{
  "items": [
    {
      "id": "event--9d87ce43-1028-5621-9310-7997e949f47f",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "7844becb4970bced0e5959968062ba88a0b18693857d1024f3cf70c9e2d2e00d",
        "md5": "70e2a688ab4d8bc1c9ea41ad58767dc6",
        "sha1": "6d077329cb55e16db500b24428bfc8b47b140129",
        "sha256": "7844becb4970bced0e5959968062ba88a0b18693857d1024f3cf70c9e2d2e00d",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/7844becb4970bced0e5959968062ba88a0b18693857d1024f3cf70c9e2d2e00d"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "symmi"
      },
      "validity": {
        "first_seen": "2022-07-03T06:45:29Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "exe",
        "executable",
        "genericrxax",
        "pe",
        "peexe",
        "setupdev",
        "spreader",
        "symmi",
        "trojan",
        "wacapew",
        "win32",
        "windows",
        "worm"
      ]
    },
    {
      "id": "event--72040ffd-a9b2-5090-9c2e-1e96a43df350",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3d9526d0bdb7cc8a19abdbc10ad0d5476b3cd95bf92aac63d4f267812bb280f0",
        "md5": "b6f2bfe04d861e97432c5bf35ac2147d",
        "sha1": "b1e59e8194a371e68781140a7b189738ce53aa7a",
        "sha256": "3d9526d0bdb7cc8a19abdbc10ad0d5476b3cd95bf92aac63d4f267812bb280f0",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3d9526d0bdb7cc8a19abdbc10ad0d5476b3cd95bf92aac63d4f267812bb280f0"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "shell"
      },
      "validity": {
        "first_seen": "2024-09-05T02:47:49Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "Bash",
        "downloader",
        "linux",
        "script",
        "sh",
        "shell",
        "trojan"
      ]
    },
    {
      "id": "event--fe568a68-0c09-55d4-b600-cba9c3730286",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "78738a336bdb7c884ee5eb63c0ea9302ddf0c5351dd529a8b391377c7171f02f",
        "md5": "e4c4b14825ef41753ac0e129fb01b12c",
        "sha1": "628b1cc6baa385133a041377780844d7b076ebe2",
        "sha256": "78738a336bdb7c884ee5eb63c0ea9302ddf0c5351dd529a8b391377c7171f02f",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/78738a336bdb7c884ee5eb63c0ea9302ddf0c5351dd529a8b391377c7171f02f"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "msil"
      },
      "validity": {
        "first_seen": "2025-04-13T19:38:45Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "assembly",
        "basic",
        "calls-wmi",
        "checks-memory-available",
        "checks-user-input",
        "detect-debug-environment",
        "dropper",
        "exe",
        "executable",
        "long-sleeps",
        "msil",
        "msildrop",
        "pe",
        "peexe",
        "spreader",
        "trojan",
        "wacatac",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--3c334f76-55db-5551-93d7-156ae0df32bb",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "7873fcc0767efde04594296fbdaeb0c42eec371fcfefb8dfd052ff68fc85694a",
        "md5": "4896cff7e408cd277101fbcca50a9055",
        "sha1": "3e56536e6fb43d9fc2fc666e1f6e4143d8cd706d",
        "sha256": "7873fcc0767efde04594296fbdaeb0c42eec371fcfefb8dfd052ff68fc85694a",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/7873fcc0767efde04594296fbdaeb0c42eec371fcfefb8dfd052ff68fc85694a"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "multiplug"
      },
      "validity": {
        "first_seen": "2015-05-22T22:06:41Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "adware",
        "cosmu",
        "exe",
        "executable",
        "mikey",
        "multiplug",
        "pe",
        "peexe",
        "spreader",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--eb4eee58-1203-5b00-a33b-1a486acfe11c",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "reason": "SEV_DOWN",
      "indicator": {
        "type": "file",
        "value": "78d390316afdd752af4ac8648ef90a51329291c2c13f80509c4163b9bab177bf",
        "md5": "4895b0e16a718f70be2bf5e9455f2c8c",
        "sha1": "134c33b14f1e2230cb25d838ee6a14235791b922",
        "sha256": "78d390316afdd752af4ac8648ef90a51329291c2c13f80509c4163b9bab177bf",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/78d390316afdd752af4ac8648ef90a51329291c2c13f80509c4163b9bab177bf"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "msil"
      },
      "validity": {
        "first_seen": "2025-11-24T01:08:33Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "bat",
        "calls-wmi",
        "detect-debug-environment",
        "downloader",
        "long-sleeps",
        "loveletter",
        "msil",
        "script",
        "trojan",
        "xclient",
        "xworm"
      ]
    },
    {
      "id": "event--dd3b0ae1-836f-5326-8621-2551984ece22",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "78df08a5b8edc064ef17142080cd14b8ca0271653188c2bd023cbbb35f79d960",
        "md5": "ea7bf3906d2c0c3bfa8a5c30deb85959",
        "sha1": "d7dacfbd660cc7c8176cf61db6c1858e12e42321",
        "sha256": "78df08a5b8edc064ef17142080cd14b8ca0271653188c2bd023cbbb35f79d960",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/78df08a5b8edc064ef17142080cd14b8ca0271653188c2bd023cbbb35f79d960"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "binder"
      },
      "validity": {
        "first_seen": "2025-06-14T14:07:02Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "asyncrat",
        "binder",
        "calls-wmi",
        "darkylock",
        "exe",
        "executable",
        "hacktool",
        "pe",
        "peexe",
        "ransomware",
        "trojan",
