{"schema_version":"1.0","feed":"hash","observable_value":"000e1e7dcda8f1852266b6cdc499e7bdca5701e2e39d67b6c8438bd4d1e01619","normalized_value":"000e1e7dcda8f1852266b6cdc499e7bdca5701e2e39d67b6c8438bd4d1e01619","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"828491a5-7510-4bad-99c7-7a87383cc84b","attribute_id":"37528842","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783100957","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["opendir","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["opendir","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"002bc08e9e4252f58e402d64fb46bb1d4ed3acf453bbd69d2a1f8888ed16616e","normalized_value":"002bc08e9e4252f58e402d64fb46bb1d4ed3acf453bbd69d2a1f8888ed16616e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ba0690bb-62fa-4889-a93a-8b685d731d02","attribute_id":"37523053","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783169628","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","geofenced","USA","superh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","USA","elf","geofenced","superh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"00466d76832193b3f8be186d00e48005b460d6895798a67bc1c21e4655cb2e62","normalized_value":"00466d76832193b3f8be186d00e48005b460d6895798a67bc1c21e4655cb2e62","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a8d73f25-3bff-4473-87cc-444b336a1c7c","attribute_id":"37749179","event_id":"60956","event_uuid":"36e03b09-a20c-4169-a875-b77a24ca82fd","event_info":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","event_date":"2023-03-14","attribute_timestamp":"1783685719","event_timestamp":"1783685737","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"event":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"all":["Ave Maria","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","Energy Sector ","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cyber espionage","infostealer","meterpreter","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","osint:source-type=\"blog-post\"","tlp:clear","warzonerat"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"015a389e5c97ec1e545978359e19c08050ce2b3d23c88557ec9f4a540a4c6c51","normalized_value":"015a389e5c97ec1e545978359e19c08050ce2b3d23c88557ec9f4a540a4c6c51","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"79d1bc1f-bc81-48e7-bfa3-bc95ba040bf4","attribute_id":"37528916","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:14.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["LALALA Stealer","misp-galaxy:malpedia=\"LALALA Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["LALALA Stealer","misp-galaxy:malpedia=\"LALALA Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"015a389e5c97ec1e545978359e19c08050ce2b3d23c88557ec9f4a540a4c6c51","normalized_value":"015a389e5c97ec1e545978359e19c08050ce2b3d23c88557ec9f4a540a4c6c51","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7acc4d82-7741-11f1-97fa-42010aa4000a","attribute_id":"37521464","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125854","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"LALALA Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"LALALA Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"01b1c767f62e48efeb86410fd014fed4295ccb084bfcd6d5b9197638b615a648","normalized_value":"01b1c767f62e48efeb86410fd014fed4295ccb084bfcd6d5b9197638b615a648","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"47720c81-a46f-4f26-82c6-1b520123b095","attribute_id":"37755332","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140495","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--18665dd7-998e-50bd-bfce-211dc1c757d5","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--18665dd7-998e-50bd-bfce-211dc1c757d5","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"01ccc662c4b5d6ff79ede2e5dd7e508c7e2029fcc13e988e22345b0e5413ed01","normalized_value":"01ccc662c4b5d6ff79ede2e5dd7e508c7e2029fcc13e988e22345b0e5413ed01","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"362a0ecd-3dd1-430b-b93c-aa7943e2f932","attribute_id":"37771803","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0275c6cf588a7e26e97cbd3a8d301370ebeb18470e86b21d295c8d93ca778d86","normalized_value":"0275c6cf588a7e26e97cbd3a8d301370ebeb18470e86b21d295c8d93ca778d86","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3859ee9e-b952-486f-bf89-2a78013c1189","attribute_id":"37528948","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:04.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["MaskGramStealer","misp-galaxy:malpedia=\"MaskGramStealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["MaskGramStealer","misp-galaxy:malpedia=\"MaskGramStealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0275c6cf588a7e26e97cbd3a8d301370ebeb18470e86b21d295c8d93ca778d86","normalized_value":"0275c6cf588a7e26e97cbd3a8d301370ebeb18470e86b21d295c8d93ca778d86","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"74fb564c-7741-11f1-97fa-42010aa4000a","attribute_id":"37521469","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125844","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"MaskGramStealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"MaskGramStealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"02ad94b00edc5004f98494aab82c0dda80eb68339a4fc999e38142f54ec29e3f","normalized_value":"02ad94b00edc5004f98494aab82c0dda80eb68339a4fc999e38142f54ec29e3f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7cbb89b1-1fec-497b-b2ab-c3b87f7755b9","attribute_id":"37528806","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783088142","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["js","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["js","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"02cb34da6e620d9428f9c8f375fe96a397464d272f723abd8296c4b420fb0e77","normalized_value":"02cb34da6e620d9428f9c8f375fe96a397464d272f723abd8296c4b420fb0e77","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3ad1614f-6a4d-4715-9a01-42be614bba52","attribute_id":"7386013","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581359","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"02d6ca25b2057f181af96d2837486b26231eaa496defdf39785b5222014ef209","normalized_value":"02d6ca25b2057f181af96d2837486b26231eaa496defdf39785b5222014ef209","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d1b84363-0b99-4a56-8624-aeaa92d198fc","attribute_id":"34370373","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581099","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0350de7cdac919529ec58d085ae1eb7ece2bafba425593fbcedb7826a84ee713","normalized_value":"0350de7cdac919529ec58d085ae1eb7ece2bafba425593fbcedb7826a84ee713","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1fef6718-7be5-4e87-b5c4-c44b34f30eb8","attribute_id":"37524595","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:16.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"03643c2de44d47baf485ac13ef19ccd5fa57872b0b54fcc51e92bb1da102dd83","normalized_value":"03643c2de44d47baf485ac13ef19ccd5fa57872b0b54fcc51e92bb1da102dd83","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c7f57531-5967-4449-8e20-77ad877b976f","attribute_id":"37528649","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783081336","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["zip","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT","zip"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"039fc34ace1012eff687f864369540b9085b167f0d66023f3b94f280a7fdf8b7","normalized_value":"039fc34ace1012eff687f864369540b9085b167f0d66023f3b94f280a7fdf8b7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"aaa7cb15-130a-494d-a895-37f6af0e72b1","attribute_id":"34370367","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581093","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"03fb4001144fb24d6a64758f6ab009920437b136a83c9be4d843b4b472adea65","normalized_value":"03fb4001144fb24d6a64758f6ab009920437b136a83c9be4d843b4b472adea65","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bb24d11a-fa3c-42b5-a5d7-555295eba78f","attribute_id":"37528541","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783063033","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"04f6fc49da69838f5b511d8f996dc409a53249099bd71b3c897b98ad97fd867c","normalized_value":"04f6fc49da69838f5b511d8f996dc409a53249099bd71b3c897b98ad97fd867c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"57cfa2c0-7b9a-4792-a11a-ff30af38ad97","attribute_id":"35288799","event_id":"54513","event_uuid":"386236f1-29ba-47df-b4e6-e0fe458cd285","event_info":"APT41 Resurfaces as Earth Baku With New Cyberespionage Campaign","event_date":"2021-08-25","attribute_timestamp":"1783512372","event_timestamp":"1784392734","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Axiom\"","misp-galaxy:mitre-intrusion-set=\"APT41 - G0096\"","misp-galaxy:threat-actor=\"APT41\"","APT","Threat Actor","threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","ncsc-nl-ndn:feed=\"generic\"","retention:1m","tlp:clear"],"event":["misp-galaxy:threat-actor=\"Axiom\"","misp-galaxy:mitre-intrusion-set=\"APT41 - G0096\"","misp-galaxy:threat-actor=\"APT41\"","APT","Threat Actor","threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","ncsc-nl-ndn:feed=\"generic\"","retention:1m","tlp:clear"],"all":["APT","Threat Actor","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-intrusion-set=\"APT41 - G0096\"","misp-galaxy:threat-actor=\"APT41\"","misp-galaxy:threat-actor=\"Axiom\"","ncsc-nl-ndn:feed=\"generic\"","retention:1m","threat-report","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"APT41 Resurfaces as Earth Baku With New Cyberespionage Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0681c37cfbb640a08028c3ba49e92dc82268f8ad2aa865b86efafc834ade3682","normalized_value":"0681c37cfbb640a08028c3ba49e92dc82268f8ad2aa865b86efafc834ade3682","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"60120dcb-fdec-4952-a857-d1beaac59e71","attribute_id":"7385982","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581385","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"069ea4a8e2610887e04490828fd088b0b3dad36ac475f6bdd477806d73e9c1d1","normalized_value":"069ea4a8e2610887e04490828fd088b0b3dad36ac475f6bdd477806d73e9c1d1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0d638671-fa23-47c9-ab3d-3ce2d1c44873","attribute_id":"37523317","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783134673","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (ConnectWise)","event_extends_uuid":"","tags":{"attribute":["ConnectWise","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ConnectWise","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (ConnectWise)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"06f713969cd8362d547ae4abe2af01a2182e2983b26a910b248abfe999506d4c","normalized_value":"06f713969cd8362d547ae4abe2af01a2182e2983b26a910b248abfe999506d4c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8bc83c4d-5797-4346-bac7-8c77e673faf6","attribute_id":"37523167","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126686","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"073d9dd98a9ca3cd03901c31ba57811a1632e316923022640670ce00622cd8a9","normalized_value":"073d9dd98a9ca3cd03901c31ba57811a1632e316923022640670ce00622cd8a9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cc280dfb-56b5-41ab-a164-79edcb73eac9","attribute_id":"37755331","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140494","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--28e3c6a1-0237-5bbe-b968-bc3591fd3ac3","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--28e3c6a1-0237-5bbe-b968-bc3591fd3ac3","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"079c13fbc30a32e4f0386cd53c56d68404961b8f1cd4d4fde1a1e9def42aa557","normalized_value":"079c13fbc30a32e4f0386cd53c56d68404961b8f1cd4d4fde1a1e9def42aa557","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ace19a0f-b209-48e0-8c38-e0abc4d9adfb","attribute_id":"7386210","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581202","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"08510ddd7019a2fb09d4893c35ddbb3356cd8ce3fe6e43fa68f9f13e95287d46","normalized_value":"08510ddd7019a2fb09d4893c35ddbb3356cd8ce3fe6e43fa68f9f13e95287d46","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"65fef6fa-9fb9-49da-b7fd-31110af66c22","attribute_id":"37523475","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"08510ddd7019a2fb09d4893c35ddbb3356cd8ce3fe6e43fa68f9f13e95287d46","normalized_value":"08510ddd7019a2fb09d4893c35ddbb3356cd8ce3fe6e43fa68f9f13e95287d46","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f6b5c10a-4668-45b6-8037-c03ee806f1aa","attribute_id":"37524478","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:56.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"08be0ddd6e5d000404d4c5f27b7a1acf98c12ac4e4e715ae750f4d80f8e830e5","normalized_value":"08be0ddd6e5d000404d4c5f27b7a1acf98c12ac4e4e715ae750f4d80f8e830e5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"551b4db3-e510-4390-946c-a8693436f551","attribute_id":"37523391","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146554","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"08be0ddd6e5d000404d4c5f27b7a1acf98c12ac4e4e715ae750f4d80f8e830e5","normalized_value":"08be0ddd6e5d000404d4c5f27b7a1acf98c12ac4e4e715ae750f4d80f8e830e5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f5be0a68-10f4-43d6-a8c1-52b1bcd0ba1b","attribute_id":"37524447","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:08.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"08c1c7abd448c1bf6bb4339a437992cd6fe945a60ebaf5bbe28f0ee3c57704b6","normalized_value":"08c1c7abd448c1bf6bb4339a437992cd6fe945a60ebaf5bbe28f0ee3c57704b6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2c3d03ef-4d72-4ff0-bd05-5c51c4c95187","attribute_id":"37532479","event_id":"58606","event_uuid":"f34db162-ecc4-440c-aa50-ccb53f0693f4","event_info":"PhantomStealer in .rar email attachment (SMTP exfil)","event_date":"2026-07-03","attribute_timestamp":"1783056977","event_timestamp":"1784166491","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"MORS_142","orgc_uuid":"11e8cd1e-4a8a-44d7-bbd3-d05f03867b7e","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["MALWARE","keylogger/infostealer","Keylogger"," Keylogger","infostealer","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","tlp:clear"," Malware"," infostealer","  Malware  ","phantom stealer","malware_name:PHANTOM STEALER","obfuscated-js"],"event":["MALWARE","keylogger/infostealer","Keylogger"," Keylogger","infostealer","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","tlp:clear"," Malware"," infostealer","  Malware  ","phantom stealer","malware_name:PHANTOM STEALER","obfuscated-js"],"all":["  Malware  "," Keylogger"," Malware"," infostealer","Keylogger","MALWARE","infostealer","keylogger/infostealer","malware_name:PHANTOM STEALER","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","obfuscated-js","phantom stealer","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"PhantomStealer in .rar email attachment (SMTP exfil)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"094c4eb7f5480fb893aa6bb24d40b1b36534c0c85ea5e3f8c485146c45328ad6","normalized_value":"094c4eb7f5480fb893aa6bb24d40b1b36534c0c85ea5e3f8c485146c45328ad6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3e9a678f-f677-4a17-a60c-1da7d8c1f663","attribute_id":"37529257","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:07.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"094c4eb7f5480fb893aa6bb24d40b1b36534c0c85ea5e3f8c485146c45328ad6","normalized_value":"094c4eb7f5480fb893aa6bb24d40b1b36534c0c85ea5e3f8c485146c45328ad6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"63fdd9e0-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521475","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176067","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Venus Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Venus Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"094c4eb7f5480fb893aa6bb24d40b1b36534c0c85ea5e3f8c485146c45328ad6","normalized_value":"094c4eb7f5480fb893aa6bb24d40b1b36534c0c85ea5e3f8c485146c45328ad6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e754ba97-3d47-4fb7-9b1f-3d1701b27079","attribute_id":"37523634","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147092","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (RemusStealer)","event_extends_uuid":"","tags":{"attribute":["RemusStealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["RemusStealer","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (RemusStealer)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0952f2aacbeb3477b2465dfe3bac85d7906e958f866478cdbffec9be8cdb01c9","normalized_value":"0952f2aacbeb3477b2465dfe3bac85d7906e958f866478cdbffec9be8cdb01c9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"21c2e7b9-db2e-4885-bfeb-918634a6a731","attribute_id":"37771804","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1","normalized_value":"09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"95e2e5cc-e56b-46a2-a872-97359d800b3c","attribute_id":"37755431","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140553","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--39286a8e-bf33-50ed-838b-0bf500ea9141","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--39286a8e-bf33-50ed-838b-0bf500ea9141","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0a0353fddca1ba1432b35411a8ce2536c9b35aad25d0819296748e13423c813b","normalized_value":"0a0353fddca1ba1432b35411a8ce2536c9b35aad25d0819296748e13423c813b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1cadbe6d-485e-4b0a-a5b4-e6e57871572f","attribute_id":"37771805","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0a1668c576fd5deb8bccc13cff8bd07cb238a68fdc5735aa12dd78b23ad0652d","normalized_value":"0a1668c576fd5deb8bccc13cff8bd07cb238a68fdc5735aa12dd78b23ad0652d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7f5a265e-b8b1-4166-bb97-32277d2c5dbb","attribute_id":"37751344","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783622540","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_09-07-2026_Phishing_SVG","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_09-07-2026_Phishing_SVG","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0a5d4b8f65eba399f0b41ac648d939650ab6422ce4c715f8a1b5b99e1178678b","normalized_value":"0a5d4b8f65eba399f0b41ac648d939650ab6422ce4c715f8a1b5b99e1178678b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fbe9e61d-4201-449c-8b1f-e6276c165435","attribute_id":"37523119","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783123693","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["opendir","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["opendir","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0acf39d174c796867aa70908c48a0bd9bf1753d888c380a03ce9e0aaf9c09c50","normalized_value":"0acf39d174c796867aa70908c48a0bd9bf1753d888c380a03ce9e0aaf9c09c50","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b619260a-fe35-4efa-9824-2490a535cbf8","attribute_id":"37523742","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783170331","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","censys","ClickFix","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ClickFix","censys","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0afd99c3f7593c760c4001313963f3e7fd709ca56046044033d790602a8cb378","normalized_value":"0afd99c3f7593c760c4001313963f3e7fd709ca56046044033d790602a8cb378","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6473e099-ac7f-4bb3-ace5-f70efbaff799","attribute_id":"7386066","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581324","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0b0bf190c3d68ead801da7152302540fa34f2ca5d81c8263dd2da0b3faf0bdc4","normalized_value":"0b0bf190c3d68ead801da7152302540fa34f2ca5d81c8263dd2da0b3faf0bdc4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6034d648-7ca5-4c70-bb35-a2ab2f697531","attribute_id":"37528286","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783037533","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0b43c5ff8e48ee940c18f117c4187e42aad1be80453ab0c028f0d475c7a1feed","normalized_value":"0b43c5ff8e48ee940c18f117c4187e42aad1be80453ab0c028f0d475c7a1feed","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ff1e8d3e-3b44-4ba7-8ed5-693e498df742","attribute_id":"37751350","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1784063798","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_14-07-2026_Phishing_SVG","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_14-07-2026_Phishing_SVG","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0c422e9fc527cc1d97a81606a42a6bea2c83295552ec3ebd49adcb41e50650c8","normalized_value":"0c422e9fc527cc1d97a81606a42a6bea2c83295552ec3ebd49adcb41e50650c8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d52a3233-1de1-48f9-b64b-04befcd31cac","attribute_id":"37524539","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:36.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0c4ad7ea7fd1d24186efc73657dd5feed3f7c7243089e4d9eae0b1f63abeb69d","normalized_value":"0c4ad7ea7fd1d24186efc73657dd5feed3f7c7243089e4d9eae0b1f63abeb69d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ea321b73-2a6d-422f-bae3-1df225b0ef67","attribute_id":"37523510","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146561","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0c4ad7ea7fd1d24186efc73657dd5feed3f7c7243089e4d9eae0b1f63abeb69d","normalized_value":"0c4ad7ea7fd1d24186efc73657dd5feed3f7c7243089e4d9eae0b1f63abeb69d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"eeb94dea-65f7-42c0-b65b-02d65a5705b4","attribute_id":"37524430","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:13.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0d0ccfe7cd476e2e2498b854cef2e6f959df817e52924b3a8bcdae7a8faaa686","normalized_value":"0d0ccfe7cd476e2e2498b854cef2e6f959df817e52924b3a8bcdae7a8faaa686","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"32fc8cc9-5939-4c99-bfed-5d0ccca18dda","attribute_id":"6724968","event_id":"26690","event_uuid":"4678ed95-1726-4820-87ba-36a935367aa4","event_info":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","event_date":"2020-08-04","attribute_timestamp":"1783581146","event_timestamp":"1783581153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"event":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"all":[" Remote Access Trojan","APT","Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:threat-actor=\"China APT\"","osint:source-type=\"technical-report\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0d0ccfe7cd476e2e2498b854cef2e6f959df817e52924b3a8bcdae7a8faaa686","normalized_value":"0d0ccfe7cd476e2e2498b854cef2e6f959df817e52924b3a8bcdae7a8faaa686","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"538f2b3d-62dc-470c-8a90-7b20572523fd","attribute_id":"6724987","event_id":"26690","event_uuid":"4678ed95-1726-4820-87ba-36a935367aa4","event_info":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","event_date":"2020-08-04","attribute_timestamp":"1783581153","event_timestamp":"1783581153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"event":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"all":[" Remote Access Trojan","APT","Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:threat-actor=\"China APT\"","osint:source-type=\"technical-report\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0d0ed90929351c08c47dbd7541073d037240718c4a2fd63c09d2377090d4cd7a","normalized_value":"0d0ed90929351c08c47dbd7541073d037240718c4a2fd63c09d2377090d4cd7a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"188e0f17-d5ac-4a67-acc0-a3a741a33fe1","attribute_id":"7385991","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581380","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0d4b32562cedf52b5add1a8755e28cccc3b2b5f00d19e85e1fd2950b86e646c0","normalized_value":"0d4b32562cedf52b5add1a8755e28cccc3b2b5f00d19e85e1fd2950b86e646c0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f0a0d7fd-7eaf-41a4-9439-975a7e041022","attribute_id":"37528352","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783042015","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0d7ee7ce88e790ad66aa53589f5a2638207bc3adf2eb4f8a813fd52b5b22ba27","normalized_value":"0d7ee7ce88e790ad66aa53589f5a2638207bc3adf2eb4f8a813fd52b5b22ba27","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ec113940-e50b-4273-b589-e4f810f7bf0f","attribute_id":"7386051","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581333","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0d8ce4ac8e61edcfbb200f354a262f879abc40c114ea238eb77f2e0349cee42a","normalized_value":"0d8ce4ac8e61edcfbb200f354a262f879abc40c114ea238eb77f2e0349cee42a","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"47e7418a-b78a-401c-8521-764fe4848aaf","attribute_id":"37529554","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101983","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0d97f33b586a7d3194af3ee17708fb0406ae2e44babcff5c992cf46191f662e6","normalized_value":"0d97f33b586a7d3194af3ee17708fb0406ae2e44babcff5c992cf46191f662e6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c65efa05-7321-4721-88e1-d46fcaa14414","attribute_id":"37528559","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783064100","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0def7dd8ebcc861d03142a1ef526d92eda15719f2c16733e4282fabdfbd22e14","normalized_value":"0def7dd8ebcc861d03142a1ef526d92eda15719f2c16733e4282fabdfbd22e14","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a0a24873-0566-4bac-8978-ba79387fdb11","attribute_id":"37528571","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783064186","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","m68k","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","m68k","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0dfcf4d5f66310de87c2e422d7804e66279fe3e3cd6a27723225aecf214e9b00","normalized_value":"0dfcf4d5f66310de87c2e422d7804e66279fe3e3cd6a27723225aecf214e9b00","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7669cb05-41fc-454e-80b9-98ade23042e9","attribute_id":"35015661","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558038","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Hades Ransomware\r\nSHA256","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Hades Ransomware\r\nSHA256","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0ecc6893276663a9210cdaeb4940d409e1ee6d0f2b5c21a3341247df4c371d89","normalized_value":"0ecc6893276663a9210cdaeb4940d409e1ee6d0f2b5c21a3341247df4c371d89","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"e950a40a-7f79-45da-a4f9-2430f4a6c351","attribute_id":"37529546","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101794","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","stone:malware-categorization=\"Stealer\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Stealer\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0ef3119504f8aa3a534bfdbe20ed88727deabdf4e8f6e3e31298a34eef768662","normalized_value":"0ef3119504f8aa3a534bfdbe20ed88727deabdf4e8f6e3e31298a34eef768662","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"aa0d0440-d75d-4b1d-8269-ef463d104c9f","attribute_id":"37771810","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0f1bcecd61092de0735dba542259b31c6566a1df62069a0a3287a0a12dcfa4f2","normalized_value":"0f1bcecd61092de0735dba542259b31c6566a1df62069a0a3287a0a12dcfa4f2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"157cf797-3182-4990-9fc2-9e208b23df88","attribute_id":"37524453","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:06.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0f1bcecd61092de0735dba542259b31c6566a1df62069a0a3287a0a12dcfa4f2","normalized_value":"0f1bcecd61092de0735dba542259b31c6566a1df62069a0a3287a0a12dcfa4f2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fe69a18d-ca9c-4685-961b-97e56217ab82","attribute_id":"37523545","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146562","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0f617eb8f229029f0573121d11986242c04875fed4795fbea20f135c8bf8b170","normalized_value":"0f617eb8f229029f0573121d11986242c04875fed4795fbea20f135c8bf8b170","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3155ff21-621d-441d-9bff-0683e7603833","attribute_id":"34891771","event_id":"54097","event_uuid":"3dd38b8c-5338-4ec6-98a1-084f56a8680c","event_info":"Malware Analysis Report (AR21-102A) MAR-10331466-1.v1: China Chopper Webshell","event_date":"2021-03-26","attribute_timestamp":"1783743718","event_timestamp":"1783743718","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["tlp:white","misp-galaxy:mitre-malware=\"China Chopper - S0020\"","misp-galaxy:tool=\"China Chopper\"","misp-galaxy:threat-actor=\"Hafnium\"","threat-report"],"event":["tlp:white","misp-galaxy:mitre-malware=\"China Chopper - S0020\"","misp-galaxy:tool=\"China Chopper\"","misp-galaxy:threat-actor=\"Hafnium\"","threat-report"],"all":["misp-galaxy:mitre-malware=\"China Chopper - S0020\"","misp-galaxy:threat-actor=\"Hafnium\"","misp-galaxy:tool=\"China Chopper\"","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware Analysis Report (AR21-102A) MAR-10331466-1.v1: China Chopper Webshell","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fc","normalized_value":"0f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fc","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"702e90f8-bbf2-43dc-83ca-60513829c217","attribute_id":"37755164","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140406","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--51adc7e4-e493-5d4a-81ce-fc721415ebe2","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--51adc7e4-e493-5d4a-81ce-fc721415ebe2","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fc","normalized_value":"0f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fc","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"da1a3770-c3f5-4735-b0e4-11b11e4f97e7","attribute_id":"37752343","event_id":"61005","event_uuid":"efee3167-4868-4f50-b35b-565a4abec419","event_info":"Campaign Targeting Government of thailand via Hermes AI Agent & Hades","event_date":"2026-07-16","attribute_timestamp":"1784906643","event_timestamp":"1784907374","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"VShell Linux Stage 1 Payload","event_extends_uuid":"","tags":{"attribute":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"event":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"all":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"VShell Linux Stage 1 Payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141","normalized_value":"0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7a87b610-df42-4ab5-96e6-0019501188cc","attribute_id":"37752428","event_id":"61009","event_uuid":"d942d9c8-237d-455a-9940-6429c473cff1","event_info":"New Stealthy Ransomware Deployed Against Asian IT Company","event_date":"2026-07-27","attribute_timestamp":"1785124152","event_timestamp":"1785124153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"event":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"all":[" Ransomware","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"New Stealthy Ransomware Deployed Against Asian IT Company","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"0fb32dc1d635993ca59dbb513610c7ea0386d8ee8ca3fc7659aa62bf306ce801","normalized_value":"0fb32dc1d635993ca59dbb513610c7ea0386d8ee8ca3fc7659aa62bf306ce801","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e7a62ddf-1873-4b1b-bc55-4413a38eceac","attribute_id":"37523311","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783134671","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (ConnectWise)","event_extends_uuid":"","tags":{"attribute":["ConnectWise","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ConnectWise","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (ConnectWise)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"103f6414452ab0352953778d6478096710a619645c5bf5d274552ed5c478ccdb","normalized_value":"103f6414452ab0352953778d6478096710a619645c5bf5d274552ed5c478ccdb","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bbc8ae9d-e98a-486c-91bd-9295e0977efe","attribute_id":"37524592","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:17.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1066003052bf79de8ab4f07bb7ff3dc980a8622b9175ef714a6df5dd01d517b7","normalized_value":"1066003052bf79de8ab4f07bb7ff3dc980a8622b9175ef714a6df5dd01d517b7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a4846a44-85fd-4bb1-9e22-eb3591d92a82","attribute_id":"37523755","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783170875","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (QuasarRAT)","event_extends_uuid":"","tags":{"attribute":["QuasarRAT","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["QuasarRAT","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (QuasarRAT)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1095cf2951bbc8b1ecd33798afad192449a102aa1b976fb60bf566a08d693587","normalized_value":"1095cf2951bbc8b1ecd33798afad192449a102aa1b976fb60bf566a08d693587","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8e50feb2-988e-4df0-8511-3c012aa117dc","attribute_id":"37524561","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:28.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"10ddbbae0070267b8d15888b09a3cdb19fa74d861315b71f21c9ace8b9f85c75","normalized_value":"10ddbbae0070267b8d15888b09a3cdb19fa74d861315b71f21c9ace8b9f85c75","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"88fc866e-614e-430f-a9dc-ddd0c4f0ab30","attribute_id":"37752220","event_id":"60993","event_uuid":"297956e5-c56a-4239-b35f-693d8c117afd","event_info":"148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet","event_date":"2026-07-22","attribute_timestamp":"1784703380","event_timestamp":"1784703385","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","Cybercrime","tlp:clear","proxy","Create-By\"Methanon\""],"event":["NCSA","NCSA_Research","Cybercrime","tlp:clear","proxy","Create-By\"Methanon\""],"all":["Create-By\"Methanon\"","Cybercrime","NCSA","NCSA_Research","proxy","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"10ddbbae0070267b8d15888b09a3cdb19fa74d861315b71f21c9ace8b9f85c75","normalized_value":"10ddbbae0070267b8d15888b09a3cdb19fa74d861315b71f21c9ace8b9f85c75","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cf41f78e-3fd5-4c1e-af4e-ff1ad2d76493","attribute_id":"37755106","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112063","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--4e63b039-a096-5047-ade5-a00e6a74844d","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--4e63b039-a096-5047-ade5-a00e6a74844d","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"122797288af9166cb10192292e0edf66abe21704010b5f93389a96860a614780","normalized_value":"122797288af9166cb10192292e0edf66abe21704010b5f93389a96860a614780","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"95f09565-9513-44df-8ba1-423282d10e37","attribute_id":"37528358","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783042761","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"12717add64ecf32d7bcb6b2662becbff6b516cf8073f399dc5e4d3615d452e89","normalized_value":"12717add64ecf32d7bcb6b2662becbff6b516cf8073f399dc5e4d3615d452e89","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a1714871-da11-4a64-9300-ddf40d6acd2e","attribute_id":"7385997","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581376","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1355d2d73a1f21b4fa4e1b97432015052c004a0ca20a0b72d47011940fd51c6a","normalized_value":"1355d2d73a1f21b4fa4e1b97432015052c004a0ca20a0b72d47011940fd51c6a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"80e50086-a44b-4470-8f4d-a004319ee3ee","attribute_id":"37771811","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"144cc3e02b7ef259abcb2d6eaf5f4f770630ad2c75dcfa48437df3b17f5094bf","normalized_value":"144cc3e02b7ef259abcb2d6eaf5f4f770630ad2c75dcfa48437df3b17f5094bf","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"699d298c-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521522","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176076","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WannaCryptor payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WannaCryptor payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"144cc3e02b7ef259abcb2d6eaf5f4f770630ad2c75dcfa48437df3b17f5094bf","normalized_value":"144cc3e02b7ef259abcb2d6eaf5f4f770630ad2c75dcfa48437df3b17f5094bf","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e8c1eafa-9245-4e76-b35f-8dfc0294cbec","attribute_id":"37529272","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:16.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"146c62f408b6d7db4c832a6b5f7bdacb1cff2c69121b9b2f7e80646c37910abd","normalized_value":"146c62f408b6d7db4c832a6b5f7bdacb1cff2c69121b9b2f7e80646c37910abd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9652a2fe-55fb-4bcb-9df4-ed0c3d940872","attribute_id":"37752333","event_id":"61004","event_uuid":"f55757e1-7aef-484b-9552-2ca3b6b7d0d8","event_info":"Banking Rewards Malware Campaign","event_date":"2026-07-24","attribute_timestamp":"1784881857","event_timestamp":"1784881991","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"event":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"all":[" trojan","BANKING TROJAN","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Banking Rewards Malware Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"15a3a92a7585b62519405c2f2a87664408ff333db7b2be8e05961b9729696fe0","normalized_value":"15a3a92a7585b62519405c2f2a87664408ff333db7b2be8e05961b9729696fe0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"38c15ad3-348c-4284-93f5-645c0e567d2a","attribute_id":"37523185","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783127734","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Emotet","doc","heodo","epoch3","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Emotet","doc","epoch3","heodo","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"162ae350c47c2e14864d0c0f927bf424eb6b844017329c9b1e216f3e2d724d98","normalized_value":"162ae350c47c2e14864d0c0f927bf424eb6b844017329c9b1e216f3e2d724d98","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3e19a258-8934-4c28-a92e-881983b4d7e7","attribute_id":"7386056","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581327","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"167bf2356e65b04407cd2d8299a9b315f213808b04c341f6aad5820fc46a3c49","normalized_value":"167bf2356e65b04407cd2d8299a9b315f213808b04c341f6aad5820fc46a3c49","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"91f8e03e-b454-4d74-9388-08041065fbe3","attribute_id":"7386042","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581340","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"16d67fa1f9e77c465e62a6a37f0c5bd54b8385215a5f40b1e5644dd3d84e0dad","normalized_value":"16d67fa1f9e77c465e62a6a37f0c5bd54b8385215a5f40b1e5644dd3d84e0dad","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7395586e-1cdc-4518-9375-5eb5e4d98173","attribute_id":"37523517","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146561","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"16d67fa1f9e77c465e62a6a37f0c5bd54b8385215a5f40b1e5644dd3d84e0dad","normalized_value":"16d67fa1f9e77c465e62a6a37f0c5bd54b8385215a5f40b1e5644dd3d84e0dad","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b14173eb-d8de-4f26-891f-467f459e6592","attribute_id":"37524484","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:54.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"16e34d5b3836f196864a8efe804d8dcb5938801d29bed451a3b67dca6f7b0929","normalized_value":"16e34d5b3836f196864a8efe804d8dcb5938801d29bed451a3b67dca6f7b0929","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"77493b59-7741-11f1-97fa-42010aa4000a","attribute_id":"37521569","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125848","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"SalatStealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SalatStealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"16e34d5b3836f196864a8efe804d8dcb5938801d29bed451a3b67dca6f7b0929","normalized_value":"16e34d5b3836f196864a8efe804d8dcb5938801d29bed451a3b67dca6f7b0929","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"86c5c5eb-50cc-4a21-9cf3-21365162fa1e","attribute_id":"37528935","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:08.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["SalatStealer","misp-galaxy:malpedia=\"SalatStealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["SalatStealer","misp-galaxy:malpedia=\"SalatStealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"17634632167d6942e821ee3dfa36f564ae1be7bcfcb2fb15c967a5db0369051b","normalized_value":"17634632167d6942e821ee3dfa36f564ae1be7bcfcb2fb15c967a5db0369051b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ab001975-97c2-4ea7-900f-c3814ea6987a","attribute_id":"37528746","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783083280","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"17997e9e0256d0f5d5d21a4852c37f16b338e4bb9c2bec09bdfd822b24aa76b4","normalized_value":"17997e9e0256d0f5d5d21a4852c37f16b338e4bb9c2bec09bdfd822b24aa76b4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1781010a-c039-440d-bbd0-86b1ee39c716","attribute_id":"37752160","event_id":"60989","event_uuid":"1856b358-880a-4c9c-acef-c8ce8bae7d01","event_info":"Threat Actor Uses Malicious PyPI Dependencies to Deliver ChocoPoC RAT Through GitHub PoCs","event_date":"2026-07-20","attribute_timestamp":"1784529523","event_timestamp":"1784529532","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","RAT","tlp:clear"],"event":["NCSA","NCSA_Research","RAT","tlp:clear"],"all":["NCSA","NCSA_Research","RAT","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Uses Malicious PyPI Dependencies to Deliver ChocoPoC RAT Through GitHub PoCs","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4","normalized_value":"17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8af65a1b-42f4-4707-a372-74bb56c0ca5a","attribute_id":"37755423","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140548","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--8fa017e3-52ba-58d4-8768-b50488c072ff","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--8fa017e3-52ba-58d4-8768-b50488c072ff","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"18db6fbabcf73332eb9bb392f7ae0cc3381f3528983587e17b7ceba8dc37e9f6","normalized_value":"18db6fbabcf73332eb9bb392f7ae0cc3381f3528983587e17b7ceba8dc37e9f6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"25c60fcf-21f9-4a32-941f-fa456dc40831","attribute_id":"37771806","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4e","normalized_value":"18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"54acde78-955b-4787-a4aa-62a21aadc185","attribute_id":"37752156","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"19ac18a50abb48dc0ea9524850acfaec49359e6b3bcc67c6193c2d56da812c71","normalized_value":"19ac18a50abb48dc0ea9524850acfaec49359e6b3bcc67c6193c2d56da812c71","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e89a2d03-3431-4c40-b52f-054c17652f50","attribute_id":"37752151","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1a4b2bb9352969a3913db57f776dbaa48b03dfb96ce3addfa346e92687b8cf20","normalized_value":"1a4b2bb9352969a3913db57f776dbaa48b03dfb96ce3addfa346e92687b8cf20","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5f75a5ce-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521585","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176059","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Ghost RAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Ghost RAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1a4b2bb9352969a3913db57f776dbaa48b03dfb96ce3addfa346e92687b8cf20","normalized_value":"1a4b2bb9352969a3913db57f776dbaa48b03dfb96ce3addfa346e92687b8cf20","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"61b0bc80-6e0f-4e2d-97c3-24b26d061bcb","attribute_id":"37529278","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:40:59.