{
  "items": [
    {
      "id": "event--9f9beb75-6c7f-50c2-9856-d23fbc089176",
      "timestamp": "2026-10-10T00:00:06Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "10140e4d5898d6ec53d4f0938c2b085471ea74fcf2458d29a19431cf01a3f880",
        "md5": "9dce1e226cda29c8fd61afff57ec073e",
        "sha1": "ccebb2db0812040775e331cdad60b3402b7575b0",
        "sha256": "10140e4d5898d6ec53d4f0938c2b085471ea74fcf2458d29a19431cf01a3f880",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/10140e4d5898d6ec53d4f0938c2b085471ea74fcf2458d29a19431cf01a3f880"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "critical",
        "risk_score": 20,
        "family": "csrvpr"
      },
      "validity": {
        "first_seen": "2026-09-25T01:22:16Z",
        "last_seen": "2026-10-09T19:10:36Z"
      },
      "tags": [
        "compressed",
        "contains-macho",
        "csrvpr",
        "detect-debug-environment",
        "java",
        "long-sleeps",
        "mac-app",
        "self-signed",
        "sets-process-name",
        "zip"
      ]
    },
    {
      "id": "event--733ba1fa-482c-5be9-827a-f23345b78a8a",
      "timestamp": "2026-10-10T00:00:06Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "80ea83fd04182dd244737a840881e16bc3285c1a51711d68cbf0306d2dd5fb29",
        "md5": "ea0fba6bb734b9291981213823f171dc",
        "sha1": "a73d462319d3c567f53fd0fa49d1df1eaaff8f4d",
        "sha256": "80ea83fd04182dd244737a840881e16bc3285c1a51711d68cbf0306d2dd5fb29",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/80ea83fd04182dd244737a840881e16bc3285c1a51711d68cbf0306d2dd5fb29"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "critical",
        "risk_score": 20,
        "family": "csrvpr"
      },
      "validity": {
        "first_seen": "2026-10-04T17:45:33Z",
        "last_seen": "2026-10-04T17:45:33Z"
      },
      "tags": [
        "compressed",
        "contains-macho",
        "csrvpr",
        "detect-debug-environment",
        "java",
        "long-sleeps",
        "mac-app",
        "self-signed",
        "sets-process-name",
        "zip"
      ]
    },
    {
      "id": "event--e96101c6-e0fe-5129-8066-25725a96125c",
      "timestamp": "2026-10-10T00:00:07Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "a99fa681241078aa43cf184285810f1e8a6afd43188ae2f1e433f0855df2ee5e",
        "md5": "96cec0605cd671a81995ad88998a79fb",
        "sha1": "ac579a232821d34e8fe9ace5e0f98c5b3af5f04f",
        "sha256": "a99fa681241078aa43cf184285810f1e8a6afd43188ae2f1e433f0855df2ee5e",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/a99fa681241078aa43cf184285810f1e8a6afd43188ae2f1e433f0855df2ee5e"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "critical",
        "risk_score": 20,
        "family": "csrvpr"
      },
      "validity": {
        "first_seen": "2026-10-09T05:54:28Z",
        "last_seen": "2026-10-09T05:54:28Z"
      },
      "tags": [
        "compressed",
        "contains-macho",
        "csrvpr",
        "detect-debug-environment",
        "java",
        "long-sleeps",
        "mac-app",
        "self-signed",
        "sets-process-name",
        "zip"
      ]
    },
    {
      "id": "event--915ffb64-7369-5669-bb41-137e5a327acb",
      "timestamp": "2026-10-10T00:00:07Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "b4de92bce10774822f8ea728658b7f382ad4d40a3288ccc1760ffde4b0e3a9d1",
        "md5": "c03c1a918b78fb359394abe10dfa181e",
        "sha1": "d223b86c1c775a6d5f09d56611d213be63d73308",
        "sha256": "b4de92bce10774822f8ea728658b7f382ad4d40a3288ccc1760ffde4b0e3a9d1",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/b4de92bce10774822f8ea728658b7f382ad4d40a3288ccc1760ffde4b0e3a9d1"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "critical",
        "risk_score": 20,
        "family": "csrvpr"
      },
      "validity": {
        "first_seen": "2026-09-27T11:45:37Z",
        "last_seen": "2026-09-27T11:45:37Z"
      },
      "tags": [
        "compressed",
        "contains-macho",
        "csrvpr",
        "detect-debug-environment",
        "java",
        "long-sleeps",
        "mac-app",
        "self-signed",
        "sets-process-name",
        "zip"
      ]
    },
    {
      "id": "event--59b48385-e45b-56d7-bf12-67e001ecc654",
      "timestamp": "2026-10-10T00:00:07Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "e7f52bd680d0f505fb9c9ea98d70374dd022819c783f95cc61c51fc62023e5f8",
        "md5": "6811533c8f6785ea77bbf9777423fccb",
        "sha1": "ea1c2bcf62d31c33af5d1724dd41984fef66b305",
        "sha256": "e7f52bd680d0f505fb9c9ea98d70374dd022819c783f95cc61c51fc62023e5f8",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/e7f52bd680d0f505fb9c9ea98d70374dd022819c783f95cc61c51fc62023e5f8"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "critical",
        "risk_score": 20,
        "family": "csrvpr"
      },
      "validity": {
        "first_seen": "2026-10-05T02:22:30Z",
        "last_seen": "2026-10-05T02:22:30Z"
      },
      "tags": [
        "compressed",
        "contains-macho",
        "csrvpr",
        "detect-debug-environment",
        "java",
        "long-sleeps",
        "mac-app",
        "self-signed",
        "sets-process-name",
        "zip"
      ]
    },
    {
      "id": "event--e075b5c8-1430-59bc-99b3-75ce4cc1e8ac",
      "timestamp": "2026-10-10T00:00:10Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "7ba2f56eac0d2882f184a82fb1b05d1073ccf0a349b6b6b33133477e0fdc8968",
        "md5": "a8f0fa7419c093ecde11159cb71e00ac",
        "sha1": "4af29726651ef697210e376b0bc7a586cadb330b",
        "sha256": "7ba2f56eac0d2882f184a82fb1b05d1073ccf0a349b6b6b33133477e0fdc8968",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/7ba2f56eac0d2882f184a82fb1b05d1073ccf0a349b6b6b33133477e0fdc8968"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 93,