        "vbinder",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--831b1610-fcb1-5c17-a954-ab5b27d81ec4",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "790a69f9920bece688b6d354568648c7430c7d727d29a099314b01c0a7e4933b",
        "md5": "9e677e3104a976b1e68f2471127bb215",
        "sha1": "425404a3fb8319b616e65a70afdc9f2f0d978cc4",
        "sha256": "790a69f9920bece688b6d354568648c7430c7d727d29a099314b01c0a7e4933b",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/790a69f9920bece688b6d354568648c7430c7d727d29a099314b01c0a7e4933b"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "hesv"
      },
      "validity": {
        "first_seen": "2024-09-26T00:51:58Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "checks-user-input",
        "detect-debug-environment",
        "exe",
        "executable",
        "hesv",
        "idayl",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "spreader",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--a6ea97ee-3d98-5090-bedb-ea57641b7b8b",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "791a4078b021bf52eff9147bcf7becb72fb3800e6cf49736f98a68f1dc245548",
        "md5": "00a38d1f175c4ceeea50312a27037245",
        "sha1": "ba47d526438d1a1167f3c9642dea03eb02d5aefd",
        "sha256": "791a4078b021bf52eff9147bcf7becb72fb3800e6cf49736f98a68f1dc245548",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/791a4078b021bf52eff9147bcf7becb72fb3800e6cf49736f98a68f1dc245548"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "jalapeno"
      },
      "validity": {
        "first_seen": "2026-08-25T15:51:19Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "assembly",
        "detect-debug-environment",
        "encoder",
        "exe",
        "executable",
        "jalapeno",
        "long-sleeps",
        "msil",
        "pe",
        "peexe",
        "ransomware",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--74f741c0-c8d5-584e-a2c9-5d387280b5a8",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "a90c56c90b27ccfe3543db2fcbebafcb38debb75bcbf1d342a1f3c767ee180fd",
        "md5": "f3d6fc965a75f82e853e95f9bda18606",
        "sha1": "8e83c4ac5fe4caabb4eb35fb924124664aafc1e5",
        "sha256": "a90c56c90b27ccfe3543db2fcbebafcb38debb75bcbf1d342a1f3c767ee180fd",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/a90c56c90b27ccfe3543db2fcbebafcb38debb75bcbf1d342a1f3c767ee180fd"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "bulz"
      },
      "validity": {
        "first_seen": "2021-02-15T13:56:29Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "bulz",
        "downloader",
        "exe",
        "executable",
        "icbundler",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "trojan",
        "vittalia",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--73599806-2480-5bc4-8278-a346b7526563",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "a930168f06a39df8425afd8125facee53bee201259357028666111033b8d806c",
        "md5": "339b9d66427ec98120819a837862a3fa",
        "sha1": "6f2066df0bbab8bc0695e3d4174edaf1b8f657fe",
        "sha256": "a930168f06a39df8425afd8125facee53bee201259357028666111033b8d806c",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/a930168f06a39df8425afd8125facee53bee201259357028666111033b8d806c"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "bulz"
      },
      "validity": {
        "first_seen": "2021-02-14T07:52:47Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "adaware",
        "bulz",
        "downloader",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "trojan",
        "vittalia",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--db12cb3a-cdad-5ac3-b24d-6fec3839a4d8",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "adae064487c8df5ecc5f31d70c4bd315c863076d052e74bf94dd9d8af4777f18",
        "md5": "d989679cc93c12df097f8358ce8b3d67",
        "sha1": "8a9acf2e8b0116e14d5eae536315e2657fd5e722",
        "sha256": "adae064487c8df5ecc5f31d70c4bd315c863076d052e74bf94dd9d8af4777f18",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/adae064487c8df5ecc5f31d70c4bd315c863076d052e74bf94dd9d8af4777f18"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 99,
        "severity": "high",
        "risk_score": 79,
        "family": "vittalia"
      },
      "validity": {
        "first_seen": "2021-02-07T00:51:12Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "signed",
        "vittalia",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--f471d3c1-00f9-51be-8fd2-c2a579635f03",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "adb462e90b0b6867d23b05a9a669dacf6a31dc060d42b7cdcd05d25290f1ccc0",
        "md5": "70e4a1226eb013c486495039b868f223",
        "sha1": "c13708fd3365616f99ee7292c5749704d9a1e018",
        "sha256": "adb462e90b0b6867d23b05a9a669dacf6a31dc060d42b7cdcd05d25290f1ccc0",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/adb462e90b0b6867d23b05a9a669dacf6a31dc060d42b7cdcd05d25290f1ccc0"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 99,
        "severity": "high",
        "risk_score": 79,
        "family": "vittalia"
      },
      "validity": {
        "first_seen": "2021-02-06T17:43:21Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "signed",
        "vittalia",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--dc36ff6d-7ed9-578f-87eb-82d2c95cfb1d",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "adb92849c86bd33b541940cd105fa4fa1a4a3c56dbe788bc24925bc3743dd20d",
        "md5": "4512d6d805b4c903c29d84fadee1a686",
        "sha1": "b9059a2bdbb398e63611a37d61be3d00de8dd310",
        "sha256": "adb92849c86bd33b541940cd105fa4fa1a4a3c56dbe788bc24925bc3743dd20d",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/adb92849c86bd33b541940cd105fa4fa1a4a3c56dbe788bc24925bc3743dd20d"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 96,