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Ghost RAT\"","Ghost Rat","misp-galaxy:malpedia=\"ANGRYREBEL\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Ghost Rat","misp-galaxy:malpedia=\"ANGRYREBEL\"","misp-galaxy:malpedia=\"Ghost RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1aa4445c35c8bfb52304fcd252451843ff671d115c9e75a123043dc79ae9cdc6","normalized_value":"1aa4445c35c8bfb52304fcd252451843ff671d115c9e75a123043dc79ae9cdc6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2ee3bfa3-eb30-4cfa-9a40-3996912ed7d3","attribute_id":"37529280","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:27.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1aa4445c35c8bfb52304fcd252451843ff671d115c9e75a123043dc79ae9cdc6","normalized_value":"1aa4445c35c8bfb52304fcd252451843ff671d115c9e75a123043dc79ae9cdc6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"70559495-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521586","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176087","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1b4875536467c7fdd5fafb5852dcc61c1f03f55a706d4a97dec56e33b7b47763","normalized_value":"1b4875536467c7fdd5fafb5852dcc61c1f03f55a706d4a97dec56e33b7b47763","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"50191b6d-fc2b-4cfd-9040-49e1fd44b562","attribute_id":"7386045","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581341","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1b68b78ec310e5043964aefd6b72c217b29b79ba8e372a939994b9264b2a4d31","normalized_value":"1b68b78ec310e5043964aefd6b72c217b29b79ba8e372a939994b9264b2a4d31","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ab28e31e-1989-4765-9794-7e4d80ba3324","attribute_id":"37528492","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783060470","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1b6aa2797915b79607c9580fc702ad34cd8acdeada2e0a7f2151e0bf3f20ff10","normalized_value":"1b6aa2797915b79607c9580fc702ad34cd8acdeada2e0a7f2151e0bf3f20ff10","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"39e6c9af-431f-47cb-9d27-2ea1526fb16e","attribute_id":"37523275","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783131409","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","censys","ClickFix","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ClickFix","censys","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591","normalized_value":"1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e9ff88d9-7aef-4148-8c02-db0b5e73d761","attribute_id":"37025673","event_id":"56910","event_uuid":"53be7197-1af5-4a19-96c3-a7c48ab0af68","event_info":"HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine","event_date":"2022-02-24","attribute_timestamp":"1783792821","event_timestamp":"1783792825","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSC-NL","orgc_uuid":"5697b0c4-9474-4336-b675-28140a950b0b","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"Merged from event 50051","event_extends_uuid":"","tags":{"attribute":["ncsc-nl-ndn:feed=\"selected\"","tlp:white","HermeticWiper","misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Create or Modify System Process - T1543\"","misp-galaxy:mitre-attack-pattern=\"Disk Wipe - T1561\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Shutdown/Reboot - T1529\"","misp-galaxy:target-information=\"Ukraine\"","misp-galaxy:sector=\"Government, Administration\""],"event":["ncsc-nl-ndn:feed=\"selected\"","tlp:white","HermeticWiper","misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Create or Modify System Process - T1543\"","misp-galaxy:mitre-attack-pattern=\"Disk Wipe - T1561\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Shutdown/Reboot - T1529\"","misp-galaxy:target-information=\"Ukraine\"","misp-galaxy:sector=\"Government, Administration\""],"all":["HermeticWiper","misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"Create or Modify System Process - T1543\"","misp-galaxy:mitre-attack-pattern=\"Disk Wipe - T1561\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Shutdown/Reboot - T1529\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:target-information=\"Ukraine\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Merged from event 50051","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bb","normalized_value":"1cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bb","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7ed4a2c4-f8f4-4ce3-bc25-ed9f302032d2","attribute_id":"37755197","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140425","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--74a12cfe-e85b-562c-9019-ea391a9168f2","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--74a12cfe-e85b-562c-9019-ea391a9168f2","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1ce5558cc258c2882174c3bba8de331ade2a393592d7bf90c3855131be550e72","normalized_value":"1ce5558cc258c2882174c3bba8de331ade2a393592d7bf90c3855131be550e72","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"68384565-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521590","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176074","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Krasue RAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Krasue RAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1ce5558cc258c2882174c3bba8de331ade2a393592d7bf90c3855131be550e72","normalized_value":"1ce5558cc258c2882174c3bba8de331ade2a393592d7bf90c3855131be550e72","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7ea048c0-2c3f-45fc-8a88-5a8a8f83d485","attribute_id":"37529284","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:14.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Krasue RAT","misp-galaxy:malpedia=\"Krasue RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Krasue RAT","misp-galaxy:malpedia=\"Krasue RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1ce5558cc258c2882174c3bba8de331ade2a393592d7bf90c3855131be550e72","normalized_value":"1ce5558cc258c2882174c3bba8de331ade2a393592d7bf90c3855131be550e72","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9230c9f6-a4b4-4bde-b740-fb0a5c1f1b90","attribute_id":"37523640","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147092","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (LxBaseRAT)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (LxBaseRAT)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1cf6d946c45f4ce73a0f97cdbc136c9eef7723292bc3b6c9a9ecc8f90386f6d2","normalized_value":"1cf6d946c45f4ce73a0f97cdbc136c9eef7723292bc3b6c9a9ecc8f90386f6d2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6112ac5e-7e3c-42ef-8add-517599cd0d27","attribute_id":"37746859","event_id":"60935","event_uuid":"ca70216a-9c9c-4533-b568-d69b639b093b","event_info":"CACTUS: Analyzing a Coordinated Ransomware Attack on Corporate Networks","event_date":"2024-03-06","attribute_timestamp":"1783839818","event_timestamp":"1783839834","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"MalwareBazaar: Source: https://github.com/TheRavenFile/Daily-Hunt/blob/main/Cactus%20Ransomware","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\""," Ransomware","OSINT","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Browser Bookmark Discovery - T1217\"","misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Resource Hijacking - T1496\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"File Permissions Modification - T1222\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","osint:source-type=\"blog-post\"","tlp:clear","Bitdefender SRL","Cactus Ransomware","misp-galaxy:financial-fraud=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Remote Access Software - T1219\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"","misp-galaxy:mitre-attack-pattern=\"Pass the Hash - T1550.002\"","misp-galaxy:mitre-attack-pattern=\"Linux and Mac File and Directory Permissions Modification - T1222.002\"","misp-galaxy:mitre-attack-pattern=\"Protocol Tunneling - T1572\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","misp-galaxy:mitre-attack-pattern=\"Group Policy Modification - T1484.001\"","misp-galaxy:mitre-attack-pattern=\"Malware - T1587.001\"","misp-galaxy:mitre-attack-pattern=\"Local Accounts - T1078.003\"","misp-galaxy:mitre-attack-pattern=\"Financial Theft - T1657\"","misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"","misp-galaxy:mitre-attack-pattern=\"Unsecured Credentials - T1552\"","misp-galaxy:mitre-attack-pattern=\"Use Alternate Authentication Material - T1550\"","misp-galaxy:mitre-attack-pattern=\"Domain Policy Modification - T1484\"","misp-galaxy:mitre-attack-pattern=\"Develop Capabilities - T1587\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white","Ransomware"],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\""," Ransomware","OSINT","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Browser Bookmark Discovery - T1217\"","misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Resource Hijacking - T1496\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"File Permissions Modification - T1222\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","osint:source-type=\"blog-post\"","tlp:clear","Bitdefender SRL","Cactus Ransomware","misp-galaxy:financial-fraud=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Remote Access Software - T1219\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"","misp-galaxy:mitre-attack-pattern=\"Pass the Hash - T1550.002\"","misp-galaxy:mitre-attack-pattern=\"Linux and Mac File and Directory Permissions Modification - T1222.002\"","misp-galaxy:mitre-attack-pattern=\"Protocol Tunneling - T1572\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","misp-galaxy:mitre-attack-pattern=\"Group Policy Modification - T1484.001\"","misp-galaxy:mitre-attack-pattern=\"Malware - T1587.001\"","misp-galaxy:mitre-attack-pattern=\"Local Accounts - T1078.003\"","misp-galaxy:mitre-attack-pattern=\"Financial Theft - T1657\"","misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"","misp-galaxy:mitre-attack-pattern=\"Unsecured Credentials - T1552\"","misp-galaxy:mitre-attack-pattern=\"Use Alternate Authentication Material - T1550\"","misp-galaxy:mitre-attack-pattern=\"Domain Policy Modification - T1484\"","misp-galaxy:mitre-attack-pattern=\"Develop Capabilities - T1587\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white","Ransomware"],"all":[" Ransomware","Bitdefender SRL","Cactus Ransomware","OSINT","Ransomware","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","misp-galaxy:financial-fraud=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Browser Bookmark Discovery - T1217\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Develop Capabilities - T1587\"","misp-galaxy:mitre-attack-pattern=\"Domain Policy Modification - T1484\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"File Permissions Modification - T1222\"","misp-galaxy:mitre-attack-pattern=\"Financial Theft - T1657\"","misp-galaxy:mitre-attack-pattern=\"Group Policy Modification - T1484.001\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"","misp-galaxy:mitre-attack-pattern=\"Linux and Mac File and Directory Permissions Modification - T1222.002\"","misp-galaxy:mitre-attack-pattern=\"Local Accounts - T1078.003\"","misp-galaxy:mitre-attack-pattern=\"Malware - T1587.001\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Pass the Hash - T1550.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"","misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"","misp-galaxy:mitre-attack-pattern=\"Protocol Tunneling - T1572\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Remote Access Software - T1219\"","misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"Resource Hijacking - T1496\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Unsecured Credentials - T1552\"","misp-galaxy:mitre-attack-pattern=\"Use Alternate Authentication Material - T1550\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","ncsc-nl-ndn:feed=\"selected\"","osint:source-type=\"blog-post\"","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"MalwareBazaar: Source: https://github.com/TheRavenFile/Daily-Hunt/blob/main/Cactus%20Ransomware","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1d3699b153b816e2e9129ecc2b5f7dcbe40d5aeee08bfa655d5f01b808d01906","normalized_value":"1d3699b153b816e2e9129ecc2b5f7dcbe40d5aeee08bfa655d5f01b808d01906","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7624fb15-adf7-4cd7-b8dc-3231ba3b2b77","attribute_id":"37524551","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:32.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1d5ee8e6b6daa36ca0b4c6e8bb59d58df94a3cae81bd1010be07adf401fcdc78","normalized_value":"1d5ee8e6b6daa36ca0b4c6e8bb59d58df94a3cae81bd1010be07adf401fcdc78","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"2b08ac56-b520-41e0-9ac1-b3f04c4cb734","attribute_id":"37529542","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101610","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","stone:malware-categorization=\"Stealer\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Stealer\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1dc12c6a44852023f1687f9f31a9e58dc7ce96d492a58a3e87dec5aa8f45ba92","normalized_value":"1dc12c6a44852023f1687f9f31a9e58dc7ce96d492a58a3e87dec5aa8f45ba92","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3c7f20fd-c5da-4560-aff5-3344f780e286","attribute_id":"34370328","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581056","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1df4f9e1438085e4aa7dfd5c5fb293aaa6bfec99cdbd371ba00d177c3c4c4c42","normalized_value":"1df4f9e1438085e4aa7dfd5c5fb293aaa6bfec99cdbd371ba00d177c3c4c4c42","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d3f411b4-aa8e-4a6f-9c7e-5817aa6159b8","attribute_id":"37528818","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783088886","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1e7243b3f2b7ed15f022de756fbea855e3b43bca6e1792c9f756951b0e07e108","normalized_value":"1e7243b3f2b7ed15f022de756fbea855e3b43bca6e1792c9f756951b0e07e108","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"93aec598-eefa-495a-894f-ff5195fef0bc","attribute_id":"37528692","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082546","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1e77992666acbbfa0d01fcefa9cc8fbdac291e0681b35745be27c6dfb159a375","normalized_value":"1e77992666acbbfa0d01fcefa9cc8fbdac291e0681b35745be27c6dfb159a375","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bebf44bf-06b5-4c63-bc42-124b1ba44c3b","attribute_id":"37752148","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1e99972b1d84b131eb55a6b49f64871c5c0c6a1bb2a099a84313001b69dc53e8","normalized_value":"1e99972b1d84b131eb55a6b49f64871c5c0c6a1bb2a099a84313001b69dc53e8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"44744cd4-c4d4-433e-be23-d099314d999a","attribute_id":"37752329","event_id":"61004","event_uuid":"f55757e1-7aef-484b-9552-2ca3b6b7d0d8","event_info":"Banking Rewards Malware Campaign","event_date":"2026-07-24","attribute_timestamp":"1784881856","event_timestamp":"1784881991","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"event":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"all":[" trojan","BANKING TROJAN","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Banking Rewards Malware Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1ef7533a8b189dce105a718e9c2ad1d54763cefa988daee311777bf779c2ec83","normalized_value":"1ef7533a8b189dce105a718e9c2ad1d54763cefa988daee311777bf779c2ec83","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d0d4815d-7d55-4147-962a-4a167f2c8e67","attribute_id":"37528698","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082546","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1f0f08699f74eb2fb690edd064cba4f2fad06761f67d0bbb585e5cd03c77ea17","normalized_value":"1f0f08699f74eb2fb690edd064cba4f2fad06761f67d0bbb585e5cd03c77ea17","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7041cb7f-3a0d-42ab-81fb-2ff623635b4b","attribute_id":"37771816","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483192","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1fb0b008bc63f128227ddaaa8bc77542c0caa198825f9c514c15cec26f1660f4","normalized_value":"1fb0b008bc63f128227ddaaa8bc77542c0caa198825f9c514c15cec26f1660f4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"38f62af9-76bb-11f1-97fa-42010aa4000a","attribute_id":"37525654","event_id":"58560","event_uuid":"e27e5e09-1e7e-4f06-b6fc-877936100793","event_info":"ThreatFox IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783070485","event_timestamp":"1783123388","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Unknown malware payload (confidence level: 100%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Unknown malware payload (confidence level: 100%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1fb0b008bc63f128227ddaaa8bc77542c0caa198825f9c514c15cec26f1660f4","normalized_value":"1fb0b008bc63f128227ddaaa8bc77542c0caa198825f9c514c15cec26f1660f4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e4e476c1-deeb-4251-9d5c-4a65133373c8","attribute_id":"37525233","event_id":"58554","event_uuid":"8401661b-ef5c-4bb5-ab44-36b18d1d67f3","event_info":"Daily Incremental ThreatFox Import - 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783071176","event_timestamp":"1784390379","first_seen":"2026-07-03T07:21:25.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n100\nhttps://tria.ge/260703-kh4h7sdy8s","event_extends_uuid":"","tags":{"attribute":["Unknown malware","HadesStealer","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["HadesStealer","Unknown malware","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n100\nhttps://tria.ge/260703-kh4h7sdy8s","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"1fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664","normalized_value":"1fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a21a9aa9-234c-466e-8106-5a87ada276e9","attribute_id":"37755196","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140425","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--505f68af-fed7-5a87-a280-715a644b0f5d","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--505f68af-fed7-5a87-a280-715a644b0f5d","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"203bf8a13a8ff01f2dc85d0ca78d47d7263d520fbe7f6626b769c26740e29ca4","normalized_value":"203bf8a13a8ff01f2dc85d0ca78d47d7263d520fbe7f6626b769c26740e29ca4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"54e48f88-95de-4555-ae4a-566476b7b0b2","attribute_id":"37751351","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1784063798","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_14-07-2026_Phishing_SVG","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_14-07-2026_Phishing_SVG","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2067fcc97df4f0b345e1b9d283270c3257abdf21b6da0eac20df9363ffb378a9","normalized_value":"2067fcc97df4f0b345e1b9d283270c3257abdf21b6da0eac20df9363ffb378a9","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"cab88cd0-c8b4-4057-9666-6aa0e47c0f88","attribute_id":"37529605","event_id":"58567","event_uuid":"ae1c645a-f761-4e34-b072-4eacf2062a93","event_info":"Formbook host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101917","event_timestamp":"1783215209","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","stone:malware-categorization=\"Stealer\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Stealer\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"206fdbe992b44ebd6720c49c79a5da3bdcb48d0d799a0ff3458323caac3cc490","normalized_value":"206fdbe992b44ebd6720c49c79a5da3bdcb48d0d799a0ff3458323caac3cc490","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c8b84866-585f-4c5f-81b4-3c7ac5b10d27","attribute_id":"37752328","event_id":"61004","event_uuid":"f55757e1-7aef-484b-9552-2ca3b6b7d0d8","event_info":"Banking Rewards Malware Campaign","event_date":"2026-07-24","attribute_timestamp":"1784881856","event_timestamp":"1784881991","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"event":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"all":[" trojan","BANKING TROJAN","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Banking Rewards Malware Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"20d47fa34fb6c5841bbebea4796b7b9fcc3f6920ef9d3be0530978f0cbc6e4d7","normalized_value":"20d47fa34fb6c5841bbebea4796b7b9fcc3f6920ef9d3be0530978f0cbc6e4d7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"668537f1-afda-4c44-ba14-aa17cc1484f0","attribute_id":"37523330","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783145947","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"20d47fa34fb6c5841bbebea4796b7b9fcc3f6920ef9d3be0530978f0cbc6e4d7","normalized_value":"20d47fa34fb6c5841bbebea4796b7b9fcc3f6920ef9d3be0530978f0cbc6e4d7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6d1b5ea9-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521609","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176082","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"20d47fa34fb6c5841bbebea4796b7b9fcc3f6920ef9d3be0530978f0cbc6e4d7","normalized_value":"20d47fa34fb6c5841bbebea4796b7b9fcc3f6920ef9d3be0530978f0cbc6e4d7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"da6cd72c-ea2d-460e-9bb1-30cd6088bdf0","attribute_id":"37529293","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:22.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"21b24f7ee1f6bdbbb670f0394d66009ee0daa8ced57048298da715e88f7a7cdd","normalized_value":"21b24f7ee1f6bdbbb670f0394d66009ee0daa8ced57048298da715e88f7a7cdd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"73824c76-52a9-4100-a499-dfb86c0717d8","attribute_id":"37752153","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"22302cf76c98f4f9162d39018746c9616ac176138889f3cabaa952807148c7db","normalized_value":"22302cf76c98f4f9162d39018746c9616ac176138889f3cabaa952807148c7db","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fdd01f79-5601-46ce-b184-9626f7b4f836","attribute_id":"37528631","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783067149","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"22a5872ba6adfe449e46d9a223cb7567697e30f89d6d42095e48de3033359de3","normalized_value":"22a5872ba6adfe449e46d9a223cb7567697e30f89d6d42095e48de3033359de3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7222b4bc-f04f-4e48-847a-4285d7903a11","attribute_id":"7386033","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581346","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2470d537fbf8c0aa85309e03f95cf244475a5317d7f0a5d7d00583bcaba20dad","normalized_value":"2470d537fbf8c0aa85309e03f95cf244475a5317d7f0a5d7d00583bcaba20dad","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9749a146-5f6c-4757-a9cb-fee893eb374d","attribute_id":"37528595","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783065096","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"247402d2a3bec3e8590798efa1adaae98fde12c194939e1ed4f3d86867ac84a8","normalized_value":"247402d2a3bec3e8590798efa1adaae98fde12c194939e1ed4f3d86867ac84a8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"93989a56-15e4-488a-89ce-514070538b9f","attribute_id":"37524583","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:21.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"24a86b9e58a4369e6c58d9b8185881a0a67987465ae18af1b7bbc7577cce724e","normalized_value":"24a86b9e58a4369e6c58d9b8185881a0a67987465ae18af1b7bbc7577cce724e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"68fcfe20-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521620","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176075","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"24a86b9e58a4369e6c58d9b8185881a0a67987465ae18af1b7bbc7577cce724e","normalized_value":"24a86b9e58a4369e6c58d9b8185881a0a67987465ae18af1b7bbc7577cce724e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7666c76d-1173-47d6-87c4-bd35ecc8e4f1","attribute_id":"37523614","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147090","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"24a86b9e58a4369e6c58d9b8185881a0a67987465ae18af1b7bbc7577cce724e","normalized_value":"24a86b9e58a4369e6c58d9b8185881a0a67987465ae18af1b7bbc7577cce724e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a2f4a1cb-ab63-4395-b5e5-a7f89ae5fb9a","attribute_id":"37529297","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:15.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2599fc6c97a60c08520c557b1cc551cdd543293291e60c81dc010d6dcb8a8b03","normalized_value":"2599fc6c97a60c08520c557b1cc551cdd543293291e60c81dc010d6dcb8a8b03","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4dfea674-b838-4f1d-83b6-3f8f90e9d763","attribute_id":"37528887","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:24.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2599fc6c97a60c08520c557b1cc551cdd543293291e60c81dc010d6dcb8a8b03","normalized_value":"2599fc6c97a60c08520c557b1cc551cdd543293291e60c81dc010d6dcb8a8b03","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"812bc541-7741-11f1-97fa-42010aa4000a","attribute_id":"37521621","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125864","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Stealc payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Stealc payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"25b2e83c211a98b07222e3706365cbf5da043062146d5258a70ff2da9185e0da","normalized_value":"25b2e83c211a98b07222e3706365cbf5da043062146d5258a70ff2da9185e0da","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b0d137ad-e208-4eff-bd76-69dd0537ed5c","attribute_id":"37523209","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783128703","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","mips","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","mips","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"25c5ef94956a60ea6bb764f8abc82898906662207b59506b9647fd1c57bbb66b","normalized_value":"25c5ef94956a60ea6bb764f8abc82898906662207b59506b9647fd1c57bbb66b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1369909c-7486-474f-b633-1f1f3215c08a","attribute_id":"37771807","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2603246549cd0da58081690c184ebac031b17d034552019089eedcbbfdf1db3a","normalized_value":"2603246549cd0da58081690c184ebac031b17d034552019089eedcbbfdf1db3a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5af8ef4f-d30f-4bb7-9411-5780ecbb54b9","attribute_id":"37529299","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:01.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2603246549cd0da58081690c184ebac031b17d034552019089eedcbbfdf1db3a","normalized_value":"2603246549cd0da58081690c184ebac031b17d034552019089eedcbbfdf1db3a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"60b045d4-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521622","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176061","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"263f89416439f5e9d7c35621153981655eec33e46fb7f7eb70ad43357d0cfad6","normalized_value":"263f89416439f5e9d7c35621153981655eec33e46fb7f7eb70ad43357d0cfad6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ea0d999b-9f8e-447a-908d-a11b1ff0df59","attribute_id":"37523017","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783175104","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","elf","arm","geofenced","USA","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","USA","arm","elf","gafgyt","geofenced","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"267071df79927abd1e57f57106924dd8a68e1c4ed74e7b69403cdcdf6e6a453b","normalized_value":"267071df79927abd1e57f57106924dd8a68e1c4ed74e7b69403cdcdf6e6a453b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"686ad0b2-eee3-47d6-a4fe-2e30c4a81e2f","attribute_id":"37746516","event_id":"60929","event_uuid":"f6732da4-728c-4bb6-8eae-2b34f20b075e","event_info":"TinyTurla Next Generation - Turla APT spies on Polish NGOs","event_date":"2024-02-16","attribute_timestamp":"1783839748","event_timestamp":"1783839753","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"0","analysis":"initial","attribute_comment":"TinyTurla-NG (TTNG) backdoor hash.","event_extends_uuid":"","tags":{"attribute":["Backdoor","admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","Turla","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","Backdoor","Powershell","OSINT","osint:source-type=\"blog-post\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Indicator Removal from Tools - T1027.005\"","misp-galaxy:mitre-attack-pattern=\"Rundll32 - T1218.011\"","windows","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"","misp-galaxy:360net-threat-actor=\"Turla - APT-C-29\"","misp-galaxy:country=\"poland\"","misp-galaxy:malpedia=\"TinyTurla\"","misp-galaxy:mitre-malware=\"TinyTurla - S0668\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","Turla","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","Backdoor","Powershell","OSINT","osint:source-type=\"blog-post\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Indicator Removal from Tools - T1027.005\"","misp-galaxy:mitre-attack-pattern=\"Rundll32 - T1218.011\"","windows","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"","misp-galaxy:360net-threat-actor=\"Turla - APT-C-29\"","misp-galaxy:country=\"poland\"","misp-galaxy:malpedia=\"TinyTurla\"","misp-galaxy:mitre-malware=\"TinyTurla - S0668\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white"],"all":["Backdoor","OSINT","Powershell","Turla","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:360net-threat-actor=\"Turla - APT-C-29\"","misp-galaxy:country=\"poland\"","misp-galaxy:malpedia=\"TinyTurla\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Indicator Removal from Tools - T1027.005\"","misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"","misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"","misp-galaxy:mitre-attack-pattern=\"Rundll32 - T1218.011\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-malware=\"TinyTurla - S0668\"","ncsc-nl-ndn:feed=\"selected\"","osint:source-type=\"blog-post\"","tlp:clear","tlp:white","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"TinyTurla-NG (TTNG) backdoor hash.","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"26a6ff252736b60277dc4ef4a24e1068b9cfe3a02f646a76d4c442fc31e06309","normalized_value":"26a6ff252736b60277dc4ef4a24e1068b9cfe3a02f646a76d4c442fc31e06309","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3a6fd568-7392-424c-9b6b-9768aaa19dfd","attribute_id":"37751345","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783622541","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_09-07-2026_Phishing_SVG","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_09-07-2026_Phishing_SVG","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"26bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394a","normalized_value":"26bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"309992c8-2830-4075-94c6-5f8908f315bf","attribute_id":"37755195","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140424","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--8680d730-a3ec-5597-bffe-c9e2831e8e94","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--8680d730-a3ec-5597-bffe-c9e2831e8e94","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"26c54b1a0cb5d8636966e6f27505035b2521c7733ee8827b21a9a76f934665e7","normalized_value":"26c54b1a0cb5d8636966e6f27505035b2521c7733ee8827b21a9a76f934665e7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5eeff5c3-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521623","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176058","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"ValleyRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"ValleyRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"26c54b1a0cb5d8636966e6f27505035b2521c7733ee8827b21a9a76f934665e7","normalized_value":"26c54b1a0cb5d8636966e6f27505035b2521c7733ee8827b21a9a76f934665e7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9c002a40-1f3d-4856-afa2-4a94647e37c9","attribute_id":"37529300","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:40:58.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ValleyRAT","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","misp-galaxy:malpedia=\"ValleyRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ValleyRAT","misp-galaxy:malpedia=\"ValleyRAT\"","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"26dfa8512e892dc8397c4ccbbe10efbcf85029bc2ad7b6b6fe17d26f946a01bb","normalized_value":"26dfa8512e892dc8397c4ccbbe10efbcf85029bc2ad7b6b6fe17d26f946a01bb","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e3bbc026-51c5-4c41-8032-f0b73468fc76","attribute_id":"7386224","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581195","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"27319e75c23693399977e92b9a7ba5680a7a9db448f93b3221840c61301604d5","normalized_value":"27319e75c23693399977e92b9a7ba5680a7a9db448f93b3221840c61301604d5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"33867116-f857-4a10-bd04-517409cb18ac","attribute_id":"7386001","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581372","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"275035f44dc9cf992964e3954ba0af5d09e0df6b5c1009befaaeb21408cc0bba","normalized_value":"275035f44dc9cf992964e3954ba0af5d09e0df6b5c1009befaaeb21408cc0bba","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"73e7a69e-b9f8-46f2-9eb1-d29511bf0f09","attribute_id":"37528919","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:13.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"275035f44dc9cf992964e3954ba0af5d09e0df6b5c1009befaaeb21408cc0bba","normalized_value":"275035f44dc9cf992964e3954ba0af5d09e0df6b5c1009befaaeb21408cc0bba","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7a39a461-7741-11f1-97fa-42010aa4000a","attribute_id":"37521624","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125853","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Stealc payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Stealc payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2759a1bc0be90cca057cbf9a76cd4d7cb50a8c052e4d9896d2c69e7ae11adc8b","normalized_value":"2759a1bc0be90cca057cbf9a76cd4d7cb50a8c052e4d9896d2c69e7ae11adc8b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d610e702-4623-4615-9bb6-1d233f87e0e4","attribute_id":"37528304","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783039506","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"27d0189c10636921860c51dcb5f48dbae0ebcb5871713973b6a1b194e5a9b761","normalized_value":"27d0189c10636921860c51dcb5f48dbae0ebcb5871713973b6a1b194e5a9b761","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bf15b280-f369-4c9b-ba19-7d24b1a1dbb7","attribute_id":"37523011","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783169781","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","geofenced","USA","PowerPC","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","PowerPC","USA","elf","geofenced","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"27e3c9b676e96ef69a0043ebf547748ac7189207dc2100cc188ea024be596266","normalized_value":"27e3c9b676e96ef69a0043ebf547748ac7189207dc2100cc188ea024be596266","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"759c1e34-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521627","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176096","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"27e3c9b676e96ef69a0043ebf547748ac7189207dc2100cc188ea024be596266","normalized_value":"27e3c9b676e96ef69a0043ebf547748ac7189207dc2100cc188ea024be596266","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f7e29e4a-5153-4995-baeb-d01fab1c3d8c","attribute_id":"37529301","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:36.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"27ef8e01f2cc70843dfc973156abacf1f2abf601d3055476084ca8991a2f02c5","normalized_value":"27ef8e01f2cc70843dfc973156abacf1f2abf601d3055476084ca8991a2f02c5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1ca36664-10a9-4884-a5d0-d50b109304f3","attribute_id":"37528967","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:56.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ValleyRAT","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","misp-galaxy:malpedia=\"ValleyRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ValleyRAT","misp-galaxy:malpedia=\"ValleyRAT\"","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"27ef8e01f2cc70843dfc973156abacf1f2abf601d3055476084ca8991a2f02c5","normalized_value":"27ef8e01f2cc70843dfc973156abacf1f2abf601d3055476084ca8991a2f02c5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"70165e09-7741-11f1-97fa-42010aa4000a","attribute_id":"37521628","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125836","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"ValleyRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"ValleyRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"28484ae186b36505be08ca8d04e35b3662a63ffe9e74a929e62711ecdde5b95a","normalized_value":"28484ae186b36505be08ca8d04e35b3662a63ffe9e74a929e62711ecdde5b95a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"306fb9ba-bc8c-42af-b739-1fce056a7c2f","attribute_id":"37523627","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147090","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"28b6748f5efd251c5927c6ad092e3a0c9a0daa3d6b0fd3b5b353e56a551de93b","normalized_value":"28b6748f5efd251c5927c6ad092e3a0c9a0daa3d6b0fd3b5b353e56a551de93b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7fee235a-f6c4-43b7-929f-0b69e2894ee2","attribute_id":"37524589","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:18.