        "severity": "high",
        "risk_score": 76,
        "family": "filerepmalware"
      },
      "validity": {
        "first_seen": "2026-05-02T10:21:42Z",
        "last_seen": "2026-05-05T16:45:31Z"
      },
      "tags": [
        "alien",
        "checks-usb-bus",
        "filerepmalware",
        "installer",
        "msi",
        "trojan",
        "windows"
      ]
    },
    {
      "id": "event--f8a49551-8a5a-556a-853f-a7256b90dcd9",
      "timestamp": "2026-10-10T00:00:11Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "5e1c86bf578683d960214146993c293ccdee51908329b36bcee3129394382acb",
        "md5": "57c49956101efe997153a2c3abfe004e",
        "sha1": "e1cfc4597760d60e1ed82cdf7993622529e541ce",
        "sha256": "5e1c86bf578683d960214146993c293ccdee51908329b36bcee3129394382acb",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/5e1c86bf578683d960214146993c293ccdee51908329b36bcee3129394382acb"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "genericfca"
      },
      "validity": {
        "first_seen": "2026-10-09T23:51:09Z",
        "last_seen": "2026-10-10T00:00:10Z"
      },
      "tags": [
        "64bits",
        "adware",
        "convagent",
        "exe",
        "executable",
        "genericfca",
        "krypt",
        "payload",
        "pe",
        "peexe",
        "spreader",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--da246e33-7fff-5397-9757-e1e8753730f1",
      "timestamp": "2026-10-10T00:00:11Z",
      "action": "revoke",
      "reason": "FP",
      "indicator": {
        "type": "file",
        "value": "e045059ebeb045ad943d2ca2bf58e85c856b3b5cd22af614cc1571453c36d822",
        "md5": "c80c01744508fb7b31710e6cdd9263e2",
        "sha1": "b4655ff2d9e44d17b1896d263a8d681dd9144878",
        "sha256": "e045059ebeb045ad943d2ca2bf58e85c856b3b5cd22af614cc1571453c36d822",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/e045059ebeb045ad943d2ca2bf58e85c856b3b5cd22af614cc1571453c36d822"
        }
      },
      "analysis": {
        "malicious": false,
        "confidence": 0,
        "severity": "low",
        "risk_score": 5
      },
      "validity": {
        "first_seen": "2026-08-04T04:42:09Z",
        "last_seen": "2026-08-17T06:36:27Z"
      },
      "tags": [
        "compressed",
        "detect-debug-environment",
        "sets-process-name",
        "zip"
      ]
    },
    {
      "id": "event--507d5fb5-ea67-5645-a750-0e95b13afc51",
      "timestamp": "2026-10-10T00:00:11Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "7aef0846a4b89dc8156fe7653b8032e04d8db10656970047c53ac6866970ff67",
        "md5": "5817602b569fc0c749c15876945263b6",
        "sha1": "be1738f3bfba1cd56f0559f92b0f89aed56ed063",
        "sha256": "7aef0846a4b89dc8156fe7653b8032e04d8db10656970047c53ac6866970ff67",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/7aef0846a4b89dc8156fe7653b8032e04d8db10656970047c53ac6866970ff67"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "socks"
      },
      "validity": {
        "first_seen": "2026-10-09T21:18:52Z",
        "last_seen": "2026-10-10T00:00:10Z"
      },
      "tags": [
        "bheu",
        "blocker",
        "exe",
        "executable",
        "overlay",
        "payload",
        "pe",
        "peexe",
        "ransomware",
        "socks",
        "trojan",
        "win32",
        "windows",
        "worm"
      ]
    },
    {
      "id": "event--ee35410b-ac1b-5674-abf6-c7a8d8b64a50",
      "timestamp": "2026-10-10T00:00:11Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3608ce72ec1bf8a483b9ce7549cb5bf78054d9650846e666e1c5c172ad53e3ec",
        "md5": "5686dccf565b4c453c84a881e9d8d42b",
        "sha1": "41f724051aa256fa57b8415f0da96288acf5b790",
        "sha256": "3608ce72ec1bf8a483b9ce7549cb5bf78054d9650846e666e1c5c172ad53e3ec",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3608ce72ec1bf8a483b9ce7549cb5bf78054d9650846e666e1c5c172ad53e3ec"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cyzt"
      },
      "validity": {
        "first_seen": "2026-10-08T21:28:53Z",
        "last_seen": "2026-10-10T00:00:10Z"
      },
      "tags": [
        "corewarrior",
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "flooder",
        "hacktool",
        "loader",
        "overlay",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--7bc86ae5-2914-5474-b08f-4fc50dbc89e4",
      "timestamp": "2026-10-10T00:00:12Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "c09bbea19905610caaa7bb277780cec2796c698b1463f8cb2641c8eeefc9203e",
        "md5": "57dc0f3158bcbe2202921e8c23855cab",
        "sha1": "16e6045384980dd573733dbbc22454c297786ddd",
        "sha256": "c09bbea19905610caaa7bb277780cec2796c698b1463f8cb2641c8eeefc9203e",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/c09bbea19905610caaa7bb277780cec2796c698b1463f8cb2641c8eeefc9203e"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 74,
        "severity": "high",
        "risk_score": 63,
        "family": "scam"
      },
      "validity": {
        "first_seen": "2026-10-09T21:23:35Z",
        "last_seen": "2026-10-10T00:00:11Z"
      },
      "tags": [
        "contains-embedded-js",
        "html",
        "internet",
        "scam"
      ]
    },
    {
      "id": "event--2dab06d1-57c9-50e2-ab4e-96af4a766628",
      "timestamp": "2026-10-10T00:00:12Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "4fe2441691eda9df9be6a462270defc9b1d3b04f7531c7d256f3d3ee64b82c4a",
        "md5": "55e2016a36be7f51697365f6cd5ea7bd",
        "sha1": "2ebdf7678dd7cbea980cb514f104a7419b982ebd",
        "sha256": "4fe2441691eda9df9be6a462270defc9b1d3b04f7531c7d256f3d3ee64b82c4a",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/4fe2441691eda9df9be6a462270defc9b1d3b04f7531c7d256f3d3ee64b82c4a"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cyzt"