        "severity": "high",
        "risk_score": 77,
        "family": "vittalia"
      },
      "validity": {
        "first_seen": "2021-01-18T15:16:14Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "signed",
        "vittalia",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--1f4ffda7-510e-5102-a2e0-58a4e2200482",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "129704616dda0dca06fbb3115b4d2534651159cf16f5edaa57464e1b99b82f11",
        "md5": "a4d31f6f973d3c630c423f549c6619b6",
        "sha1": "dfef1894e8d89c960dc9e4c47747a06d29a583ff",
        "sha256": "129704616dda0dca06fbb3115b4d2534651159cf16f5edaa57464e1b99b82f11",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/129704616dda0dca06fbb3115b4d2534651159cf16f5edaa57464e1b99b82f11"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 40,
        "severity": "high",
        "risk_score": 42
      },
      "validity": {
        "first_seen": "2022-01-07T07:07:52Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "detect-debug-environment",
        "direct-cpu-clock-access",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "runtime-modules",
        "signed",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--0e2afff7-e5e5-5959-883d-7bb65d73edb3",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "1047282ae269eebf84c607fe26748557409b0904b144c17502b69a44e4936eba",
        "md5": "171d3cb66af001abb2dc66fd8550de47",
        "sha1": "583f447b7625fdc5ad6689800faf339c07469e3e",
        "sha256": "1047282ae269eebf84c607fe26748557409b0904b144c17502b69a44e4936eba",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/1047282ae269eebf84c607fe26748557409b0904b144c17502b69a44e4936eba"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 68,
        "severity": "high",
        "risk_score": 60,
        "family": "hjqbs"
      },
      "validity": {
        "first_seen": "2025-12-15T20:32:32Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "64bits",
        "checks-user-input",
        "exe",
        "executable",
        "hjqbs",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--5c0620f4-e9d2-518c-8d9d-e8041e19454b",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "10481a94ca99d4d6a38dd2915c105a0675707bf0b0209b8fa2246842990e4ad7",
        "md5": "a0b4a9bfbe3ac841713ee83cf2b1fa8f",
        "sha1": "886f612bcc109c785de058d2e02a302c8ae4bc80",
        "sha256": "10481a94ca99d4d6a38dd2915c105a0675707bf0b0209b8fa2246842990e4ad7",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/10481a94ca99d4d6a38dd2915c105a0675707bf0b0209b8fa2246842990e4ad7"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "low",
        "risk_score": 5
      },
      "validity": {
        "first_seen": "2020-05-12T13:06:09Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "direct-cpu-clock-access",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "runtime-modules",
        "signed",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--ddf473a5-7e19-5345-b21e-c05b39138555",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "270a4a48159056c606c658f090dd95ddac9a839377579800fac4fdef01850300",
        "md5": "2d68c517ffb64890c30a8f67bf793a53",
        "sha1": "e6be6d6a9e68ad57f6dcdb3746bb0cda12e6f479",
        "sha256": "270a4a48159056c606c658f090dd95ddac9a839377579800fac4fdef01850300",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/270a4a48159056c606c658f090dd95ddac9a839377579800fac4fdef01850300"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "low",
        "risk_score": 5
      },
      "validity": {
        "first_seen": "2026-07-04T10:29:21Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "compressed",
        "contains-pe",
        "detect-debug-environment",
        "long-sleeps",
        "zip"
      ]
    },
    {
      "id": "event--856246d3-e648-53f1-8bfc-9b185d9cdec8",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "1d4f7785546e81d3fc5b309a727b42f688e8d3392650b330df94e3db11e8ba40",
        "md5": "18f47e8d0d9370825e6fcefa18fdf6ab",
        "sha1": "6c1e1da366f2dc2b1834e19506bdb806535d5ed1",
        "sha256": "1d4f7785546e81d3fc5b309a727b42f688e8d3392650b330df94e3db11e8ba40",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/1d4f7785546e81d3fc5b309a727b42f688e8d3392650b330df94e3db11e8ba40"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "encpk"
      },
      "validity": {
        "first_seen": "2023-05-11T20:43:12Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "corrupt",
        "encpk",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "spreader",
        "trojan",
        "upkm",
        "viking",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--b21537cf-a620-5464-a4cf-2ff573beb19e",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "96740876b23e56232d63160e67b0c43f20e22de1df98211d0c892c7503437094",
        "md5": "4927f2ca906f6e3cfdd42467c45621e0",
        "sha1": "00e91f8053d41164586b278add23060e514200bb",
        "sha256": "96740876b23e56232d63160e67b0c43f20e22de1df98211d0c892c7503437094",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/96740876b23e56232d63160e67b0c43f20e22de1df98211d0c892c7503437094"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 25,
        "severity": "medium",
        "risk_score": 20
      },
      "validity": {
        "first_seen": "2024-11-13T07:00:43Z",
        "last_seen": "2026-10-08T23:59:55Z"
      },
      "tags": [
        "checks-user-input",
        "clipboard",
        "detect-debug-environment",
        "exe",
        "executable",
        "long-sleeps",
        "overlay",
        "pe",
        "peexe",