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"290d70472f4b00a1cf01f5c1311aacffaa39057bb1c826c99419999ccef7ae53","normalized_value":"290d70472f4b00a1cf01f5c1311aacffaa39057bb1c826c99419999ccef7ae53","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"50e20b24-e24e-4fac-971d-a59a9e99dc2d","attribute_id":"34370370","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581096","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"295c135578f3c57850502104ed31a23147457984e3af4cedf7e285e4d9062a37","normalized_value":"295c135578f3c57850502104ed31a23147457984e3af4cedf7e285e4d9062a37","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1196147f-e212-4b8a-9f9d-41901a8bc1c5","attribute_id":"37528836","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783100957","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["opendir","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["opendir","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2961e6615f06a1bfddcab227c412e82cd0b3fd1d199f62aecfd1009d10f0ff72","normalized_value":"2961e6615f06a1bfddcab227c412e82cd0b3fd1d199f62aecfd1009d10f0ff72","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"10d70c12-c63a-4501-9c42-b461665cfe6b","attribute_id":"37751346","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783622541","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_09-07-2026_Phishing_SVG","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_09-07-2026_Phishing_SVG","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"29aef790399029029e0443455d72a8b928854a0706f2e211ae7a03bba0e3d4f4","normalized_value":"29aef790399029029e0443455d72a8b928854a0706f2e211ae7a03bba0e3d4f4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"098ef5f0-de2c-4142-bc42-9e1e9bdca26e","attribute_id":"7386052","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581331","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2a206b085fedf8b20d1db883814c15e0202617da223dbb4e28b7109df98645df","normalized_value":"2a206b085fedf8b20d1db883814c15e0202617da223dbb4e28b7109df98645df","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ea030d63-cba6-4c7d-979b-c18d1e7460e3","attribute_id":"37755315","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140485","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--7bdd6932-ded4-5173-b7df-5f91afe7fa6b","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--7bdd6932-ded4-5173-b7df-5f91afe7fa6b","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2a4cb412efa93fed7c3b3b3e49d6247b11a95ce9fddf71d9fe9db8e5f0068e0d","normalized_value":"2a4cb412efa93fed7c3b3b3e49d6247b11a95ce9fddf71d9fe9db8e5f0068e0d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5c0e9893-8952-4278-a11d-7a3b3447e24f","attribute_id":"37755163","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140406","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--985b4867-4669-5d6c-8ab7-6b3d3470d251","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--985b4867-4669-5d6c-8ab7-6b3d3470d251","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2a51dabd7c6c63d88ae13ca65a8a01c99fae1d4913a08ace28910c6f47074323","normalized_value":"2a51dabd7c6c63d88ae13ca65a8a01c99fae1d4913a08ace28910c6f47074323","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d7aefa0b-5d8c-4075-a4c5-1160a7757735","attribute_id":"37523155","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126201","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","mips","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","mips","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2a5c7af5106a2cbd6b0f5a96a3716b29271f0b476a3c21a7c9b59fdc7d5e561b","normalized_value":"2a5c7af5106a2cbd6b0f5a96a3716b29271f0b476a3c21a7c9b59fdc7d5e561b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e3c5e908-ea87-4e70-8fae-21c949efad4a","attribute_id":"37771808","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2b33b5185e93e1655eb27dbaa025d7ee088627db3d640fe4709be705646b189c","normalized_value":"2b33b5185e93e1655eb27dbaa025d7ee088627db3d640fe4709be705646b189c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1972a402-5e78-4ca0-a414-47ac655b751e","attribute_id":"37755117","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112070","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--c522a585-a5d1-5d20-a6d7-2a8ddc5ac16f","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--c522a585-a5d1-5d20-a6d7-2a8ddc5ac16f","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2b8a15c5d7e23a69b8052e1ec298c075324e8fa95ea06d191124326b848cb0ff","normalized_value":"2b8a15c5d7e23a69b8052e1ec298c075324e8fa95ea06d191124326b848cb0ff","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"768b580a-d02d-4af8-a382-7e9ae093d377","attribute_id":"37771809","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2c245db9fb9b2c6e84832662dda3dfff3c6b21128d9fec115f5b989fb090841d","normalized_value":"2c245db9fb9b2c6e84832662dda3dfff3c6b21128d9fec115f5b989fb090841d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"47c66cc7-9dd4-464d-ba54-dc00d821d858","attribute_id":"7385977","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581391","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2c3ec8df887b5d9f65017917554c23d41830be217e26757dcf45aaa0b96500f5","normalized_value":"2c3ec8df887b5d9f65017917554c23d41830be217e26757dcf45aaa0b96500f5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2a3f5f94-6ca4-4d1c-8daa-39adb95f22f2","attribute_id":"37523005","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147089","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["exe","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["exe","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2df999997d8533f13020269a70d366bd7226c2a48d7119f1f4354b6c4cf93031","normalized_value":"2df999997d8533f13020269a70d366bd7226c2a48d7119f1f4354b6c4cf93031","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"7e43539d-a115-4713-b83b-0a3f8d56c2a5","attribute_id":"37529649","event_id":"58570","event_uuid":"73b7ed82-0d87-402a-adfd-2462e0268878","event_info":"Remcos host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101671","event_timestamp":"1783215210","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:malware-categorization=\"Rat\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Rat\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2f23f605ee60821e4f9f370883162971efb7fe6a0ef5fb3d5389d29396e5a290","normalized_value":"2f23f605ee60821e4f9f370883162971efb7fe6a0ef5fb3d5389d29396e5a290","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3e51bcd5-7f27-47d8-91a6-01832a1d38a2","attribute_id":"37528328","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783041634","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2f4540de210f137cfc19c6e77b79c79d8121750964d1be0e11079e05a77a5925","normalized_value":"2f4540de210f137cfc19c6e77b79c79d8121750964d1be0e11079e05a77a5925","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e7a237f6-8c24-4571-a7c2-2957a4ffcb0e","attribute_id":"37528764","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783084788","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["zip","Vidar","stealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","stealer","tlp:white","type:OSINT","zip"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2f72550c99a297558235caa97d025054f70a276283998d9686c282612ebdbea0","normalized_value":"2f72550c99a297558235caa97d025054f70a276283998d9686c282612ebdbea0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"52e1d70d-1de9-4dfd-b30b-e7e1454b19b0","attribute_id":"35015691","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558051","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Custom CobaltStrike loader samples  SHA256 hashes","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Custom CobaltStrike loader samples  SHA256 hashes","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a","normalized_value":"2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0fa93ca5-eeb3-4043-a213-d61879e49ec6","attribute_id":"37755420","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140546","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--2603fc42-8b19-57ee-b10e-952566778b84","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--2603fc42-8b19-57ee-b10e-952566778b84","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"30aae5e7151e4dc8741c9b8b5170424499ae7f84ed453dd3c05136b3c2ee1a66","normalized_value":"30aae5e7151e4dc8741c9b8b5170424499ae7f84ed453dd3c05136b3c2ee1a66","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6426f4a1-45a2-43bd-88b0-efe7e6553184","attribute_id":"37565757","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783087432","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_03-07-2026 HTML_Smuggling","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_03-07-2026 HTML_Smuggling","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"316ac119eef39b921d33f69cde46351f2caafc7cae17fe4f2dcbd6a38284da0a","normalized_value":"316ac119eef39b921d33f69cde46351f2caafc7cae17fe4f2dcbd6a38284da0a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6bb9b5a0-9d2d-4a52-b002-7eea5d9f8ded","attribute_id":"37523447","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"31a276aae8a45873beecf4137bb27cd5a6dedde882a7b1e79f70ad0abeaa3ee1","normalized_value":"31a276aae8a45873beecf4137bb27cd5a6dedde882a7b1e79f70ad0abeaa3ee1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a33638ee-3643-4150-b98f-ec73a9668f1a","attribute_id":"37771812","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483191","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"31d293ffa5e55ff2df504ab951b785e902b335974826a9bfbcd4dfb29ab59068","normalized_value":"31d293ffa5e55ff2df504ab951b785e902b335974826a9bfbcd4dfb29ab59068","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6ddd0703-7741-11f1-97fa-42010aa4000a","attribute_id":"37521634","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125832","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Agent Tesla payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Agent Tesla payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"31d293ffa5e55ff2df504ab951b785e902b335974826a9bfbcd4dfb29ab59068","normalized_value":"31d293ffa5e55ff2df504ab951b785e902b335974826a9bfbcd4dfb29ab59068","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bb76acfd-da9d-4fe7-8ccb-0aadbd7518f6","attribute_id":"37528981","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:52.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Agent Tesla\"","Agent Tesla","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Agent Tesla","misp-galaxy:malpedia=\"Agent Tesla\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"31d293ffa5e55ff2df504ab951b785e902b335974826a9bfbcd4dfb29ab59068","normalized_value":"31d293ffa5e55ff2df504ab951b785e902b335974826a9bfbcd4dfb29ab59068","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"d37d3e2a-254a-4f00-9791-93709b6fe034","attribute_id":"37529581","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783102001","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"31da18115d031c335b2b4f2b2d3a1277ace95a139e7293e469ee2f55d084d3a3","normalized_value":"31da18115d031c335b2b4f2b2d3a1277ace95a139e7293e469ee2f55d084d3a3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"569667c4-4b7c-44d9-b5e1-4b821b38073a","attribute_id":"37523440","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"31da18115d031c335b2b4f2b2d3a1277ace95a139e7293e469ee2f55d084d3a3","normalized_value":"31da18115d031c335b2b4f2b2d3a1277ace95a139e7293e469ee2f55d084d3a3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9bde6ae2-4054-4efa-ba45-9f495ba9e49a","attribute_id":"37524490","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:52.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"320b29844892e3c59bc6fcb07e701b2b3230a37cb4a13176174e9e294ec6d43e","normalized_value":"320b29844892e3c59bc6fcb07e701b2b3230a37cb4a13176174e9e294ec6d43e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cd739c2d-6a48-4913-b93f-600226ed7e6b","attribute_id":"37752163","event_id":"60989","event_uuid":"1856b358-880a-4c9c-acef-c8ce8bae7d01","event_info":"Threat Actor Uses Malicious PyPI Dependencies to Deliver ChocoPoC RAT Through GitHub PoCs","event_date":"2026-07-20","attribute_timestamp":"1784529523","event_timestamp":"1784529532","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","RAT","tlp:clear"],"event":["NCSA","NCSA_Research","RAT","tlp:clear"],"all":["NCSA","NCSA_Research","RAT","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Uses Malicious PyPI Dependencies to Deliver ChocoPoC RAT Through GitHub PoCs","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3228da011423853efd3d94ce3a28046b5ca19e921861ea5aee2700bc90fc1d55","normalized_value":"3228da011423853efd3d94ce3a28046b5ca19e921861ea5aee2700bc90fc1d55","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b5889841-b17e-4969-803b-376f142e87a5","attribute_id":"37755506","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785351654","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--d11b84c6-096b-55d9-bc21-87bb13ae756d","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--d11b84c6-096b-55d9-bc21-87bb13ae756d","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3233333c0fcd64bc55bbf19ec34fd16c1a819f5e08ffa0f3c40850ca57ae861d","normalized_value":"3233333c0fcd64bc55bbf19ec34fd16c1a819f5e08ffa0f3c40850ca57ae861d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f287e071-55e7-4b92-af83-7e5d37ce2632","attribute_id":"37523600","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147089","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"32f962b039acdce9870921caca91f7f5920e54567d6d011cd0eed131f8f1840f","normalized_value":"32f962b039acdce9870921caca91f7f5920e54567d6d011cd0eed131f8f1840f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0c12874b-fde6-4674-885a-96609174aa32","attribute_id":"37523724","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783154840","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Emotet","doc","heodo","epoch3","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Emotet","doc","epoch3","heodo","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"334e740f01b9db15c709c92ca07b32d8a9ad1d68468d8c2796c93eb4da51a8b8","normalized_value":"334e740f01b9db15c709c92ca07b32d8a9ad1d68468d8c2796c93eb4da51a8b8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f3906f77-20d9-4e6c-bf27-b768f3943397","attribute_id":"37528529","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783062715","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","arm","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arm","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3368d7c3e01ae5c705b3461d99d39b7622333786503a651e09940d5ca3b7d191","normalized_value":"3368d7c3e01ae5c705b3461d99d39b7622333786503a651e09940d5ca3b7d191","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"765cdf8e-2e0e-4bd8-89a9-6fb522e35fdb","attribute_id":"37746613","event_id":"60932","event_uuid":"ae102ba0-f797-4201-b557-0fb163a9e03f","event_info":"Unmasking the Hidden Threat: Inside a Sophisticated Excel-Based Attack Delivering Fileless Remcos RAT","event_date":"2024-09-12","attribute_timestamp":"1783581629","event_timestamp":"1784392758","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Template Injection - T1221\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Third-party Software - T1072\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Execution through API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\""," Agent Tesla","FormBook","GuLoader","OSINT","Remcos","RevengeRAT","SnakeKeylogger","excel","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Technology\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Mshta - T1218.005\"","misp-galaxy:mitre-attack-pattern=\"Steganography - T1027.003\"","misp-galaxy:mitre-attack-pattern=\"Shortcut Modification - T1547.009\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities - T1127\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities Proxy Execution - T1127\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\""," RemcosRAT","FinFisher.Botnet","finspy","LatentBot","misp-galaxy:country=\"australia\"","misp-galaxy:country=\"belgium\"","misp-galaxy:country=\"canada\"","misp-galaxy:country=\"germany\"","misp-galaxy:country=\"japan\"","misp-galaxy:country=\"south korea\"","misp-galaxy:country=\"united states of america\"","Agent Tesla","RemcosRAT"],"event":["admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Template Injection - T1221\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Third-party Software - T1072\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Execution through API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\""," Agent Tesla","FormBook","GuLoader","OSINT","Remcos","RevengeRAT","SnakeKeylogger","excel","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Technology\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Mshta - T1218.005\"","misp-galaxy:mitre-attack-pattern=\"Steganography - T1027.003\"","misp-galaxy:mitre-attack-pattern=\"Shortcut Modification - T1547.009\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities - T1127\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities Proxy Execution - T1127\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\""," RemcosRAT","FinFisher.Botnet","finspy","LatentBot","misp-galaxy:country=\"australia\"","misp-galaxy:country=\"belgium\"","misp-galaxy:country=\"canada\"","misp-galaxy:country=\"germany\"","misp-galaxy:country=\"japan\"","misp-galaxy:country=\"south korea\"","misp-galaxy:country=\"united states of america\"","Agent Tesla","RemcosRAT"],"all":[" Agent Tesla"," RemcosRAT","Agent Tesla","FinFisher.Botnet","FormBook","GuLoader","LatentBot","OSINT","Remcos","RemcosRAT","RevengeRAT","SnakeKeylogger","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","excel","finspy","misp-galaxy:country=\"australia\"","misp-galaxy:country=\"belgium\"","misp-galaxy:country=\"canada\"","misp-galaxy:country=\"germany\"","misp-galaxy:country=\"japan\"","misp-galaxy:country=\"south korea\"","misp-galaxy:country=\"united states of america\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"","misp-galaxy:mitre-attack-pattern=\"Execution through API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Mshta - T1218.005\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Shortcut Modification - T1547.009\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Steganography - T1027.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Template Injection - T1221\"","misp-galaxy:mitre-attack-pattern=\"Third-party Software - T1072\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities - T1127\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities Proxy Execution - T1127\"","misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Technology\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Unmasking the Hidden Threat: Inside a Sophisticated Excel-Based Attack Delivering Fileless Remcos RAT","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"337463ea7d1ef14be117bf0461be4dd342794f5919c820173651b9d7a7269ae3","normalized_value":"337463ea7d1ef14be117bf0461be4dd342794f5919c820173651b9d7a7269ae3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6bb9a830-58b0-4255-a672-2d038be9e055","attribute_id":"37524460","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:04.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"337463ea7d1ef14be117bf0461be4dd342794f5919c820173651b9d7a7269ae3","normalized_value":"337463ea7d1ef14be117bf0461be4dd342794f5919c820173651b9d7a7269ae3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b5977ec1-89be-4834-af37-821c1a1d20f9","attribute_id":"37523349","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146552","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"33994fc3030bd7f7136d1e7a6ef0bdc38ddfde0166fadcee7832abbf5104b4a8","normalized_value":"33994fc3030bd7f7136d1e7a6ef0bdc38ddfde0166fadcee7832abbf5104b4a8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0c673893-b1d0-49d4-a855-838b02b46939","attribute_id":"37528547","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783063132","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"33b317b7ffc3ea442add1da7aa7a7c444b670c62943e684c2ec2c5d6fa97904c","normalized_value":"33b317b7ffc3ea442add1da7aa7a7c444b670c62943e684c2ec2c5d6fa97904c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7f5d2787-6207-4782-a3a3-46160861afcd","attribute_id":"37524474","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:57.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"33b317b7ffc3ea442add1da7aa7a7c444b670c62943e684c2ec2c5d6fa97904c","normalized_value":"33b317b7ffc3ea442add1da7aa7a7c444b670c62943e684c2ec2c5d6fa97904c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"901854b8-8136-4c61-8d6d-9a2f8a70bf8e","attribute_id":"37523356","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146553","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"33ed102236533c8b01a224bd5ffb220cecc32900285d2984d4e41803f1b2b58d","normalized_value":"33ed102236533c8b01a224bd5ffb220cecc32900285d2984d4e41803f1b2b58d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b237d170-56bf-4f72-8777-70c64f32c63c","attribute_id":"69130","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686519","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3401c2aaca3a00145c37086dbb1b35b4a10347e77a1f492cd30cf626c5ebfcbb","normalized_value":"3401c2aaca3a00145c37086dbb1b35b4a10347e77a1f492cd30cf626c5ebfcbb","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"2e40f795-3f7f-4391-a1c3-94134ab919e7","attribute_id":"37529657","event_id":"58570","event_uuid":"73b7ed82-0d87-402a-adfd-2462e0268878","event_info":"Remcos host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101981","event_timestamp":"1783215210","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"352cd5d318e4cff15910dc70b609ef9bf1d1ee0b7f01e186bedb5e7d245e3ec6","normalized_value":"352cd5d318e4cff15910dc70b609ef9bf1d1ee0b7f01e186bedb5e7d245e3ec6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5fb8845f-ff31-4b93-bb52-2ea5f30497ac","attribute_id":"7386048","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581335","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"35feef0e6806c14f4ccdb4fceff8a5757956c50fb5ec9644dedae665304f9f96","normalized_value":"35feef0e6806c14f4ccdb4fceff8a5757956c50fb5ec9644dedae665304f9f96","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6dbc9a79-0672-4440-bae7-6d43426359a4","attribute_id":"37755285","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140468","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--a9ef7f7c-44db-58d8-adc2-6b9280239867","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--a9ef7f7c-44db-58d8-adc2-6b9280239867","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"360e3c6d428da649c77a426d3f0379a3a1eced35f0d7a68f5a925d4b300ccaf7","normalized_value":"360e3c6d428da649c77a426d3f0379a3a1eced35f0d7a68f5a925d4b300ccaf7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"42b03bb0-1105-420e-ba42-3e1039d9cb8f","attribute_id":"37523496","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"360e3c6d428da649c77a426d3f0379a3a1eced35f0d7a68f5a925d4b300ccaf7","normalized_value":"360e3c6d428da649c77a426d3f0379a3a1eced35f0d7a68f5a925d4b300ccaf7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cddc7ced-2b63-4fb8-a1e7-fee1122526a8","attribute_id":"37524493","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:51.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"363ea096a3f6d06d56dc97ff1618607d462f366139df70c88310bbf77b9f9f90","normalized_value":"363ea096a3f6d06d56dc97ff1618607d462f366139df70c88310bbf77b9f9f90","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e05a0ef8-673f-4ebc-8a2b-2168f8d5a101","attribute_id":"6724967","event_id":"26690","event_uuid":"4678ed95-1726-4820-87ba-36a935367aa4","event_info":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","event_date":"2020-08-04","attribute_timestamp":"1783581143","event_timestamp":"1783581153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"event":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"all":[" Remote Access Trojan","APT","Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:threat-actor=\"China APT\"","osint:source-type=\"technical-report\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"36669b2129c9bb80926741214cf045703aafdeddf48604fcd348a41fb80ad9aa","normalized_value":"36669b2129c9bb80926741214cf045703aafdeddf48604fcd348a41fb80ad9aa","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ec52b157-c89d-4dc5-9293-459886ee8e92","attribute_id":"37523191","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783127880","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","arm","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arm","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"36a9a24404963678edab15248ca95a4065bdc6a84e32fcb7a2387c3198641374","normalized_value":"36a9a24404963678edab15248ca95a4065bdc6a84e32fcb7a2387c3198641374","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a20f64a4-fa76-45d9-a9de-e43ebb3d8897","attribute_id":"69088","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686492","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"36eb85e475954e2815c40e0c1546895de5419aa704cadf01d9e096a70ee84517","normalized_value":"36eb85e475954e2815c40e0c1546895de5419aa704cadf01d9e096a70ee84517","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"29c71ef1-9f11-4e87-aa2e-1c18bcde837a","attribute_id":"37771813","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483192","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3791dca1f4ec6b509c5d806eb52c9e843fd926e988bc79833c2e4e2ebb69395b","normalized_value":"3791dca1f4ec6b509c5d806eb52c9e843fd926e988bc79833c2e4e2ebb69395b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0f1a7bed-2987-40a3-a0b6-ed479d9d9eb9","attribute_id":"37565758","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783087432","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_03-07-2026 HTML_Smuggling","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_03-07-2026 HTML_Smuggling","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"381dbc9012d02b3a42916813b99e481b1cc89d15da918b58db40ce330cc13fca","normalized_value":"381dbc9012d02b3a42916813b99e481b1cc89d15da918b58db40ce330cc13fca","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fc2cdcd0-d8fb-44d0-a796-041774d83c15","attribute_id":"37771817","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483192","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3855f94e68b2b0353b8e318a2864b959631ecff88e90fddde4e5a77c69acac72","normalized_value":"3855f94e68b2b0353b8e318a2864b959631ecff88e90fddde4e5a77c69acac72","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6e24571a-3877-4817-960f-d1bf3bcd4be9","attribute_id":"37529313","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:33.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ACR Stealer","misp-galaxy:malpedia=\"ACR Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ACR Stealer","misp-galaxy:malpedia=\"ACR Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3855f94e68b2b0353b8e318a2864b959631ecff88e90fddde4e5a77c69acac72","normalized_value":"3855f94e68b2b0353b8e318a2864b959631ecff88e90fddde4e5a77c69acac72","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"73791c3a-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521643","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176093","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"ACR Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"ACR Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"389f2000a22e839ddafb28d9cf522b0b71e303e0ae89e5fc2cd5b53ae9256848","normalized_value":"389f2000a22e839ddafb28d9cf522b0b71e303e0ae89e5fc2cd5b53ae9256848","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b0e9a0bc-b01c-42e1-a67f-1c7251c15c7a","attribute_id":"35015692","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558055","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Custom CobaltStrike loader samples  SHA256 hashes","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Custom CobaltStrike loader samples  SHA256 hashes","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3a87b24c57f5a83bfadca1e83360618f89f8d53c1bfccb1a8c005547877feac2","normalized_value":"3a87b24c57f5a83bfadca1e83360618f89f8d53c1bfccb1a8c005547877feac2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"56d93426-3f38-4862-ad00-c84a1f2fc53d","attribute_id":"37529316","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:18.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3a87b24c57f5a83bfadca1e83360618f89f8d53c1bfccb1a8c005547877feac2","normalized_value":"3a87b24c57f5a83bfadca1e83360618f89f8d53c1bfccb1a8c005547877feac2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6ab7b278-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521646","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176078","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Venus Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Venus Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3aa70d6b1aa448cf3bbe8f7f3f95807bc390925303ddb4f3c4d5575a173dde9e","normalized_value":"3aa70d6b1aa448cf3bbe8f7f3f95807bc390925303ddb4f3c4d5575a173dde9e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ecca08f1-fc74-4b32-9e17-5cbb29c5f64e","attribute_id":"37528770","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783085358","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["AsyncRAT","opendir","vbs","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["AsyncRAT","opendir","tlp:white","type:OSINT","ua-wget","vbs"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3b3b9a18d9b9073e9bc94a6e5367d42a2c248274daa70856e3dc4935106e4218","normalized_value":"3b3b9a18d9b9073e9bc94a6e5367d42a2c248274daa70856e3dc4935106e4218","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"50bc3040-2eb3-4ba9-b1c8-b1dd80dd2263","attribute_id":"7386046","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581337","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3ba905e1cda7307163d4c8fe3fd03c2fbce7eda030522084e33d0604c204630e","normalized_value":"3ba905e1cda7307163d4c8fe3fd03c2fbce7eda030522084e33d0604c204630e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ef4e0b1e-cecb-44d0-af37-48f0b0483bf0","attribute_id":"7386295","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581166","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3bb81c977bb34fadb3bdeac7e61193dd009725783fb2cf453e15ced70fc39e9b","normalized_value":"3bb81c977bb34fadb3bdeac7e61193dd009725783fb2cf453e15ced70fc39e9b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"430d266b-f41f-4880-a41b-3ae83f8e955c","attribute_id":"37752464","event_id":"61011","event_uuid":"a5827ddb-b1cc-450d-9811-00a4b3a7d21a","event_info":"TikTok Videos Promise Pirated Apps, Deliver Vidar and StealC Infostealers Instead","event_date":"2026-07-27","attribute_timestamp":"1785118596","event_timestamp":"1785118597","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":[" C2"," infostealer","NCSA","Social Engineering","Tiktok","tlp:clear"],"event":[" C2"," infostealer","NCSA","Social Engineering","Tiktok","tlp:clear"],"all":[" C2"," infostealer","NCSA","Social Engineering","Tiktok","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TikTok Videos Promise Pirated Apps, Deliver Vidar and StealC Infostealers Instead","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e","normalized_value":"3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"30ce5f94-2c5e-40a8-8cf4-01c66688ba3a","attribute_id":"37755419","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140545","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--7fc006c4-5cf9-543e-a31a-5cf9934068f8","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--7fc006c4-5cf9-543e-a31a-5cf9934068f8","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3c279bc94d37eeaf2b81f78820ada90c8e40814e45818c7c5666ea8c49688d67","normalized_value":"3c279bc94d37eeaf2b81f78820ada90c8e40814e45818c7c5666ea8c49688d67","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ed9c5438-5783-4de1-9f3c-3bcbf9baed6f","attribute_id":"37523682","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783149127","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["dropped-by-amadey","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["dropped-by-amadey","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3cdd082de74b996e163163dbb7f6ee55911f7226ef5750e05b5fc14f7a26d48c","normalized_value":"3cdd082de74b996e163163dbb7f6ee55911f7226ef5750e05b5fc14f7a26d48c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"53500052-1c37-4b23-b41c-3b7fb30202ec","attribute_id":"37523077","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162510","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","arm","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arm","elf","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3d41830f943c31f69eb6ed7804cc18b289ba2172d258bd118a8503d120318d63","normalized_value":"3d41830f943c31f69eb6ed7804cc18b289ba2172d258bd118a8503d120318d63","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"35bf0165-5145-4384-a011-e4c24b6c9298","attribute_id":"34370349","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581076","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3d4d751665fc9f5247f34d7c3db5381d83c55cd1d49311b3570f2c002b36cb1e","normalized_value":"3d4d751665fc9f5247f34d7c3db5381d83c55cd1d49311b3570f2c002b36cb1e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0feb4926-3599-4db0-8786-6f23ca56d712","attribute_id":"37528944","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:05.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Monero Miner\"","misp-galaxy:malpedia=\"Coinminer\"","CoinMiner","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["CoinMiner","misp-galaxy:malpedia=\"Coinminer\"","misp-galaxy:malpedia=\"Monero Miner\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3d4d751665fc9f5247f34d7c3db5381d83c55cd1d49311b3570f2c002b36cb1e","normalized_value":"3d4d751665fc9f5247f34d7c3db5381d83c55cd1d49311b3570f2c002b36cb1e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7581e044-7741-11f1-97fa-42010aa4000a","attribute_id":"37521650","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125845","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Coinminer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Coinminer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3d4d751665fc9f5247f34d7c3db5381d83c55cd1d49311b3570f2c002b36cb1e","normalized_value":"3d4d751665fc9f5247f34d7c3db5381d83c55cd1d49311b3570f2c002b36cb1e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"eae3f9d8-c7a0-4e15-882b-6bdbe0f7b9d8","attribute_id":"37528425","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783045873","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (CoinMiner)","event_extends_uuid":"","tags":{"attribute":["CoinMiner","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["CoinMiner","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (CoinMiner)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3d776e8445933dee504ffe673a96480d5313c1e71979faebb74c3c9734b96b31","normalized_value":"3d776e8445933dee504ffe673a96480d5313c1e71979faebb74c3c9734b96b31","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4410e515-0814-43f5-90f5-fc7bf74175f0","attribute_id":"37524450","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:07.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3d776e8445933dee504ffe673a96480d5313c1e71979faebb74c3c9734b96b31","normalized_value":"3d776e8445933dee504ffe673a96480d5313c1e71979faebb74c3c9734b96b31","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8a29846a-5f2c-4205-948d-7b8fd63a4778","attribute_id":"37523363","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146553","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3da8d1bfb8192f43cf5d9247035aa4445381d2d26bed981662e3db34824c71fd","normalized_value":"3da8d1bfb8192f43cf5d9247035aa4445381d2d26bed981662e3db34824c71fd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ff8d3216-5043-4d17-b59f-74293625257d","attribute_id":"34346285","event_id":"51335","event_uuid":"39b2e10d-763c-44e8-a2c5-dee828c98f37","event_info":"KdcSponge, NGLite, Godzilla Webshell Used in Targeted Attack Campaign","event_date":"2021-11-09","attribute_timestamp":"1783686410","event_timestamp":"1783686416","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"13ac2113-2834-4088-a591-1f400c778f54","tags":{"attribute":["threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","cert-ist:malware_type=\"Webshell\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:enriched","cert-ist:confidence=\"medium\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_type=\"apt\"","tlp:clear"],"event":["threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","cert-ist:malware_type=\"Webshell\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:enriched","cert-ist:confidence=\"medium\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_type=\"apt\"","tlp:clear"],"all":["cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:confidence=\"medium\"","cert-ist:enriched","cert-ist:malware_type=\"Webshell\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:threat_type=\"apt\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","threat-report","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"KdcSponge, NGLite, Godzilla Webshell Used in Targeted Attack Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3dfb4e7ca12b7176a0cf12edce288b26a970339e6529a0b2dad7114bba0e16c3","normalized_value":"3dfb4e7ca12b7176a0cf12edce288b26a970339e6529a0b2dad7114bba0e16c3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b5cbc068-f98a-49bc-b293-95b2fc613a07","attribute_id":"35015693","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558058","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Custom CobaltStrike loader samples  SHA256 hashes","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Custom CobaltStrike loader samples  SHA256 hashes","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3c","normalized_value":"3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"38a35f81-d3a7-4584-a9df-9f70405f3512","attribute_id":"37755444","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140560","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--540be906-4b9d-5e55-8361-3f820627b6db","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--540be906-4b9d-5e55-8361-3f820627b6db","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d","normalized_value":"3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"317466a6-190b-4cf2-93fc-bafd29d98aad","attribute_id":"37755410","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140540","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--a474b477-5745-5611-a1b8-e7e95be3f454","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--a474b477-5745-5611-a1b8-e7e95be3f454","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3f868ac52916ebb6f6186ac20b20903f63bc8e9c460e2418f2b032a207d8f21d","normalized_value":"3f868ac52916ebb6f6186ac20b20903f63bc8e9c460e2418f2b032a207d8f21d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5974c478-cb29-4d93-9701-be8d2bb46271","attribute_id":"34346254","event_id":"51335","event_uuid":"39b2e10d-763c-44e8-a2c5-dee828c98f37","event_info":"KdcSponge, NGLite, Godzilla Webshell Used in Targeted Attack Campaign","event_date":"2021-11-09","attribute_timestamp":"1783686397","event_timestamp":"1783686416","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"NGLite SHA256","event_extends_uuid":"13ac2113-2834-4088-a591-1f400c778f54","tags":{"attribute":["threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","cert-ist:malware_type=\"Webshell\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:enriched","cert-ist:confidence=\"medium\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_type=\"apt\"","tlp:clear"],"event":["threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","cert-ist:malware_type=\"Webshell\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:enriched","cert-ist:confidence=\"medium\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_type=\"apt\"","tlp:clear"],"all":["cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:confidence=\"medium\"","cert-ist:enriched","cert-ist:malware_type=\"Webshell\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:threat_type=\"apt\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","threat-report","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"NGLite SHA256","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3fc02d5534d74a38e1ef4b6121818ce3358bbe1e9a823f7e6c741e9d1911cc48","normalized_value":"3fc02d5534d74a38e1ef4b6121818ce3358bbe1e9a823f7e6c741e9d1911cc48","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5c55b7c2-72e9-4ef9-90bd-76bc636a05ed","attribute_id":"37529321","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:23.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"3fc02d5534d74a38e1ef4b6121818ce3358bbe1e9a823f7e6c741e9d1911cc48","normalized_value":"3fc02d5534d74a38e1ef4b6121818ce3358bbe1e9a823f7e6c741e9d1911cc48","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6dace4bc-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521659","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176083","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4036c7596c0805eedda9eaaa5983ba5c75e59119febf18b60e2f4231779cadff","normalized_value":"4036c7596c0805eedda9eaaa5983ba5c75e59119febf18b60e2f4231779cadff","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"de0f9be7-4a2b-4412-9918-8b424828e48e","attribute_id":"37523675","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147452","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["njRat","Vidar","AveMariaRAT","dropped-by-amadey","d52f85","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["AveMariaRAT","Vidar","d52f85","dropped-by-amadey","njRat","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"40569318e89db751ff3886b2617d990d8a343f0d1d8727b7f978a28129ca36bc","normalized_value":"40569318e89db751ff3886b2617d990d8a343f0d1d8727b7f978a28129ca36bc","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4308cead-3923-4dd5-a0b7-1642c1a64a1d","attribute_id":"37752162","event_id":"60989","event_uuid":"1856b358-880a-4c9c-acef-c8ce8bae7d01","event_info":"Threat Actor Uses Malicious PyPI Dependencies to Deliver ChocoPoC RAT Through GitHub PoCs","event_date":"2026-07-20","attribute_timestamp":"1784529523","event_timestamp":"1784529532","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","RAT","tlp:clear"],"event":["NCSA","NCSA_Research","RAT","tlp:clear"],"all":["NCSA","NCSA_Research","RAT","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Uses Malicious PyPI Dependencies to Deliver ChocoPoC RAT Through GitHub PoCs","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4094900fddc8bac1960c115bc63efa417113f9fca272c69799969a260addd243","normalized_value":"4094900fddc8bac1960c115bc63efa417113f9fca272c69799969a260addd243","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0a26f6f3-9f7d-4c42-8429-5c755a52ad2d","attribute_id":"37528824","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783089078","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"40b46bae5cca53c55f7b7f941b0a02aeb5ef5150d9eff7258c48f92de5435216","normalized_value":"40b46bae5cca53c55f7b7f941b0a02aeb5ef5150d9eff7258c48f92de5435216","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f0bb27f4-3d95-4461-b06e-bcd1a88e0762","attribute_id":"69102","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686498","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"40fd96e5c870ccefd680bf559b7f72e7e994e3ccb4d0cb5d68836db41180bf64","normalized_value":"40fd96e5c870ccefd680bf559b7f72e7e994e3ccb4d0cb5d68836db41180bf64","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"996b40a3-a1ea-4e1d-a308-08282dabdbb5","attribute_id":"37528322","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783040960","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4158ad6eca8c3087ed221953f7a69d3d40a772c5af415f32e110a46da8a9f8ac","normalized_value":"4158ad6eca8c3087ed221953f7a69d3d40a772c5af415f32e110a46da8a9f8ac","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"eb94fa65-6262-4044-840f-cc835f987d09","attribute_id":"7386020","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581366","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4169382903429aeff24b14eb04a4dcada79f63e08044d9e1f28af10dab81bcfb","normalized_value":"4169382903429aeff24b14eb04a4dcada79f63e08044d9e1f28af10dab81bcfb","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ef12e6d9-bcf6-4432-ab0d-fe42ae847482","attribute_id":"37528437","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783057017","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"41a9784f8787ed86f1e5d20f9895059dac7a030d8d6e426b9ddcaf547c3393aa","normalized_value":"41a9784f8787ed86f1e5d20f9895059dac7a030d8d6e426b9ddcaf547c3393aa","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dc32a2f0-eaa3-4d21-ac7e-22d426bbf552","attribute_id":"37748488","event_id":"60948","event_uuid":"de525eea-c091-4fa7-8dc6-218ce63d53ad","event_info":"Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials","event_date":"2024-04-23","attribute_timestamp":"1783666994","event_timestamp":"1783666998","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Hash of wayzgoose[%n].dll – where %n is a random number","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","OSINT","osint:source-type=\"blog-post\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","APT","Actor: APT28","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"United States\"","tlp:clear","Microsoft Corporation","windows","JavaScript","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:threat-actor=\"APT28\"","misp-galaxy:country=\"russia\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","PrintNightmare"],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","OSINT","osint:source-type=\"blog-post\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","APT","Actor: APT28","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"United States\"","tlp:clear","Microsoft Corporation","windows","JavaScript","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:threat-actor=\"APT28\"","misp-galaxy:country=\"russia\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","PrintNightmare"],"all":["APT","Actor: APT28","JavaScript","Microsoft Corporation","OSINT","PrintNightmare","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:country=\"russia\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:threat-actor=\"APT28\"","osint:source-type=\"blog-post\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Hash of wayzgoose[%n].dll – where %n is a random number","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"422c55e0219b09d0262782b25420c601304f5d1b46a325f2b4859ef77244ff42","normalized_value":"422c55e0219b09d0262782b25420c601304f5d1b46a325f2b4859ef77244ff42","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"73876873-48f1-4df3-b012-ff89a475a8a5","attribute_id":"37524520","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:42.