "last_seen": "2026-10-08T00:00:29Z"
      },
      "tags": [
        "apkd",
        "corrupt",
        "exe",
        "executable",
        "pe",
        "peexe",
        "sality",
        "spreader",
        "trojan",
        "upx",
        "virus",
        "win32",
        "windows",
        "zusy"
      ]
    },
    {
      "id": "event--75a7e167-17e3-52b7-b280-aef96dc2d074",
      "timestamp": "2026-10-08T00:00:30Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "43b386d82e1e4ff1bda044c516317fc5ef9755211a0b3c941445459e5a78b406",
        "md5": "f434c8e79415a74d41f118edbc8765d0",
        "sha1": "5b98be7402be8c6a2ec5aea2afb0d0c492768c9a",
        "sha256": "43b386d82e1e4ff1bda044c516317fc5ef9755211a0b3c941445459e5a78b406",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/43b386d82e1e4ff1bda044c516317fc5ef9755211a0b3c941445459e5a78b406"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cyzt"
      },
      "validity": {
        "first_seen": "2026-10-07T11:56:46Z",
        "last_seen": "2026-10-08T00:00:28Z"
      },
      "tags": [
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "flooder",
        "hacktool",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--ad0353e9-7216-5780-a937-4e3a6c9c7c27",
      "timestamp": "2026-10-08T00:00:30Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "c15c4989cdbbf1c446dd136e3071bdac38e5b5d23312f433b1f4caeff117beb0",
        "md5": "a7a6f679bb352c76533c4e9f4457f7a2",
        "sha1": "28aa3d61534a2f274ceb22d353a397558adbdaad",
        "sha256": "c15c4989cdbbf1c446dd136e3071bdac38e5b5d23312f433b1f4caeff117beb0",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/c15c4989cdbbf1c446dd136e3071bdac38e5b5d23312f433b1f4caeff117beb0"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "obfscred"
      },
      "validity": {
        "first_seen": "2026-10-07T23:20:02Z",
        "last_seen": "2026-10-08T00:00:30Z"
      },
      "tags": [
        "contains-embedded-js",
        "cryxos",
        "gen2",
        "html",
        "internet",
        "jsfiretruck",
        "obfscred",
        "phishing",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--b845fb87-6266-539c-ab95-e28626597e5c",
      "timestamp": "2026-10-08T00:00:31Z",
      "action": "upsert",
      "reason": "CON_UP",
      "indicator": {
        "type": "file",
        "value": "2462ba0b94c4ba810802ad4e43918bf1a7546f48ebf950cac4c8e55636170e19",
        "md5": "9407a22ebf6763bc1017cb766c404231",
        "sha1": "48eaa03735edcf29088a1b875224f2915c91322d",
        "sha256": "2462ba0b94c4ba810802ad4e43918bf1a7546f48ebf950cac4c8e55636170e19",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/2462ba0b94c4ba810802ad4e43918bf1a7546f48ebf950cac4c8e55636170e19"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "offloader"
      },
      "validity": {
        "first_seen": "2026-08-24T03:33:11Z",
        "last_seen": "2026-10-08T00:00:27Z"
      },
      "tags": [
        "abdownloader",
        "compressed",
        "contains-pe",
        "crit",
        "detect-debug-environment",
        "downloader",
        "long-sleeps",
        "offloader",
        "pua",
        "trojan",
        "windows",
        "zip"
      ]
    },
    {
      "id": "event--8851bd07-e090-5b09-bc09-c269c8f1af06",
      "timestamp": "2026-10-08T00:00:31Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "c9252acb9499392d3165811d1e83e1ac69bc2b808ced49527bbb7c21633c9ff3",
        "md5": "a77816f2c13f22a654b7c2f52b57a8b2",
        "sha1": "c537156db1b2329eef459ca114e820b15bea6510",
        "sha256": "c9252acb9499392d3165811d1e83e1ac69bc2b808ced49527bbb7c21633c9ff3",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/c9252acb9499392d3165811d1e83e1ac69bc2b808ced49527bbb7c21633c9ff3"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "baidence"
      },
      "validity": {
        "first_seen": "2026-10-07T18:28:39Z",
        "last_seen": "2026-10-08T00:00:29Z"
      },
      "tags": [
        "baidence",
        "baidt",