        "signed",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--a470dfb8-42a5-57d4-8d3f-dfb2c4fcfe0a",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "270dffe1db819968e3e0182dd83e884fa21d1a228e0c4fc5db072cea41ef66d5",
        "md5": "3301efb35a65e8c92b945ac3d41567d9",
        "sha1": "22ab2dac666b69c6256f8bcbee28f5b5a684cc1b",
        "sha256": "270dffe1db819968e3e0182dd83e884fa21d1a228e0c4fc5db072cea41ef66d5",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/270dffe1db819968e3e0182dd83e884fa21d1a228e0c4fc5db072cea41ef66d5"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "darkkomet"
      },
      "validity": {
        "first_seen": "2022-09-17T00:46:28Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "bobsoft",
        "checks-disk-space",
        "checks-network-adapters",
        "darkkomet",
        "direct-cpu-clock-access",
        "exe",
        "executable",
        "long-sleeps",
        "pe",
        "peexe",
        "persistence",
        "runtime-modules",
        "spreader",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--6c4cc4c2-39ca-5070-93ee-bee66e1fee39",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "96788e7d133e2303f1b12c83b86af0a853ce00a6636019b8d8779ed38b415482",
        "md5": "7a05ce9843905b85da61ec2bc203c372",
        "sha1": "207e94455b694c0aaee56f2c6212bd1b7531860c",
        "sha256": "96788e7d133e2303f1b12c83b86af0a853ce00a6636019b8d8779ed38b415482",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/96788e7d133e2303f1b12c83b86af0a853ce00a6636019b8d8779ed38b415482"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-08-01T06:54:28Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "64bits",
        "elf",
        "executable",
        "linux",
        "shared-lib",
        "trojan"
      ]
    },
    {
      "id": "event--e193bf4d-82a2-5594-a3cb-953c78f2aadb",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "79bdb0142d52b14ecdf811a9c083ac9c2356efa41675e5c057e899caa2d270a1",
        "md5": "ebae9555855259122f0bb84e19c0f117",
        "sha1": "f02df5835b580519a00335bda536bc97ab30f697",
        "sha256": "79bdb0142d52b14ecdf811a9c083ac9c2356efa41675e5c057e899caa2d270a1",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/79bdb0142d52b14ecdf811a9c083ac9c2356efa41675e5c057e899caa2d270a1"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 97,
        "severity": "high",
        "risk_score": 78,
        "family": "crack"
      },
      "validity": {
        "first_seen": "2025-08-17T23:03:51Z",
        "last_seen": "2026-10-08T23:59:55Z"
      },
      "tags": [
        "compressed",
        "contains-pe",
        "crack",
        "detect-debug-environment",
        "hacktool",
        "long-sleeps",
        "pua",
        "trojan",
        "vmprotect",
        "windows",
        "zip"
      ]
    },
    {
      "id": "event--57f5a267-3f0c-57a9-a363-ed866eb1aced",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "96831b0ea4cef3f42ae4de7bd78cc1cff416575912983d5a720e23e09dff32af",
        "md5": "ddf6dfb97baddc01fb8d976982b644a4",
        "sha1": "6e683bcd14d1d0e061ba110ec11ac31d32f9cd9e",
        "sha256": "96831b0ea4cef3f42ae4de7bd78cc1cff416575912983d5a720e23e09dff32af",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/96831b0ea4cef3f42ae4de7bd78cc1cff416575912983d5a720e23e09dff32af"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 25,
        "severity": "medium",
        "risk_score": 20
      },
      "validity": {
        "first_seen": "2024-12-07T22:18:53Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "checks-user-input",
        "compressed",
        "contains-pe",
        "detect-debug-environment",
        "long-sleeps",
        "zip"
      ]
    },
    {
      "id": "event--47c18b2f-d3c7-53e5-afbb-398c5a35206b",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "79bf7504e0ce239e3943a731098bcbf3032c7227aacd83b7dfa1b25f553016da",
        "md5": "e5d7f9f1eebb4fb2a51092524806263f",
        "sha1": "3ebadd4f4d59f94e2c79c59f9fe23bb8034762a8",
        "sha256": "79bf7504e0ce239e3943a731098bcbf3032c7227aacd83b7dfa1b25f553016da",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/79bf7504e0ce239e3943a731098bcbf3032c7227aacd83b7dfa1b25f553016da"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 95,
        "severity": "high",
        "risk_score": 77,
        "family": "agentb"
      },
      "validity": {
        "first_seen": "2024-12-07T15:48:10Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "agentb",
        "checks-user-input",
        "compressed",
        "detect-debug-environment",
        "long-sleeps",
        "miscx",
        "rar",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--3d2b6b96-21c7-5cd8-b9b3-748c4c7feead",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "79c7fe397c2636343fa00d47e8e55b37ce4515625c4037817efcafa53677a31f",
        "md5": "a35246664a72ddf88a1c7f187dd940c7",
        "sha1": "b8419203fe3653325ee5e10361b48e99b8eb249f",
        "sha256": "79c7fe397c2636343fa00d47e8e55b37ce4515625c4037817efcafa53677a31f",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/79c7fe397c2636343fa00d47e8e55b37ce4515625c4037817efcafa53677a31f"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 97,
        "severity": "high",
        "risk_score": 78,
        "family": "crack"
      },
      "validity": {
        "first_seen": "2026-01-30T05:47:31Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "compressed",
        "crack",
        "detect-debug-environment",
        "hacktool",
        "long-sleeps",
        "onlinegames",
        "pua",
        "rar",
        "trojan",
        "vmprotect",
        "windows"
      ]
    },
    {