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"42fa6071fd7cf7ac8ff6740d6c297f5b8527a93116f84146a515449070abf488","normalized_value":"42fa6071fd7cf7ac8ff6740d6c297f5b8527a93116f84146a515449070abf488","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a04f3d18-467d-4af6-9525-bd68ce921eea","attribute_id":"37524567","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:26.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ACR Stealer","misp-galaxy:malpedia=\"ACR Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ACR Stealer","misp-galaxy:malpedia=\"ACR Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"434243e615b93a1b948c26ad55902bd78f9fa18e42375c15790634375c1ad3f4","normalized_value":"434243e615b93a1b948c26ad55902bd78f9fa18e42375c15790634375c1ad3f4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f696222f-5739-44dc-a43a-af3d009bb636","attribute_id":"37755116","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112069","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--ca95fa5b-2e60-5fab-b88a-910c6fb308a3","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--ca95fa5b-2e60-5fab-b88a-910c6fb308a3","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"43f8a66d3f3f1ba574bc932a7bc8e5886fbeeab0b279d1dea654d7119e80a494","normalized_value":"43f8a66d3f3f1ba574bc932a7bc8e5886fbeeab0b279d1dea654d7119e80a494","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7f7caa65-7c56-4fa8-aedb-abeafb615d62","attribute_id":"34872978","event_id":"53500","event_uuid":"ee548bbf-73a6-4efd-83c5-5b65157c1756","event_info":"Yanluowang: Further Insights on New Ransomware Threat","event_date":"2021-12-01","attribute_timestamp":"1783580526","event_timestamp":"1783580536","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:sector=\"Consulting\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1503\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\""," Ransomware","threat-report","tlp:white","misp-galaxy:target-information=\"United States\"","malware_classification:malware-category=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","Ransomware","tlp:clear"],"event":["misp-galaxy:sector=\"Consulting\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1503\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\""," Ransomware","threat-report","tlp:white","misp-galaxy:target-information=\"United States\"","malware_classification:malware-category=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","Ransomware","tlp:clear"],"all":[" Ransomware","Ransomware","malware_classification:malware-category=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1503\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:sector=\"Consulting\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:target-information=\"United States\"","threat-report","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Yanluowang: Further Insights on New Ransomware Threat","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"441b840809e8680e9291c90412a23310f156a65950c56e700ed77736c17e30d2","normalized_value":"441b840809e8680e9291c90412a23310f156a65950c56e700ed77736c17e30d2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2c1a7966-5038-4083-b76e-96737d292d6e","attribute_id":"37751347","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783622542","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_09-07-2026_Phishing_SVG","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_09-07-2026_Phishing_SVG","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"444169e156b48a54e9f96b6b3a1c333670546663c8a2e14e561884c052420043","normalized_value":"444169e156b48a54e9f96b6b3a1c333670546663c8a2e14e561884c052420043","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"528581e4-5ee8-4d8e-b189-19ca7cf17749","attribute_id":"7385986","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581383","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1","normalized_value":"444f1c0c82b3f6cc31d685bac68b20edbde5722ce219af9cceab0c2a6537efc1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cf9bbe63-2590-453c-970c-d2f5e7462b08","attribute_id":"37751401","event_id":"60979","event_uuid":"fea39f60-0010-477f-b097-b30d1547c5a4","event_info":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","event_date":"2026-07-17","attribute_timestamp":"1784273256","event_timestamp":"1784273257","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"event":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"all":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645df","normalized_value":"449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645df","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"16730261-aa05-4e9c-bec9-9a7efe1ac7e1","attribute_id":"37752181","event_id":"60991","event_uuid":"58e75ed8-2394-41b3-a563-2324bec70d3a","event_info":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","event_date":"2026-07-22","attribute_timestamp":"1784691371","event_timestamp":"1784691372","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"event":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"all":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"44b38a0cd590ada2d96dcf98b6a88d3c17997cac574ab9e68b9f33c6f985dec4","normalized_value":"44b38a0cd590ada2d96dcf98b6a88d3c17997cac574ab9e68b9f33c6f985dec4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"69825f73-75da-47f7-b88f-59c32ae519bf","attribute_id":"37523293","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783133897","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"44e83f84a5d5219e2f7c3cf1e4f02489cae81361227f46946abe4b8d8245b879","normalized_value":"44e83f84a5d5219e2f7c3cf1e4f02489cae81361227f46946abe4b8d8245b879","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ce6aa71f-8506-4d7a-985d-ca4ee1cfffb9","attribute_id":"35953","event_id":"354","event_uuid":"bfdf7203-3742-4cff-b16d-46231f7c49a2","event_info":"The Covert Operator's Playbook: Infiltration of Global Telecom Networks","event_date":"2025-08-01","attribute_timestamp":"1783447304","event_timestamp":"1783447319","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Backdoor","RAT","c2","linux","misp-galaxy:region=\"034 - Southern Asia\"","tlp:clear","#ICMP","Asia","CVE-2016-5195","CVE-2021-3156","dns","DirtyCow","FishMonger","Palo Alto Networks Unit 42","Responder","SSHBrute","StatelyTaurus","UNC3886","cert-ist:threat_targeted_region=\"Southern Asia\"","cert-ist:threat_targeted_sector=\"Telecom\"","cve-2021-4034","feedly:industry=\"Telecom\"","feedly:threat-actor=\"UNC5174\"","frp","fscan","paloalto Netoworks: Unit42","recorded-future:threat-actor=Earth Estries","ssh","misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"Invalid Code Signature - T1036.001\"","misp-galaxy:mitre-attack-pattern=\"Pluggable Authentication Modules - T1556.003\"","misp-galaxy:mitre-attack-pattern=\"Rename System Utilities - T1036.003\"","misp-galaxy:region=\"142 - Asia\"","Linux malware","Malwaree","windows","tlp:white","ncsc-nl-ndn:feed=\"generic\""],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Backdoor","RAT","c2","linux","misp-galaxy:region=\"034 - Southern Asia\"","tlp:clear","#ICMP","Asia","CVE-2016-5195","CVE-2021-3156","dns","DirtyCow","FishMonger","Palo Alto Networks Unit 42","Responder","SSHBrute","StatelyTaurus","UNC3886","cert-ist:threat_targeted_region=\"Southern Asia\"","cert-ist:threat_targeted_sector=\"Telecom\"","cve-2021-4034","feedly:industry=\"Telecom\"","feedly:threat-actor=\"UNC5174\"","frp","fscan","paloalto Netoworks: Unit42","recorded-future:threat-actor=Earth Estries","ssh","misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"Invalid Code Signature - T1036.001\"","misp-galaxy:mitre-attack-pattern=\"Pluggable Authentication Modules - T1556.003\"","misp-galaxy:mitre-attack-pattern=\"Rename System Utilities - T1036.003\"","misp-galaxy:region=\"142 - Asia\"","Linux malware","Malwaree","windows","tlp:white","ncsc-nl-ndn:feed=\"generic\""],"all":["#ICMP","Asia","Backdoor","CVE-2016-5195","CVE-2021-3156","DirtyCow","FishMonger","Linux malware","Malwaree","Palo Alto Networks Unit 42","RAT","Responder","SSHBrute","StatelyTaurus","UNC3886","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","c2","cert-ist:threat_targeted_region=\"Southern Asia\"","cert-ist:threat_targeted_sector=\"Telecom\"","cve-2021-4034","dns","feedly:industry=\"Telecom\"","feedly:threat-actor=\"UNC5174\"","frp","fscan","linux","misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"Invalid Code Signature - T1036.001\"","misp-galaxy:mitre-attack-pattern=\"Pluggable Authentication Modules - T1556.003\"","misp-galaxy:mitre-attack-pattern=\"Rename System Utilities - T1036.003\"","misp-galaxy:region=\"034 - Southern Asia\"","misp-galaxy:region=\"142 - Asia\"","ncsc-nl-ndn:feed=\"generic\"","paloalto Netoworks: Unit42","recorded-future:threat-actor=Earth Estries","ssh","tlp:clear","tlp:white","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"The Covert Operator's Playbook: Infiltration of Global Telecom Networks","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4521f532bf22c3155a95a71c4797253680dc60618c74c18522506a603ef43a03","normalized_value":"4521f532bf22c3155a95a71c4797253680dc60618c74c18522506a603ef43a03","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3e2cbefa-f848-46b7-bd02-9a42c8622680","attribute_id":"37523454","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4521f532bf22c3155a95a71c4797253680dc60618c74c18522506a603ef43a03","normalized_value":"4521f532bf22c3155a95a71c4797253680dc60618c74c18522506a603ef43a03","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c0ff2f62-3c87-4fa8-8034-d1c11a383d9b","attribute_id":"37524441","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:10.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"45b81360ed62ec817fb63c5522fc3400ce0c73a369ea3b381267c2e24051db2b","normalized_value":"45b81360ed62ec817fb63c5522fc3400ce0c73a369ea3b381267c2e24051db2b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b9d339f9-237b-46e9-a72f-837fc7bad92f","attribute_id":"35286601","event_id":"54509","event_uuid":"43607dc8-e6b0-44d5-b4b6-d8449e476051","event_info":"MAR-10333243.r3.v1: Pulse Secure --> Malware Analysis Report (AR21-236B)","event_date":"2021-07-20","attribute_timestamp":"1783738851","event_timestamp":"1783814379","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["tlp:white","threat-report"],"event":["tlp:white","threat-report"],"all":["threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"MAR-10333243.r3.v1: Pulse Secure --> Malware Analysis Report (AR21-236B)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"45dc99df6e435b5a7683d0cd3802c654ce1c79d6aed9eee33888ca2da3dba5b6","normalized_value":"45dc99df6e435b5a7683d0cd3802c654ce1c79d6aed9eee33888ca2da3dba5b6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"27b76099-e1aa-437f-9bab-ed9aafe511ea","attribute_id":"37523767","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783175365","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"46880af4b7bbb74def06569aecda2d96702de4b8b7723b05af927674928ce327","normalized_value":"46880af4b7bbb74def06569aecda2d96702de4b8b7723b05af927674928ce327","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dfaff678-6213-4338-b956-f435809ec79d","attribute_id":"37524516","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:44.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4694ccf2399010c0e069f481e3471745dfe0a4f72003ed476ecf86b7b6b4ef7f","normalized_value":"4694ccf2399010c0e069f481e3471745dfe0a4f72003ed476ecf86b7b6b4ef7f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7e202824-7741-11f1-97fa-42010aa4000a","attribute_id":"37521669","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125859","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Quasar RAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Quasar RAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4694ccf2399010c0e069f481e3471745dfe0a4f72003ed476ecf86b7b6b4ef7f","normalized_value":"4694ccf2399010c0e069f481e3471745dfe0a4f72003ed476ecf86b7b6b4ef7f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8d684d7c-b282-4b41-b52e-2cfc92f8da3e","attribute_id":"37528902","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:19.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Quasar RAT\"","Quasar RAT","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Quasar RAT","misp-galaxy:malpedia=\"Quasar RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4694ccf2399010c0e069f481e3471745dfe0a4f72003ed476ecf86b7b6b4ef7f","normalized_value":"4694ccf2399010c0e069f481e3471745dfe0a4f72003ed476ecf86b7b6b4ef7f","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"5a48a67c-f970-4b71-8a7d-c6b4ab7a9463","attribute_id":"37529919","event_id":"58580","event_uuid":"f6da4016-152c-4ce2-ae4a-7f384674aa87","event_info":"QuasarRAT host indicators [2026-07-02]","event_date":"2026-07-02","attribute_timestamp":"1783018873","event_timestamp":"1783018873","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white"],"event":["tlp:white"],"all":["kill-chain:Installation","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"46dbb7709411b1429233e0d8d33a02cccd54005a2b4015dcfa8a890252177df9","normalized_value":"46dbb7709411b1429233e0d8d33a02cccd54005a2b4015dcfa8a890252177df9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6849d0d3-ca9d-4a89-9471-e07b2265ae8f","attribute_id":"7386019","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581365","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4863840ed49a1779ad7acc7fbfa1ee80c531813f05c73be76c5ae2807a9036b3","normalized_value":"4863840ed49a1779ad7acc7fbfa1ee80c531813f05c73be76c5ae2807a9036b3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"509dbd33-3ee3-49ea-b47a-4b83aacdecdc","attribute_id":"7385994","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581377","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"48723a33bab89f174750576f9a62da35b3b9e5ac31a5a8f1ce9859a1b35bf8b8","normalized_value":"48723a33bab89f174750576f9a62da35b3b9e5ac31a5a8f1ce9859a1b35bf8b8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"797a3fee-b04a-49e9-923c-43260b70a0f5","attribute_id":"37752152","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"48d642c2c77eeabff36249c59ce397a9ee5f3d825d735f839c5c05939499406e","normalized_value":"48d642c2c77eeabff36249c59ce397a9ee5f3d825d735f839c5c05939499406e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bbdddb5c-94a4-4b7b-a6f9-6cfa7e1add14","attribute_id":"34370331","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581059","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"48ed2a2fc7652fc12c6edfc2efbef6d65a9f85bf5874dbaf275301775265e136","normalized_value":"48ed2a2fc7652fc12c6edfc2efbef6d65a9f85bf5874dbaf275301775265e136","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7b64017f-7741-11f1-97fa-42010aa4000a","attribute_id":"37521673","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125855","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WannaCryptor payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WannaCryptor payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"48ed2a2fc7652fc12c6edfc2efbef6d65a9f85bf5874dbaf275301775265e136","normalized_value":"48ed2a2fc7652fc12c6edfc2efbef6d65a9f85bf5874dbaf275301775265e136","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a2bc78c1-c20a-46cb-a1e9-ea2ac40dc771","attribute_id":"37528913","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:15.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"496e34b70c8099e6af1332ab836a1a6eb70755dbe4e36b4417095f1fbc3be900","normalized_value":"496e34b70c8099e6af1332ab836a1a6eb70755dbe4e36b4417095f1fbc3be900","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b2d027ed-c254-4026-a181-14ab742256c8","attribute_id":"37528637","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783067214","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","sparc","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","sparc","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"49d828087ca77abc8d3ac2e4719719ca48578b265bbb632a1a7a36560ec47f2d","normalized_value":"49d828087ca77abc8d3ac2e4719719ca48578b265bbb632a1a7a36560ec47f2d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7d3fa30f-d6a8-4190-a981-6e1df2ac4aae","attribute_id":"34872994","event_id":"53500","event_uuid":"ee548bbf-73a6-4efd-83c5-5b65157c1756","event_info":"Yanluowang: Further Insights on New Ransomware Threat","event_date":"2021-12-01","attribute_timestamp":"1783580536","event_timestamp":"1783580536","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:sector=\"Consulting\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1503\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\""," Ransomware","threat-report","tlp:white","misp-galaxy:target-information=\"United States\"","malware_classification:malware-category=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","Ransomware","tlp:clear"],"event":["misp-galaxy:sector=\"Consulting\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1503\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\""," Ransomware","threat-report","tlp:white","misp-galaxy:target-information=\"United States\"","malware_classification:malware-category=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","Ransomware","tlp:clear"],"all":[" Ransomware","Ransomware","malware_classification:malware-category=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1503\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:sector=\"Consulting\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:target-information=\"United States\"","threat-report","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Yanluowang: Further Insights on New Ransomware Threat","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4a0688baf9661d3737ee82f8992a0a665732c91704f28688f643115648c107d4","normalized_value":"4a0688baf9661d3737ee82f8992a0a665732c91704f28688f643115648c107d4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f81e2087-e553-47ec-99d3-3f929374b725","attribute_id":"6724976","event_id":"26690","event_uuid":"4678ed95-1726-4820-87ba-36a935367aa4","event_info":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","event_date":"2020-08-04","attribute_timestamp":"1783581147","event_timestamp":"1783581153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"event":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"all":[" Remote Access Trojan","APT","Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:threat-actor=\"China APT\"","osint:source-type=\"technical-report\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4a4c0918bdacd60e792a814ddacc5dc7edb83644268611313cb9b453991ac628","normalized_value":"4a4c0918bdacd60e792a814ddacc5dc7edb83644268611313cb9b453991ac628","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"52bbca53-3f98-42c4-9112-7cd3acbd0a00","attribute_id":"69242","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686564","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4abf2d4b604ad5c3dca0006e9762562ea104e76e7c0dcfa8fddafda8b11b2eaf","normalized_value":"4abf2d4b604ad5c3dca0006e9762562ea104e76e7c0dcfa8fddafda8b11b2eaf","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"37c180b1-35a6-45e1-9ef2-9b9a834c2f56","attribute_id":"7385967","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581397","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4ae4d4f2faf96941187abdf2d292b4ce995ecc94dc68f8e7d4e0e49747caed6d","normalized_value":"4ae4d4f2faf96941187abdf2d292b4ce995ecc94dc68f8e7d4e0e49747caed6d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"72678594-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521676","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176091","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Kuiper payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Kuiper payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4ae4d4f2faf96941187abdf2d292b4ce995ecc94dc68f8e7d4e0e49747caed6d","normalized_value":"4ae4d4f2faf96941187abdf2d292b4ce995ecc94dc68f8e7d4e0e49747caed6d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9e924e22-b461-48f6-a5b4-35f5ddac6e05","attribute_id":"37529329","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:31.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4ae932c3a530a58fbdaa8fe29fbf8ab9472ab8fcf3026b61446a5fad689120ae","normalized_value":"4ae932c3a530a58fbdaa8fe29fbf8ab9472ab8fcf3026b61446a5fad689120ae","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f4881409-f332-4a03-b285-34e20151f247","attribute_id":"37524588","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:19.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4b188d179e50e8208a6efec85e273e88d8fc390c836f299ba12915e0840408fd","normalized_value":"4b188d179e50e8208a6efec85e273e88d8fc390c836f299ba12915e0840408fd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e1101d1f-e738-4c35-9700-b38651dc4e8f","attribute_id":"37755105","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112063","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--c4c345f2-af1d-5ff2-a1a7-ebcca4b4cd0f","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--c4c345f2-af1d-5ff2-a1a7-ebcca4b4cd0f","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4b7301f02b8312ae6de614981f325dbbabee32166630618fdff74615d9a487ba","normalized_value":"4b7301f02b8312ae6de614981f325dbbabee32166630618fdff74615d9a487ba","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"81bc08f8-1d84-4cc7-9165-f6feea3a639b","attribute_id":"37521411","event_id":"58527","event_uuid":"bb3d2aed-e7ff-4097-b022-849110a41ab8","event_info":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","event_date":"2026-07-06","attribute_timestamp":"1783319886","event_timestamp":"1783319886","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"event":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"all":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4b9811f1f8176ec9f2ee647a4c2f171854f296fbc18e47cc08eb82357a6eeec7","normalized_value":"4b9811f1f8176ec9f2ee647a4c2f171854f296fbc18e47cc08eb82357a6eeec7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"414be1e3-8b78-4a86-b95f-7e1708dbb53c","attribute_id":"37749177","event_id":"60956","event_uuid":"36e03b09-a20c-4169-a875-b77a24ca82fd","event_info":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","event_date":"2023-03-14","attribute_timestamp":"1783685715","event_timestamp":"1783685737","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"event":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"all":["Ave Maria","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","Energy Sector ","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cyber espionage","infostealer","meterpreter","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","osint:source-type=\"blog-post\"","tlp:clear","warzonerat"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4b98c014977ad113c22aaf5f794c567c41f8b7e6b77a3cab964116a1d8b0a542","normalized_value":"4b98c014977ad113c22aaf5f794c567c41f8b7e6b77a3cab964116a1d8b0a542","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"1a74569b-df22-4b53-8a0e-284409fcea18","attribute_id":"37522064","event_id":"58545","event_uuid":"96aef3b3-c8d2-468d-af4c-7c0205a6d196","event_info":"Gh0stRAT host indicators [2026-07-04]","event_date":"2026-07-04","attribute_timestamp":"1783202567","event_timestamp":"1783249473","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white"],"event":["tlp:white"],"all":["kill-chain:Installation","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4b9a95ebf5e471d11443fa2f19b75595fc1fcf6be234024cc1d4a2255068c19b","normalized_value":"4b9a95ebf5e471d11443fa2f19b75595fc1fcf6be234024cc1d4a2255068c19b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8b9376e4-e515-43da-8be9-b00e9ffb2c54","attribute_id":"37752334","event_id":"61004","event_uuid":"f55757e1-7aef-484b-9552-2ca3b6b7d0d8","event_info":"Banking Rewards Malware Campaign","event_date":"2026-07-24","attribute_timestamp":"1784881857","event_timestamp":"1784881991","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"event":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"all":[" trojan","BANKING TROJAN","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Banking Rewards Malware Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4c60e04f097673cccf47c8d43cc5a99621f8afeeba68e52e09bec32ece43dced","normalized_value":"4c60e04f097673cccf47c8d43cc5a99621f8afeeba68e52e09bec32ece43dced","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"46ab7fec-1c31-4c84-985c-74aa3f36478b","attribute_id":"7386008","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581354","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4c697bdcbe64036ba8a79e587462960e856a37e3b8c94f9b3e7875aeb2f91959","normalized_value":"4c697bdcbe64036ba8a79e587462960e856a37e3b8c94f9b3e7875aeb2f91959","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"28af3ec5-a5b9-4ebc-9b12-4f2157b15ccc","attribute_id":"69116","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686508","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4c9fdc2823da505ef339d43c6ad38499b7e3447736733e42b5ab6b1afcfd42aa","normalized_value":"4c9fdc2823da505ef339d43c6ad38499b7e3447736733e42b5ab6b1afcfd42aa","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1b0226b7-5750-4ce3-bb19-642a1781c8c5","attribute_id":"37752144","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4ca2c863d740bb7022776dccabd8ae34bb9998768928042d76ebcf08984eefcb","normalized_value":"4ca2c863d740bb7022776dccabd8ae34bb9998768928042d76ebcf08984eefcb","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dee7f399-54ce-40ed-a6b8-db1eb206a3cc","attribute_id":"37752157","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649","normalized_value":"4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4e251317-c6f3-489d-b3ae-3da691940a44","attribute_id":"37752429","event_id":"61009","event_uuid":"d942d9c8-237d-455a-9940-6429c473cff1","event_info":"New Stealthy Ransomware Deployed Against Asian IT Company","event_date":"2026-07-27","attribute_timestamp":"1785124153","event_timestamp":"1785124153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"event":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"all":[" Ransomware","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"New Stealthy Ransomware Deployed Against Asian IT Company","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4dc9b2f11546e5bf8fb9901809a0707ff1e23acdc52742b991ddff18ce03733c","normalized_value":"4dc9b2f11546e5bf8fb9901809a0707ff1e23acdc52742b991ddff18ce03733c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"04bb91b3-9ee4-4208-bc4b-84de96462465","attribute_id":"825515","event_id":"1538","event_uuid":"d111d331-0c25-404b-b5b5-8ccf73753aea","event_info":"Travel Themed Phishing URLs Set to Prey on Eager Travelers","event_date":"2021-09-16","attribute_timestamp":"1783580588","event_timestamp":"1783580592","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["threat-report","tlp:white","Dridex","MalSpam","misp-galaxy:mitre-attack-pattern=\"Brute Force - T1110\"","misp-galaxy:mitre-attack-pattern=\"Create Account - T1136\"","misp-galaxy:mitre-attack-pattern=\"Drive-by Compromise - T1189\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"","misp-galaxy:mitre-attack-pattern=\"System Service Discovery - T1007\"","misp-galaxy:mitre-malware=\"Dridex - S0384\"","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Travel\"","cert-ist:attack_vector=\"Phishing\"","cert-ist:threat_type=\"phishing\"","cert-ist:enriched","cert-ist:ioc_accuracy=\"medium\"","misp-galaxy:tool=\"Dridex\"","misp-galaxy:banker=\"Dridex\"","misp-galaxy:malpedia=\"Dridex\"","tlp:clear"],"event":["threat-report","tlp:white","Dridex","MalSpam","misp-galaxy:mitre-attack-pattern=\"Brute Force - T1110\"","misp-galaxy:mitre-attack-pattern=\"Create Account - T1136\"","misp-galaxy:mitre-attack-pattern=\"Drive-by Compromise - T1189\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"","misp-galaxy:mitre-attack-pattern=\"System Service Discovery - T1007\"","misp-galaxy:mitre-malware=\"Dridex - S0384\"","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Travel\"","cert-ist:attack_vector=\"Phishing\"","cert-ist:threat_type=\"phishing\"","cert-ist:enriched","cert-ist:ioc_accuracy=\"medium\"","misp-galaxy:tool=\"Dridex\"","misp-galaxy:banker=\"Dridex\"","misp-galaxy:malpedia=\"Dridex\"","tlp:clear"],"all":["Dridex","MalSpam","cert-ist:attack_vector=\"Phishing\"","cert-ist:enriched","cert-ist:ioc_accuracy=\"medium\"","cert-ist:threat_type=\"phishing\"","misp-galaxy:banker=\"Dridex\"","misp-galaxy:malpedia=\"Dridex\"","misp-galaxy:mitre-attack-pattern=\"Brute Force - T1110\"","misp-galaxy:mitre-attack-pattern=\"Create Account - T1136\"","misp-galaxy:mitre-attack-pattern=\"Drive-by Compromise - T1189\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"","misp-galaxy:mitre-attack-pattern=\"System Service Discovery - T1007\"","misp-galaxy:mitre-malware=\"Dridex - S0384\"","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Travel\"","misp-galaxy:tool=\"Dridex\"","threat-report","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Travel Themed Phishing URLs Set to Prey on Eager Travelers","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4df67a9e8abab33856a586cea38b0d365fbbe0d91ee848f270c65f0125d2d677","normalized_value":"4df67a9e8abab33856a586cea38b0d365fbbe0d91ee848f270c65f0125d2d677","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6dfd7f12-1ec4-46ee-96cc-834ead395778","attribute_id":"7386236","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581188","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4e2532c5ba90c45d1693dea76d31070edd5e3472ece0d723be303531e6f7c768","normalized_value":"4e2532c5ba90c45d1693dea76d31070edd5e3472ece0d723be303531e6f7c768","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dab72081-be56-4533-a1f9-74f7d6072605","attribute_id":"37523113","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162565","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","arm","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arm","elf","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4e5b2ae91379b8069c04c6639bb0bca5ddea0dde567bea8cb9bc9822b9cdda0d","normalized_value":"4e5b2ae91379b8069c04c6639bb0bca5ddea0dde567bea8cb9bc9822b9cdda0d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7ffa0788-7741-11f1-97fa-42010aa4000a","attribute_id":"37521680","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125862","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Luca Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Luca Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4e5b2ae91379b8069c04c6639bb0bca5ddea0dde567bea8cb9bc9822b9cdda0d","normalized_value":"4e5b2ae91379b8069c04c6639bb0bca5ddea0dde567bea8cb9bc9822b9cdda0d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d092d7db-69fe-44a2-b354-7bbbafeac8aa","attribute_id":"37528893","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:22.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Luca Stealer\"","Luca Stealer","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Luca Stealer","misp-galaxy:malpedia=\"Luca Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864","normalized_value":"4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"eb6a24d3-223a-454b-be0f-da5530be8f30","attribute_id":"37755443","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140559","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--7f8eb0d7-3495-5210-98d0-a9230e23e844","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--7f8eb0d7-3495-5210-98d0-a9230e23e844","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4ebb25ef9621c44cdb52630e44bcd1b5a848c0c56f01fa759863d50166bb0928","normalized_value":"4ebb25ef9621c44cdb52630e44bcd1b5a848c0c56f01fa759863d50166bb0928","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"40311205-2357-4cbf-b5d9-311b5cc59e3b","attribute_id":"35286053","event_id":"54507","event_uuid":"234daefa-6a93-4240-80b8-23582ad75013","event_info":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","event_date":"2021-07-30","attribute_timestamp":"1783639111","event_timestamp":"1783639112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["tlp:white","threat-report"],"event":["tlp:white","threat-report"],"all":["threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4f0925945aedb397ad3cbdd0e9b9a3ebf96d64c242699a971c2c016636383569","normalized_value":"4f0925945aedb397ad3cbdd0e9b9a3ebf96d64c242699a971c2c016636383569","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5051a1ca-2ca0-4395-86e0-c42c05b30190","attribute_id":"37528878","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:27.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4f0925945aedb397ad3cbdd0e9b9a3ebf96d64c242699a971c2c016636383569","normalized_value":"4f0925945aedb397ad3cbdd0e9b9a3ebf96d64c242699a971c2c016636383569","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"82e1e2ba-7741-11f1-97fa-42010aa4000a","attribute_id":"37521681","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125867","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Formbook payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Formbook payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"4f1c8de304a855c2a4d1995b41069641dee84f1b51b6fb4a6e24eee59c6a30e4","normalized_value":"4f1c8de304a855c2a4d1995b41069641dee84f1b51b6fb4a6e24eee59c6a30e4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bc5bc0b6-5307-447d-b87d-a5b707cf57f4","attribute_id":"37755314","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140484","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--a731706d-be68-5596-a2e9-43ca1e598dae","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--a731706d-be68-5596-a2e9-43ca1e598dae","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"50d21dbf380006ed82f9ddd3620db9553d46bf562777fc5853e0bb761a06024d","normalized_value":"50d21dbf380006ed82f9ddd3620db9553d46bf562777fc5853e0bb761a06024d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8691a64c-81b3-460b-8cbc-c7bd2c8a3804","attribute_id":"37528752","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783083428","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","arm","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arm","elf","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93b","normalized_value":"51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1ce91e48-7577-467d-884d-10e76dd01666","attribute_id":"37752185","event_id":"60991","event_uuid":"58e75ed8-2394-41b3-a563-2324bec70d3a","event_info":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","event_date":"2026-07-22","attribute_timestamp":"1784691371","event_timestamp":"1784691372","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"event":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"all":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"52bbf76f3cf2dddd96c72cc97a701e06e650af628ecdb119c5d448ea5a961b34","normalized_value":"52bbf76f3cf2dddd96c72cc97a701e06e650af628ecdb119c5d448ea5a961b34","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f2f2735b-0572-4a19-a65e-265739b71eb0","attribute_id":"37528298","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783038770","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","Ngioweb","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Ngioweb","elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"52e6e819720fede0d12dcc5430ff15f70b5656cbd3d5d251abfc2dcd22783293","normalized_value":"52e6e819720fede0d12dcc5430ff15f70b5656cbd3d5d251abfc2dcd22783293","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fd1f1bac-4466-4be7-8278-d997d69c65ce","attribute_id":"46556","event_id":"410","event_uuid":"568e08e1-0d11-5880-b306-f8b7abfc28c6","event_info":"Fix the Click: Preventing the ClickFix Attack Vector","event_date":"2025-07-10","attribute_timestamp":"1783666980","event_timestamp":"1784392767","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Clipboard Data - T1115\"","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:malpedia=\"NetSupportManager RAT\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","DocuSign","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"High tech\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Retail\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Hospitality\"","misp-galaxy:sector=\"Pharmacy\"","misp-galaxy:sector=\"Telecoms\"","osint:source-type=\"blog-post\"","tlp:clear","feedly:feedly-ai","feedly:source=\"Unit 42\"","misp-galaxy:mitre-attack-pattern=\"DLL - T1574.001\"","misp-galaxy:mitre-attack-pattern=\"AutoHotKey & AutoIT - T1059.010\"","misp-galaxy:mitre-attack-pattern=\"Malvertising - T1583.008\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious Copy and Paste - T1204.004\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Task or Service - T1036.004\"","misp-galaxy:mitre-attack-pattern=\"Msiexec - T1218.007\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Dynamic API Resolution - T1027.007\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Mutual Exclusion - T1480.002\"","misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"","misp-galaxy:mitre-attack-pattern=\"Command Obfuscation - T1027.010\"","misp-galaxy:mitre-malware=\"Lumma Stealer - S1213\"","misp-galaxy:mitre-malware=\"Latrodectus - S1160\"","misp-galaxy:malpedia=\"lampion\"","misp-galaxy:malpedia=\"Lumma Stealer\"","misp-galaxy:malpedia=\"Latrodectus\"","misp-galaxy:malpedia=\"Havoc\"","misp-galaxy:malpedia=\"ClearFake\"","ClickFix","Palo Alto Networks Unit 42","Clipboard hijacking","Latrodectus","Lumma Stealer","NetSupportRAT","Typosquatting","windows","misp-galaxy:sector=\"Legal\""],"event":["misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Clipboard Data - T1115\"","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:malpedia=\"NetSupportManager RAT\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","DocuSign","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"High tech\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Retail\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Hospitality\"","misp-galaxy:sector=\"Pharmacy\"","misp-galaxy:sector=\"Telecoms\"","osint:source-type=\"blog-post\"","tlp:clear","feedly:feedly-ai","feedly:source=\"Unit 42\"","misp-galaxy:mitre-attack-pattern=\"DLL - T1574.001\"","misp-galaxy:mitre-attack-pattern=\"AutoHotKey & AutoIT - T1059.010\"","misp-galaxy:mitre-attack-pattern=\"Malvertising - T1583.008\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious Copy and Paste - T1204.004\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Task or Service - T1036.004\"","misp-galaxy:mitre-attack-pattern=\"Msiexec - T1218.007\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Dynamic API Resolution - T1027.007\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Mutual Exclusion - T1480.002\"","misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"","misp-galaxy:mitre-attack-pattern=\"Command Obfuscation - T1027.010\"","misp-galaxy:mitre-malware=\"Lumma Stealer - S1213\"","misp-galaxy:mitre-malware=\"Latrodectus - S1160\"","misp-galaxy:malpedia=\"lampion\"","misp-galaxy:malpedia=\"Lumma Stealer\"","misp-galaxy:malpedia=\"Latrodectus\"","misp-galaxy:malpedia=\"Havoc\"","misp-galaxy:malpedia=\"ClearFake\"","ClickFix","Palo Alto Networks Unit 42","Clipboard hijacking","Latrodectus","Lumma Stealer","NetSupportRAT","Typosquatting","windows","misp-galaxy:sector=\"Legal\""],"all":["ClickFix","Clipboard hijacking","DocuSign","Latrodectus","Lumma Stealer","NetSupportRAT","Palo Alto Networks Unit 42","Typosquatting","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","feedly:feedly-ai","feedly:source=\"Unit 42\"","misp-galaxy:malpedia=\"ClearFake\"","misp-galaxy:malpedia=\"Havoc\"","misp-galaxy:malpedia=\"Latrodectus\"","misp-galaxy:malpedia=\"Lumma Stealer\"","misp-galaxy:malpedia=\"NetSupportManager RAT\"","misp-galaxy:malpedia=\"lampion\"","misp-galaxy:mitre-attack-pattern=\"AutoHotKey & AutoIT - T1059.010\"","misp-galaxy:mitre-attack-pattern=\"Clipboard Data - T1115\"","misp-galaxy:mitre-attack-pattern=\"Command Obfuscation - T1027.010\"","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"DLL - T1574.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"Dynamic API Resolution - T1027.007\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Malicious Copy and Paste - T1204.004\"","misp-galaxy:mitre-attack-pattern=\"Malvertising - T1583.008\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Task or Service - T1036.004\"","misp-galaxy:mitre-attack-pattern=\"Msiexec - T1218.007\"","misp-galaxy:mitre-attack-pattern=\"Mutual Exclusion - T1480.002\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"","misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"","misp-galaxy:mitre-malware=\"Latrodectus - S1160\"","misp-galaxy:mitre-malware=\"Lumma Stealer - S1213\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"High tech\"","misp-galaxy:sector=\"Hospitality\"","misp-galaxy:sector=\"Legal\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Pharmacy\"","misp-galaxy:sector=\"Retail\"","misp-galaxy:sector=\"Telecoms\"","osint:source-type=\"blog-post\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Fix the Click: Preventing the ClickFix Attack Vector","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"532624cd75bfb2645c4d9152a52d97f1f782ede50288ab5b06e8d0a3dba20bbc","normalized_value":"532624cd75bfb2645c4d9152a52d97f1f782ede50288ab5b06e8d0a3dba20bbc","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"676f576d-3136-4337-870c-a585f2d8c626","attribute_id":"37528674","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082383","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Remcos","AsyncRAT","opendir","vbs","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["AsyncRAT","Remcos","opendir","tlp:white","type:OSINT","ua-wget","vbs"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5346c531627987f260c115b3839aeb729cdc1d43ab2fe79f522b8da6672e3bf7","normalized_value":"5346c531627987f260c115b3839aeb729cdc1d43ab2fe79f522b8da6672e3bf7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4a636ec2-e9a8-485f-96cf-f97efe840795","attribute_id":"37528480","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783060467","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"53e00f1e8d2d6aa2d8a0eda2bf2d924fbc6f67db12ac3238d7c4b4520de7fadc","normalized_value":"53e00f1e8d2d6aa2d8a0eda2bf2d924fbc6f67db12ac3238d7c4b4520de7fadc","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"743ce8a1-0220-4f1e-a9ec-2e76bff1f7d6","attribute_id":"34370346","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581073","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"53ed971b48ae0b2ff6bcdd7bf4e8970d6eac3e7cdcd3ae6fa05860b9e5ac58ee","normalized_value":"53ed971b48ae0b2ff6bcdd7bf4e8970d6eac3e7cdcd3ae6fa05860b9e5ac58ee","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"64d8a43f-4065-45b0-92d8-986d378206d6","attribute_id":"34370382","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581108","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"540ee1936e61d2344b5ebc93485589a351ec2f113a9b4940ae16f3baa4807392","normalized_value":"540ee1936e61d2344b5ebc93485589a351ec2f113a9b4940ae16f3baa4807392","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"93514a3d-949e-4706-8b0a-712ec2c44833","attribute_id":"37752141","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529371","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"54479fbb2f3c8c16714e526925537e738b1b586310c8d15ce10f33327392e879","normalized_value":"54479fbb2f3c8c16714e526925537e738b1b586310c8d15ce10f33327392e879","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"41f6d81d-867a-4860-9fe2-4afd818b34b0","attribute_id":"34370361","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581087","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9","normalized_value":"54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ed5e8a30-915e-4a4b-be92-96d71c291e8e","attribute_id":"37755442","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140559","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--9e350404-ab8a-521f-9dbb-f8747203cb6e","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--9e350404-ab8a-521f-9dbb-f8747203cb6e","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"551aa018350fcf2b435b4d361dd4f117349a5136851f84ac10c02da1526e4e67","normalized_value":"551aa018350fcf2b435b4d361dd4f117349a5136851f84ac10c02da1526e4e67","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e8b9a1d4-34d6-4cff-96ec-e88f6b0a0599","attribute_id":"37524529","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:39.