      },
      "validity": {
        "first_seen": "2026-10-09T08:16:31Z",
        "last_seen": "2026-10-10T00:00:10Z"
      },
      "tags": [
        "banker",
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "nemucod",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--a17f78db-e883-54ee-a7ce-b976562d0d73",
      "timestamp": "2026-10-10T00:00:12Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "ae483559a3bb363d4609d492022a42d1db49b56b7b694cd5734db6b7c1aa054b",
        "md5": "372f98f296e7a8a405881d32bae0e294",
        "sha1": "06f9bd4cd31f783e1987f6f8680b326c4ac755a6",
        "sha256": "ae483559a3bb363d4609d492022a42d1db49b56b7b694cd5734db6b7c1aa054b",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/ae483559a3bb363d4609d492022a42d1db49b56b7b694cd5734db6b7c1aa054b"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 25,
        "severity": "medium",
        "risk_score": 20
      },
      "validity": {
        "first_seen": "2025-12-21T12:43:58Z",
        "last_seen": "2026-10-07T17:18:37Z"
      },
      "tags": [
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--7d31acfb-de2f-5165-9933-2ee2dfe12be1",
      "timestamp": "2026-10-10T00:00:12Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "24d5805bcbd542dc500aad54b14324861cf03697855de2b4764f56173e98522a",
        "md5": "57a4d24b7b7bcf2719447c20a7f71962",
        "sha1": "a177e05e535661831192d0b9aa7121d5df823ddb",
        "sha256": "24d5805bcbd542dc500aad54b14324861cf03697855de2b4764f56173e98522a",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/24d5805bcbd542dc500aad54b14324861cf03697855de2b4764f56173e98522a"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cyzt"
      },
      "validity": {
        "first_seen": "2026-10-09T15:21:38Z",
        "last_seen": "2026-10-10T00:00:10Z"
      },
      "tags": [
        "banker",
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "nemucod",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--d7a68046-da37-5f3f-b0c5-720cd4b202da",
      "timestamp": "2026-10-10T00:00:13Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "f970261cf6dd7cbc56e17fcd1bbb984cf084f3189f24cfece6f0e8d55614a88f",
        "md5": "5661bcb3e026641ea7693d4750472916",
        "sha1": "ae613a93144ee28f3d554c6d611efcf972673d0f",
        "sha256": "f970261cf6dd7cbc56e17fcd1bbb984cf084f3189f24cfece6f0e8d55614a88f",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/f970261cf6dd7cbc56e17fcd1bbb984cf084f3189f24cfece6f0e8d55614a88f"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 99,
        "severity": "high",
        "risk_score": 79,
        "family": "asrisk"
      },
      "validity": {
        "first_seen": "2026-10-07T01:08:06Z",
        "last_seen": "2026-10-10T00:00:11Z"
      },
      "tags": [
        "asrisk",
        "downloader",
        "exe",
        "executable",
        "inno",
        "nnou",
        "payload",
        "pe",
        "peexe",
        "sabsik",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--4fdac077-9bc0-5e49-98ba-99fbb210091c",
      "timestamp": "2026-10-10T00:00:14Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "6a406785e424d60d8cf733bbb9d3861444707b7d8ddf3b5216f087873916a378",
        "md5": "58411be98e664bde190bca7e611ab50f",
        "sha1": "88b4b39c627e9e104e68512c0afc10bab0502b25",
        "sha256": "6a406785e424d60d8cf733bbb9d3861444707b7d8ddf3b5216f087873916a378",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/6a406785e424d60d8cf733bbb9d3861444707b7d8ddf3b5216f087873916a378"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 99,
        "severity": "high",
        "risk_score": 79,
        "family": "asrisk"
      },
      "validity": {
        "first_seen": "2026-10-08T18:45:27Z",
        "last_seen": "2026-10-10T00:00:12Z"
      },
      "tags": [
        "asrisk",
        "downloader",
        "exe",
        "executable",
        "inno",
        "nnou",
        "payload",
        "pe",
        "peexe",
        "sabsik",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--58820ebd-445a-596f-8579-1016f68c915f",
      "timestamp": "2026-10-10T00:00:15Z",
      "action": "upsert",
      "reason": "SEV_DOWN",
      "indicator": {
        "type": "domain",
        "value": "wolrdcup2026202620262026.dynuddns.net",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/domains/wolrdcup2026202620262026.dynuddns.net"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 96,
        "severity": "medium",
        "risk_score": 45
      },
      "validity": {
        "first_seen": "2026-04-17T09:35:16Z",
        "last_seen": "2026-10-04T20:11:41Z",
        "expires_at": "2027-04-02T20:11:41Z"
      },
      "tags": [
        "dga",
        "hex",
        "phishing"
      ]
    },
    {
      "id": "event--ce4697b1-686e-51dd-83ee-fea7dc8c1cb9",
      "timestamp": "2026-10-10T00:00:15Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "fd1e8016c04076fc3a03a41ec004b02094bc7ed85c04fadc1a808907e6031877",
        "md5": "59a06c163daa190481cc918caeae63fd",
        "sha1": "8f6f9afd6044ea635e389066a3d9da54d0208707",
        "sha256": "fd1e8016c04076fc3a03a41ec004b02094bc7ed85c04fadc1a808907e6031877",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/fd1e8016c04076fc3a03a41ec004b02094bc7ed85c04fadc1a808907e6031877"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "obfscred"
      },
      "validity": {
        "first_seen": "2026-10-06T22:39:33Z",
        "last_seen": "2026-10-10T00:00:14Z"
      },
      "tags": [
        "gen3",
        "javascript",
        "js",
        "obfscred",
        "phishing",
        "redir",
        "source",
        "trojan"
      ]
    },
    {
      "id": "event--9cc4e5a6-0851-5f8d-b318-b9f0064e7854",