      "id": "event--f330dc1d-de50-5715-a50d-3d6b1e4c5961",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3006a23b8ec691b280bfcb100f004977f3301bf61d7aeaa0556c26d1f8d9277c",
        "md5": "a10ae6b589921338e32a15125778aa52",
        "sha1": "9aaace2908ab81cbee09972fa82ce57a9c950766",
        "sha256": "3006a23b8ec691b280bfcb100f004977f3301bf61d7aeaa0556c26d1f8d9277c",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3006a23b8ec691b280bfcb100f004977f3301bf61d7aeaa0556c26d1f8d9277c"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 50,
        "severity": "high",
        "risk_score": 48
      },
      "validity": {
        "first_seen": "2024-11-27T15:30:13Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "calls-wmi",
        "checks-disk-space",
        "detect-debug-environment",
        "exe",
        "executable",
        "long-sleeps",
        "overlay",
        "pe",
        "peexe",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--ab31147c-9075-5c3b-8136-384f7cb1f2f2",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "79cd43e0d9b9ace58b36b9a512776ad93b94f6f967018de102abfc73468f7d49",
        "md5": "18f9c6d3ac398250b691df341f13ba0a",
        "sha1": "db93431062d001b605e3c5786a338f70adb66f93",
        "sha256": "79cd43e0d9b9ace58b36b9a512776ad93b94f6f967018de102abfc73468f7d49",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/79cd43e0d9b9ace58b36b9a512776ad93b94f6f967018de102abfc73468f7d49"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "crack"
      },
      "validity": {
        "first_seen": "2026-10-02T23:33:00Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "abapplication",
        "applicunwnt",
        "compressed",
        "crack",
        "detect-debug-environment",
        "hacktool",
        "long-sleeps",
        "onlinegames",
        "pua",
        "rar",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--8cfdd598-176d-5b6b-812d-16df9e079e70",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "860df6fc56819148b6461f304d24ecfc0b6ffd6eb1a7e703049cffb27f7866ec",
        "md5": "a0079ce81e9c315ad5d22a798e881a4a",
        "sha1": "cdfc1763d668a88d2da1164894b43a40db6a15ee",
        "sha256": "860df6fc56819148b6461f304d24ecfc0b6ffd6eb1a7e703049cffb27f7866ec",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/860df6fc56819148b6461f304d24ecfc0b6ffd6eb1a7e703049cffb27f7866ec"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16,
        "family": "wacatac"
      },
      "validity": {
        "first_seen": "2026-10-04T13:21:14Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "detect-debug-environment",
        "exe",
        "executable",
        "long-sleeps",
        "overlay",
        "pe",
        "peexe",
        "signed",
        "trojan",
        "wacatac",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--aa4d5374-0cd8-51e2-997a-e54a6dd90d4a",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "30099dd0ab20c83cafdaae7898ad3a1a69668bc6b28a8b26a9984d5e7dd89d08",
        "md5": "719b3b0cb64be3ca24668154a221bd0e",
        "sha1": "b14ec02d9ea6de931a3fab47853ab906994745ae",
        "sha256": "30099dd0ab20c83cafdaae7898ad3a1a69668bc6b28a8b26a9984d5e7dd89d08",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/30099dd0ab20c83cafdaae7898ad3a1a69668bc6b28a8b26a9984d5e7dd89d08"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2025-02-25T10:16:13Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "checks-user-input",
        "compressed",
        "detect-debug-environment",
        "long-sleeps",
        "rar",
        "windows"
      ]
    },
    {
      "id": "event--8805eefc-fdf2-5ff9-b28a-15ec7d4a6457",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "86757711973954c8a498bb3007b1e2ae4d70cbe89f63816f1da6625246c2106c",
        "md5": "7b6c42a782dd34831cde71516096cfcf",
        "sha1": "616c52a3fe68709e218e2f38fea12d0a4df6b831",
        "sha256": "86757711973954c8a498bb3007b1e2ae4d70cbe89f63816f1da6625246c2106c",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/86757711973954c8a498bb3007b1e2ae4d70cbe89f63816f1da6625246c2106c"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "pasnaino"
      },
      "validity": {
        "first_seen": "2022-10-06T14:09:02Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "direct-cpu-clock-access",
        "exe",
        "executable",
        "overlay",
        "pasnaino",
        "pe",
        "peexe",
        "runtime-modules",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--e1a3a1ed-b04c-5d5c-89f0-8936b6982218",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "79dadc0a452d662493edf8f2a0216178570cb5506c76e10d9179fcd00f113ab9",
        "md5": "211d46831bfbe9d23f632d57536beea0",
        "sha1": "1e9cb1e48dc4c309c387e949b74a9c20b6883873",
        "sha256": "79dadc0a452d662493edf8f2a0216178570cb5506c76e10d9179fcd00f113ab9",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/79dadc0a452d662493edf8f2a0216178570cb5506c76e10d9179fcd00f113ab9"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 94,
        "severity": "high",
        "risk_score": 76,
        "family": "cryxos"
      },
      "validity": {
        "first_seen": "2023-03-06T23:11:50Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "checks-user-input",
        "compressed",
        "contains-pe",
        "cryxos",
        "detect-debug-environment",
        "long-sleeps",
        "sets-process-name",
        "windows",
        "zip"
      ]
    },
    {
      "id": "event--22ce877a-3d5f-5fe9-910a-3a9056d5ae45",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "86bbff32b664de340e2d1c0b2818a0d9f3eaf8205dc3a20ba69c62e4f5e01286",
        "md5": "686c592e11d4563a017d54d1b228bb9b",