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5525784bfcc0c3340da0289ab8a5aed5565e73dc7246366b246ff000f7757ac5","normalized_value":"5525784bfcc0c3340da0289ab8a5aed5565e73dc7246366b246ff000f7757ac5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1eab0d90-6ffa-4b5d-829c-d2afa16e6fe5","attribute_id":"37523524","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146561","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5525784bfcc0c3340da0289ab8a5aed5565e73dc7246366b246ff000f7757ac5","normalized_value":"5525784bfcc0c3340da0289ab8a5aed5565e73dc7246366b246ff000f7757ac5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"23afe136-3692-40af-b023-b5ff121df61e","attribute_id":"37524481","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:55.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"55489cc3ce1f7d3129f1bebc8103631692993a66bc05f5e136ad3f4760c13fe7","normalized_value":"55489cc3ce1f7d3129f1bebc8103631692993a66bc05f5e136ad3f4760c13fe7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e34fea99-7f03-4c85-a6d5-553e8cb66b5b","attribute_id":"37528334","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783041644","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5633bc0033fde3aad929d6cbd47c554e264180360b017aae04687c2d6d83f753","normalized_value":"5633bc0033fde3aad929d6cbd47c554e264180360b017aae04687c2d6d83f753","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e967a999-46ad-43c4-9a1c-8f7d9f5b011b","attribute_id":"37755162","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140405","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--d31f2d6c-471c-5fee-9376-b4a48138a3f5","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--d31f2d6c-471c-5fee-9376-b4a48138a3f5","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"56692bacf62805a187f27e0cbb7d52d335abfc014d44e7d6fef9096b09d7f118","normalized_value":"56692bacf62805a187f27e0cbb7d52d335abfc014d44e7d6fef9096b09d7f118","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a53c5d26-a387-47de-9695-f33a168eb14e","attribute_id":"37523239","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783130247","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","censys","ClickFix","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ClickFix","censys","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"571131d40c836c5f50e831e2b0605c79194268e15dcc2878dae87026cc0a1473","normalized_value":"571131d40c836c5f50e831e2b0605c79194268e15dcc2878dae87026cc0a1473","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2a62915a-1bf1-49fa-a5b2-bf03a7f871e0","attribute_id":"37523700","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783151524","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"572d88c419c6ae75aeb784ceab327d040cb589903d6285bbffa77338111af14b","normalized_value":"572d88c419c6ae75aeb784ceab327d040cb589903d6285bbffa77338111af14b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"598fd35f-0911-4877-90fc-84b324b7bbe0","attribute_id":"37746552","event_id":"60930","event_uuid":"aba80fe0-808e-48aa-885d-1c424c819cbb","event_info":"Inside the Dragon: DragonForce Ransomware Group","event_date":"2024-09-27","attribute_timestamp":"1783557836","event_timestamp":"1784263639","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Mimikatz","misp-galaxy:target-information=\"Argentina\"","misp-galaxy:target-information=\"Australia\"","misp-galaxy:target-information=\"Canada\"","misp-galaxy:target-information=\"Colombia\"","misp-galaxy:target-information=\"France\"","misp-galaxy:target-information=\"Ireland\"","misp-galaxy:target-information=\"Italy\"","misp-galaxy:target-information=\"Spain\"","misp-galaxy:target-information=\"Sweden\"","misp-galaxy:target-information=\"United Kingdom\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:target-information=\"China\"","misp-galaxy:target-information=\"Czech Republic\"","misp-galaxy:target-information=\"India\"","misp-galaxy:target-information=\"Malaysia\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Food\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Hospitality\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Retail\"","misp-galaxy:sector=\"Sport\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Domain Trust Discovery - T1482\"","misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"","misp-galaxy:mitre-attack-pattern=\"System Network Configuration Discovery - T1016\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","tlp:clear"," Cobalt Strike","misp-galaxy:target-information=\"Belgium\"","misp-galaxy:target-information=\"Curaçao\"","misp-galaxy:target-information=\"Switzerland\"","misp-galaxy:target-information=\"New Zealand\"","misp-galaxy:target-information=\"Palau\"","misp-galaxy:target-information=\"Singapore\"","misp-galaxy:target-information=\"United Arab Emirates\"","misp-galaxy:sector=\"Engineering\"","misp-galaxy:sector=\"Marketing\"","misp-galaxy:sector=\"Security Service\"","misp-galaxy:sector=\"Tourism\"","misp-galaxy:mitre-attack-pattern=\"Domain Accounts - T1078.002\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"","misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","Cobalt Strike"],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Mimikatz","misp-galaxy:target-information=\"Argentina\"","misp-galaxy:target-information=\"Australia\"","misp-galaxy:target-information=\"Canada\"","misp-galaxy:target-information=\"Colombia\"","misp-galaxy:target-information=\"France\"","misp-galaxy:target-information=\"Ireland\"","misp-galaxy:target-information=\"Italy\"","misp-galaxy:target-information=\"Spain\"","misp-galaxy:target-information=\"Sweden\"","misp-galaxy:target-information=\"United Kingdom\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:target-information=\"China\"","misp-galaxy:target-information=\"Czech Republic\"","misp-galaxy:target-information=\"India\"","misp-galaxy:target-information=\"Malaysia\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Food\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Hospitality\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Retail\"","misp-galaxy:sector=\"Sport\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Domain Trust Discovery - T1482\"","misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"","misp-galaxy:mitre-attack-pattern=\"System Network Configuration Discovery - T1016\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","tlp:clear"," Cobalt Strike","misp-galaxy:target-information=\"Belgium\"","misp-galaxy:target-information=\"Curaçao\"","misp-galaxy:target-information=\"Switzerland\"","misp-galaxy:target-information=\"New Zealand\"","misp-galaxy:target-information=\"Palau\"","misp-galaxy:target-information=\"Singapore\"","misp-galaxy:target-information=\"United Arab Emirates\"","misp-galaxy:sector=\"Engineering\"","misp-galaxy:sector=\"Marketing\"","misp-galaxy:sector=\"Security Service\"","misp-galaxy:sector=\"Tourism\"","misp-galaxy:mitre-attack-pattern=\"Domain Accounts - T1078.002\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"","misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","Cobalt Strike"],"all":[" Cobalt Strike","Cobalt Strike","Mimikatz","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Domain Accounts - T1078.002\"","misp-galaxy:mitre-attack-pattern=\"Domain Trust Discovery - T1482\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"","misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Network Configuration Discovery - T1016\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Engineering\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Food\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Hospitality\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Marketing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Retail\"","misp-galaxy:sector=\"Security Service\"","misp-galaxy:sector=\"Sport\"","misp-galaxy:sector=\"Tourism\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"Argentina\"","misp-galaxy:target-information=\"Australia\"","misp-galaxy:target-information=\"Belgium\"","misp-galaxy:target-information=\"Canada\"","misp-galaxy:target-information=\"China\"","misp-galaxy:target-information=\"Colombia\"","misp-galaxy:target-information=\"Curaçao\"","misp-galaxy:target-information=\"Czech Republic\"","misp-galaxy:target-information=\"France\"","misp-galaxy:target-information=\"India\"","misp-galaxy:target-information=\"Ireland\"","misp-galaxy:target-information=\"Italy\"","misp-galaxy:target-information=\"Malaysia\"","misp-galaxy:target-information=\"New Zealand\"","misp-galaxy:target-information=\"Palau\"","misp-galaxy:target-information=\"Singapore\"","misp-galaxy:target-information=\"Spain\"","misp-galaxy:target-information=\"Sweden\"","misp-galaxy:target-information=\"Switzerland\"","misp-galaxy:target-information=\"United Arab Emirates\"","misp-galaxy:target-information=\"United Kingdom\"","misp-galaxy:target-information=\"United States\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Inside the Dragon: DragonForce Ransomware Group","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"576c70e12be8b2e8e7c35a5feb082e90621989adce8e64400126918d37f13e49","normalized_value":"576c70e12be8b2e8e7c35a5feb082e90621989adce8e64400126918d37f13e49","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"de90237d-b2d8-4d3a-af43-4920735f91c0","attribute_id":"37755161","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140405","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--f33dd430-fc96-504f-9516-fae35aee74a2","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--f33dd430-fc96-504f-9516-fae35aee74a2","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5787723b2221464337e6bbe4200aab912f1f711447224e4e6c4c96c451ff41bf","normalized_value":"5787723b2221464337e6bbe4200aab912f1f711447224e4e6c4c96c451ff41bf","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9390a8d7-edcb-4677-8ab7-fb8a5c0fb8dc","attribute_id":"34370337","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581065","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"57d26f045da134f570eb745cee88057c0c3872d6aeab9477fc17ae46853e93c2","normalized_value":"57d26f045da134f570eb745cee88057c0c3872d6aeab9477fc17ae46853e93c2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"71f1f60d-7741-11f1-97fa-42010aa4000a","attribute_id":"37521690","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125839","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Creal Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Creal Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"57d26f045da134f570eb745cee88057c0c3872d6aeab9477fc17ae46853e93c2","normalized_value":"57d26f045da134f570eb745cee88057c0c3872d6aeab9477fc17ae46853e93c2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c194460d-feb2-4f73-982a-7e802b7a2132","attribute_id":"37528960","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:59.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Creal Stealer","misp-galaxy:malpedia=\"Creal Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Creal Stealer","misp-galaxy:malpedia=\"Creal Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"57e75c98b22d1453da5b2642c8daf6c363c60552e77a52ad154c200187d20b9a","normalized_value":"57e75c98b22d1453da5b2642c8daf6c363c60552e77a52ad154c200187d20b9a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f010ec0f-7f79-4a6a-9c36-ae31ac1e3ceb","attribute_id":"46502","event_id":"410","event_uuid":"568e08e1-0d11-5880-b306-f8b7abfc28c6","event_info":"Fix the Click: Preventing the ClickFix Attack Vector","event_date":"2025-07-10","attribute_timestamp":"1783666969","event_timestamp":"1784392767","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Clipboard Data - T1115\"","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:malpedia=\"NetSupportManager RAT\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","DocuSign","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"High tech\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Retail\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Hospitality\"","misp-galaxy:sector=\"Pharmacy\"","misp-galaxy:sector=\"Telecoms\"","osint:source-type=\"blog-post\"","tlp:clear","feedly:feedly-ai","feedly:source=\"Unit 42\"","misp-galaxy:mitre-attack-pattern=\"DLL - T1574.001\"","misp-galaxy:mitre-attack-pattern=\"AutoHotKey & AutoIT - T1059.010\"","misp-galaxy:mitre-attack-pattern=\"Malvertising - T1583.008\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious Copy and Paste - T1204.004\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Task or Service - T1036.004\"","misp-galaxy:mitre-attack-pattern=\"Msiexec - T1218.007\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Dynamic API Resolution - T1027.007\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Mutual Exclusion - T1480.002\"","misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"","misp-galaxy:mitre-attack-pattern=\"Command Obfuscation - T1027.010\"","misp-galaxy:mitre-malware=\"Lumma Stealer - S1213\"","misp-galaxy:mitre-malware=\"Latrodectus - S1160\"","misp-galaxy:malpedia=\"lampion\"","misp-galaxy:malpedia=\"Lumma Stealer\"","misp-galaxy:malpedia=\"Latrodectus\"","misp-galaxy:malpedia=\"Havoc\"","misp-galaxy:malpedia=\"ClearFake\"","ClickFix","Palo Alto Networks Unit 42","Clipboard hijacking","Latrodectus","Lumma Stealer","NetSupportRAT","Typosquatting","windows","misp-galaxy:sector=\"Legal\""],"event":["misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Clipboard Data - T1115\"","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:malpedia=\"NetSupportManager RAT\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","DocuSign","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"High tech\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Retail\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Hospitality\"","misp-galaxy:sector=\"Pharmacy\"","misp-galaxy:sector=\"Telecoms\"","osint:source-type=\"blog-post\"","tlp:clear","feedly:feedly-ai","feedly:source=\"Unit 42\"","misp-galaxy:mitre-attack-pattern=\"DLL - T1574.001\"","misp-galaxy:mitre-attack-pattern=\"AutoHotKey & AutoIT - T1059.010\"","misp-galaxy:mitre-attack-pattern=\"Malvertising - T1583.008\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious Copy and Paste - T1204.004\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Task or Service - T1036.004\"","misp-galaxy:mitre-attack-pattern=\"Msiexec - T1218.007\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Dynamic API Resolution - T1027.007\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Mutual Exclusion - T1480.002\"","misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"","misp-galaxy:mitre-attack-pattern=\"Command Obfuscation - T1027.010\"","misp-galaxy:mitre-malware=\"Lumma Stealer - S1213\"","misp-galaxy:mitre-malware=\"Latrodectus - S1160\"","misp-galaxy:malpedia=\"lampion\"","misp-galaxy:malpedia=\"Lumma Stealer\"","misp-galaxy:malpedia=\"Latrodectus\"","misp-galaxy:malpedia=\"Havoc\"","misp-galaxy:malpedia=\"ClearFake\"","ClickFix","Palo Alto Networks Unit 42","Clipboard hijacking","Latrodectus","Lumma Stealer","NetSupportRAT","Typosquatting","windows","misp-galaxy:sector=\"Legal\""],"all":["ClickFix","Clipboard hijacking","DocuSign","Latrodectus","Lumma Stealer","NetSupportRAT","Palo Alto Networks Unit 42","Typosquatting","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","feedly:feedly-ai","feedly:source=\"Unit 42\"","misp-galaxy:malpedia=\"ClearFake\"","misp-galaxy:malpedia=\"Havoc\"","misp-galaxy:malpedia=\"Latrodectus\"","misp-galaxy:malpedia=\"Lumma Stealer\"","misp-galaxy:malpedia=\"NetSupportManager RAT\"","misp-galaxy:malpedia=\"lampion\"","misp-galaxy:mitre-attack-pattern=\"AutoHotKey & AutoIT - T1059.010\"","misp-galaxy:mitre-attack-pattern=\"Clipboard Data - T1115\"","misp-galaxy:mitre-attack-pattern=\"Command Obfuscation - T1027.010\"","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"DLL - T1574.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"Dynamic API Resolution - T1027.007\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Malicious Copy and Paste - T1204.004\"","misp-galaxy:mitre-attack-pattern=\"Malvertising - T1583.008\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Task or Service - T1036.004\"","misp-galaxy:mitre-attack-pattern=\"Msiexec - T1218.007\"","misp-galaxy:mitre-attack-pattern=\"Mutual Exclusion - T1480.002\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"","misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"","misp-galaxy:mitre-malware=\"Latrodectus - S1160\"","misp-galaxy:mitre-malware=\"Lumma Stealer - S1213\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"High tech\"","misp-galaxy:sector=\"Hospitality\"","misp-galaxy:sector=\"Legal\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Pharmacy\"","misp-galaxy:sector=\"Retail\"","misp-galaxy:sector=\"Telecoms\"","osint:source-type=\"blog-post\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Fix the Click: Preventing the ClickFix Attack Vector","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"58338a93fee4e008ea28e459c4d1598313d1524763ab13894ab63bf2bec4302a","normalized_value":"58338a93fee4e008ea28e459c4d1598313d1524763ab13894ab63bf2bec4302a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"15de4726-97b8-4bb4-adb4-8d0c99ab632f","attribute_id":"37755160","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140404","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--fa0505b2-c51b-5bd7-98ff-0916ea16dce3","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--fa0505b2-c51b-5bd7-98ff-0916ea16dce3","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5837e47198a20877e1b04b270c36d9194206ee38d4f32fe3151b3c3b396c4f0d","normalized_value":"5837e47198a20877e1b04b270c36d9194206ee38d4f32fe3151b3c3b396c4f0d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0a54ebac-9ab2-41dc-bd1c-90dc22a51d88","attribute_id":"37752158","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"58a919673d1c3d581fe9e14a437a94297a77cce098191c286d5021a2211d6130","normalized_value":"58a919673d1c3d581fe9e14a437a94297a77cce098191c286d5021a2211d6130","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7378f325-5cbb-484a-8ee3-4dbb510fd3b8","attribute_id":"37528906","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:17.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ratonrat","misp-galaxy:malpedia=\"RatonRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["misp-galaxy:malpedia=\"RatonRAT\"","osint:source-type=\"block-or-filter-list\"","ratonrat","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"58a919673d1c3d581fe9e14a437a94297a77cce098191c286d5021a2211d6130","normalized_value":"58a919673d1c3d581fe9e14a437a94297a77cce098191c286d5021a2211d6130","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7c7be6a6-7741-11f1-97fa-42010aa4000a","attribute_id":"37521692","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125857","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"RatonRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"RatonRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed","normalized_value":"58aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0442d60f-1ad5-4322-81cf-69c1d177966f","attribute_id":"37751396","event_id":"60979","event_uuid":"fea39f60-0010-477f-b097-b30d1547c5a4","event_info":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","event_date":"2026-07-17","attribute_timestamp":"1784273256","event_timestamp":"1784273257","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"event":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"all":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"592300a78fd752a1432b93f4a7699d23836508c61cb3a52fbb4abd0f5e98e285","normalized_value":"592300a78fd752a1432b93f4a7699d23836508c61cb3a52fbb4abd0f5e98e285","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d8acaa52-e476-4324-8915-80e54ffd4411","attribute_id":"37523281","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783133890","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5971c4311611d94ae809f00b0ac2142e3e2db8b9a7ee5851ccd6321274c20c73","normalized_value":"5971c4311611d94ae809f00b0ac2142e3e2db8b9a7ee5851ccd6321274c20c73","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6c3e7785-7741-11f1-97fa-42010aa4000a","attribute_id":"37521695","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125829","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Formbook payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Formbook payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5971c4311611d94ae809f00b0ac2142e3e2db8b9a7ee5851ccd6321274c20c73","normalized_value":"5971c4311611d94ae809f00b0ac2142e3e2db8b9a7ee5851ccd6321274c20c73","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d3b5b84c-c004-41d3-afb1-6365118cf7ce","attribute_id":"37528992","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:49.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"59a260716d05c20229c6a46fe0a2fb5b80fa30c9c73a850222d9d3454426a60a","normalized_value":"59a260716d05c20229c6a46fe0a2fb5b80fa30c9c73a850222d9d3454426a60a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ed5b8227-78ca-4fd2-b595-0558e5c67580","attribute_id":"37521410","event_id":"58527","event_uuid":"bb3d2aed-e7ff-4097-b022-849110a41ab8","event_info":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","event_date":"2026-07-06","attribute_timestamp":"1783319885","event_timestamp":"1783319886","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"event":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"all":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347","normalized_value":"59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b07572b1-d67a-49fd-992e-b119b1757ea9","attribute_id":"37755409","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140540","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--fe8d78cf-8bd2-53a0-990a-511b17f45bdd","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--fe8d78cf-8bd2-53a0-990a-511b17f45bdd","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"59e582776c777c32bdd25b39eb6cc09ad26064f699425c9bb889ad518c72fbd7","normalized_value":"59e582776c777c32bdd25b39eb6cc09ad26064f699425c9bb889ad518c72fbd7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a564fa20-20e5-417d-96f1-8a8cb240634e","attribute_id":"37523299","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783134670","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (ConnectWise)","event_extends_uuid":"","tags":{"attribute":["ConnectWise","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ConnectWise","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (ConnectWise)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5a2ed557c357ba8f96f2d55a8a00695987806b5df766cd1dfdab0cbed111774a","normalized_value":"5a2ed557c357ba8f96f2d55a8a00695987806b5df766cd1dfdab0cbed111774a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bf2542f4-75b1-45bd-9ed5-3d62b734a21b","attribute_id":"37752150","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5a67fd7e1f3bd5d1bca01efa7bd91407635d0c69e4d8924b0c4c87296dc11d40","normalized_value":"5a67fd7e1f3bd5d1bca01efa7bd91407635d0c69e4d8924b0c4c87296dc11d40","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"74265f83-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521697","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176094","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"ACR Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"ACR Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5a67fd7e1f3bd5d1bca01efa7bd91407635d0c69e4d8924b0c4c87296dc11d40","normalized_value":"5a67fd7e1f3bd5d1bca01efa7bd91407635d0c69e4d8924b0c4c87296dc11d40","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d6aaee31-e700-48d5-a604-141475927dc8","attribute_id":"37529344","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:34.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ACR Stealer","misp-galaxy:malpedia=\"ACR Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ACR Stealer","misp-galaxy:malpedia=\"ACR Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5ac5caec854c0f6a753870b6a6604d00b709b01a3cb61807255994edbfbf6d49","normalized_value":"5ac5caec854c0f6a753870b6a6604d00b709b01a3cb61807255994edbfbf6d49","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1a46c7ba-65ac-4fa7-8b94-6bf5ca1cb89c","attribute_id":"37528274","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783036963","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5b0aa6ccddf29703fe8a7799ca1b6dc56c8c3868538022861c932888bbe36fb6","normalized_value":"5b0aa6ccddf29703fe8a7799ca1b6dc56c8c3868538022861c932888bbe36fb6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"45d80633-85f1-4cfc-a6c6-3f67b6c199de","attribute_id":"7386010","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581355","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df","normalized_value":"5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a2d890a8-d5e7-47b5-9501-9284952990e7","attribute_id":"37755428","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140551","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--be2564dd-aa3b-5641-a566-67528b36d4ba","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--be2564dd-aa3b-5641-a566-67528b36d4ba","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5b4faea96a95e9d448af8710a08e959eb6c0e01af9af630f50ec8417f6440eab","normalized_value":"5b4faea96a95e9d448af8710a08e959eb6c0e01af9af630f50ec8417f6440eab","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"11dc5382-e35e-4e7f-ac64-db31ded9c7ea","attribute_id":"37528625","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783066556","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5bad7866c4a4fb5cc5015e4eb840920e128b78d51b2a96eebe943864fcc52376","normalized_value":"5bad7866c4a4fb5cc5015e4eb840920e128b78d51b2a96eebe943864fcc52376","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4fac6905-fa09-458a-b0be-c0456ee7bb27","attribute_id":"37523748","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783170747","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","censys","ClickFix","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ClickFix","censys","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5bcd63edfe85569733cd75e76cb89fa3e9b3628694fa66e23e953a6724cb3ed9","normalized_value":"5bcd63edfe85569733cd75e76cb89fa3e9b3628694fa66e23e953a6724cb3ed9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1137cac4-cd66-4f19-8610-fb3acb44efb8","attribute_id":"37524421","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:16.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5bcd63edfe85569733cd75e76cb89fa3e9b3628694fa66e23e953a6724cb3ed9","normalized_value":"5bcd63edfe85569733cd75e76cb89fa3e9b3628694fa66e23e953a6724cb3ed9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"82e7ecc5-2c80-491f-94ae-fd35d2b42f2e","attribute_id":"37523370","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146554","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5cd04805f9753ca08b82e88c27bf5426d1d356bb26b281885573051048911367","normalized_value":"5cd04805f9753ca08b82e88c27bf5426d1d356bb26b281885573051048911367","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5a7571c8-6f4b-4460-a650-32d0f67e6b2f","attribute_id":"35015718","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558067","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"WastedLocker samples (sha256 hashes)","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WastedLocker samples (sha256 hashes)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5e06af187b45476ade0d953e834fced6197d0a33ac60c2575877660e26ab15e8","normalized_value":"5e06af187b45476ade0d953e834fced6197d0a33ac60c2575877660e26ab15e8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c4d2d99a-70e3-4d8f-aa5e-25ac33f54081","attribute_id":"37752145","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5e4cb6e2b0947184199d16f75a95da19e32ba730eeddf68dd6a2d65da7357e5e","normalized_value":"5e4cb6e2b0947184199d16f75a95da19e32ba730eeddf68dd6a2d65da7357e5e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6470e8f8-f676-467d-a787-ba5909e62f03","attribute_id":"37523263","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783131269","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","superh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","superh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5e4eb9f4385d946174ab9f26d773cf870afb150102e9f580ca530b70e10f61c5","normalized_value":"5e4eb9f4385d946174ab9f26d773cf870afb150102e9f580ca530b70e10f61c5","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"516a2e18-0ad5-4425-8375-d9a909d55978","attribute_id":"37529562","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101989","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5e9c2eb32e1c5e0e9f69c8eda4e5ff2ec9e46d43e75ce098b830016ae17f291a","normalized_value":"5e9c2eb32e1c5e0e9f69c8eda4e5ff2ec9e46d43e75ce098b830016ae17f291a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bfaa9c45-c741-4e69-aff2-1f3d17cb285c","attribute_id":"37771814","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483192","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5f078709543c9f97fed54bdb60879c83ea00aa038cf25ab88a1a555a880b596e","normalized_value":"5f078709543c9f97fed54bdb60879c83ea00aa038cf25ab88a1a555a880b596e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d2f07b7c-6f20-408a-b414-5110152beff0","attribute_id":"37524587","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:20.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5f94e59c132a7ed0e35b60146d973a728ab9f390c8291f9547cee26c56427738","normalized_value":"5f94e59c132a7ed0e35b60146d973a728ab9f390c8291f9547cee26c56427738","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2b629181-90ed-4d12-9a76-021def2d7f93","attribute_id":"37529163","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783149779","event_timestamp":"1783231919","first_seen":"2026-07-04T05:10:22.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n100","event_extends_uuid":"","tags":{"attribute":["dropper","Android","apk ","craxsrat","misp-galaxy:mandiant-malware-family=\"f5acf861-c801-4961-9154-f3dcabc198e4\"","SafeRussia","misp-galaxy:malpedia=\"CraxsRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Android","SafeRussia","apk ","craxsrat","dropper","misp-galaxy:malpedia=\"CraxsRAT\"","misp-galaxy:mandiant-malware-family=\"f5acf861-c801-4961-9154-f3dcabc198e4\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n100","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5f94e59c132a7ed0e35b60146d973a728ab9f390c8291f9547cee26c56427738","normalized_value":"5f94e59c132a7ed0e35b60146d973a728ab9f390c8291f9547cee26c56427738","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"99c3255d-7705-11f1-97fa-42010aa4000a","attribute_id":"37521699","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783149022","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"CraxsRAT payload (confidence level: 100%)","event_extends_uuid":"","tags":{"attribute":["dropper","Android","apk ","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Android","apk ","dropper","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"CraxsRAT payload (confidence level: 100%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"5fcc9f3b514b853e8e9077ed4940538aba7b3044edbba28ca92ed37199292058","normalized_value":"5fcc9f3b514b853e8e9077ed4940538aba7b3044edbba28ca92ed37199292058","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f4165e07-6469-4874-8174-e62a8c31a997","attribute_id":"34346278","event_id":"51335","event_uuid":"39b2e10d-763c-44e8-a2c5-dee828c98f37","event_info":"KdcSponge, NGLite, Godzilla Webshell Used in Targeted Attack Campaign","event_date":"2021-11-09","attribute_timestamp":"1783686405","event_timestamp":"1783686416","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"13ac2113-2834-4088-a591-1f400c778f54","tags":{"attribute":["threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","cert-ist:malware_type=\"Webshell\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:enriched","cert-ist:confidence=\"medium\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_type=\"apt\"","tlp:clear"],"event":["threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","cert-ist:malware_type=\"Webshell\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:enriched","cert-ist:confidence=\"medium\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_type=\"apt\"","tlp:clear"],"all":["cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:confidence=\"medium\"","cert-ist:enriched","cert-ist:malware_type=\"Webshell\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:threat_type=\"apt\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","threat-report","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"KdcSponge, NGLite, Godzilla Webshell Used in Targeted Attack Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"607cb58b8a592885eef5cfbe35ddce962741b0775c575f58cb3a96ca0ee893a6","normalized_value":"607cb58b8a592885eef5cfbe35ddce962741b0775c575f58cb3a96ca0ee893a6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6f00fb5f-513e-4006-9933-b102c5b96be6","attribute_id":"37521409","event_id":"58527","event_uuid":"bb3d2aed-e7ff-4097-b022-849110a41ab8","event_info":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","event_date":"2026-07-06","attribute_timestamp":"1783319885","event_timestamp":"1783319886","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"event":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"all":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6082f79e85694bfa247dcb9fae7c5661f2ee2398e990a298de987615175755ad","normalized_value":"6082f79e85694bfa247dcb9fae7c5661f2ee2398e990a298de987615175755ad","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e79790b2-4356-40fc-8e14-6a59d5b2355d","attribute_id":"7386017","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581362","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"609ebd0f88a38653e61a25d6d68ec130c006eafb891085b7ce6dbcb299dfdc61","normalized_value":"609ebd0f88a38653e61a25d6d68ec130c006eafb891085b7ce6dbcb299dfdc61","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2809939a-05dd-40fb-98a4-9272f1ddae41","attribute_id":"37528486","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783060467","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"61232799da2bc49bb8c17ff355e8863ad5e64c47aed917311f56106f11b44917","normalized_value":"61232799da2bc49bb8c17ff355e8863ad5e64c47aed917311f56106f11b44917","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"e6e02002-e262-4812-98bf-d501d329c33e","attribute_id":"37529655","event_id":"58570","event_uuid":"73b7ed82-0d87-402a-adfd-2462e0268878","event_info":"Remcos host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101978","event_timestamp":"1783215210","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"61be40709d5c60fdb8c8ca54cf3cfccd16f2e86cf47ad8e3e17d045d6ab3bb05","normalized_value":"61be40709d5c60fdb8c8ca54cf3cfccd16f2e86cf47ad8e3e17d045d6ab3bb05","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d5768064-65a6-4016-91ef-3f8ded3a7e7d","attribute_id":"37751341","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783439275","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_07-07-2026 Adjunto_svg_ofuscated_cpl","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_07-07-2026 Adjunto_svg_ofuscated_cpl","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"623305edd87e280eecd50a340f8f5e94b8c5a416a8d457ef46f8a1fb3094bfbd","normalized_value":"623305edd87e280eecd50a340f8f5e94b8c5a416a8d457ef46f8a1fb3094bfbd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ce1874fb-a16b-41d7-86c6-d27f040ae50a","attribute_id":"37751348","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783622542","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_09-07-2026_Phishing_SVG","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_09-07-2026_Phishing_SVG","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"62a48bcb2d2f22017ce67b853654903464c19892a07a3c0ca020048cb049f0cd","normalized_value":"62a48bcb2d2f22017ce67b853654903464c19892a07a3c0ca020048cb049f0cd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c27d98c3-08e1-4f88-9c2c-7ccd098064d9","attribute_id":"34370388","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581114","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"62c83c1d1d9c25f424e9a0d36f3c9f7d7cfb13c72d606b055c9db784354d4320","normalized_value":"62c83c1d1d9c25f424e9a0d36f3c9f7d7cfb13c72d606b055c9db784354d4320","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c75e499e-b244-4a96-b0f0-fff6a2fab14d","attribute_id":"37528535","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783062896","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"62d519d2145d24a251dee3cf9b4b8cd72fb48bdb5697289e38a784e8fffe7003","normalized_value":"62d519d2145d24a251dee3cf9b4b8cd72fb48bdb5697289e38a784e8fffe7003","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6bcaafff-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521703","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176080","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Nanocore RAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Nanocore RAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"62d519d2145d24a251dee3cf9b4b8cd72fb48bdb5697289e38a784e8fffe7003","normalized_value":"62d519d2145d24a251dee3cf9b4b8cd72fb48bdb5697289e38a784e8fffe7003","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c9aa7855-fc90-4b53-a977-f30e8cb5616c","attribute_id":"37529348","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:20.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"62d519d2145d24a251dee3cf9b4b8cd72fb48bdb5697289e38a784e8fffe7003","normalized_value":"62d519d2145d24a251dee3cf9b4b8cd72fb48bdb5697289e38a784e8fffe7003","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"30f32562-e4c2-4d3b-a777-301a9c4e71dc","attribute_id":"37521457","event_id":"58543","event_uuid":"c4505b05-707b-43d6-be9e-7280c9f43b72","event_info":"Nanocore host indicators [2026-07-04]","event_date":"2026-07-04","attribute_timestamp":"1783148481","event_timestamp":"1783208131","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:malware-categorization=\"Rat\"","tlp:white","tlp:clear","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","tlp:clear","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Rat\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"62f1532516f3008ca2e15699e9862cd1c72eb84c7fb42289e81259d64c89b4f1","normalized_value":"62f1532516f3008ca2e15699e9862cd1c72eb84c7fb42289e81259d64c89b4f1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"37a0ef32-f316-44c9-86e3-a96181174e7c","attribute_id":"37528985","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:51.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"62f1532516f3008ca2e15699e9862cd1c72eb84c7fb42289e81259d64c89b4f1","normalized_value":"62f1532516f3008ca2e15699e9862cd1c72eb84c7fb42289e81259d64c89b4f1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6d58319a-7741-11f1-97fa-42010aa4000a","attribute_id":"37521704","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125831","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WannaCryptor payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WannaCryptor payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"62f16a144816655addc35fa23adb766203296c38b75452e6d30aa4a3a13df6b5","normalized_value":"62f16a144816655addc35fa23adb766203296c38b75452e6d30aa4a3a13df6b5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0056dc17-0a2e-417a-a4ef-94369bc35643","attribute_id":"37523377","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146554","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"62f16a144816655addc35fa23adb766203296c38b75452e6d30aa4a3a13df6b5","normalized_value":"62f16a144816655addc35fa23adb766203296c38b75452e6d30aa4a3a13df6b5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4cf9ed26-b586-48a7-8e66-cbf11c59b2d6","attribute_id":"37524477","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:57.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"63096f288f49b25d50f4aea52dc1fc00871b3927fa2a81fa0b0d752b261a3059","normalized_value":"63096f288f49b25d50f4aea52dc1fc00871b3927fa2a81fa0b0d752b261a3059","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ac67d1ef-2889-4de6-9103-936e13deeb5f","attribute_id":"7386085","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581281","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"63737ab4e5b5310e0468b3707e749c53609e9962ed0e4a19ab1ce2a358dcd3a4","normalized_value":"63737ab4e5b5310e0468b3707e749c53609e9962ed0e4a19ab1ce2a358dcd3a4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"49b776a8-32ff-4150-ade0-77a13930b41a","attribute_id":"37529349","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:05.