      "timestamp": "2026-10-10T00:00:16Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "2e6a8efe72cbef506e36e02153ac02bf9ca716d8bdce073a0f9daf3202998de5",
        "md5": "5a22dd2ca7f6bb4a7f5d245fbd8b1108",
        "sha1": "e5de900cd007fbfdb97ffdb9d34885e438ace500",
        "sha256": "2e6a8efe72cbef506e36e02153ac02bf9ca716d8bdce073a0f9daf3202998de5",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/2e6a8efe72cbef506e36e02153ac02bf9ca716d8bdce073a0f9daf3202998de5"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "socks"
      },
      "validity": {
        "first_seen": "2026-10-09T21:09:30Z",
        "last_seen": "2026-10-10T00:00:16Z"
      },
      "tags": [
        "bbvx",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "ransomware",
        "socks",
        "stealer",
        "trojan",
        "upx",
        "win32",
        "windows",
        "worm"
      ]
    },
    {
      "id": "event--acdc059b-5ada-5ccc-aaca-4ddf32a37257",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "f05d1e53bb0a7ad9352cda4acdf2c9bfb115d2441648694506362c638b6a1715",
        "md5": "5ac48638bcc9c5d74460ae81c16ecc36",
        "sha1": "1f492402da0fe8ada8e67d28ccedc7841fe20ac2",
        "sha256": "f05d1e53bb0a7ad9352cda4acdf2c9bfb115d2441648694506362c638b6a1715",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/f05d1e53bb0a7ad9352cda4acdf2c9bfb115d2441648694506362c638b6a1715"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "obfscred"
      },
      "validity": {
        "first_seen": "2026-10-09T17:21:51Z",
        "last_seen": "2026-10-10T00:00:16Z"
      },
      "tags": [
        "gen3",
        "javascript",
        "js",
        "obfscred",
        "phishing",
        "redir",
        "source",
        "trojan"
      ]
    },
    {
      "id": "event--012e1b76-30b2-50c0-9266-863ef64d94f9",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "82680e2351fa916eaad477f4879871c56dfe289e12970cb17fa4717b784d9d73",
        "md5": "5a507c63b03edf4ac26826325ebbb5c5",
        "sha1": "59c4352bc28abd10bc098a90558506560fead606",
        "sha256": "82680e2351fa916eaad477f4879871c56dfe289e12970cb17fa4717b784d9d73",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/82680e2351fa916eaad477f4879871c56dfe289e12970cb17fa4717b784d9d73"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "socks"
      },
      "validity": {
        "first_seen": "2026-10-09T21:23:35Z",
        "last_seen": "2026-10-10T00:00:16Z"
      },
      "tags": [
        "bi2s",
        "dropper",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "socks",
        "spreader",
        "stealer",
        "trojan",
        "upx",
        "win32",
        "windows",
        "worm"
      ]
    },
    {
      "id": "event--6bc671e7-0bb3-55a5-9f9f-f6eb91169561",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "a961311557c664ade619c649eb9342845d5ba065b59cbb661439a3149812fcfa",
        "md5": "59137aa6ea0046a9a9239312ac459a80",
        "sha1": "ee572662745654f3699d93331d914e151bfeef5f",
        "sha256": "a961311557c664ade619c649eb9342845d5ba065b59cbb661439a3149812fcfa",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/a961311557c664ade619c649eb9342845d5ba065b59cbb661439a3149812fcfa"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "truesight"
      },
      "validity": {
        "first_seen": "2026-10-09T06:31:58Z",
        "last_seen": "2026-10-10T00:00:15Z"
      },
      "tags": [
        "64bits",
        "adlice",
        "downloader",
        "exe",
        "executable",
        "native",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "trojan",
        "truesight",
        "vulndriver",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--f798e857-5d15-5db4-b37b-265c6f5991c6",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "9e30b8b85643909aa7a334a06837f9bb8814311ba487d7964cb2762c75552e4f",
        "md5": "6b999aaa09011c4337f72efb389c80a1",
        "sha1": "0901fb7d3d653220248ec429af755a8195ac801c",
        "sha256": "9e30b8b85643909aa7a334a06837f9bb8814311ba487d7964cb2762c75552e4f",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/9e30b8b85643909aa7a334a06837f9bb8814311ba487d7964cb2762c75552e4f"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 94,
        "severity": "critical",
        "risk_score": 95,
        "family": "downloader50"
      },
      "validity": {
        "first_seen": "2026-10-09T10:32:07Z",
        "last_seen": "2026-10-10T00:00:16Z"
      },
      "tags": [
        "64bits",
        "corrupt",
        "downloader50",
        "dropper",
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "phishing",
        "shellcoderunner",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--33ab143d-f46d-5bdc-b290-b44b2d168134",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "0b38874b8e4e90bc700e66267d10306dbd534c8113f19c3e92a2cfbd0d775cab",
        "md5": "f5a3acd2417d293e4ac83e9acf13c903",
        "sha1": "3b73093175a5e33765d36b2307bfeaf3c3e9b346",
        "sha256": "0b38874b8e4e90bc700e66267d10306dbd534c8113f19c3e92a2cfbd0d775cab",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/0b38874b8e4e90bc700e66267d10306dbd534c8113f19c3e92a2cfbd0d775cab"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-06-04T04:37:41Z",
        "last_seen": "2026-07-18T05:46:13Z"
      },
      "tags": [
        "64bits",
        "corrupt",
        "dll",
        "executable",
        "pe",
        "pedll",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--50850ef5-79f5-5c41-be1f-335f7a9f3ced",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "0d94397ff274ac22babd4f5c85c11507cf814fd4547a01e18a3d4db2428a68c5",
        "md5": "846899b63490674da8f2b974b44da55e",
        "sha1": "27ff761e04a4690e8b6a943b2a86ad79c309397c",