        "sha1": "9f3911a4d5902c04ef83995eb624111590b820fb",
        "sha256": "86bbff32b664de340e2d1c0b2818a0d9f3eaf8205dc3a20ba69c62e4f5e01286",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/86bbff32b664de340e2d1c0b2818a0d9f3eaf8205dc3a20ba69c62e4f5e01286"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "msil"
      },
      "validity": {
        "first_seen": "2025-05-26T09:02:27Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "assembly",
        "dropper",
        "exe",
        "executable",
        "msil",
        "pe",
        "peexe",
        "ransomware",
        "trojan",
        "wacapew",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--5f38b35f-2f57-5e13-bc08-c3000daef572",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "767950017f688ff9f218273f7b05468ec98022759f7f899a60d6d17b95cc5a3c",
        "md5": "c4e350a587b6801102c209b4ba89f57b",
        "sha1": "d856a85865e97be6aadf09c5cadd36c2a40b176d",
        "sha256": "767950017f688ff9f218273f7b05468ec98022759f7f899a60d6d17b95cc5a3c",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/767950017f688ff9f218273f7b05468ec98022759f7f899a60d6d17b95cc5a3c"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 25,
        "severity": "low",
        "risk_score": 10
      },
      "validity": {
        "first_seen": "2024-08-09T09:25:56Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "checks-user-input",
        "compressed",
        "contains-pe",
        "detect-debug-environment",
        "long-sleeps",
        "zip"
      ]
    },
    {
      "id": "event--6d4ae26f-2aa4-538f-95a8-517a72b293e0",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "7739e92e478a57e56570ee77f567b6ff30bc1d0ca73e5b3fd874f3d3b326b89c",
        "md5": "d5a8b607c7f77a91cad8a7cdba8f43d5",
        "sha1": "d278c8ba45c2896d5a1c59599c9a5caa796c2220",
        "sha256": "7739e92e478a57e56570ee77f567b6ff30bc1d0ca73e5b3fd874f3d3b326b89c",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/7739e92e478a57e56570ee77f567b6ff30bc1d0ca73e5b3fd874f3d3b326b89c"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "defendercontrol"
      },
      "validity": {
        "first_seen": "2025-05-28T09:48:43Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "compressed",
        "contains-pe",
        "defendercontrol",
        "detect-debug-environment",
        "disabledefender",
        "hacktool",
        "long-sleeps",
        "pua",
        "trojan",
        "windows",
        "zip"
      ]
    },
    {
      "id": "event--8a077623-fb5e-5242-afa0-bb88bac86bae",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "79196d42773b397e2f8d3db2e8f13eae95fd27df54d24576e0c28abf1050dbd8",
        "md5": "2f2e057dcc979217f531c5d7daeedf91",
        "sha1": "97c2641a1d78243a1037ba563e9027d634a2bb96",
        "sha256": "79196d42773b397e2f8d3db2e8f13eae95fd27df54d24576e0c28abf1050dbd8",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/79196d42773b397e2f8d3db2e8f13eae95fd27df54d24576e0c28abf1050dbd8"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "systemmod"
      },
      "validity": {
        "first_seen": "2025-08-29T23:00:33Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "compressed",
        "contains-pe",
        "detect-debug-environment",
        "long-sleeps",
        "redcap",
        "systemmod",
        "trojan",
        "windows",
        "zip"
      ]
    },
    {
      "id": "event--6d5b28c8-b118-57d8-8311-e5e31910267a",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3da036fef7c7d36a99489907afd648fa5ed4e615f1f5e974a0f10fd7531778aa",
        "md5": "446adfedd4e9a80b863339c18ddf61d6",
        "sha1": "044ceb6ccee109ab3df7542558fbc13745514c11",
        "sha256": "3da036fef7c7d36a99489907afd648fa5ed4e615f1f5e974a0f10fd7531778aa",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3da036fef7c7d36a99489907afd648fa5ed4e615f1f5e974a0f10fd7531778aa"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "shell"
      },
      "validity": {
        "first_seen": "2024-09-02T02:41:13Z",
        "last_seen": "2026-10-08T23:59:56Z"
      },
      "tags": [
        "checks-hostname",
        "cve-2016-0101",
        "detect-debug-environment",
        "downloader",
        "exploit",
        "linux",
        "persistence",
        "script",
        "sets-process-name",
        "sh",
        "shell",
        "trojan"
      ]
    },
    {
      "id": "event--f9cea248-f5a5-5657-b58d-72bad3f18b93",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3db6db5f1f3632600bac39268a98e86bc1902b8d6ada95078825a7f04be3baaf",
        "md5": "655c50f507a8aa94da846324c28b3c03",
        "sha1": "d31c7e8e9c62deb10428337cfa867146b9cef868",
        "sha256": "3db6db5f1f3632600bac39268a98e86bc1902b8d6ada95078825a7f04be3baaf",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3db6db5f1f3632600bac39268a98e86bc1902b8d6ada95078825a7f04be3baaf"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "shell"
      },
      "validity": {
        "first_seen": "2024-08-20T00:59:12Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "Bash",
        "checks-hostname",
        "cve-2009-1128",
        "detect-debug-environment",
        "downloader",
        "exploit",
        "linux",
        "persistence",
        "script",
        "service-scan",
        "sets-process-name",
        "sh",
        "shell",
        "trojan"
      ]
    },
    {
      "id": "event--b1d73858-4ac3-561a-bfba-fec1ebaf663a",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3dbab1c7a9d19002a3b4b32442f16b1de68265364fce1203a8fab388b8ed5007",
        "md5": "c0ff0ddad4302098ae40fcb3a0b1be59",
        "sha1": "c8a288e7cee74ebb004b0b5a5808a6dfdd5b1371",