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Monero Miner\"","misp-galaxy:malpedia=\"Coinminer\"","CoinMiner","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["CoinMiner","misp-galaxy:malpedia=\"Coinminer\"","misp-galaxy:malpedia=\"Monero Miner\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"63737ab4e5b5310e0468b3707e749c53609e9962ed0e4a19ab1ce2a358dcd3a4","normalized_value":"63737ab4e5b5310e0468b3707e749c53609e9962ed0e4a19ab1ce2a358dcd3a4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"62e1d1c4-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521705","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176065","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Coinminer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Coinminer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"63ad8faf3c2b306ccd8aa7874e24e7d48e0f6bbeeb37adab26c2efa1410022c4","normalized_value":"63ad8faf3c2b306ccd8aa7874e24e7d48e0f6bbeeb37adab26c2efa1410022c4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cb71293d-2b45-47d5-a4b9-ca7fbbf15716","attribute_id":"7386054","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581328","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"643de2a1cf9148b896efecf560c9476fa56118ec477c4e15eb5c2da4b318061f","normalized_value":"643de2a1cf9148b896efecf560c9476fa56118ec477c4e15eb5c2da4b318061f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"72373157-8d8f-4667-a3d2-2f0ef7caf68d","attribute_id":"37746209","event_id":"60922","event_uuid":"c76359e3-b520-43df-a2e4-adc41224a2d7","event_info":"Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems","event_date":"2026-07-16","attribute_timestamp":"1784171703","event_timestamp":"1784186616","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Ar70qICi (TencShell x86 variant) [VT: 16/63 malicious as of 2026-07-16]","event_extends_uuid":"","tags":{"attribute":["tlp:clear","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"","misp-galaxy:mitre-attack-pattern=\"Gather Victim Identity Information - T1589\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","NCSA"," C2","APT","Social Engineering","compromised"],"event":["tlp:clear","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"","misp-galaxy:mitre-attack-pattern=\"Gather Victim Identity Information - T1589\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","NCSA"," C2","APT","Social Engineering","compromised"],"all":[" C2","APT","NCSA","Social Engineering","compromised","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Gather Victim Identity Information - T1589\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Ar70qICi (TencShell x86 variant) [VT: 16/63 malicious as of 2026-07-16]","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6453182787fa76dc0043ca1fb77af822584066d02b1491b25ae042a40b140901","normalized_value":"6453182787fa76dc0043ca1fb77af822584066d02b1491b25ae042a40b140901","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6521c738-9a2c-4f82-af52-938b4d30155f","attribute_id":"37528340","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783041895","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"65736a4315b49718b68e1a72d24ff61e1b0537f2c2deb19f5bb339f2aa10e459","normalized_value":"65736a4315b49718b68e1a72d24ff61e1b0537f2c2deb19f5bb339f2aa10e459","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e3abc2ba-4b29-4c4f-bf86-fa7f83afe67f","attribute_id":"37524548","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:33.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["gcleaner","misp-galaxy:malpedia=\"GCleaner\"","misp-galaxy:mandiant-malware-family=\"ba0f5d6b-0db7-4e34-8db5-04d0e17444ba\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["gcleaner","misp-galaxy:malpedia=\"GCleaner\"","misp-galaxy:mandiant-malware-family=\"ba0f5d6b-0db7-4e34-8db5-04d0e17444ba\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"65c1a998bac48e02b52b1c850cd500e9fb87521e21755c3a4a491243f5f9a700","normalized_value":"65c1a998bac48e02b52b1c850cd500e9fb87521e21755c3a4a491243f5f9a700","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"15d4b5a0-9518-4118-853b-5d95be64bd60","attribute_id":"37752146","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"661f5870a5d8675719b95f123fa27c46bfcedd45001ce3479a9252b653940540","normalized_value":"661f5870a5d8675719b95f123fa27c46bfcedd45001ce3479a9252b653940540","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ca294a2a-89a5-4bf8-9e16-db419322a696","attribute_id":"69123","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686514","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865","normalized_value":"66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f81ef426-ec93-4502-a1ab-9fa56c1394ac","attribute_id":"37755408","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140539","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--698f6770-0f31-55d2-89a0-3985ffe5241d","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--698f6770-0f31-55d2-89a0-3985ffe5241d","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"674fc0b5ead7acd834747c2a568ef218640b7787a2201d4724dd8d43292904ce","normalized_value":"674fc0b5ead7acd834747c2a568ef218640b7787a2201d4724dd8d43292904ce","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f9e2d6de-84f7-49c3-acc6-10d4e12e8d9f","attribute_id":"37528346","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783041981","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"67aa3033ac68dadc36096277895080e9de3191d75541a884d761f4d38bd4a770","normalized_value":"67aa3033ac68dadc36096277895080e9de3191d75541a884d761f4d38bd4a770","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"d8e1ebe6-5aa4-4702-88f2-5e250ad44f99","attribute_id":"37529996","event_id":"58586","event_uuid":"4710d87c-7688-4d32-9365-b74b49008b28","event_info":"Remcos host indicators [2026-07-02]","event_date":"2026-07-02","attribute_timestamp":"1783018809","event_timestamp":"1783019655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6887fa9f10ad20a3a78cd33335a065ac9266cd2709ffa56d9f60877cbf3170a6","normalized_value":"6887fa9f10ad20a3a78cd33335a065ac9266cd2709ffa56d9f60877cbf3170a6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"922812ac-49fa-47d8-a7b6-a246373fde58","attribute_id":"7385987","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581383","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"68a1452172636b081873b9f7c1ae3794035c4ff50d5538b656caf07016b74d07","normalized_value":"68a1452172636b081873b9f7c1ae3794035c4ff50d5538b656caf07016b74d07","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7d29009e-4954-4979-92b8-9b47d816eac4","attribute_id":"34370376","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581102","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"68cf2072515bb9cf6ad418615c1f52dcdf24ca1ee46d115a3de2146d1d40d59e","normalized_value":"68cf2072515bb9cf6ad418615c1f52dcdf24ca1ee46d115a3de2146d1d40d59e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"45c18b6a-69c2-43d8-8094-c2bbc0abae86","attribute_id":"7385970","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581394","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"68eb2d2d7866775d6bf106a914281491d23769a9eda88fc078328150b8432bb3","normalized_value":"68eb2d2d7866775d6bf106a914281491d23769a9eda88fc078328150b8432bb3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6ca6f962-ed7a-407f-87f6-87e7f840afef","attribute_id":"7386089","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581286","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"695646d788062d36fb6925823c9bb59610cfc5b92fc16600527038d4e5f6a2cd","normalized_value":"695646d788062d36fb6925823c9bb59610cfc5b92fc16600527038d4e5f6a2cd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"16e349e1-ebf1-4a14-8d8f-fd08e6726394","attribute_id":"37523107","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162510","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","opendir","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6959bbbe345b9699282b8a599b6a65e53731720905e2a40aaca16fa796ffe767","normalized_value":"6959bbbe345b9699282b8a599b6a65e53731720905e2a40aaca16fa796ffe767","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"440e37e1-6fcd-4d78-b770-ffa9b8dd6748","attribute_id":"35285931","event_id":"54507","event_uuid":"234daefa-6a93-4240-80b8-23582ad75013","event_info":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","event_date":"2021-07-30","attribute_timestamp":"1783639110","event_timestamp":"1783639112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["tlp:white","threat-report"],"event":["tlp:white","threat-report"],"all":["threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"69775389eb0207fec3a3f5649a0ad9315856c810f595c086ac49d68cdbc1d136","normalized_value":"69775389eb0207fec3a3f5649a0ad9315856c810f595c086ac49d68cdbc1d136","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6f0dd356-ce5d-4d45-9a31-ee35fd77d2a3","attribute_id":"35015725","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558089","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Evil Corp - A Threat Actor with Multiple Alter Egos","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6a0f490846218d0e9cb7c57bed95ae22ca172affb19ab3ee89c20ca75add676b","normalized_value":"6a0f490846218d0e9cb7c57bed95ae22ca172affb19ab3ee89c20ca75add676b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"170bb355-d6eb-4a39-81e2-6af580a6a3a4","attribute_id":"37523251","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783131030","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["MALWARE","stealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["MALWARE","stealer","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6af02f9f08e5d6e9318ed302e4d74618148f7c600af1b394e05812b18b8ca040","normalized_value":"6af02f9f08e5d6e9318ed302e4d74618148f7c600af1b394e05812b18b8ca040","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4334ef7a-cb85-4d30-921b-4edccb71364d","attribute_id":"37529352","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:37.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6af02f9f08e5d6e9318ed302e4d74618148f7c600af1b394e05812b18b8ca040","normalized_value":"6af02f9f08e5d6e9318ed302e4d74618148f7c600af1b394e05812b18b8ca040","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7625c714-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521711","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176097","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Stealc payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Stealc payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6b311c0a977d21e772ac4e99762234da852bbf84293386fbe78622a96c0b052f","normalized_value":"6b311c0a977d21e772ac4e99762234da852bbf84293386fbe78622a96c0b052f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bc701a7e-bb2b-4d43-9cb0-12092e50182d","attribute_id":"37748489","event_id":"60948","event_uuid":"de525eea-c091-4fa7-8dc6-218ce63d53ad","event_info":"Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials","event_date":"2024-04-23","attribute_timestamp":"1783666995","event_timestamp":"1783666998","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Hash of GooseEgg binary justice.exe","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","OSINT","osint:source-type=\"blog-post\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","APT","Actor: APT28","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"United States\"","tlp:clear","Microsoft Corporation","windows","JavaScript","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:threat-actor=\"APT28\"","misp-galaxy:country=\"russia\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","PrintNightmare"],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","OSINT","osint:source-type=\"blog-post\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","APT","Actor: APT28","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"United States\"","tlp:clear","Microsoft Corporation","windows","JavaScript","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:threat-actor=\"APT28\"","misp-galaxy:country=\"russia\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","PrintNightmare"],"all":["APT","Actor: APT28","JavaScript","Microsoft Corporation","OSINT","PrintNightmare","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:country=\"russia\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:threat-actor=\"APT28\"","osint:source-type=\"blog-post\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Hash of GooseEgg binary justice.exe","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6bc2e11b0917f47d0557288c4f0cb20bd7589185943b989a969fdc6d3704ee73","normalized_value":"6bc2e11b0917f47d0557288c4f0cb20bd7589185943b989a969fdc6d3704ee73","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2b481f4f-892b-46a6-8723-c3d0259df03e","attribute_id":"37752140","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529371","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6bd34d33ccb47430751ae964ca56ec206da0fa3bdc5eb670fc54edf4c11629bc","normalized_value":"6bd34d33ccb47430751ae964ca56ec206da0fa3bdc5eb670fc54edf4c11629bc","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8073ce68-218b-4328-8e1d-09752a3a2063","attribute_id":"7385965","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581399","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6c109c0a95546cb495003464b596291095e5fc0a9502644b99eaa5cb5f1c0c3e","normalized_value":"6c109c0a95546cb495003464b596291095e5fc0a9502644b99eaa5cb5f1c0c3e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"168caec8-ba42-497b-aa85-c90e10e13da9","attribute_id":"37523023","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783173029","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","geofenced","USA","m68k","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","USA","elf","geofenced","m68k","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6c419d26fdf99bc352570d32094e9e78b06e5b3e3b5fb64989292593e58048b3","normalized_value":"6c419d26fdf99bc352570d32094e9e78b06e5b3e3b5fb64989292593e58048b3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"662f2d66-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521717","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176070","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6c419d26fdf99bc352570d32094e9e78b06e5b3e3b5fb64989292593e58048b3","normalized_value":"6c419d26fdf99bc352570d32094e9e78b06e5b3e3b5fb64989292593e58048b3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"979ded69-f252-41be-939b-39534ad5652d","attribute_id":"37529359","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:10.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6c419d26fdf99bc352570d32094e9e78b06e5b3e3b5fb64989292593e58048b3","normalized_value":"6c419d26fdf99bc352570d32094e9e78b06e5b3e3b5fb64989292593e58048b3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"be9a71c6-2b58-4602-a034-295f6989d5ad","attribute_id":"37523559","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146565","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6c84c701190032361e71713159e3c501810c42b56af1664d016f291e405c0e44","normalized_value":"6c84c701190032361e71713159e3c501810c42b56af1664d016f291e405c0e44","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f19a9909-ab44-43de-a0cf-9c4129826e52","attribute_id":"37528310","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783040316","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6c9ea909a5ad96f420da62f11b3a1aa83b426f98b853685531bf17e6c8e66e44","normalized_value":"6c9ea909a5ad96f420da62f11b3a1aa83b426f98b853685531bf17e6c8e66e44","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fe413ac0-2dee-42ea-b022-712b26990c82","attribute_id":"37523143","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125173","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6cd57dbf7ab873eb4def39ab547422021e676b09209692a67555c583839da493","normalized_value":"6cd57dbf7ab873eb4def39ab547422021e676b09209692a67555c583839da493","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e6863515-f893-4466-ad62-ba5cc45d99fe","attribute_id":"37528668","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082148","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Remcos","AsyncRAT","opendir","vbs","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["AsyncRAT","Remcos","opendir","tlp:white","type:OSINT","ua-wget","vbs"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6d32be92b12fa0a7f39fb49c2870673cd8bd8e89374eff5255725711372e9bcc","normalized_value":"6d32be92b12fa0a7f39fb49c2870673cd8bd8e89374eff5255725711372e9bcc","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"80221073-b58e-4eae-8c2c-c6e84c207dc2","attribute_id":"37523215","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783128866","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","PowerPC","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","PowerPC","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6db05c4473760c44fa572ffac4c5911b35caf2467a37726c21c5f87e25cb2ea8","normalized_value":"6db05c4473760c44fa572ffac4c5911b35caf2467a37726c21c5f87e25cb2ea8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c08d1dad-76f8-4aaa-94ae-9bc666cb826e","attribute_id":"37752276","event_id":"60998","event_uuid":"5d50bb0c-c021-4540-808f-bbd176218e0d","event_info":"Malicious GitHub Campaign Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer","event_date":"2026-07-22","attribute_timestamp":"1784704450","event_timestamp":"1784704564","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","malicious","tlp:clear","  Malware  "," infostealer"],"event":["NCSA","NCSA_Research","malicious","tlp:clear","  Malware  "," infostealer"],"all":["  Malware  "," infostealer","NCSA","NCSA_Research","malicious","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malicious GitHub Campaign Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac","normalized_value":"6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0551b7ac-a6a7-4d19-a982-4823bff7a57d","attribute_id":"37755407","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140538","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--596f7836-9419-5313-b663-c6744503e380","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--596f7836-9419-5313-b663-c6744503e380","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6e6d3a831c03b09d9e4a54859329fbfd428083f8f5bc5f27abbfdd9c47ec0e57","normalized_value":"6e6d3a831c03b09d9e4a54859329fbfd428083f8f5bc5f27abbfdd9c47ec0e57","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"77b58236-bb23-4942-9808-75fff4e29658","attribute_id":"6724983","event_id":"26690","event_uuid":"4678ed95-1726-4820-87ba-36a935367aa4","event_info":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","event_date":"2020-08-04","attribute_timestamp":"1783581149","event_timestamp":"1783581153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"event":["APT","misp-galaxy:target-information=\"United States\"","osint:source-type=\"technical-report\"","tlp:white"," Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:threat-actor=\"China APT\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","Remote Access Trojan"],"all":[" Remote Access Trojan","APT","Remote Access Trojan","misp-galaxy:mitre-attack-pattern=\"Connection Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Taidoor - G0015\"","misp-galaxy:mitre-malware=\"Taidoor - S0011\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:threat-actor=\"China APT\"","osint:source-type=\"technical-report\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware Analysis Report (AR20-216A) Chinese Remote Access Trojan: TAIDOOR","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6eaa4e25359d0b61c37a9884fbdb8c53bf00e8e9a5478e325e63338d0d2ad51b","normalized_value":"6eaa4e25359d0b61c37a9884fbdb8c53bf00e8e9a5478e325e63338d0d2ad51b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7d99bf31-7741-11f1-97fa-42010aa4000a","attribute_id":"37521720","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125858","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"CrossRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"CrossRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6eaa4e25359d0b61c37a9884fbdb8c53bf00e8e9a5478e325e63338d0d2ad51b","normalized_value":"6eaa4e25359d0b61c37a9884fbdb8c53bf00e8e9a5478e325e63338d0d2ad51b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e471218a-1b0f-43a5-9386-0b0acfb07219","attribute_id":"37528905","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:18.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["crossrat","misp-galaxy:malpedia=\"CrossRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["crossrat","misp-galaxy:malpedia=\"CrossRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6eaa4e25359d0b61c37a9884fbdb8c53bf00e8e9a5478e325e63338d0d2ad51b","normalized_value":"6eaa4e25359d0b61c37a9884fbdb8c53bf00e8e9a5478e325e63338d0d2ad51b","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"7148cf81-04d1-4d4b-a584-e0b40cc64d92","attribute_id":"37529992","event_id":"58586","event_uuid":"4710d87c-7688-4d32-9365-b74b49008b28","event_info":"Remcos host indicators [2026-07-02]","event_date":"2026-07-02","attribute_timestamp":"1783018809","event_timestamp":"1783019655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6ebd94209f4a45ea9919b17f13d6c07a6db2be45a399e9f8db989d7e961e0d83","normalized_value":"6ebd94209f4a45ea9919b17f13d6c07a6db2be45a399e9f8db989d7e961e0d83","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6a8a2f5d-7741-11f1-97fa-42010aa4000a","attribute_id":"37521721","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125826","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Formbook payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Formbook payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6ebd94209f4a45ea9919b17f13d6c07a6db2be45a399e9f8db989d7e961e0d83","normalized_value":"6ebd94209f4a45ea9919b17f13d6c07a6db2be45a399e9f8db989d7e961e0d83","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f69219fb-890d-4a3c-8bc0-f84c2445636a","attribute_id":"37529001","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:46.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6ed2f848536d84e6fd14eb4258f1f5ac95a1c3ad87dbc42c5b7fc5af812d06d7","normalized_value":"6ed2f848536d84e6fd14eb4258f1f5ac95a1c3ad87dbc42c5b7fc5af812d06d7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fa6a4c80-0b5e-407e-a5af-1be35ab53580","attribute_id":"37523779","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783192817","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","IoT","elf","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["IoT","Mirai","elf","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6f8075452b80f23418fd92e80429999ae270a6c4b88ce22cfb4223ba9853d6e1","normalized_value":"6f8075452b80f23418fd92e80429999ae270a6c4b88ce22cfb4223ba9853d6e1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"65249dfd-d1e8-47f2-8bb4-62c31f9aff5f","attribute_id":"37529360","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:30.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"6f8075452b80f23418fd92e80429999ae270a6c4b88ce22cfb4223ba9853d6e1","normalized_value":"6f8075452b80f23418fd92e80429999ae270a6c4b88ce22cfb4223ba9853d6e1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"71d9e341-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521722","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176090","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Venus Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Venus Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"70eae6d411554b0587f9bc3e7e7cc753e81b8086310dc5fa8181c44632fe1ada","normalized_value":"70eae6d411554b0587f9bc3e7e7cc753e81b8086310dc5fa8181c44632fe1ada","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"672e9c40-9713-422f-84e6-4f67187314f2","attribute_id":"942755","event_id":"4182","event_uuid":"0fab15db-e11a-4ca2-9506-ad66da1d8119","event_info":"Cobalt Strike Loaders Linked to Evil Corp Shared on Twitter","event_date":"2020-07-31","attribute_timestamp":"1783687095","event_timestamp":"1783687097","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Cobalt Strike\"","Partner Feed","Recorded Future","inthreat:event-src=\"feed-osint\"","tlp:white","misp-galaxy:threat-actor=\"INDRIK SPIDER\""],"event":["misp-galaxy:malpedia=\"Cobalt Strike\"","Partner Feed","Recorded Future","inthreat:event-src=\"feed-osint\"","tlp:white","misp-galaxy:threat-actor=\"INDRIK SPIDER\""],"all":["Partner Feed","Recorded Future","inthreat:event-src=\"feed-osint\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:threat-actor=\"INDRIK SPIDER\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Cobalt Strike Loaders Linked to Evil Corp Shared on Twitter","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"70fe7576f20f5dd6a3d872753c922f1394d91487f5eabb417b240b83c22e31b2","normalized_value":"70fe7576f20f5dd6a3d872753c922f1394d91487f5eabb417b240b83c22e31b2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"38147783-56d6-4a8f-afd7-d2f184d66310","attribute_id":"37755115","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112069","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--9a36be67-ac18-524d-8de4-24f6b6e8dd8c","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--9a36be67-ac18-524d-8de4-24f6b6e8dd8c","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"716608d7e9a26e980f916e73792abcb86bbb21fb949436b7f359afcaf730b078","normalized_value":"716608d7e9a26e980f916e73792abcb86bbb21fb949436b7f359afcaf730b078","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9e2cfeb4-104a-42bd-acbc-b2cbc19c0591","attribute_id":"37524512","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:45.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"71768f2099e7c880dfd25b5e20df9424d0967689abe6fd7cf4896941b8977cb0","normalized_value":"71768f2099e7c880dfd25b5e20df9424d0967689abe6fd7cf4896941b8977cb0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e372b7b3-5dba-49eb-ab29-15c55f518422","attribute_id":"7386030","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581347","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"71a395a22d8ad7421b7050c650187c771ea52d5820640b259d79dfcd8c4adb1b","normalized_value":"71a395a22d8ad7421b7050c650187c771ea52d5820640b259d79dfcd8c4adb1b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0841d189-c785-48c3-b961-6ca716967143","attribute_id":"37523173","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126826","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"71c142a6e398c3e631d5e6be4b554c120af4a6790e5f5dfe2957514eafc9673d","normalized_value":"71c142a6e398c3e631d5e6be4b554c120af4a6790e5f5dfe2957514eafc9673d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a10203b8-4078-4c95-9598-968ba189d6f8","attribute_id":"37528680","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082546","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7273a46d2d79c54ed184dd03b42a3e8e48bb9deaceca01936a6ebc754868c5af","normalized_value":"7273a46d2d79c54ed184dd03b42a3e8e48bb9deaceca01936a6ebc754868c5af","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"995b8045-a110-4cf5-8077-7db87dfd50ce","attribute_id":"37528686","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082546","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7286691d7986d2ba342adfc68697a81a3c7050ccbcad3ca4600f4205993c6588","normalized_value":"7286691d7986d2ba342adfc68697a81a3c7050ccbcad3ca4600f4205993c6588","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"33ecd198-f403-4b5e-9f2f-918166ca223a","attribute_id":"37528418","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783045776","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","Ngioweb","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Ngioweb","elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"73b1fffd35d3a72775e0ac4c836e70efefa0930551a2f813843bdfb32df4579a","normalized_value":"73b1fffd35d3a72775e0ac4c836e70efefa0930551a2f813843bdfb32df4579a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"92353fdf-d475-4212-a5b1-e2272dc957bc","attribute_id":"37229878","event_id":"57908","event_uuid":"4e87d89d-e1ea-4c1a-aaa7-f3979dabe12c","event_info":"Agenda Ransomware Propagates to vCenters and ESXi via Custom PowerShell Script","event_date":"2024-03-29","attribute_timestamp":"1783558013","event_timestamp":"1783558017","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"MalwareBazaar: Source: https://github.com/TheRavenFile/Daily-Hunt/blob/main/Qilin%20Ransomware","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Execution Guardrails - T1480\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Defense Evasion - T1211\"","osint:source-type=\"technical-report\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"","misp-galaxy:mitre-attack-pattern=\"SSH - T1021.004\"","misp-galaxy:mitre-attack-pattern=\"Lateral Tool Transfer - T1570\"","misp-galaxy:ransomware=\"Agenda Ransomware\"","ESXi","PowerShell_script","Trend Micro","tlp:white","ncsc-nl-ndn:feed=\"generic\""],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Execution Guardrails - T1480\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Defense Evasion - T1211\"","osint:source-type=\"technical-report\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"","misp-galaxy:mitre-attack-pattern=\"SSH - T1021.004\"","misp-galaxy:mitre-attack-pattern=\"Lateral Tool Transfer - T1570\"","misp-galaxy:ransomware=\"Agenda Ransomware\"","ESXi","PowerShell_script","Trend Micro","tlp:white","ncsc-nl-ndn:feed=\"generic\""],"all":["ESXi","PowerShell_script","Trend Micro","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Execution Guardrails - T1480\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Defense Evasion - T1211\"","misp-galaxy:mitre-attack-pattern=\"Lateral Tool Transfer - T1570\"","misp-galaxy:mitre-attack-pattern=\"SSH - T1021.004\"","misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"","misp-galaxy:ransomware=\"Agenda Ransomware\"","ncsc-nl-ndn:feed=\"generic\"","osint:source-type=\"technical-report\"","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"MalwareBazaar: Source: https://github.com/TheRavenFile/Daily-Hunt/blob/main/Qilin%20Ransomware","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"741eea6f598af241e1337ad567b7c6d52e601309a381f934ab6ce245c7906469","normalized_value":"741eea6f598af241e1337ad567b7c6d52e601309a381f934ab6ce245c7906469","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d2ab5132-52e3-419a-8b95-f42aba3c7d88","attribute_id":"37524427","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:14.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"741eea6f598af241e1337ad567b7c6d52e601309a381f934ab6ce245c7906469","normalized_value":"741eea6f598af241e1337ad567b7c6d52e601309a381f934ab6ce245c7906469","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e8cb0247-4b28-41c6-aa51-e97d6317645a","attribute_id":"37523489","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"74df3452a6b9dcdba658af7a9cf5afb09cce51534f9bc63079827bf73075243b","normalized_value":"74df3452a6b9dcdba658af7a9cf5afb09cce51534f9bc63079827bf73075243b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c87f6abf-cbce-414c-9f40-1d5b1e36d275","attribute_id":"37749120","event_id":"60955","event_uuid":"369b384c-ccbf-462c-aa79-a12b3eb6407c","event_info":"Exploring the (Not So) Secret Code of Black Hunt Ransomware","event_date":"2024-02-06","attribute_timestamp":"1783512321","event_timestamp":"1783512325","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Black Hunt ransomware","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\""," Ransomware","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Network Share Discovery - T1135\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","osint:source-type=\"technical-report\"","OSINT","tlp:clear","misp-galaxy:target-information=\"Paraguay\"","misp-galaxy:malpedia=\"LockBit (ELF)\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Bypass User Account Control - T1548.002\"","misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"Safe Mode Boot - T1562.009\"","misp-galaxy:mitre-attack-pattern=\"Hidden Window - T1564.003\"","misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","Ransomware"],"event":["admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\""," Ransomware","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Network Share Discovery - T1135\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","osint:source-type=\"technical-report\"","OSINT","tlp:clear","misp-galaxy:target-information=\"Paraguay\"","misp-galaxy:malpedia=\"LockBit (ELF)\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Bypass User Account Control - T1548.002\"","misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"Safe Mode Boot - T1562.009\"","misp-galaxy:mitre-attack-pattern=\"Hidden Window - T1564.003\"","misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","Ransomware"],"all":[" Ransomware","OSINT","Ransomware","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","misp-galaxy:malpedia=\"LockBit (ELF)\"","misp-galaxy:mitre-attack-pattern=\"Bypass User Account Control - T1548.002\"","misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Hidden Window - T1564.003\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"","misp-galaxy:mitre-attack-pattern=\"Network Share Discovery - T1135\"","misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Safe Mode Boot - T1562.009\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:target-information=\"Paraguay\"","osint:source-type=\"technical-report\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Black Hunt ransomware","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"74f90183362202e89f37c1616678c7a5a6ded5d2241d992d5b9efa7076fbc7d5","normalized_value":"74f90183362202e89f37c1616678c7a5a6ded5d2241d992d5b9efa7076fbc7d5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0f9d34d7-51ba-4a76-b8c8-ed1c2a075fc5","attribute_id":"37751349","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1784063796","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_14-07-2026_Phishing_SVG","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_14-07-2026_Phishing_SVG","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"74fd9bbdd8a484640e4b0405a1da84734a0a9c2604ac1b0a39fa2e28b0c12614","normalized_value":"74fd9bbdd8a484640e4b0405a1da84734a0a9c2604ac1b0a39fa2e28b0c12614","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8c5a7115-bebd-402c-a08c-579badc35b5e","attribute_id":"7386238","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581186","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7604fc93b4e521fd559dc4afd168d833f14ee63908cf733dfdfa8bab02a9d656","normalized_value":"7604fc93b4e521fd559dc4afd168d833f14ee63908cf733dfdfa8bab02a9d656","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e934ce4f-469d-4423-985e-75ca015711bc","attribute_id":"37524598","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:15.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7630246096e94226a10bb5b13165c9d90ff0ef993c9a3b0814aebda16fc342ae","normalized_value":"7630246096e94226a10bb5b13165c9d90ff0ef993c9a3b0814aebda16fc342ae","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bd1b3e50-6200-4715-b188-b793ff32daa5","attribute_id":"37528431","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783056803","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"765bfb5d7829184a23f615b871baebf893563d911dddd1d1c1a34604e5456cce","normalized_value":"765bfb5d7829184a23f615b871baebf893563d911dddd1d1c1a34604e5456cce","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"789a9c59-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521725","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176101","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Ghost RAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Ghost RAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"765bfb5d7829184a23f615b871baebf893563d911dddd1d1c1a34604e5456cce","normalized_value":"765bfb5d7829184a23f615b871baebf893563d911dddd1d1c1a34604e5456cce","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b2b81cf7-2515-435b-9ed9-f01da8ce925f","attribute_id":"37529363","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:41.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Ghost RAT\"","Ghost Rat","misp-galaxy:malpedia=\"ANGRYREBEL\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Ghost Rat","misp-galaxy:malpedia=\"ANGRYREBEL\"","misp-galaxy:malpedia=\"Ghost RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"770db614b0e7b3cd571f12eb94bc8b06c7c151f37c4ecc41656476bbb4d3084e","normalized_value":"770db614b0e7b3cd571f12eb94bc8b06c7c151f37c4ecc41656476bbb4d3084e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"50d26da7-e9a7-4943-909f-11c159476f1d","attribute_id":"37528388","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783043765","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7777f9917be9ce17233c35e1b38cbb34c45878c23e1b39d7956fa52cd7bb4983","normalized_value":"7777f9917be9ce17233c35e1b38cbb34c45878c23e1b39d7956fa52cd7bb4983","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ec33d4f2-d11d-411b-8bd7-63ec902b74d3","attribute_id":"37523336","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146368","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (RemcosRAT)","event_extends_uuid":"","tags":{"attribute":["RemcosRAT","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["RemcosRAT","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (RemcosRAT)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"77c6d0732cbe5f1fb1adbbf04885f40ffc7a617f0cc08bbfc0839fb399233c5f","normalized_value":"77c6d0732cbe5f1fb1adbbf04885f40ffc7a617f0cc08bbfc0839fb399233c5f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"51fa7ceb-5ade-4707-ae8e-bf89e93f4bba","attribute_id":"7385978","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581390","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"77f2de0a837eb3b6891f5984a542af71f559afb3d9e9e4e9d0b6cbf1f19a3dad","normalized_value":"77f2de0a837eb3b6891f5984a542af71f559afb3d9e9e4e9d0b6cbf1f19a3dad","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b1d00970-4221-4207-842b-a5aef318e4ba","attribute_id":"37524558","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:29.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"NetWire RC\"","Netwire RC","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Netwire RC","misp-galaxy:malpedia=\"NetWire RC\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8","normalized_value":"7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3214793d-7e9f-4f86-8c6a-21539c14b8a4","attribute_id":"37755406","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140538","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--ef44b068-2fe6-5799-afeb-ad7d18d44956","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--ef44b068-2fe6-5799-afeb-ad7d18d44956","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"78b8ea25449147ec183b1c4092ce18f43345647e183977fc5571c637e7e7418b","normalized_value":"78b8ea25449147ec183b1c4092ce18f43345647e183977fc5571c637e7e7418b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"991d0388-b95f-48f6-bad6-da13267954e7","attribute_id":"37523071","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162511","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","m68k","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","m68k","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"78ce14986dcd70c0fcf65e9a3dea518a6a66c17589dca2149134406d3e95c414","normalized_value":"78ce14986dcd70c0fcf65e9a3dea518a6a66c17589dca2149134406d3e95c414","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"746ecc95-7741-11f1-97fa-42010aa4000a","attribute_id":"37521729","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125843","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Coinminer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Coinminer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"78ce14986dcd70c0fcf65e9a3dea518a6a66c17589dca2149134406d3e95c414","normalized_value":"78ce14986dcd70c0fcf65e9a3dea518a6a66c17589dca2149134406d3e95c414","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ed53658d-566a-4c9a-a90c-29447ee85b7a","attribute_id":"37528951","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:03.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Monero Miner\"","misp-galaxy:malpedia=\"Coinminer\"","CoinMiner","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["CoinMiner","misp-galaxy:malpedia=\"Coinminer\"","misp-galaxy:malpedia=\"Monero Miner\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"79a2ef6dd3056588d046746120a10ef1fceec80bf05e4221598101115d9215e9","normalized_value":"79a2ef6dd3056588d046746120a10ef1fceec80bf05e4221598101115d9215e9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7fa4618b-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521730","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176113","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"ValleyRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"ValleyRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"79a2ef6dd3056588d046746120a10ef1fceec80bf05e4221598101115d9215e9","normalized_value":"79a2ef6dd3056588d046746120a10ef1fceec80bf05e4221598101115d9215e9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d696263d-2c53-40d9-a57b-a8315fb3f3c5","attribute_id":"37529365","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:53.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ValleyRAT","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","misp-galaxy:malpedia=\"ValleyRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ValleyRAT","misp-galaxy:malpedia=\"ValleyRAT\"","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7a17f4c1e1a0c21ea5ed8837383b641c28244adb39c0a3f47da4d47ebe080271","normalized_value":"7a17f4c1e1a0c21ea5ed8837383b641c28244adb39c0a3f47da4d47ebe080271","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2b1f1e06-78dd-4414-824a-dd18916dca63","attribute_id":"34891780","event_id":"54097","event_uuid":"3dd38b8c-5338-4ec6-98a1-084f56a8680c","event_info":"Malware Analysis Report (AR21-102A) MAR-10331466-1.v1: China Chopper Webshell","event_date":"2021-03-26","attribute_timestamp":"1783743718","event_timestamp":"1783743718","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["tlp:white","misp-galaxy:mitre-malware=\"China Chopper - S0020\"","misp-galaxy:tool=\"China Chopper\"","misp-galaxy:threat-actor=\"Hafnium\"","threat-report"],"event":["tlp:white","misp-galaxy:mitre-malware=\"China Chopper - S0020\"","misp-galaxy:tool=\"China Chopper\"","misp-galaxy:threat-actor=\"Hafnium\"","threat-report"],"all":["misp-galaxy:mitre-malware=\"China Chopper - S0020\"","misp-galaxy:threat-actor=\"Hafnium\"","misp-galaxy:tool=\"China Chopper\"","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware Analysis Report (AR21-102A) MAR-10331466-1.v1: China Chopper Webshell","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7a2a6726e3c26a67505dde920857b1f759a5b2ba6ead92604d668c167be31ce4","normalized_value":"7a2a6726e3c26a67505dde920857b1f759a5b2ba6ead92604d668c167be31ce4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d1bac07a-33cd-444d-8ebd-1584cdb4ac65","attribute_id":"37528830","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783089360","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7a5ddf0ddbe18b048b75dfe5153fc8ee5b6b5e8d9832c96ac7ea18591d272cdb","normalized_value":"7a5ddf0ddbe18b048b75dfe5153fc8ee5b6b5e8d9832c96ac7ea18591d272cdb","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2e75137e-abaf-4d36-a9c2-302533e29484","attribute_id":"37523137","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125167","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0","normalized_value":"7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b14345ac-0b1a-483a-9ef2-b90785ee7316","attribute_id":"37524605","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:12.