        "downloader",
        "dropper",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "trojan",
        "win32",
        "windows",
        "zbot"
      ]
    },
    {
      "id": "event--4e339c5c-8ad7-55e4-b164-d3be9014ee4c",
      "timestamp": "2026-10-08T00:00:31Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "e0f9ee26347302dbf432de0270df5c358fd2d489a56ab7296b827ca60130c268",
        "md5": "a7a7bf6b1e9ae2ba3048d6e344adb4c5",
        "sha1": "28ea398c073db32f3f7c58675f0a88a308026678",
        "sha256": "e0f9ee26347302dbf432de0270df5c358fd2d489a56ab7296b827ca60130c268",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/e0f9ee26347302dbf432de0270df5c358fd2d489a56ab7296b827ca60130c268"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "misc"
      },
      "validity": {
        "first_seen": "2026-10-07T20:49:32Z",
        "last_seen": "2026-10-08T00:00:30Z"
      },
      "tags": [
        "64bits",
        "cmrtazoddc5l2bwdt4qvlo46o6v0",
        "exe",
        "executable",
        "gencirc",
        "misc",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "ransomware",
        "sabsik",
        "spreader",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--09a05e66-e806-57cd-8901-c92b89a65051",
      "timestamp": "2026-10-08T00:00:32Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "8c4b9a5d9cd39e490c4629416bcdc5deedca8a80fba9964dc19fda90727e714f",
        "md5": "a7f83d8d3a166c83880554b31d7ad4f9",
        "sha1": "affd20b1d549db8129e7ef983ecca478f6a499e8",
        "sha256": "8c4b9a5d9cd39e490c4629416bcdc5deedca8a80fba9964dc19fda90727e714f",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/8c4b9a5d9cd39e490c4629416bcdc5deedca8a80fba9964dc19fda90727e714f"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "farfli"
      },
      "validity": {
        "first_seen": "2026-10-07T17:27:57Z",
        "last_seen": "2026-10-08T00:00:31Z"
      },
      "tags": [
        "downloader",
        "exe",
        "executable",
        "farfli",
        "gen3",
        "overlay",
        "pe",
        "peexe",
        "trojan",
        "venik",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--1436be97-4bed-57a2-b7c2-477967904e51",
      "timestamp": "2026-10-08T00:00:32Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "1013553494979cbffb19410b096024b1334145e140ba4ea7b74079dadca06d12",
        "md5": "c3a258e73a345b4ea8f2fba1907523cb",
        "sha1": "ac80993f185f4a1df547cdf1c11f462c09068585",
        "sha256": "1013553494979cbffb19410b096024b1334145e140ba4ea7b74079dadca06d12",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/1013553494979cbffb19410b096024b1334145e140ba4ea7b74079dadca06d12"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cerbu"
      },
      "validity": {
        "first_seen": "2026-10-07T20:42:46Z",
        "last_seen": "2026-10-08T00:00:31Z"
      },
      "tags": [
        "cerbu",
        "exe",
        "executable",
        "pe",
        "peexe",
        "protect",
        "rdml",
        "spreader",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--54d3dd5d-847d-543b-9e6c-d2d0f362fbfd",
      "timestamp": "2026-10-08T00:00:32Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "50bdb709b91c3316f9a6b94c471bb4b4030b9333b37993f8ba303b7525b09899",
        "md5": "a83afc75392c4bf94b9b8603905f5966",
        "sha1": "a06a30c54027a53854b9985af506ba8f686392ce",
        "sha256": "50bdb709b91c3316f9a6b94c471bb4b4030b9333b37993f8ba303b7525b09899",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/50bdb709b91c3316f9a6b94c471bb4b4030b9333b37993f8ba303b7525b09899"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "zusy"
      },
      "validity": {
        "first_seen": "2026-10-07T18:25:18Z",
        "last_seen": "2026-10-08T00:00:32Z"
      },
      "tags": [
        "exe",
        "executable",
        "hackav",
        "hacktool",
        "kiser",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "scar",
        "spreader",
        "trojan",