        "sha256": "3dbab1c7a9d19002a3b4b32442f16b1de68265364fce1203a8fab388b8ed5007",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3dbab1c7a9d19002a3b4b32442f16b1de68265364fce1203a8fab388b8ed5007"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2024-08-19T12:49:05Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "Bash",
        "checks-hostname",
        "detect-debug-environment",
        "linux",
        "persistence",
        "script",
        "service-scan",
        "sets-process-name",
        "sh",
        "shell"
      ]
    },
    {
      "id": "event--33b1f927-f0c3-56f8-addf-66bed00e48c3",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3dca0c838e2e2a17d0d1d3e47556b84c3c5ff48ea4aa7716295a6c935093bae4",
        "md5": "83537d0025119dcba2c9bb68bd9d944e",
        "sha1": "4673dcdcd98f55f5aa81c126e5c2553e1b8058f2",
        "sha256": "3dca0c838e2e2a17d0d1d3e47556b84c3c5ff48ea4aa7716295a6c935093bae4",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3dca0c838e2e2a17d0d1d3e47556b84c3c5ff48ea4aa7716295a6c935093bae4"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 76,
        "severity": "high",
        "risk_score": 65,
        "family": "shell"
      },
      "validity": {
        "first_seen": "2024-08-23T08:03:30Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "Bash",
        "checks-hostname",
        "detect-debug-environment",
        "downloader",
        "linux",
        "persistence",
        "script",
        "service-scan",
        "sets-process-name",
        "sh",
        "shell",
        "trojan"
      ]
    },
    {
      "id": "event--23a1665b-e95a-5684-942a-f3831101df17",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3df7631c035dc34c6c7ffb618bc14d07cffd0670e3617391a3cc7833e68fa986",
        "md5": "2b0e4a6347f38ea4a9d044c05e0cc7b3",
        "sha1": "4a2dfcea637e28eda707c486de9ca52533f8cadb",
        "sha256": "3df7631c035dc34c6c7ffb618bc14d07cffd0670e3617391a3cc7833e68fa986",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3df7631c035dc34c6c7ffb618bc14d07cffd0670e3617391a3cc7833e68fa986"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "shell"
      },
      "validity": {
        "first_seen": "2024-09-06T16:41:56Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "detect-debug-environment",
        "downloader",
        "linux",
        "long-sleeps",
        "nxdomain",
        "persistence",
        "script",
        "sets-process-name",
        "sh",
        "shell",
        "trojan"
      ]
    },
    {
      "id": "event--643d0c3a-d855-5b96-9f10-3282fb36d38d",
      "timestamp": "2026-10-09T00:00:00Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "8c092a047883ac90c4107d716d5386cf582c782ea2ca4be8356682f1958a4d17",
        "md5": "e1ff6979d6275a48da82caf7748b39b5",
        "sha1": "42bea882239dacac5fb5ef96b598f8859f2db440",
        "sha256": "8c092a047883ac90c4107d716d5386cf582c782ea2ca4be8356682f1958a4d17",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/8c092a047883ac90c4107d716d5386cf582c782ea2ca4be8356682f1958a4d17"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "netpass"
      },
      "validity": {
        "first_seen": "2026-04-28T12:18:24Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "compressed",
        "contains-pe",
        "detect-debug-environment",
        "hacktool",
        "long-sleeps",
        "netpass",
        "nirsoft",
        "passview",
        "pua",
        "trojan",
        "windows",
        "wirelesskeyview",
        "zip"
      ]
    },
    {
      "id": "event--db9836c3-f210-5003-85b8-334a31ca4711",
      "timestamp": "2026-10-09T00:00:01Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3df84942ec9dd597f5a2401159017e8c420a7575b5d1b99f0b223974ec63d72f",
        "md5": "034594677ac940c65b26066a59f32f25",
        "sha1": "85cc1382a367a69b03759244f1ca0b6ce5004ba7",
        "sha256": "3df84942ec9dd597f5a2401159017e8c420a7575b5d1b99f0b223974ec63d72f",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3df84942ec9dd597f5a2401159017e8c420a7575b5d1b99f0b223974ec63d72f"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "shell"
      },
      "validity": {
        "first_seen": "2024-09-03T07:38:41Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "checks-hostname",
        "downloader",
        "linux",
        "script",
        "sh",
        "shell",
        "trojan"
      ]
    },
    {
      "id": "event--eaff4307-3cc3-55f0-881c-8f778c8384de",
      "timestamp": "2026-10-09T00:00:01Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3e003e1f17ad77703c5abc74af8236c52d80e0693a84bde40901453063f64371",
        "md5": "3aee346db6894e4cb663ad912c1f52d6",
        "sha1": "957117b8394e448f81730274ae542f34919c8072",
        "sha256": "3e003e1f17ad77703c5abc74af8236c52d80e0693a84bde40901453063f64371",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3e003e1f17ad77703c5abc74af8236c52d80e0693a84bde40901453063f64371"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "shell"
      },
      "validity": {
        "first_seen": "2024-08-20T05:45:07Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "checks-hostname",
        "detect-debug-environment",
        "downloader",
        "linux",
        "mirai",
        "persistence",
        "script",
        "service-scan",
        "sets-process-name",
        "sh",
        "shell",
        "trojan"
      ]
    },
    {
      "id": "event--822c655f-d143-504f-a9fe-131b672bf461",
      "timestamp": "2026-10-09T00:00:01Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3e0fabebfb50ea0b9d12801941a51984c333517e9b8a6de42c20eb89b6a54e79",
        "md5": "7223b99de7604af3ff3bab76cc17d463",
        "sha1": "453bc5a9ecc0e265b80b44843a536fb28619286a",