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Ghost RAT\"","Ghost Rat","misp-galaxy:malpedia=\"ANGRYREBEL\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Ghost Rat","misp-galaxy:malpedia=\"ANGRYREBEL\"","misp-galaxy:malpedia=\"Ghost RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7aac112635cbde748a97b38f6a52aaebbc3f0050f81cf36ccdc6c294c214fd73","normalized_value":"7aac112635cbde748a97b38f6a52aaebbc3f0050f81cf36ccdc6c294c214fd73","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"371d4279-83fa-4a5a-b060-5df766625f02","attribute_id":"7386053","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581329","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3","normalized_value":"7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f66b1714-ffad-4e19-8af2-99a131c41673","attribute_id":"37524604","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:13.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Ghost RAT\"","Ghost Rat","misp-galaxy:malpedia=\"ANGRYREBEL\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Ghost Rat","misp-galaxy:malpedia=\"ANGRYREBEL\"","misp-galaxy:malpedia=\"Ghost RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7bb8ff1a5d1262d63167c0db64c00ae1965671c5168720fda081ca62d41d57d3","normalized_value":"7bb8ff1a5d1262d63167c0db64c00ae1965671c5168720fda081ca62d41d57d3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"06eb3797-3351-47fd-ad01-2edd1672bbfa","attribute_id":"37528964","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:57.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ValleyRAT","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","misp-galaxy:malpedia=\"ValleyRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ValleyRAT","misp-galaxy:malpedia=\"ValleyRAT\"","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7bb8ff1a5d1262d63167c0db64c00ae1965671c5168720fda081ca62d41d57d3","normalized_value":"7bb8ff1a5d1262d63167c0db64c00ae1965671c5168720fda081ca62d41d57d3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"70a366a4-7741-11f1-97fa-42010aa4000a","attribute_id":"37521731","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125837","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"ValleyRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"ValleyRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7c055f06c245ba0cc6afd6f7d0edf0dbc7934e53424c92e4174519726559dcec","normalized_value":"7c055f06c245ba0cc6afd6f7d0edf0dbc7934e53424c92e4174519726559dcec","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"b614765d-b8b9-44a7-bc45-c1adecf66742","attribute_id":"37529638","event_id":"58570","event_uuid":"73b7ed82-0d87-402a-adfd-2462e0268878","event_info":"Remcos host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783062018","event_timestamp":"1783215210","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:malware-categorization=\"Rat\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Rat\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7c4d1e3bff4c3d62adb8352b78e586b01eeba9e6d4b96715df89da84bae79c92","normalized_value":"7c4d1e3bff4c3d62adb8352b78e586b01eeba9e6d4b96715df89da84bae79c92","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"206c86d2-088a-40d0-95fe-8d2f9d37c187","attribute_id":"37528928","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:10.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7c4d1e3bff4c3d62adb8352b78e586b01eeba9e6d4b96715df89da84bae79c92","normalized_value":"7c4d1e3bff4c3d62adb8352b78e586b01eeba9e6d4b96715df89da84bae79c92","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"786cd305-7741-11f1-97fa-42010aa4000a","attribute_id":"37521733","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125850","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WannaCryptor payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WannaCryptor payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7ca918b727a7de4b9b009889f53b0d884018cedb936760c6b3915f77598d0b87","normalized_value":"7ca918b727a7de4b9b009889f53b0d884018cedb936760c6b3915f77598d0b87","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9dcb1332-7789-4ae6-941d-c901cc40acba","attribute_id":"37523736","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783168940","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","censys","ClickFix","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ClickFix","censys","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7cb67b8103522a1d89545b62b98b240dd9b08701689c87978d37fe4be081e4a5","normalized_value":"7cb67b8103522a1d89545b62b98b240dd9b08701689c87978d37fe4be081e4a5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e123a4fb-d79e-4de9-9003-1e882789dd3c","attribute_id":"37528734","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082590","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7ccf139c5192acdec6370f391801390935df872849212349f27f388b0a39674d","normalized_value":"7ccf139c5192acdec6370f391801390935df872849212349f27f388b0a39674d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"39e356c3-3f62-44fe-aa9d-758517a378b4","attribute_id":"37528394","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783043777","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7d51e5cc51c43da5deae5fbc2dce9b85c0656c465bb25ab6bd063a503c1806a9","normalized_value":"7d51e5cc51c43da5deae5fbc2dce9b85c0656c465bb25ab6bd063a503c1806a9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e57b6766-8c57-420b-8138-a96d3036bdef","attribute_id":"37748485","event_id":"60948","event_uuid":"de525eea-c091-4fa7-8dc6-218ce63d53ad","event_info":"Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials","event_date":"2024-04-23","attribute_timestamp":"1783666993","event_timestamp":"1783666998","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Batch script artifact","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","OSINT","osint:source-type=\"blog-post\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","APT","Actor: APT28","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"United States\"","tlp:clear","Microsoft Corporation","windows","JavaScript","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:threat-actor=\"APT28\"","misp-galaxy:country=\"russia\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","PrintNightmare"],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","OSINT","osint:source-type=\"blog-post\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","APT","Actor: APT28","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"United States\"","tlp:clear","Microsoft Corporation","windows","JavaScript","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:threat-actor=\"APT28\"","misp-galaxy:country=\"russia\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","PrintNightmare"],"all":["APT","Actor: APT28","JavaScript","Microsoft Corporation","OSINT","PrintNightmare","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:country=\"russia\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:threat-actor=\"APT28\"","osint:source-type=\"blog-post\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Batch script artifact","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7dd595347aea3817cde5da19e3a6b76adf2f0baef0ecbd67ff3d80be1d5930a4","normalized_value":"7dd595347aea3817cde5da19e3a6b76adf2f0baef0ecbd67ff3d80be1d5930a4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6cd31995-7741-11f1-97fa-42010aa4000a","attribute_id":"37521735","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125830","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Agent Tesla payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Agent Tesla payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7dd595347aea3817cde5da19e3a6b76adf2f0baef0ecbd67ff3d80be1d5930a4","normalized_value":"7dd595347aea3817cde5da19e3a6b76adf2f0baef0ecbd67ff3d80be1d5930a4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ef69d230-7775-47db-a44c-675a45b665a4","attribute_id":"37528989","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:50.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Agent Tesla\"","Agent Tesla","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Agent Tesla","misp-galaxy:malpedia=\"Agent Tesla\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7dd595347aea3817cde5da19e3a6b76adf2f0baef0ecbd67ff3d80be1d5930a4","normalized_value":"7dd595347aea3817cde5da19e3a6b76adf2f0baef0ecbd67ff3d80be1d5930a4","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"a1f666aa-1b86-43fc-8ab5-d7858ddcbd7c","attribute_id":"37529550","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101855","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","stone:malware-categorization=\"Stealer\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Stealer\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7e4afbb8e7d84224ab10d6c02b4988160837964e63515f8dcf0a9211963e9d65","normalized_value":"7e4afbb8e7d84224ab10d6c02b4988160837964e63515f8dcf0a9211963e9d65","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"779185da-a13d-43b5-a3b4-b101413d3ed2","attribute_id":"37523287","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783133894","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b","normalized_value":"7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b1ce1ddf-8b11-49c8-b39c-fd09c3aa6d83","attribute_id":"37752430","event_id":"61009","event_uuid":"d942d9c8-237d-455a-9940-6429c473cff1","event_info":"New Stealthy Ransomware Deployed Against Asian IT Company","event_date":"2026-07-27","attribute_timestamp":"1785124153","event_timestamp":"1785124153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"event":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"all":[" Ransomware","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"New Stealthy Ransomware Deployed Against Asian IT Company","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"7f603216a0a7bae2c8cec65a800608ac22cfff8cd98c699677e44d36267a9798","normalized_value":"7f603216a0a7bae2c8cec65a800608ac22cfff8cd98c699677e44d36267a9798","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"30c87132-5474-4e3d-bf42-ab9f678edd47","attribute_id":"34370364","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581090","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"805b92787ca7833eef5e61e2df1310e4b6544955e812e60b5f834f904623fd9f","normalized_value":"805b92787ca7833eef5e61e2df1310e4b6544955e812e60b5f834f904623fd9f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"73eb6e87-48eb-49ca-9962-d3eae9807ada","attribute_id":"34346258","event_id":"51335","event_uuid":"39b2e10d-763c-44e8-a2c5-dee828c98f37","event_info":"KdcSponge, NGLite, Godzilla Webshell Used in Targeted Attack Campaign","event_date":"2021-11-09","attribute_timestamp":"1783686400","event_timestamp":"1783686416","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"NGLite SHA256","event_extends_uuid":"13ac2113-2834-4088-a591-1f400c778f54","tags":{"attribute":["threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","cert-ist:malware_type=\"Webshell\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:enriched","cert-ist:confidence=\"medium\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_type=\"apt\"","tlp:clear"],"event":["threat-report","tlp:white","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","cert-ist:malware_type=\"Webshell\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:enriched","cert-ist:confidence=\"medium\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_type=\"apt\"","tlp:clear"],"all":["cert-ist:attack_vector=\"Vulnerability Exploitation\"","cert-ist:confidence=\"medium\"","cert-ist:enriched","cert-ist:malware_type=\"Webshell\"","cert-ist:threat_level=\"medium\"","cert-ist:threat_targeted_system=\"Windows\"","cert-ist:threat_type=\"apt\"","misp-galaxy:malpedia=\"Godzilla Loader\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Credential API Hooking - T1056.004\"","misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"","misp-galaxy:mitre-attack-pattern=\"Data Staged - T1074\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Command and Control Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:target-information=\"United States\"","threat-report","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"NGLite SHA256","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"81515b3edf11ef17b2727f65ee6d33661fcbb7cc98625e56f442ae46128ff2ab","normalized_value":"81515b3edf11ef17b2727f65ee6d33661fcbb7cc98625e56f442ae46128ff2ab","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"819e9533-e244-4976-9958-eacfd4dd4b5f","attribute_id":"37528716","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082547","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"81554399487f2cd5013f51a594fcb10a79129e3d43dc63149713f172fbc214e7","normalized_value":"81554399487f2cd5013f51a594fcb10a79129e3d43dc63149713f172fbc214e7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cc983b06-dbf6-4938-97e0-7ce8814da055","attribute_id":"37523257","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783131066","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Emotet","doc","heodo","epoch2","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Emotet","doc","epoch2","heodo","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8200735c40ff9727a5de977d9b01f51e4f3cc564304595de530f03f8d07b242c","normalized_value":"8200735c40ff9727a5de977d9b01f51e4f3cc564304595de530f03f8d07b242c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"26a2d1b9-e9c2-4871-8921-50a3bafc8a7f","attribute_id":"37523101","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162510","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","mips","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","mips","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"82c33345d6c7d51ade8e4069829d1ee2f7b284252664699e86f1f2738139ca0e","normalized_value":"82c33345d6c7d51ade8e4069829d1ee2f7b284252664699e86f1f2738139ca0e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"72d7d09b-c685-4492-9c85-05f76fffc81a","attribute_id":"37528788","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783087327","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923","normalized_value":"82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5b8a104f-d984-48ce-9e7d-23538b8c0626","attribute_id":"37752186","event_id":"60991","event_uuid":"58e75ed8-2394-41b3-a563-2324bec70d3a","event_info":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","event_date":"2026-07-22","attribute_timestamp":"1784691371","event_timestamp":"1784691372","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"event":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"all":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8324266e25d6a8dbc6e561e035b9e713c3bd339ba9bb5e5b9d4f0821a0262510","normalized_value":"8324266e25d6a8dbc6e561e035b9e713c3bd339ba9bb5e5b9d4f0821a0262510","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e444ae5b-6440-49da-bf20-ac87428b69e7","attribute_id":"34370352","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581079","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"836da0de8ba87bd62b094e1b10f9fb6ffb8eee1be7bc4aedea73a40950fce2a3","normalized_value":"836da0de8ba87bd62b094e1b10f9fb6ffb8eee1be7bc4aedea73a40950fce2a3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6089f7ae-22cd-479f-85ed-b1516ad55203","attribute_id":"37528364","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783043264","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","botnet","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","botnet","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8395641e48805249d1146bb87ea1ac3af90de2edd74f6604b37a10e2bdc01fe2","normalized_value":"8395641e48805249d1146bb87ea1ac3af90de2edd74f6604b37a10e2bdc01fe2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8e666a30-bbc0-49a2-a1a8-8f8a9cf9bf2f","attribute_id":"37528589","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783064530","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","arm","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arm","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"839c56270979bc4138b53a8372b59e63fb27ae9522f5b0b31d279efe2416f787","normalized_value":"839c56270979bc4138b53a8372b59e63fb27ae9522f5b0b31d279efe2416f787","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"44cee3a9-bd66-43cf-9872-cd3b8d285e79","attribute_id":"37529593","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783105220","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892","normalized_value":"83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"79c65d74-9d8e-4cb7-a202-7d26391202fd","attribute_id":"37752431","event_id":"61009","event_uuid":"d942d9c8-237d-455a-9940-6429c473cff1","event_info":"New Stealthy Ransomware Deployed Against Asian IT Company","event_date":"2026-07-27","attribute_timestamp":"1785124153","event_timestamp":"1785124153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"event":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"all":[" Ransomware","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"New Stealthy Ransomware Deployed Against Asian IT Company","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"84b8dbafd5cd64fb300b30bf943430a18f34cad3f0d8f7251d34354fea85aab2","normalized_value":"84b8dbafd5cd64fb300b30bf943430a18f34cad3f0d8f7251d34354fea85aab2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3a3424d8-e697-4ad9-8194-41868436ef12","attribute_id":"7386027","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581350","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d","normalized_value":"84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3c1c6d63-439a-443f-893d-4b4e82407989","attribute_id":"37752432","event_id":"61009","event_uuid":"d942d9c8-237d-455a-9940-6429c473cff1","event_info":"New Stealthy Ransomware Deployed Against Asian IT Company","event_date":"2026-07-27","attribute_timestamp":"1785124153","event_timestamp":"1785124153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"event":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"all":[" Ransomware","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"New Stealthy Ransomware Deployed Against Asian IT Company","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"85ec743443fe4830daddd95a454fc05b6434adf486a6889134b5d50c29570c9d","normalized_value":"85ec743443fe4830daddd95a454fc05b6434adf486a6889134b5d50c29570c9d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5b59b160-2165-43fb-9de7-a9c5e57c66c3","attribute_id":"37528468","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783060389","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (AsyncRAT)","event_extends_uuid":"","tags":{"attribute":["AsyncRAT","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["AsyncRAT","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (AsyncRAT)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"85ec743443fe4830daddd95a454fc05b6434adf486a6889134b5d50c29570c9d","normalized_value":"85ec743443fe4830daddd95a454fc05b6434adf486a6889134b5d50c29570c9d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"77d90673-7741-11f1-97fa-42010aa4000a","attribute_id":"37521743","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125849","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"AsyncRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"AsyncRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"85ec743443fe4830daddd95a454fc05b6434adf486a6889134b5d50c29570c9d","normalized_value":"85ec743443fe4830daddd95a454fc05b6434adf486a6889134b5d50c29570c9d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"998621b6-5cb0-4436-8749-8f35bf11d93d","attribute_id":"37528931","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:09.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["AsyncRAT","misp-galaxy:malpedia=\"AsyncRAT\"","misp-galaxy:mandiant-malware-family=\"2a7e208b-4c79-4e6b-bc16-d5ea2046729e\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["AsyncRAT","misp-galaxy:malpedia=\"AsyncRAT\"","misp-galaxy:mandiant-malware-family=\"2a7e208b-4c79-4e6b-bc16-d5ea2046729e\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"85ef348d39610c1d5f58e2524c0e929ec815a9fbe1f5924cdef7a0c05e58e5ad","normalized_value":"85ef348d39610c1d5f58e2524c0e929ec815a9fbe1f5924cdef7a0c05e58e5ad","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0b3ed487-119a-463e-a744-e64b88fa1ef4","attribute_id":"7385479","event_id":"34110","event_uuid":"d4d6cb78-8234-49dd-afa7-e64013021e6a","event_info":"Ryuk Ransomware Incident Analysis","event_date":"2020-10-09","attribute_timestamp":"1783581515","event_timestamp":"1783581532","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"Ryuk\"","misp-galaxy:mitre-attack-pattern=\"Account Discovery - T1087\"","misp-galaxy:mitre-attack-pattern=\"Commonly Used Port - T1043\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Disabling Security Tools - T1089\"","misp-galaxy:mitre-attack-pattern=\"Domain Trust Discovery - T1482\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1086\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"","misp-galaxy:mitre-attack-pattern=\"Rundll32 - T1085\"","misp-galaxy:mitre-attack-pattern=\"Scripting - T1064\"","misp-galaxy:mitre-attack-pattern=\"Security Software Discovery - T1063\"","misp-galaxy:mitre-attack-pattern=\"Service Execution - T1035\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:ransomware=\"Ryuk ransomware\"","Ransomware","Ryuk","tlp:white","misp-galaxy:sector=\"Health\"","ncsc-nl-ndn:feed=\"selected\"","retention:2w","retention:expired","tlp:clear"],"event":["misp-galaxy:malpedia=\"Ryuk\"","misp-galaxy:mitre-attack-pattern=\"Account Discovery - T1087\"","misp-galaxy:mitre-attack-pattern=\"Commonly Used Port - T1043\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Disabling Security Tools - T1089\"","misp-galaxy:mitre-attack-pattern=\"Domain Trust Discovery - T1482\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1086\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"","misp-galaxy:mitre-attack-pattern=\"Rundll32 - T1085\"","misp-galaxy:mitre-attack-pattern=\"Scripting - T1064\"","misp-galaxy:mitre-attack-pattern=\"Security Software Discovery - T1063\"","misp-galaxy:mitre-attack-pattern=\"Service Execution - T1035\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:ransomware=\"Ryuk ransomware\"","Ransomware","Ryuk","tlp:white","misp-galaxy:sector=\"Health\"","ncsc-nl-ndn:feed=\"selected\"","retention:2w","retention:expired","tlp:clear"],"all":["Ransomware","Ryuk","misp-galaxy:malpedia=\"Ryuk\"","misp-galaxy:mitre-attack-pattern=\"Account Discovery - T1087\"","misp-galaxy:mitre-attack-pattern=\"Commonly Used Port - T1043\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Disabling Security Tools - T1089\"","misp-galaxy:mitre-attack-pattern=\"Domain Trust Discovery - T1482\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1086\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"","misp-galaxy:mitre-attack-pattern=\"Rundll32 - T1085\"","misp-galaxy:mitre-attack-pattern=\"Scripting - T1064\"","misp-galaxy:mitre-attack-pattern=\"Security Software Discovery - T1063\"","misp-galaxy:mitre-attack-pattern=\"Service Execution - T1035\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:ransomware=\"Ryuk ransomware\"","misp-galaxy:sector=\"Health\"","ncsc-nl-ndn:feed=\"selected\"","retention:2w","retention:expired","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Ryuk Ransomware Incident Analysis","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1","normalized_value":"862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5c8325a8-5b50-4113-99d3-135700c7dd1d","attribute_id":"37752433","event_id":"61009","event_uuid":"d942d9c8-237d-455a-9940-6429c473cff1","event_info":"New Stealthy Ransomware Deployed Against Asian IT Company","event_date":"2026-07-27","attribute_timestamp":"1785124153","event_timestamp":"1785124153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"event":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"all":[" Ransomware","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"New Stealthy Ransomware Deployed Against Asian IT Company","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8639825230d5504fd8126ed55b2d7aeb72944ffe17e762801aab8d4f8f880160","normalized_value":"8639825230d5504fd8126ed55b2d7aeb72944ffe17e762801aab8d4f8f880160","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fdeca8b9-779e-4d2d-be0d-2e7efccbad96","attribute_id":"7386294","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581165","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"86fdc44c5e0be58626c960ee7509fe1f6f044c9854c4a992581065596ec8a642","normalized_value":"86fdc44c5e0be58626c960ee7509fe1f6f044c9854c4a992581065596ec8a642","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b048f260-dd6d-4d93-9e3b-fcd41692a7e9","attribute_id":"37751343","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783439276","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_07-07-2026 Adjunto_svg_ofuscated_cpl","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_07-07-2026 Adjunto_svg_ofuscated_cpl","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"876de7e7e43dbfacb7e37487d926eac189ddf717966e09fc439b986a20719b54","normalized_value":"876de7e7e43dbfacb7e37487d926eac189ddf717966e09fc439b986a20719b54","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"561730eb-0e8f-4b73-a727-8d7c4e33e6e1","attribute_id":"37528376","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783043470","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"87cf4ad614dbe8696401992fb8dde991f921adce680d91057e8fdb7c88e1a8c0","normalized_value":"87cf4ad614dbe8696401992fb8dde991f921adce680d91057e8fdb7c88e1a8c0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"017679c7-3638-44bf-baae-111c1dc1193b","attribute_id":"37524556","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:30.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"NetWire RC\"","Netwire RC","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Netwire RC","misp-galaxy:malpedia=\"NetWire RC\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"882e89ea1b8d70646bdf6476d8cb46991b950f27e03e93bf49ea3209c2d69581","normalized_value":"882e89ea1b8d70646bdf6476d8cb46991b950f27e03e93bf49ea3209c2d69581","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"79475bfb-7550-4888-bcde-a1edddee5f66","attribute_id":"7386063","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581322","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"887aac61771af200f7e58bf0d02cb96d9befa11deda4e448f0a700ccb186ce9d","normalized_value":"887aac61771af200f7e58bf0d02cb96d9befa11deda4e448f0a700ccb186ce9d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"118ba76e-d85b-4219-806e-e6b1d8d592fc","attribute_id":"35015719","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558070","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"WastedLocker samples (sha256 hashes)","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WastedLocker samples (sha256 hashes)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8897db876553f942b2eb4005f8475a232bafb82a50ca7761a621842e894a3d80","normalized_value":"8897db876553f942b2eb4005f8475a232bafb82a50ca7761a621842e894a3d80","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d4b4fee7-fae2-468c-a8dd-04f80b79d6c4","attribute_id":"35015720","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558075","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"WastedLocker samples (sha256 hashes)","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WastedLocker samples (sha256 hashes)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"889cc3e793cb39889c7acc8e73a84973e9a08fcd69451f7b546509c74ffdda90","normalized_value":"889cc3e793cb39889c7acc8e73a84973e9a08fcd69451f7b546509c74ffdda90","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5174a268-6777-4775-8e9e-8f98a0d3b697","attribute_id":"37529375","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:58.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"MimiKatz\"","Mimikatz","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Mimikatz","misp-galaxy:malpedia=\"MimiKatz\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"889cc3e793cb39889c7acc8e73a84973e9a08fcd69451f7b546509c74ffdda90","normalized_value":"889cc3e793cb39889c7acc8e73a84973e9a08fcd69451f7b546509c74ffdda90","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"82ac214d-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521748","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176118","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"MimiKatz payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"MimiKatz payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"88d03e683c01d9979c752844579bd367892edbbdc876b03df8e1d09412f761c5","normalized_value":"88d03e683c01d9979c752844579bd367892edbbdc876b03df8e1d09412f761c5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"70809cd1-5652-476d-ba22-a2d37309d029","attribute_id":"34370394","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581120","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8995d7c4e9ee6dbad5fa508482f17e19f6b70ba24770d69838f39238254e0f08","normalized_value":"8995d7c4e9ee6dbad5fa508482f17e19f6b70ba24770d69838f39238254e0f08","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8afe4337-06c6-423b-b998-eb26a0d63e62","attribute_id":"37528412","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783045658","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8a9dc5e4d7bed616871882b6038941598aeecd64b4bde11fee2eb4ce1a8f7e7a","normalized_value":"8a9dc5e4d7bed616871882b6038941598aeecd64b4bde11fee2eb4ce1a8f7e7a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f5056b03-f0d7-4e63-a9b5-303f3d314299","attribute_id":"37523245","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783131006","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8b41ec3362f432707b61c40c966e011c10f320fb5c2ebc02314ae9154a3cdf3c","normalized_value":"8b41ec3362f432707b61c40c966e011c10f320fb5c2ebc02314ae9154a3cdf3c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"34379b96-e85e-4f18-bdf0-a792a0d480d4","attribute_id":"37565759","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783087431","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_03-07-2026 HTML_Smuggling","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_03-07-2026 HTML_Smuggling","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8c05ec2767831c22d7b910c169c42de571e11ba992a4095f16bdf4f0dccd9677","normalized_value":"8c05ec2767831c22d7b910c169c42de571e11ba992a4095f16bdf4f0dccd9677","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"75fab5b9-ba5e-4e79-849e-a3155f558088","attribute_id":"7386016","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581361","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8c5ce574ae676e0687e803e78c52e3c8672f7dbc4a63655c1067f2849135da25","normalized_value":"8c5ce574ae676e0687e803e78c52e3c8672f7dbc4a63655c1067f2849135da25","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"67a94e67-e2e5-4d29-94d3-828adb708be6","attribute_id":"7385992","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581379","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8cb0c223b018cecef1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2","normalized_value":"8cb0c223b018cecef1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4cc7c1f4-aaee-4967-bb9f-36a09ab81ef0","attribute_id":"37755351","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140505","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--f4d66504-856e-5f2e-b24f-a74731894808","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--f4d66504-856e-5f2e-b24f-a74731894808","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8cbe48fc14585b878bda6c568ae10e1c0f063034c86f868b3cc324354596d32f","normalized_value":"8cbe48fc14585b878bda6c568ae10e1c0f063034c86f868b3cc324354596d32f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"35a6fee8-9802-4432-9cb9-bc98db09a52c","attribute_id":"37529377","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:35.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ACR Stealer","misp-galaxy:malpedia=\"ACR Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ACR Stealer","misp-galaxy:malpedia=\"ACR Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8cbe48fc14585b878bda6c568ae10e1c0f063034c86f868b3cc324354596d32f","normalized_value":"8cbe48fc14585b878bda6c568ae10e1c0f063034c86f868b3cc324354596d32f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7503cdb7-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521752","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176095","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"ACR Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"ACR Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8cbe62af6851946174acb28c1d7da9170985d32aa1b42abe4dbe231d5144156b","normalized_value":"8cbe62af6851946174acb28c1d7da9170985d32aa1b42abe4dbe231d5144156b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3047fa75-b2ac-411c-9464-aa6e3a84938b","attribute_id":"37523718","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783154718","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8dd5fd174ee703a43ab5084fdaba84d074152e46b84d588bf63f9d5cd2f673d1","normalized_value":"8dd5fd174ee703a43ab5084fdaba84d074152e46b84d588bf63f9d5cd2f673d1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"97928b7f-b4d2-4dcd-9ab2-3ec0d6804640","attribute_id":"69214","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686551","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8e1897382a75baf8d62f21fc5266e64d06fbc1bd5e209d0f1d35131ea5b521d9","normalized_value":"8e1897382a75baf8d62f21fc5266e64d06fbc1bd5e209d0f1d35131ea5b521d9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5b5b8e17-c999-493c-a0dd-29d4c51f7b00","attribute_id":"37528776","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783086211","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8e1ea6d9a8ccb303be9a2aad3524a529d0d99b1b24a136d8422276e942c4c4b8","normalized_value":"8e1ea6d9a8ccb303be9a2aad3524a529d0d99b1b24a136d8422276e942c4c4b8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dca80204-ad33-4b85-a5f1-dd2b324416f7","attribute_id":"37752278","event_id":"60998","event_uuid":"5d50bb0c-c021-4540-808f-bbd176218e0d","event_info":"Malicious GitHub Campaign Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer","event_date":"2026-07-22","attribute_timestamp":"1784704450","event_timestamp":"1784704564","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","malicious","tlp:clear","  Malware  "," infostealer"],"event":["NCSA","NCSA_Research","malicious","tlp:clear","  Malware  "," infostealer"],"all":["  Malware  "," infostealer","NCSA","NCSA_Research","malicious","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malicious GitHub Campaign Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8e3cf3dc6e5d8fdfbcc8575e9e97003f7f919c6ba2ea5889ec3ac658ceacc8a9","normalized_value":"8e3cf3dc6e5d8fdfbcc8575e9e97003f7f919c6ba2ea5889ec3ac658ceacc8a9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"40b8e074-6696-4c17-a014-cb81fc346527","attribute_id":"37524502","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:48.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8e3cf3dc6e5d8fdfbcc8575e9e97003f7f919c6ba2ea5889ec3ac658ceacc8a9","normalized_value":"8e3cf3dc6e5d8fdfbcc8575e9e97003f7f919c6ba2ea5889ec3ac658ceacc8a9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6f6c1d04-0f52-4d16-82a6-cfd3e3f2bb67","attribute_id":"37523538","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146562","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1e","normalized_value":"8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"33ae33d8-005d-45ba-8411-af98ff807f1b","attribute_id":"37755441","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140558","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--35689c50-45b4-52e7-8a57-ac542578c603","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--35689c50-45b4-52e7-8a57-ac542578c603","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8ee45671a9bfc0c4f45c228cdb8a0bbb70898303739a2b787a1ec47ecffb9805","normalized_value":"8ee45671a9bfc0c4f45c228cdb8a0bbb70898303739a2b787a1ec47ecffb9805","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"32a525e4-7342-471e-a83d-7b2bf30d2355","attribute_id":"37529380","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:00.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8ee45671a9bfc0c4f45c228cdb8a0bbb70898303739a2b787a1ec47ecffb9805","normalized_value":"8ee45671a9bfc0c4f45c228cdb8a0bbb70898303739a2b787a1ec47ecffb9805","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"602309cf-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521757","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176060","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Venus Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Venus Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8f06645838d3d75e44d4527e2928c71af0a7214254867379359eb3e46109cbde","normalized_value":"8f06645838d3d75e44d4527e2928c71af0a7214254867379359eb3e46109cbde","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d146bfa3-deed-49d8-8414-e89b0918c1c5","attribute_id":"7386005","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581368","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8f2734b349066f67b40ca3ddb4a6678e89cc1d0dfc5d90afb20a1dccb1073c8f","normalized_value":"8f2734b349066f67b40ca3ddb4a6678e89cc1d0dfc5d90afb20a1dccb1073c8f","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"c0234eeb-f17a-44da-a7cd-3be9ee0579ca","attribute_id":"37529566","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101991","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8f2e8a2f9d3edc12d39ca07f4717277e863d4bfeb8ec31fe4f391ddd0f64df84","normalized_value":"8f2e8a2f9d3edc12d39ca07f4717277e863d4bfeb8ec31fe4f391ddd0f64df84","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8c435bb8-820e-4c39-9315-0394e1702e14","attribute_id":"37755242","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140443","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--aec03aca-6ab8-55e9-826a-e00a4986f833","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--aec03aca-6ab8-55e9-826a-e00a4986f833","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8f718c4590f4b47e990071b4a139c08a8a130c35913106d3014360d87f18309f","normalized_value":"8f718c4590f4b47e990071b4a139c08a8a130c35913106d3014360d87f18309f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6a28777a-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521758","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176077","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Venus Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Venus Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"8f718c4590f4b47e990071b4a139c08a8a130c35913106d3014360d87f18309f","normalized_value":"8f718c4590f4b47e990071b4a139c08a8a130c35913106d3014360d87f18309f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8cfcc228-9fc6-4ace-856e-464765f159a9","attribute_id":"37529381","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:17.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"903f7182ad5cb63e3db43df0b86f781665c55c2bd2e62b92782ec44c8d867146","normalized_value":"903f7182ad5cb63e3db43df0b86f781665c55c2bd2e62b92782ec44c8d867146","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d100bb61-e8b4-47db-9736-7d5f0e44166e","attribute_id":"37523203","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783128466","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","arm","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arm","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"90b7b2c6f3d05234dc55678243039d7e51f0d54190239e5234a0005533337dc8","normalized_value":"90b7b2c6f3d05234dc55678243039d7e51f0d54190239e5234a0005533337dc8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b582ca42-9c09-4f30-a6ac-ba3823ba255a","attribute_id":"37746208","event_id":"60922","event_uuid":"c76359e3-b520-43df-a2e4-adc41224a2d7","event_info":"Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems","event_date":"2026-07-16","attribute_timestamp":"1784171702","event_timestamp":"1784186616","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"HSEWH-Ur, 8eA-GlbK, r4l3DqLA (TencShell ARM) [VT: 23/59 malicious as of 2026-07-16]","event_extends_uuid":"","tags":{"attribute":["tlp:clear","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"","misp-galaxy:mitre-attack-pattern=\"Gather Victim Identity Information - T1589\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","NCSA"," C2","APT","Social Engineering","compromised"],"event":["tlp:clear","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"","misp-galaxy:mitre-attack-pattern=\"Gather Victim Identity Information - T1589\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","NCSA"," C2","APT","Social Engineering","compromised"],"all":[" C2","APT","NCSA","Social Engineering","compromised","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Gather Victim Identity Information - T1589\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"HSEWH-Ur, 8eA-GlbK, r4l3DqLA (TencShell ARM) [VT: 23/59 malicious as of 2026-07-16]","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9156f5bd322306c9038a3bc830e53e7b13c272e121fb70b3b8d7d9968fb97e4f","normalized_value":"9156f5bd322306c9038a3bc830e53e7b13c272e121fb70b3b8d7d9968fb97e4f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"34fc3020-85dc-48e5-aa4d-e14af39137bb","attribute_id":"34370397","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581123","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"91e7539be877509b04b7425e35185615e76cabd3e9cb9e9ca4bfad36ad9096b9","normalized_value":"91e7539be877509b04b7425e35185615e76cabd3e9cb9e9ca4bfad36ad9096b9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"809b33a1-7741-11f1-97fa-42010aa4000a","attribute_id":"37521763","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125863","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Venus Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Venus Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"91e7539be877509b04b7425e35185615e76cabd3e9cb9e9ca4bfad36ad9096b9","normalized_value":"91e7539be877509b04b7425e35185615e76cabd3e9cb9e9ca4bfad36ad9096b9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"99dfb152-0364-406b-8bcb-f37938ee7fc1","attribute_id":"37528890","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:23.