        "sha256": "0d94397ff274ac22babd4f5c85c11507cf814fd4547a01e18a3d4db2428a68c5",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/0d94397ff274ac22babd4f5c85c11507cf814fd4547a01e18a3d4db2428a68c5"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-06-05T21:58:38Z",
        "last_seen": "2026-07-17T03:36:04Z"
      },
      "tags": [
        "64bits",
        "exe",
        "executable",
        "pe",
        "peexe",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--3652a7ad-f268-57d2-b334-f89744a4e8df",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3f1b9aeca9eed7df7139fe0121edf52d4a26e9f4c7f4db3feec98c3846a03c56",
        "md5": "c552473f11d0f2aeb541318106d8779d",
        "sha1": "ff6f4ce7aa41a52db656d234857e40a4659c12e5",
        "sha256": "3f1b9aeca9eed7df7139fe0121edf52d4a26e9f4c7f4db3feec98c3846a03c56",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3f1b9aeca9eed7df7139fe0121edf52d4a26e9f4c7f4db3feec98c3846a03c56"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-06-05T05:41:48Z",
        "last_seen": "2026-07-19T00:40:25Z"
      },
      "tags": [
        "64bits",
        "dll",
        "executable",
        "pe",
        "pedll",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--58a864c3-02cf-5ffd-83e2-f1e5180f5a8d",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "41e1b97e5092231b27f14f6b1e3d5e719546713fc89fdb531b602cfa190c3cfe",
        "md5": "734673e29c298c91d06399ef9a5eaae4",
        "sha1": "c5ed2da0dec379bdbd34e75b6dddd64f27d57114",
        "sha256": "41e1b97e5092231b27f14f6b1e3d5e719546713fc89fdb531b602cfa190c3cfe",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/41e1b97e5092231b27f14f6b1e3d5e719546713fc89fdb531b602cfa190c3cfe"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-06-04T05:35:58Z",
        "last_seen": "2026-07-10T11:23:54Z"
      },
      "tags": [
        "64bits",
        "dll",
        "executable",
        "pe",
        "pedll",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--b66e3e49-d2f5-512a-b10f-ce41f0a4ab96",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "519d7c6c5d1e24fee021042891fdc37b79f00dae4d8d968257165dab58f8ee4c",
        "md5": "b1458c5c0a8ada645df6ac521b738f2c",
        "sha1": "b40d51d3ee320e761e11e7ead140647c3d840d3d",
        "sha256": "519d7c6c5d1e24fee021042891fdc37b79f00dae4d8d968257165dab58f8ee4c",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/519d7c6c5d1e24fee021042891fdc37b79f00dae4d8d968257165dab58f8ee4c"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-06-04T04:37:41Z",
        "last_seen": "2026-07-16T20:25:02Z"
      },
      "tags": [
        "64bits",
        "dll",
        "executable",
        "pe",
        "pedll",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--12a857a1-4a6d-506b-9652-a0899048e94e",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "5c28ad1c86c8a9060bd4e2e97c3aa1a2f71c6729d469336f3c3678ee383ba805",
        "md5": "1e6b7c7441f217fdbfcbcc2f2a695939",
        "sha1": "3bfe5cf38c4685af0948667ea29596a07b22b324",
        "sha256": "5c28ad1c86c8a9060bd4e2e97c3aa1a2f71c6729d469336f3c3678ee383ba805",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/5c28ad1c86c8a9060bd4e2e97c3aa1a2f71c6729d469336f3c3678ee383ba805"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-06-05T21:58:38Z",
        "last_seen": "2026-07-12T13:15:32Z"
      },
      "tags": [
        "64bits",
        "dll",
        "executable",
        "pe",
        "pedll",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--a3fc770d-39a4-50a0-a74d-843011e3be60",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "778a5d3decaa3e60e40979adb3a351f0be91973025e99b06b9a4b41c3b853e38",
        "md5": "8478b2d974f857ac2d0f9997327df93b",
        "sha1": "e9bbbb407af962aab50f616d7bf884a7c7c5e2a0",
        "sha256": "778a5d3decaa3e60e40979adb3a351f0be91973025e99b06b9a4b41c3b853e38",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/778a5d3decaa3e60e40979adb3a351f0be91973025e99b06b9a4b41c3b853e38"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-06-03T06:41:02Z",
        "last_seen": "2026-07-18T08:16:53Z"
      },
      "tags": [
        "64bits",
        "dll",
        "executable",
        "pe",
        "pedll",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--49e534fd-cd01-50af-9aec-756e87edbaad",
      "timestamp": "2026-10-10T00:00:17Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "84c580092537057550bd8de19ef3af0626f9827f8d10ec55581fe57ee5c3bccb",
        "md5": "3b2d038149da9c16c1a814f939e280aa",
        "sha1": "9a1a8cd097fee310d2077c1768661c88e60a63c7",
        "sha256": "84c580092537057550bd8de19ef3af0626f9827f8d10ec55581fe57ee5c3bccb",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/84c580092537057550bd8de19ef3af0626f9827f8d10ec55581fe57ee5c3bccb"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-06-04T05:35:58Z",
        "last_seen": "2026-07-12T02:57:06Z"
      },
      "tags": [
        "64bits",
        "dll",
        "executable",
        "pe",
        "pedll",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--d67e2a86-e6de-5671-906b-e44dfbe2e8bb",
      "timestamp": "2026-10-10T00:00:18Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "1cab8275d0d496ea089a545fdb63ae6a66c33516cdb7109e979c1934c8d80c5f",
        "md5": "5bab9d0029733928c251f85ba6e79067",
        "sha1": "a611098c2aad8c33d11f24d34c208a20164a5779",
        "sha256": "1cab8275d0d496ea089a545fdb63ae6a66c33516cdb7109e979c1934c8d80c5f",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/1cab8275d0d496ea089a545fdb63ae6a66c33516cdb7109e979c1934c8d80c5f"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 92,
        "severity": "high",
        "risk_score": 75,
        "family": "fakeale"
      },
      "validity": {
        "first_seen": "2026-10-09T21:29:18Z",
        "last_seen": "2026-10-10T00:00:17Z"
      },
      "tags": [