        "sha256": "3e0fabebfb50ea0b9d12801941a51984c333517e9b8a6de42c20eb89b6a54e79",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3e0fabebfb50ea0b9d12801941a51984c333517e9b8a6de42c20eb89b6a54e79"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 91,
        "severity": "high",
        "risk_score": 74,
        "family": "shell"
      },
      "validity": {
        "first_seen": "2024-09-08T17:59:40Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "downloader",
        "linux",
        "script",
        "sh",
        "shell",
        "trojan"
      ]
    },
    {
      "id": "event--b376d002-b052-52f0-8434-0870fabaa346",
      "timestamp": "2026-10-09T00:00:01Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "4812f312e0ae95da7a4a3358d2d8e79b0ff43642636c717b0147064af3136c05",
        "md5": "e359520f03a6faf653afc36e1057c3a2",
        "sha1": "1af056c4e41e601d69506aa718be2a0c2b135e24",
        "sha256": "4812f312e0ae95da7a4a3358d2d8e79b0ff43642636c717b0147064af3136c05",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/4812f312e0ae95da7a4a3358d2d8e79b0ff43642636c717b0147064af3136c05"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 92,
        "severity": "high",
        "risk_score": 75
      },
      "validity": {
        "first_seen": "2024-09-02T16:41:06Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "Bash",
        "checks-hostname",
        "detect-debug-environment",
        "downloader",
        "linux",
        "script",
        "sh",
        "shell",
        "trojan"
      ]
    },
    {
      "id": "event--50c12e17-24cc-5f7d-b1aa-689bed071d41",
      "timestamp": "2026-10-09T00:00:01Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "b75f8e1b8319e8df0ebbad3e48dd17aec611ab7da943474fb1ba5845164fc268",
        "md5": "1cba38becac88db6c10561cba1ef74fa",
        "sha1": "4a99712e9801e68884e048973037e3c80f3a0c66",
        "sha256": "b75f8e1b8319e8df0ebbad3e48dd17aec611ab7da943474fb1ba5845164fc268",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/b75f8e1b8319e8df0ebbad3e48dd17aec611ab7da943474fb1ba5845164fc268"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "wirelesskeyview"
      },
      "validity": {
        "first_seen": "2025-01-27T03:06:47Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "7zip",
        "checks-user-input",
        "compressed",
        "contains-pe",
        "detect-debug-environment",
        "hacktool",
        "long-sleeps",
        "nirsoft",
        "productkey",
        "trojan",
        "windows",
        "wirelesskeyview"
      ]
    },
    {
      "id": "event--ffd0d2f5-af53-573d-8c93-6e1f61b17f64",
      "timestamp": "2026-10-09T00:00:01Z",
      "action": "upsert",
      "reason": "RECUR",
      "indicator": {
        "type": "ip",
        "version": "v4",
        "value": "88.99.13.69",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/ips/88.99.13.69"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "low",
        "risk_score": 5
      },
      "validity": {
        "first_seen": "2023-10-05T23:48:25Z",
        "last_seen": "2026-10-08T23:59:57Z",
        "expires_at": "2026-11-07T23:59:57Z"
      }
    },
    {
      "id": "event--aa4964df-6dbc-5126-9ef0-293e97023c52",
      "timestamp": "2026-10-09T00:00:01Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "b7c5c75c7cb46b1be2086d41440aa85bf268e8024e9f1ca4c2bbb75f7a597b62",
        "md5": "e2530e22447c7d09cc9f479f451e51af",
        "sha1": "1e5c397d42ef926ba1a5764fe852adf6ca153751",
        "sha256": "b7c5c75c7cb46b1be2086d41440aa85bf268e8024e9f1ca4c2bbb75f7a597b62",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/b7c5c75c7cb46b1be2086d41440aa85bf268e8024e9f1ca4c2bbb75f7a597b62"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 88,
        "severity": "high",
        "risk_score": 72,
        "family": "productkey"
      },
      "validity": {
        "first_seen": "2024-12-20T03:17:00Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "checks-user-input",
        "compressed",
        "detect-debug-environment",
        "long-sleeps",
        "passview",
        "productkey",
        "pua",
        "rar",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--1eb634a4-c76b-516f-8d97-bce088836fe2",
      "timestamp": "2026-10-09T00:00:01Z",
      "action": "upsert",
      "reason": "RECUR",
      "indicator": {
        "type": "domain",
        "value": "a7788.1apps.com",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/domains/a7788.1apps.com"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 70,
        "severity": "medium",
        "risk_score": 38
      },
      "validity": {
        "first_seen": "2023-11-30T12:05:27Z",
        "last_seen": "2026-10-08T23:59:57Z",
        "expires_at": "2027-02-05T23:59:57Z"
      }
    },
    {
      "id": "event--029bb9f1-1400-593d-8819-81065d00fab0",
      "timestamp": "2026-10-09T00:00:01Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "104c50d2f2c4c6a91b4530daf9cbe63c277427f0002ba49687061497cde51b9b",
        "md5": "67998179870205f2b713c53b148f917c",
        "sha1": "d51247faae8198f7a2a299c26393dd5cc5443845",
        "sha256": "104c50d2f2c4c6a91b4530daf9cbe63c277427f0002ba49687061497cde51b9b",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/104c50d2f2c4c6a91b4530daf9cbe63c277427f0002ba49687061497cde51b9b"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2024-11-28T14:27:41Z",
        "last_seen": "2026-10-08T23:59:57Z"
      },
      "tags": [
        "checks-usb-bus",
        "detect-debug-environment",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "persistence",
        "signed",
        "win32",
        "windows"
      ]
    }
  ]
}