        "upx",
        "win32",
        "windows",
        "zusy"
      ]
    },
    {
      "id": "event--7a996619-781c-5523-b5c7-3536150b5334",
      "timestamp": "2026-10-08T00:00:33Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "2ca7412a926eaa9461387eafab3fca46db1661fdbd007626cb2dd88055552418",
        "md5": "c37d4a2ed22653d1d43de8b0ea5ff7cc",
        "sha1": "17ececb720cd6c9e047da23c6410d8e591e58253",
        "sha256": "2ca7412a926eaa9461387eafab3fca46db1661fdbd007626cb2dd88055552418",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/2ca7412a926eaa9461387eafab3fca46db1661fdbd007626cb2dd88055552418"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "lazy"
      },
      "validity": {
        "first_seen": "2026-10-07T20:28:54Z",
        "last_seen": "2026-10-08T00:00:32Z"
      },
      "tags": [
        "exe",
        "executable",
        "l8d6yf8mkedga",
        "lazy",
        "pe",
        "peexe",
        "protect",
        "spreader",
        "trojan",
        "wacatac",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--223d031f-7a42-59b2-8b9c-38a52feebf9f",
      "timestamp": "2026-10-08T00:00:33Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "5cda4940d1b381afb3935f7df50b8834c5a7784e4fedd8aa3759cc7bdf1fc3fd",
        "md5": "c53508ac545508ebb00187b3b8806d18",
        "sha1": "9460d94c5c24ebb66b669376d4e6001fd77dbee0",
        "sha256": "5cda4940d1b381afb3935f7df50b8834c5a7784e4fedd8aa3759cc7bdf1fc3fd",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/5cda4940d1b381afb3935f7df50b8834c5a7784e4fedd8aa3759cc7bdf1fc3fd"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "zusy"
      },
      "validity": {
        "first_seen": "2026-10-07T19:48:36Z",
        "last_seen": "2026-10-08T00:00:32Z"
      },
      "tags": [
        "apkd",
        "corrupt",
        "exe",
        "executable",
        "pe",
        "peexe",
        "sality",
        "spreader",
        "trojan",
        "upx",
        "virus",
        "win32",
        "windows",
        "zusy"
      ]
    },
    {
      "id": "event--939d5b55-0986-53da-b2dd-c8624151be0f",
      "timestamp": "2026-10-08T00:00:33Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "71f51431fcdf86ac0118efc947beabf69bbd2b759ede1275e25fe8c4a4d7e23e",
        "md5": "a871ec88ba1a0e1cea8def87d5522a0d",
        "sha1": "180c047a26f34ac3aee758f9f69b07dcb496194f",
        "sha256": "71f51431fcdf86ac0118efc947beabf69bbd2b759ede1275e25fe8c4a4d7e23e",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/71f51431fcdf86ac0118efc947beabf69bbd2b759ede1275e25fe8c4a4d7e23e"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "copak"
      },
      "validity": {
        "first_seen": "2026-10-07T18:51:41Z",
        "last_seen": "2026-10-08T00:00:33Z"
      },
      "tags": [
        "bgzj",
        "copak",
        "exe",
        "executable",
        "lazy",
        "overlay",
        "pe",
        "peexe",
        "ransomware",
        "spreader",
        "teslacrypt",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--7bfb8d1a-4850-5dbe-8f4b-49f73586a547",
      "timestamp": "2026-10-08T00:00:33Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "c6b3b48870296182fcf402e86e694f890c633e68f3f0ecfc09c3e70d6512ab13",
        "md5": "a6dcf96331a47f2e8b2c87eaec3e2af5",
        "sha1": "4417eae1602e29787b3f1f2d4462448b6697b54c",
        "sha256": "c6b3b48870296182fcf402e86e694f890c633e68f3f0ecfc09c3e70d6512ab13",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/c6b3b48870296182fcf402e86e694f890c633e68f3f0ecfc09c3e70d6512ab13"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "msil"
      },
      "validity": {
        "first_seen": "2026-10-07T20:21:24Z",
        "last_seen": "2026-10-08T00:00:32Z"
      },
      "tags": [
        "assembly",
        "exe",
        "executable",
        "jalapeno",
        "misc",
        "msil",
        "pe",
        "peexe",
        "trojan",
        "win32",
        "windows"
      ]
    }
  ]
}