        "contains-embedded-js",
        "fakeale",
        "html",
        "internet",
        "phishing",
        "scamt",
        "techscam",
        "trojan"
      ]
    },
    {
      "id": "event--b061ad3a-56f9-5495-b071-5a4aad55605f",
      "timestamp": "2026-10-10T00:00:18Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "e41306132539349506c4a269f83fd6865b928eea558ef625b30377700869f55e",
        "md5": "59b24fa570c06ead3483aa32cb894b11",
        "sha1": "3f65c483f9b1f35a49434f78d6f77f3a707e835f",
        "sha256": "e41306132539349506c4a269f83fd6865b928eea558ef625b30377700869f55e",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/e41306132539349506c4a269f83fd6865b928eea558ef625b30377700869f55e"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "corewarrior"
      },
      "validity": {
        "first_seen": "2026-10-07T14:54:21Z",
        "last_seen": "2026-10-10T00:00:15Z"
      },
      "tags": [
        "corewarrior",
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "flooder",
        "hacktool",
        "loader",
        "overlay",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--e58a9891-4f49-568e-abd8-dbc24cf90e81",
      "timestamp": "2026-10-10T00:00:18Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "77ca8b8e22ae243393cc7e9d93bfb0368be98aa6c6814135497f27a3518393c5",
        "md5": "5a3b9b49770c75b49d12b2f03d3b7927",
        "sha1": "b5a7877b3d4a82b07af1c9f632151ce2e8a0dec7",
        "sha256": "77ca8b8e22ae243393cc7e9d93bfb0368be98aa6c6814135497f27a3518393c5",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/77ca8b8e22ae243393cc7e9d93bfb0368be98aa6c6814135497f27a3518393c5"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cyzt"
      },
      "validity": {
        "first_seen": "2026-10-09T13:29:22Z",
        "last_seen": "2026-10-10T00:00:16Z"
      },
      "tags": [
        "banker",
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "nemucod",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--6e73f11f-2e12-58b0-a1da-2eb2b6f59876",
      "timestamp": "2026-10-10T00:00:19Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "0fe8340606259382737ffd1b778b0af74fa7830859969d6bb574a9dd98b96611",
        "md5": "5b0b0678af4c40861a9f59f9dcce7b8c",
        "sha1": "b6609f17ab95c5a1c4e1209ced00ab122379037b",
        "sha256": "0fe8340606259382737ffd1b778b0af74fa7830859969d6bb574a9dd98b96611",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/0fe8340606259382737ffd1b778b0af74fa7830859969d6bb574a9dd98b96611"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "corewarrior"
      },
      "validity": {
        "first_seen": "2026-10-09T11:43:56Z",
        "last_seen": "2026-10-10T00:00:17Z"
      },
      "tags": [
        "corewarrior",
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "flooder",
        "hacktool",
        "loader",
        "overlay",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--89f71b8b-8fc3-5582-a908-884a739d8161",
      "timestamp": "2026-10-10T00:00:19Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "2fb3269cf1057acce4f6a3b1550b7b15af86845f34f826f5307b45d5c3546afe",
        "md5": "5a25e4c4114f2814f588f85a98650c7e",
        "sha1": "543b6a963dd6ba4598da63ee8381bf134a42d1a7",
        "sha256": "2fb3269cf1057acce4f6a3b1550b7b15af86845f34f826f5307b45d5c3546afe",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/2fb3269cf1057acce4f6a3b1550b7b15af86845f34f826f5307b45d5c3546afe"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "corewarrior"
      },
      "validity": {
        "first_seen": "2026-10-07T05:27:18Z",
        "last_seen": "2026-10-10T00:00:17Z"
      },
      "tags": [
        "corewarrior",
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "flooder",
        "hacktool",
        "loader",
        "overlay",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--32105046-406d-5cc4-a07f-b81b73d9ce28",
      "timestamp": "2026-10-10T00:00:19Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "5a0769d582aa006b95148bee1d15ce14f840e5d6e61e1814b1c21d99bc44db02",
        "md5": "5a54d186003d9ed5ac638651c268acf6",
        "sha1": "a04214c9c06ba7b60b9117ee4d448fa3841d26e9",
        "sha256": "5a0769d582aa006b95148bee1d15ce14f840e5d6e61e1814b1c21d99bc44db02",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/5a0769d582aa006b95148bee1d15ce14f840e5d6e61e1814b1c21d99bc44db02"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "socks"
      },
      "validity": {
        "first_seen": "2026-10-09T09:47:13Z",
        "last_seen": "2026-10-10T00:00:18Z"
      },
      "tags": [
        "bheu",
        "blocker",
        "exe",
        "executable",
        "overlay",
        "payload",
        "pe",
        "peexe",
        "ransomware",
        "socks",
        "trojan",
        "win32",
        "windows",
        "worm"
      ]
    },
    {
      "id": "event--8fed22fd-37c6-595a-a7ee-9b43fc3e266c",
      "timestamp": "2026-10-10T00:00:19Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "07ea3b5965d99a14bdd3f0887acb7123a16e7d0d5e3b9f97998abc9e0b410a1b",
        "md5": "b966b66cf2975ea2e950854be094189b",
        "sha1": "41a9385c320d74dabba06db79e8e17450e23d3c1",
        "sha256": "07ea3b5965d99a14bdd3f0887acb7123a16e7d0d5e3b9f97998abc9e0b410a1b",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/07ea3b5965d99a14bdd3f0887acb7123a16e7d0d5e3b9f97998abc9e0b410a1b"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-05-26T19:16:57Z",
        "last_seen": "2026-07-01T20:33:16Z"
      },
      "tags": [
        "64bits",
        "exe",
        "executable",
        "pe",
        "peexe",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--ee72123d-81a8-5589-804a-70639149e319",
      "timestamp": "2026-10-10T00:00:19Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "222401568c7043c46f7a64f6f42855830a1a5e42d3c2fdbc5f81f861a87ef59c",
        "md5": "4dc43da56a470f251b89b048b8c003ce",
        "sha1": "aa8aeaa664dce87d8c5fafa6f8960bad89b10969",
        "sha256": "222401568c7043c46f7a64f6f42855830a1a5e42d3c2fdbc5f81f861a87ef59c",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/222401568c7043c46f7a64f6f42855830a1a5e42d3c2fdbc5f81f861a87ef59c"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "low",
        "risk_score": 5
      },
      "validity": {
        "first_seen": "2026-05-28T05:09:19Z",
        "last_seen": "2026-07-09T20:44:14Z"
      },
      "tags": [
        "exe",
        "executable",
        "overlay",
        "pe",
        "peexe",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--91479254-69f1-539c-9d9b-873a4f524e4e",
      "timestamp": "2026-10-10T00:00:19Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "26c89dfba18850733b287fc7e3787ea71c0b76c7ef338aeefd80d929cc1aa52f",
        "md5": "fd4cd5e710810fc5397e73a8b8b58c4b",
        "sha1": "0a80c784bd445445a930976aa8a3f687c529b2d9",
        "sha256": "26c89dfba18850733b287fc7e3787ea71c0b76c7ef338aeefd80d929cc1aa52f",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/26c89dfba18850733b287fc7e3787ea71c0b76c7ef338aeefd80d929cc1aa52f"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "low",
        "risk_score": 5
      },
      "validity": {
        "first_seen": "2026-05-26T18:57:57Z",
        "last_seen": "2026-07-12T00:48:53Z"
      },
      "tags": [
        "64bits",
        "dll",
        "executable",
        "pe",
        "pedll",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--e261f0dc-509a-5426-9914-2239976031d5",
      "timestamp": "2026-10-10T00:00:19Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "35a62af17ce9fe313fc9bce186d8f566ee86a3bfc5946144fb09b6eab31c8605",
        "md5": "bb9a4064ed48805e8a57a7f4a5f2f359",
        "sha1": "55b2b965eb940933b246096c954e3e3afba4dbb3",
        "sha256": "35a62af17ce9fe313fc9bce186d8f566ee86a3bfc5946144fb09b6eab31c8605",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/35a62af17ce9fe313fc9bce186d8f566ee86a3bfc5946144fb09b6eab31c8605"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "high",
        "risk_score": 16
      },
      "validity": {
        "first_seen": "2026-05-29T08:07:15Z",
        "last_seen": "2026-07-11T21:00:06Z"
      },
      "tags": [
        "64bits",
        "dll",
        "executable",
        "pe",
        "pedll",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--4d5ac377-fe80-538b-ac01-1c19b13aad2c",
      "timestamp": "2026-10-10T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "c6f2723443dc5dafe31bbe9618233811e5ebe2a4e92735d6c0703bfb091d159a",
        "md5": "578e2de58fa030e39135f198008276b8",
        "sha1": "8943dfd9a25dd5ccef13ce7e6135f164c11c444b",
        "sha256": "c6f2723443dc5dafe31bbe9618233811e5ebe2a4e92735d6c0703bfb091d159a",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/c6f2723443dc5dafe31bbe9618233811e5ebe2a4e92735d6c0703bfb091d159a"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 98,
        "severity": "high",
        "risk_score": 79,
        "family": "powershell"
      },
      "validity": {
        "first_seen": "2026-10-09T07:21:24Z",
        "last_seen": "2026-10-10T00:00:19Z"
      },
      "tags": [
        "downloader",
        "jsceal",
        "powershell",
        "ps",
        "ps1",
        "psagent",
        "source",
        "trojan",
        "url-pattern"
      ]
    },
    {
      "id": "event--54467ccb-4f77-59f6-b5a6-fa5656ed53ce",
      "timestamp": "2026-10-10T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "49f6f35fd285da4f9c7739c2f85853aa2f310c78be3b9971c316775f6e071168",
        "md5": "a21d1a42977864e34e5f71a5a698492c",
        "sha1": "30ea1b849b5223f77a11dafde54045cdedf0503a",
        "sha256": "49f6f35fd285da4f9c7739c2f85853aa2f310c78be3b9971c316775f6e071168",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/49f6f35fd285da4f9c7739c2f85853aa2f310c78be3b9971c316775f6e071168"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 0,
        "severity": "low",
        "risk_score": 5
      },
      "validity": {
        "first_seen": "2026-05-28T13:32:50Z",
        "last_seen": "2026-07-10T16:26:54Z"
      },
      "tags": [
        "64bits",
        "dll",
        "executable",
        "pe",
        "pedll",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--f0f2f7ac-0464-5074-bf30-d84dc6313a78",
      "timestamp": "2026-10-10T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "c587cd4a6abc4e1dec2207bd87100e6b7742e289eb64a7d204d64a8a2939d383",
        "md5": "5b6ced3ed08877e20feff46e59c6aa77",
        "sha1": "96d7c7079685dfd072991a50d0cc51ab77f36e83",
        "sha256": "c587cd4a6abc4e1dec2207bd87100e6b7742e289eb64a7d204d64a8a2939d383",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/c587cd4a6abc4e1dec2207bd87100e6b7742e289eb64a7d204d64a8a2939d383"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cyzt"
      },
      "validity": {
        "first_seen": "2026-10-09T19:04:56Z",
        "last_seen": "2026-10-10T00:00:17Z"
      },
      "tags": [
        "corewarrior",
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "flooder",
        "hacktool",
        "overlay",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--de4be65b-ecb4-561a-9380-8fecf9ca3562",
      "timestamp": "2026-10-10T00:00:20Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "3845d4327da5813213f5e17b58dc7fa970a9a680e04a67e251b19434516fd6cb",
        "md5": "5bb9a2a65c4117293833a3f632a158a8",
        "sha1": "bb96deec28e89003ec87e3756a0f4bcaea15aa45",
        "sha256": "3845d4327da5813213f5e17b58dc7fa970a9a680e04a67e251b19434516fd6cb",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/3845d4327da5813213f5e17b58dc7fa970a9a680e04a67e251b19434516fd6cb"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "genericfca"
      },
      "validity": {
        "first_seen": "2026-10-08T21:05:38Z",
        "last_seen": "2026-10-10T00:00:18Z"
      },
      "tags": [
        "64bits",
        "exe",
        "executable",
        "genericfca",
        "miner",
        "overlay",
        "pe",
        "peexe",
        "pua",
        "r002c0pa326",
        "trojan",
        "unwantedx",
        "win32",
        "windows",
        "xmrig"
      ]
    },
    {
      "id": "event--5c3f1bde-e215-5096-817f-f954a761b1a8",
      "timestamp": "2026-10-10T00:00:21Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "9f4918d92d8250c923f87376c96c35727e8160162decb4b993eeea4f59c59455",
        "md5": "5a6d826f38e89f394707ef46d63684c4",
        "sha1": "4ad82d4c42478a8d52a8ded1b5d026bc99c8f3c3",
        "sha256": "9f4918d92d8250c923f87376c96c35727e8160162decb4b993eeea4f59c59455",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/9f4918d92d8250c923f87376c96c35727e8160162decb4b993eeea4f59c59455"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "critical",
        "risk_score": 100,
        "family": "socks"
      },
      "validity": {
        "first_seen": "2026-10-08T14:24:20Z",
        "last_seen": "2026-10-10T00:00:17Z"
      },
      "tags": [
        "bbvx",
        "checks-usb-bus",
        "detect-debug-environment",
        "exe",
        "executable",
        "long-sleeps",
        "overlay",
        "pe",
        "peexe",
        "persistence",
        "ransomware",
        "socks",
        "stealer",
        "trojan",
        "upx",
        "win32",
        "windows",
        "worm"
      ]
    },
    {
      "id": "event--18909d9c-1010-57fa-888c-88bd86f676dd",
      "timestamp": "2026-10-10T00:00:21Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "f1330c532a24c2ff9cde3ea4ae9f8a3c8d2788a8672cccabb6aa1fbb575d9cbc",
        "md5": "5c96fabd666126ad91b8841857444240",
        "sha1": "57e1bce9f342e03a40cce2df0a9a12fad29d1855",
        "sha256": "f1330c532a24c2ff9cde3ea4ae9f8a3c8d2788a8672cccabb6aa1fbb575d9cbc",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/f1330c532a24c2ff9cde3ea4ae9f8a3c8d2788a8672cccabb6aa1fbb575d9cbc"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "lazy"
      },
      "validity": {
        "first_seen": "2026-10-08T00:21:12Z",
        "last_seen": "2026-10-10T00:00:20Z"
      },
      "tags": [
        "64bits",
        "banker",
        "clipbanker",
        "dll",
        "executable",
        "lazy",
        "misc",
        "pe",
        "pedll",
        "trojan",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--6814e9fe-3824-5f68-ac74-10fbe9a29125",
      "timestamp": "2026-10-10T00:00:22Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "d63b9ba616dde047c33200ce78f4ccceea21ba715d4781e12b87e1c6db4ca2f4",
        "md5": "5c40f82ce9a35895e42677c68966d98e",
        "sha1": "f0c836de17e7224d87878208fac3914728cbb879",
        "sha256": "d63b9ba616dde047c33200ce78f4ccceea21ba715d4781e12b87e1c6db4ca2f4",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/d63b9ba616dde047c33200ce78f4ccceea21ba715d4781e12b87e1c6db4ca2f4"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cyzt"
      },
      "validity": {
        "first_seen": "2026-10-08T18:25:13Z",
        "last_seen": "2026-10-10T00:00:18Z"
      },
      "tags": [
        "corewarrior",
        "cyzt",
        "downloader",
        "exe",
        "executable",
        "flooder",
        "hacktool",
        "loader",
        "overlay",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    },
    {
      "id": "event--aa8300c1-b37a-5ea9-9de8-194eadb8a3cd",
      "timestamp": "2026-10-10T00:00:22Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "2c2d4a57e9d8fa0051a83af68c0b4d26e9fa1727da3a4d8a54e82a6626cf3116",
        "md5": "5d3bcd0b1190f30f7eeb38992bd4aa62",
        "sha1": "4e8c6fa1fa93e498f0f1c33cb3bc6b54cbcaa69b",
        "sha256": "2c2d4a57e9d8fa0051a83af68c0b4d26e9fa1727da3a4d8a54e82a6626cf3116",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/2c2d4a57e9d8fa0051a83af68c0b4d26e9fa1727da3a4d8a54e82a6626cf3116"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "obfscred"
      },
      "validity": {
        "first_seen": "2026-10-08T19:51:19Z",
        "last_seen": "2026-10-10T00:00:21Z"
      },
      "tags": [
        "gen3",
        "javascript",
        "js",
        "obfscred",
        "phishing",
        "redir",
        "source",
        "trojan"
      ]
    },
    {
      "id": "event--774d4b99-e3cc-5fde-98fa-c1f1b5b01130",
      "timestamp": "2026-10-10T00:00:22Z",
      "action": "upsert",
      "indicator": {
        "type": "file",
        "value": "d3c3757ecc6a725ec41d0e84197f22221e9a1cc8015b594d0ed02c114065a5ea",
        "md5": "352a140a8d76bf72a9172d2c4eddae6b",
        "sha1": "d636e732d953c2dba3cbb028ed84552710388289",
        "sha256": "d3c3757ecc6a725ec41d0e84197f22221e9a1cc8015b594d0ed02c114065a5ea",
        "links": {
          "self": "https://api.virussign.com/v1/ioc/files/d3c3757ecc6a725ec41d0e84197f22221e9a1cc8015b594d0ed02c114065a5ea"
        }
      },
      "analysis": {
        "malicious": true,
        "confidence": 100,
        "severity": "high",
        "risk_score": 80,
        "family": "cyzt"
      },
      "validity": {
        "first_seen": "2026-10-08T20:16:31Z",
        "last_seen": "2026-10-10T00:00:20Z"
      },
      "tags": [
        "corewarrior",
        "cyzt",
        "detect-debug-environment",
        "downloader",
        "exe",
        "executable",
        "flooder",
        "hacktool",
        "long-sleeps",
        "overlay",
        "pe",
        "peexe",
        "snojan",
        "trojan",
        "upx",
        "win32",
        "windows"
      ]
    }
  ]
}