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"93739477cd379adef95126b22758c0e644282d2028dd297328ce856fa111dd06","normalized_value":"93739477cd379adef95126b22758c0e644282d2028dd297328ce856fa111dd06","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5ace780e-6613-4d97-8904-f69453cd8137","attribute_id":"37752161","event_id":"60989","event_uuid":"1856b358-880a-4c9c-acef-c8ce8bae7d01","event_info":"Threat Actor Uses Malicious PyPI Dependencies to Deliver ChocoPoC RAT Through GitHub PoCs","event_date":"2026-07-20","attribute_timestamp":"1784529523","event_timestamp":"1784529532","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","RAT","tlp:clear"],"event":["NCSA","NCSA_Research","RAT","tlp:clear"],"all":["NCSA","NCSA_Research","RAT","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Uses Malicious PyPI Dependencies to Deliver ChocoPoC RAT Through GitHub PoCs","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"944b774d592f5e7fe2c34ac6c3abb2a77bfa96707c4f3c33ac77b8d54800244f","normalized_value":"944b774d592f5e7fe2c34ac6c3abb2a77bfa96707c4f3c33ac77b8d54800244f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2a84e0f6-aef4-4ea8-8f31-27fb10f02736","attribute_id":"37755505","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785351653","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--b75ceb42-f23c-5a9a-b063-852bd128637c","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--b75ceb42-f23c-5a9a-b063-852bd128637c","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9462805f80c946c49bf44a3d567a682b666d1d0bd74e3819050339e6f3e93451","normalized_value":"9462805f80c946c49bf44a3d567a682b666d1d0bd74e3819050339e6f3e93451","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"354c08df-2d10-47e1-8fe1-e373c358809a","attribute_id":"37524505","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:47.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9462805f80c946c49bf44a3d567a682b666d1d0bd74e3819050339e6f3e93451","normalized_value":"9462805f80c946c49bf44a3d567a682b666d1d0bd74e3819050339e6f3e93451","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"36524b9d-0014-42fd-83b3-3f22cb5d17a4","attribute_id":"37523461","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9493ad437ea4b55629ee0a8d18141977c2632de42349a995730112727549f40e","normalized_value":"9493ad437ea4b55629ee0a8d18141977c2632de42349a995730112727549f40e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ce324cef-1974-44be-b5af-0fabfce8769c","attribute_id":"69165","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686536","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"MalwareBazaar: RemcosRAT C2:\nrenajazinw.duckdns.org:53848","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"MalwareBazaar: RemcosRAT C2:\nrenajazinw.duckdns.org:53848","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"94f2e4d8d4436874785cd14e6e6d403507b8750852f7f2040352069a75da4c00","normalized_value":"94f2e4d8d4436874785cd14e6e6d403507b8750852f7f2040352069a75da4c00","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b632fd4c-fd77-4e34-b4ab-4ec37ea0efef","attribute_id":"37524313","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783258978","event_timestamp":"1784390661","first_seen":"2026-07-05T11:28:35.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n75","event_extends_uuid":"","tags":{"attribute":["xmrig","ssh","Panchan","misp-galaxy:malpedia=\"xmrig\"","Unknown malware","cowrie","honeypot","p2p","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Panchan","Unknown malware","cowrie","honeypot","misp-galaxy:malpedia=\"xmrig\"","osint:source-type=\"block-or-filter-list\"","p2p","source:threatfox.abuse.ch","ssh","tlp:clear","xmrig"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n75","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"94faff7500a2f959889a3fff9bed01cb30fdb6ab5dbcbe984f592a3891333f36","normalized_value":"94faff7500a2f959889a3fff9bed01cb30fdb6ab5dbcbe984f592a3891333f36","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"76b7f756-7741-11f1-97fa-42010aa4000a","attribute_id":"37521769","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125847","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WannaCryptor payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WannaCryptor payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"94faff7500a2f959889a3fff9bed01cb30fdb6ab5dbcbe984f592a3891333f36","normalized_value":"94faff7500a2f959889a3fff9bed01cb30fdb6ab5dbcbe984f592a3891333f36","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a6265c5a-a547-4004-bc79-985f73413b3f","attribute_id":"37528938","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:07.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"956cec034e34f187af8b9b4ad497ead753b0f7ef6c26a735d7c2c35294d238c0","normalized_value":"956cec034e34f187af8b9b4ad497ead753b0f7ef6c26a735d7c2c35294d238c0","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"d043cd25-3824-41b3-9c99-3b5f518c2765","attribute_id":"37529645","event_id":"58570","event_uuid":"73b7ed82-0d87-402a-adfd-2462e0268878","event_info":"Remcos host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101625","event_timestamp":"1783215210","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:malware-categorization=\"Rat\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Rat\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"95ebb02315da2e1b32a56df3613778de16ed4f0c55b6cb5d5e786de23cc45df8","normalized_value":"95ebb02315da2e1b32a56df3613778de16ed4f0c55b6cb5d5e786de23cc45df8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3378f553-0e7f-4bd7-a74f-c4c44683b8bc","attribute_id":"37523573","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146566","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"95ebb02315da2e1b32a56df3613778de16ed4f0c55b6cb5d5e786de23cc45df8","normalized_value":"95ebb02315da2e1b32a56df3613778de16ed4f0c55b6cb5d5e786de23cc45df8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"64b521db-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521772","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176068","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"95ebb02315da2e1b32a56df3613778de16ed4f0c55b6cb5d5e786de23cc45df8","normalized_value":"95ebb02315da2e1b32a56df3613778de16ed4f0c55b6cb5d5e786de23cc45df8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c38f41ce-97e9-4255-a97e-e8062f563f46","attribute_id":"37529386","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:08.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9617fa7894af55085e09a06b1b91488af37b8159b22616dfd5c74e6b9a081739","normalized_value":"9617fa7894af55085e09a06b1b91488af37b8159b22616dfd5c74e6b9a081739","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6064ac90-f75d-434e-b695-82bb61d2858f","attribute_id":"69137","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686524","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20","normalized_value":"96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6fdb15d5-7df2-42b5-bd47-bd65efd02f8a","attribute_id":"37755440","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140558","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--942d7f6a-73a6-5d6f-81d2-4867ae550464","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--942d7f6a-73a6-5d6f-81d2-4867ae550464","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"96a70a20a24959dc270e12889e4bff81a86c0e4a0f23b8dc9976843940ec8ddd","normalized_value":"96a70a20a24959dc270e12889e4bff81a86c0e4a0f23b8dc9976843940ec8ddd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"356a1a2f-30fb-49f9-81cc-3f701398192b","attribute_id":"37749165","event_id":"60956","event_uuid":"36e03b09-a20c-4169-a875-b77a24ca82fd","event_info":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","event_date":"2023-03-14","attribute_timestamp":"1783685708","event_timestamp":"1783685737","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"event":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"all":["Ave Maria","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","Energy Sector ","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cyber espionage","infostealer","meterpreter","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","osint:source-type=\"blog-post\"","tlp:clear","warzonerat"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"96b027a3b87e055b40f28ff38e4f6b5f159122802c9fd7fde5307969e0f8fb27","normalized_value":"96b027a3b87e055b40f28ff38e4f6b5f159122802c9fd7fde5307969e0f8fb27","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7cc83d89-40a0-454f-b7cf-13370acd2dee","attribute_id":"37528280","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783037019","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Emotet","doc","heodo","epoch2","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Emotet","doc","epoch2","heodo","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477eb","normalized_value":"9733a3f6409de81271f21993c7f8b9865ac9f5c68c3d4336e91afe6b312477eb","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7d60dec8-8fee-43d0-b6ef-4a0f84845f3a","attribute_id":"37751400","event_id":"60979","event_uuid":"fea39f60-0010-477f-b097-b30d1547c5a4","event_info":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","event_date":"2026-07-17","attribute_timestamp":"1784273256","event_timestamp":"1784273257","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"event":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"all":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"97f6da2917e358287321571ea5aca6dcd706d8791e52f882c39937b347169b21","normalized_value":"97f6da2917e358287321571ea5aca6dcd706d8791e52f882c39937b347169b21","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fd13d31b-eb4e-40dd-a81c-e283f6388316","attribute_id":"37523047","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783172651","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","elf","mips","geofenced","USA","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","USA","elf","gafgyt","geofenced","mips","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"98964a5573fa7c77675dab99f0b9db0aca5531d7db971aa8245e51ce83593602","normalized_value":"98964a5573fa7c77675dab99f0b9db0aca5531d7db971aa8245e51ce83593602","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a77d39d8-6576-4568-b63f-33b5d8b321b1","attribute_id":"37528643","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783076878","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"992f8357342cbd40f25ec6fb8b4c4ecaeecd20e1c53fc28d925b3146075187ad","normalized_value":"992f8357342cbd40f25ec6fb8b4c4ecaeecd20e1c53fc28d925b3146075187ad","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"652c09c7-79ab-4d54-abd2-af9eeaa52219","attribute_id":"37529569","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101994","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"99597a1e872c4bc2ef740522090868854bfef090d1375c4906b1696d4161834e","normalized_value":"99597a1e872c4bc2ef740522090868854bfef090d1375c4906b1696d4161834e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0857ec74-3c2a-4bb0-9075-699f14d49ffb","attribute_id":"7385980","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581389","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9bdd7f965d1c67396afb0a84c78b4d12118ff377db7efdca4a1340933120f376","normalized_value":"9bdd7f965d1c67396afb0a84c78b4d12118ff377db7efdca4a1340933120f376","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a7836079-961f-464c-9980-17599a16b07a","attribute_id":"7386088","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581284","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9bde3bbe88824b115539416a4fbc46940a52622e81851daabea3baaf06c21a98","normalized_value":"9bde3bbe88824b115539416a4fbc46940a52622e81851daabea3baaf06c21a98","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6f68b441-4a6d-4339-80c2-65e1742ac8f1","attribute_id":"37528722","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082547","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9c18f28b8872ad69c5dddccc432cb3eab992aff1f9d95c2c103aca16c46a3247","normalized_value":"9c18f28b8872ad69c5dddccc432cb3eab992aff1f9d95c2c103aca16c46a3247","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"66057da9-b073-4c39-9bac-c595e06a84dc","attribute_id":"37529585","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783102004","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9c555a75b0c94ab3f2a29a3a21c7fd09c6f2893ff0c26523b773ab89fd7795b4","normalized_value":"9c555a75b0c94ab3f2a29a3a21c7fd09c6f2893ff0c26523b773ab89fd7795b4","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"f1e4d491-01e1-45ca-8192-9f6274981762","attribute_id":"37529663","event_id":"58570","event_uuid":"73b7ed82-0d87-402a-adfd-2462e0268878","event_info":"Remcos host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783105212","event_timestamp":"1783215210","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9c8738bb0a3663b08bbd4a0b78db2d4d1204f120c959717a7471864828956655","normalized_value":"9c8738bb0a3663b08bbd4a0b78db2d4d1204f120c959717a7471864828956655","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c58101c5-71ef-4f9c-8482-478b004b6337","attribute_id":"37523035","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783169173","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","arm","geofenced","USA","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","USA","arm","elf","geofenced","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9cd9c0a79450290b1ac0ea3235df6cd68332cc5a426991fa1d53eb7f19ec5a09","normalized_value":"9cd9c0a79450290b1ac0ea3235df6cd68332cc5a426991fa1d53eb7f19ec5a09","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"aa56a465-a16d-4576-9295-274e15ca3450","attribute_id":"37523468","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9cd9c0a79450290b1ac0ea3235df6cd68332cc5a426991fa1d53eb7f19ec5a09","normalized_value":"9cd9c0a79450290b1ac0ea3235df6cd68332cc5a426991fa1d53eb7f19ec5a09","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c589bca4-705f-4699-8b3d-63e7e9aa0806","attribute_id":"37524463","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:01.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9d07a83cf89685651ea8992047ae694c24f6ddef193044357debd15ce07a64fe","normalized_value":"9d07a83cf89685651ea8992047ae694c24f6ddef193044357debd15ce07a64fe","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f82312c5-e6d3-4398-8d3a-dc5c6d3df6c7","attribute_id":"37752143","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9df01d242ef46adfedf8c35cb7cc67b1d27d7dc4a1ce74ab32e984090d579886","normalized_value":"9df01d242ef46adfedf8c35cb7cc67b1d27d7dc4a1ce74ab32e984090d579886","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"44daa07d-2cfd-43e9-a4b3-a6ab97cf13f9","attribute_id":"37755439","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140557","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--33fb6fce-9004-50e4-b06e-9dcd66edb133","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--33fb6fce-9004-50e4-b06e-9dcd66edb133","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9df5a7b74fadadc12c289fff3f5c7f58e3893e5a36df8a287b1f69e588a7e818","normalized_value":"9df5a7b74fadadc12c289fff3f5c7f58e3893e5a36df8a287b1f69e588a7e818","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e5562297-7c61-4373-89cc-128215a6b20c","attribute_id":"37524542","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:35.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["QuirkyLoader","misp-galaxy:malpedia=\"QuirkyLoader\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["QuirkyLoader","misp-galaxy:malpedia=\"QuirkyLoader\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9e81ade09cc18f0fc09d73e72d2e0bffad02f52fdcc26553e473cee8cabc1567","normalized_value":"9e81ade09cc18f0fc09d73e72d2e0bffad02f52fdcc26553e473cee8cabc1567","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"757a0ec6-2c04-4a6c-8632-06aad3df93b1","attribute_id":"37752147","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9eb3e292b091c691943b70fc0e9d6d2c5e5c55727518e40018ba72b27d71e0a3","normalized_value":"9eb3e292b091c691943b70fc0e9d6d2c5e5c55727518e40018ba72b27d71e0a3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"37bb4169-7136-4730-baff-958965eebbec","attribute_id":"37524437","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:11.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9eb3e292b091c691943b70fc0e9d6d2c5e5c55727518e40018ba72b27d71e0a3","normalized_value":"9eb3e292b091c691943b70fc0e9d6d2c5e5c55727518e40018ba72b27d71e0a3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"504f3978-16a9-42c2-aa1d-b807ab022034","attribute_id":"37523433","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9ebe58ec528e0153eb1113aec8024c58d21a0d513912a496ff4daf1b8c8393f5","normalized_value":"9ebe58ec528e0153eb1113aec8024c58d21a0d513912a496ff4daf1b8c8393f5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7ff59a75-840e-4e66-98ab-b5ddc511a620","attribute_id":"37523041","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783171020","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","geofenced","USA","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","USA","elf","geofenced","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9f9027b5db5c408ee43ef2a7c7dd1aecbdb244ef6b16d9aafb599e8c40368967","normalized_value":"9f9027b5db5c408ee43ef2a7c7dd1aecbdb244ef6b16d9aafb599e8c40368967","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"adc37535-e417-4659-a258-5ac20a90825a","attribute_id":"7386296","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581167","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"9ff4b6d3b7dbb023bad65d2538ade745d46b763e5a12116c9c83aa2f6f5d96aa","normalized_value":"9ff4b6d3b7dbb023bad65d2538ade745d46b763e5a12116c9c83aa2f6f5d96aa","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"87c269ad-c318-499d-a999-ffce85ad43db","attribute_id":"37755159","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140404","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--b9cc5a42-57e7-543c-a0e7-a1b1cf0c5647","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--b9cc5a42-57e7-543c-a0e7-a1b1cf0c5647","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a09b8f3482137394a421f6a96eaa3664f468ddfbcdf01651dae8fc0898e9a13e","normalized_value":"a09b8f3482137394a421f6a96eaa3664f468ddfbcdf01651dae8fc0898e9a13e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"088e778a-5373-4d29-a195-bba1df8abf16","attribute_id":"37523621","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147090","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a1074b798ae9279088f3e7ee3c8ad6fdf2653b9e6b80de69aa85c03ca0b8c7c3","normalized_value":"a1074b798ae9279088f3e7ee3c8ad6fdf2653b9e6b80de69aa85c03ca0b8c7c3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f6f1b921-f210-47f0-9388-60c19f73fcff","attribute_id":"37523233","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783130011","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","censys","ClickFix","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ClickFix","censys","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a166b4f2f9c5565737ba6512416030b2518c812cd0abb3af52749b5bebdd9625","normalized_value":"a166b4f2f9c5565737ba6512416030b2518c812cd0abb3af52749b5bebdd9625","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"35ae16fe-1749-4ae3-ab55-7b59959dafbb","attribute_id":"37523125","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783123913","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a2f9b36903b3f2bb82cff00b8b916db81dcf33a9764b9a94d429c92bc0120b1d","normalized_value":"a2f9b36903b3f2bb82cff00b8b916db81dcf33a9764b9a94d429c92bc0120b1d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"67a6d2cd-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521782","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176073","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a2f9b36903b3f2bb82cff00b8b916db81dcf33a9764b9a94d429c92bc0120b1d","normalized_value":"a2f9b36903b3f2bb82cff00b8b916db81dcf33a9764b9a94d429c92bc0120b1d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"742e9f5a-2369-4107-8428-e231b7de1ce6","attribute_id":"37523566","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146566","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a2f9b36903b3f2bb82cff00b8b916db81dcf33a9764b9a94d429c92bc0120b1d","normalized_value":"a2f9b36903b3f2bb82cff00b8b916db81dcf33a9764b9a94d429c92bc0120b1d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ca54a9a6-9560-4837-b2ce-ad3f0eaa34b3","attribute_id":"37529396","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:13.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a34d7aa860ddd60d571be3eb9b0c0a75a00d76a7285892ae66eaf3d25a00f5df","normalized_value":"a34d7aa860ddd60d571be3eb9b0c0a75a00d76a7285892ae66eaf3d25a00f5df","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a9b530f7-ea7e-489c-82f8-8205afc0991b","attribute_id":"37528523","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783062714","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","mips","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","mips","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a3797856766fef6651f8c679febd12378fc3196c5cc74923d90377045107700d","normalized_value":"a3797856766fef6651f8c679febd12378fc3196c5cc74923d90377045107700d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"24bc5070-51ae-41cc-b717-3f532f7a69c3","attribute_id":"34370400","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581126","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a3e695c3a15b52b59c86875a9a5c47c0f932186b8433bb70ab4aa6c72ba58e3b","normalized_value":"a3e695c3a15b52b59c86875a9a5c47c0f932186b8433bb70ab4aa6c72ba58e3b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b377dd40-dd9e-4625-ae9e-b794885da29b","attribute_id":"37528607","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783066126","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","opendir","elf","mips","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","mips","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86","normalized_value":"a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ab19c518-337f-456d-b30c-c53d52d6ccb7","attribute_id":"37752423","event_id":"61008","event_uuid":"9337bf84-8d94-4826-a516-5564ea3501a8","event_info":"jscrambler npm Supply-Chain Operation","event_date":"2026-07-27","attribute_timestamp":"1785123850","event_timestamp":"1785124058","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"event":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"all":["Cybercrime","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"jscrambler npm Supply-Chain Operation","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a422649564f3069ed4fcd02f25796ca99ed25cdaa0192652a11688005182a3fe","normalized_value":"a422649564f3069ed4fcd02f25796ca99ed25cdaa0192652a11688005182a3fe","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"62081924-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521783","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176063","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"TinyMet payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TinyMet payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a422649564f3069ed4fcd02f25796ca99ed25cdaa0192652a11688005182a3fe","normalized_value":"a422649564f3069ed4fcd02f25796ca99ed25cdaa0192652a11688005182a3fe","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ed385175-a025-4b48-8971-0b1575de8530","attribute_id":"37529397","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:03.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"TinyMet\"","tinymet","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["misp-galaxy:malpedia=\"TinyMet\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tinymet","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a59fb8591157cead98a304e4f777a5d2d7f6caf0e562c3362db3a8b26402e284","normalized_value":"a59fb8591157cead98a304e4f777a5d2d7f6caf0e562c3362db3a8b26402e284","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0ff2be8a-6238-4136-94a9-872aaa3ecfb2","attribute_id":"37528382","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783043624","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["RemcosRAT","opendir","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["RemcosRAT","opendir","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a5b5f6027b463d82fded3c38153086d5accc466df33123070ea541e62124b943","normalized_value":"a5b5f6027b463d82fded3c38153086d5accc466df33123070ea541e62124b943","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"16fc2c5e-d42f-4f36-b2db-d38b07fe1d19","attribute_id":"34370322","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581053","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a5e09f90cfc6652180250c327e517ddc63476c63fc009dcff763b28393330b67","normalized_value":"a5e09f90cfc6652180250c327e517ddc63476c63fc009dcff763b28393330b67","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"99ed56ce-cdfa-4af6-991b-9a138fbe8fc3","attribute_id":"37528758","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783083730","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["zip","Vidar","stealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","stealer","tlp:white","type:OSINT","zip"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a6264afd465d3a04bc0594251771ca50e372a8d40068707a67830be581bb2c2b","normalized_value":"a6264afd465d3a04bc0594251771ca50e372a8d40068707a67830be581bb2c2b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"76131a24-7741-11f1-97fa-42010aa4000a","attribute_id":"37521785","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125846","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Formbook payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Formbook payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a6264afd465d3a04bc0594251771ca50e372a8d40068707a67830be581bb2c2b","normalized_value":"a6264afd465d3a04bc0594251771ca50e372a8d40068707a67830be581bb2c2b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"aa7a4efa-d973-455e-8475-3ee8c2e6ed3b","attribute_id":"37528940","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:06.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a6264afd465d3a04bc0594251771ca50e372a8d40068707a67830be581bb2c2b","normalized_value":"a6264afd465d3a04bc0594251771ca50e372a8d40068707a67830be581bb2c2b","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"672a63f8-48cf-43ca-9e2a-c148d5448cee","attribute_id":"37529601","event_id":"58567","event_uuid":"ae1c645a-f761-4e34-b072-4eacf2062a93","event_info":"Formbook host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783047785","event_timestamp":"1783215209","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","stone:malware-categorization=\"Stealer\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Stealer\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a64c3e0522fad787b95bfb6a30c3aed1b5786e69e88e023c062ec7e5cebf4d3e","normalized_value":"a64c3e0522fad787b95bfb6a30c3aed1b5786e69e88e023c062ec7e5cebf4d3e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dfc4438d-6fd2-4e3f-a35a-4c16a94d4a54","attribute_id":"37025666","event_id":"56910","event_uuid":"53be7197-1af5-4a19-96c3-a7c48ab0af68","event_info":"HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine","event_date":"2022-02-24","attribute_timestamp":"1783792814","event_timestamp":"1783792825","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSC-NL","orgc_uuid":"5697b0c4-9474-4336-b675-28140a950b0b","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"Trojan.Killdisk MalwareBazaar: FoxBlade ( #Hermetic) #Wiper MalwareBazaar: FoxBlade ( #Hermetic) #Wiper","event_extends_uuid":"","tags":{"attribute":["ncsc-nl-ndn:feed=\"selected\"","tlp:white","HermeticWiper","misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Create or Modify System Process - T1543\"","misp-galaxy:mitre-attack-pattern=\"Disk Wipe - T1561\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Shutdown/Reboot - T1529\"","misp-galaxy:target-information=\"Ukraine\"","misp-galaxy:sector=\"Government, Administration\""],"event":["ncsc-nl-ndn:feed=\"selected\"","tlp:white","HermeticWiper","misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Create or Modify System Process - T1543\"","misp-galaxy:mitre-attack-pattern=\"Disk Wipe - T1561\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Shutdown/Reboot - T1529\"","misp-galaxy:target-information=\"Ukraine\"","misp-galaxy:sector=\"Government, Administration\""],"all":["HermeticWiper","misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"Create or Modify System Process - T1543\"","misp-galaxy:mitre-attack-pattern=\"Disk Wipe - T1561\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Shutdown/Reboot - T1529\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:target-information=\"Ukraine\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Trojan.Killdisk MalwareBazaar: FoxBlade ( #Hermetic) #Wiper MalwareBazaar: FoxBlade ( #Hermetic) #Wiper","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a65205ca49ac9a4308981ef7de0d1e5f834741ecfb6f5f2196f2ede18fc0a1cd","normalized_value":"a65205ca49ac9a4308981ef7de0d1e5f834741ecfb6f5f2196f2ede18fc0a1cd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"81bcee26-7741-11f1-97fa-42010aa4000a","attribute_id":"37521786","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125865","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"ValleyRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"ValleyRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a65205ca49ac9a4308981ef7de0d1e5f834741ecfb6f5f2196f2ede18fc0a1cd","normalized_value":"a65205ca49ac9a4308981ef7de0d1e5f834741ecfb6f5f2196f2ede18fc0a1cd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d299fb0f-5cfb-409f-a7d5-e9283ea7b6d0","attribute_id":"37528884","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:25.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ValleyRAT","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","misp-galaxy:malpedia=\"ValleyRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ValleyRAT","misp-galaxy:malpedia=\"ValleyRAT\"","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02","normalized_value":"a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f982cdc2-3a39-4a54-ab2d-c553fd7f3993","attribute_id":"37755405","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140537","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--100d3036-9c6e-5837-8057-cb128b807347","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--100d3036-9c6e-5837-8057-cb128b807347","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a73cd72f82f334e31d4669d43ec819a033c3f088dc96f5fc21002941ace6b61e","normalized_value":"a73cd72f82f334e31d4669d43ec819a033c3f088dc96f5fc21002941ace6b61e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6b25cba4-7741-11f1-97fa-42010aa4000a","attribute_id":"37521787","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125827","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Formbook payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Formbook payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a73cd72f82f334e31d4669d43ec819a033c3f088dc96f5fc21002941ace6b61e","normalized_value":"a73cd72f82f334e31d4669d43ec819a033c3f088dc96f5fc21002941ace6b61e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e3e90ff7-af7f-4cdf-9f41-c35b2ea5d95e","attribute_id":"37528998","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:47.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60","normalized_value":"a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"10d0da77-0e14-45e4-84b4-e68592f8c0bd","attribute_id":"37752422","event_id":"61008","event_uuid":"9337bf84-8d94-4826-a516-5564ea3501a8","event_info":"jscrambler npm Supply-Chain Operation","event_date":"2026-07-27","attribute_timestamp":"1785123850","event_timestamp":"1785124058","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"event":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"all":["Cybercrime","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"jscrambler npm Supply-Chain Operation","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a760dd07a310f681cabbcbb7fe094ca0bdeb7b35270fb8e20be558fde0e5694a","normalized_value":"a760dd07a310f681cabbcbb7fe094ca0bdeb7b35270fb8e20be558fde0e5694a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b3b1209c-5361-471b-bf4d-67f2238753da","attribute_id":"7385966","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581398","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9","normalized_value":"a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"17bdf3f9-b7d8-4a92-b0ba-36d1d346964c","attribute_id":"37752183","event_id":"60991","event_uuid":"58e75ed8-2394-41b3-a563-2324bec70d3a","event_info":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","event_date":"2026-07-22","attribute_timestamp":"1784691371","event_timestamp":"1784691372","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"event":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"all":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509","normalized_value":"a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3743df60-6cb2-404c-82eb-d3ac97d2bc8c","attribute_id":"37755158","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140403","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--fe2f8ad6-ea5f-58ea-bca9-d2c0ead4ad44","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--fe2f8ad6-ea5f-58ea-bca9-d2c0ead4ad44","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509","normalized_value":"a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9c8bd082-dbf9-4786-a89f-6f7ea49b9116","attribute_id":"37752344","event_id":"61005","event_uuid":"efee3167-4868-4f50-b35b-565a4abec419","event_info":"Campaign Targeting Government of thailand via Hermes AI Agent & Hades","event_date":"2026-07-16","attribute_timestamp":"1784906643","event_timestamp":"1784907374","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"VShell Windows Stage 1 Payload","event_extends_uuid":"","tags":{"attribute":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"event":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"all":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"VShell Windows Stage 1 Payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3","normalized_value":"a955d7e2819d5fa8b5f879cb970e1a1a91327098a7383f2a03a5e1e7e19435e3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dddda71c-1342-4eb7-9e78-2405a8e03c0d","attribute_id":"37751399","event_id":"60979","event_uuid":"fea39f60-0010-477f-b097-b30d1547c5a4","event_info":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","event_date":"2026-07-17","attribute_timestamp":"1784273256","event_timestamp":"1784273257","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"event":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"all":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"a9a147313861a5a4e7abd76b3287ce5f6183966b89c5ca95c0e0cf587f40189d","normalized_value":"a9a147313861a5a4e7abd76b3287ce5f6183966b89c5ca95c0e0cf587f40189d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"174851ef-1e1f-45ca-b48e-4b9141a07999","attribute_id":"7386002","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581371","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ab9824b61587c77a8d8649545cdbdc63ed2c384e45c9aba534e3f457f96efa7a","normalized_value":"ab9824b61587c77a8d8649545cdbdc63ed2c384e45c9aba534e3f457f96efa7a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"85491256-0b9b-4cc2-9b82-706f21ea81e2","attribute_id":"37755350","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140505","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--be9b0d73-5f38-5eb3-a04b-7a53ac853ce3","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--be9b0d73-5f38-5eb3-a04b-7a53ac853ce3","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"acff38c20f19afa1c3318528dc1ba6d262f10870f95e053a4908c2a66889d8fd","normalized_value":"acff38c20f19afa1c3318528dc1ba6d262f10870f95e053a4908c2a66889d8fd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dd5fc79f-a952-4ffe-b42c-023364bc5db8","attribute_id":"37523647","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147092","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (MaskGramStealer)","event_extends_uuid":"","tags":{"attribute":["MaskGramStealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["MaskGramStealer","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (MaskGramStealer)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ad55dc11d13afb3fca23cef73a358c9dbfc48a9f4dcfe21755403e6a0d12bc9f","normalized_value":"ad55dc11d13afb3fca23cef73a358c9dbfc48a9f4dcfe21755403e6a0d12bc9f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"eb5aec89-4ea1-45a4-83a7-9196b13dfe62","attribute_id":"37523269","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783131279","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","censys","ClickFix","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ClickFix","censys","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ade49335dd276f96fe3ba89de5eb02ea380901b5ef60ff6311235b6318c57f66","normalized_value":"ade49335dd276f96fe3ba89de5eb02ea380901b5ef60ff6311235b6318c57f66","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"48367c60-fe4e-4fb3-9261-274a1424f874","attribute_id":"35285870","event_id":"54507","event_uuid":"234daefa-6a93-4240-80b8-23582ad75013","event_info":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","event_date":"2021-07-30","attribute_timestamp":"1783639110","event_timestamp":"1783639112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["tlp:white","threat-report"],"event":["tlp:white","threat-report"],"all":["threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"afaa75e5224f201cd71ded822e1bc2e08274c77ad0ad429a538053732c75bd5a","normalized_value":"afaa75e5224f201cd71ded822e1bc2e08274c77ad0ad429a538053732c75bd5a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9012c498-c332-4c36-b831-9deb9a9033de","attribute_id":"37528728","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082589","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"afc72f0d8f24657d0090566ebda910a3be89d4bdd68b029a99a19d146d63adc5","normalized_value":"afc72f0d8f24657d0090566ebda910a3be89d4bdd68b029a99a19d146d63adc5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d34fa64a-9d84-4bdd-bebc-b7539a36a99d","attribute_id":"37752465","event_id":"61011","event_uuid":"a5827ddb-b1cc-450d-9811-00a4b3a7d21a","event_info":"TikTok Videos Promise Pirated Apps, Deliver Vidar and StealC Infostealers Instead","event_date":"2026-07-27","attribute_timestamp":"1785118596","event_timestamp":"1785118597","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":[" C2"," infostealer","NCSA","Social Engineering","Tiktok","tlp:clear"],"event":[" C2"," infostealer","NCSA","Social Engineering","Tiktok","tlp:clear"],"all":[" C2"," infostealer","NCSA","Social Engineering","Tiktok","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TikTok Videos Promise Pirated Apps, Deliver Vidar and StealC Infostealers Instead","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"aff0445b3068a5edbb0a827fe06bbd1153d8939c1709f997d8f583252ba71359","normalized_value":"aff0445b3068a5edbb0a827fe06bbd1153d8939c1709f997d8f583252ba71359","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"11d33528-c5b7-483a-8e72-ca9a81f0314d","attribute_id":"37524564","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:27.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b02174f08e5f467415dbd2a8e61404c8a370e2adcbfaa68bd8e3b52ad68097b4","normalized_value":"b02174f08e5f467415dbd2a8e61404c8a370e2adcbfaa68bd8e3b52ad68097b4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6b3f55cd-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521827","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176079","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Nanocore RAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Nanocore RAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b02174f08e5f467415dbd2a8e61404c8a370e2adcbfaa68bd8e3b52ad68097b4","normalized_value":"b02174f08e5f467415dbd2a8e61404c8a370e2adcbfaa68bd8e3b52ad68097b4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"eef84f1c-f7a1-470b-a89f-36db196e88de","attribute_id":"37529419","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:19.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b02174f08e5f467415dbd2a8e61404c8a370e2adcbfaa68bd8e3b52ad68097b4","normalized_value":"b02174f08e5f467415dbd2a8e61404c8a370e2adcbfaa68bd8e3b52ad68097b4","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"25883dc0-86fa-40f5-a8b5-ee86e44fde1d","attribute_id":"37521453","event_id":"58543","event_uuid":"c4505b05-707b-43d6-be9e-7280c9f43b72","event_info":"Nanocore host indicators [2026-07-04]","event_date":"2026-07-04","attribute_timestamp":"1783148420","event_timestamp":"1783208131","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:malware-categorization=\"Rat\"","tlp:white","tlp:clear","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","tlp:clear","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Rat\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b15fabb4f73fff2dd8dbb1a58e46423e9d33d985af34880d17e410b9ecd6bc47","normalized_value":"b15fabb4f73fff2dd8dbb1a58e46423e9d33d985af34880d17e410b9ecd6bc47","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"663c57c4-7741-11f1-97fa-42010aa4000a","attribute_id":"37521830","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125819","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WannaCryptor payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WannaCryptor payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b15fabb4f73fff2dd8dbb1a58e46423e9d33d985af34880d17e410b9ecd6bc47","normalized_value":"b15fabb4f73fff2dd8dbb1a58e46423e9d33d985af34880d17e410b9ecd6bc47","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e610b0a4-284b-4418-8c7f-f0451f142cbf","attribute_id":"37529020","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:39.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b19e9f8b8b5cefd798ffd7a3b428aa842798d697a049f32cf80c720ccb5602f0","normalized_value":"b19e9f8b8b5cefd798ffd7a3b428aa842798d697a049f32cf80c720ccb5602f0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"52e977ca-e7fe-4c6c-a638-7c635ba0264e","attribute_id":"37523384","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146554","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b19e9f8b8b5cefd798ffd7a3b428aa842798d697a049f32cf80c720ccb5602f0","normalized_value":"b19e9f8b8b5cefd798ffd7a3b428aa842798d697a049f32cf80c720ccb5602f0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a549808a-9801-4e8a-8897-fc37d3fcdc30","attribute_id":"37524473","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:58.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b1df569ad4686e16ec0c661733d56778f59cdb78207a3c2ad66df9b9828c84ab","normalized_value":"b1df569ad4686e16ec0c661733d56778f59cdb78207a3c2ad66df9b9828c84ab","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f2806d72-bee9-4b15-845c-d6e1d53b99be","attribute_id":"34370379","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581105","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b2d68a79a621c3f9e46f9df52ed19b8fec22c3cf5f4e3d8630a2bc68fd43d2ee","normalized_value":"b2d68a79a621c3f9e46f9df52ed19b8fec22c3cf5f4e3d8630a2bc68fd43d2ee","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"19eee228-f4e7-4ad5-ba7d-e51d7e3e9633","attribute_id":"7386230","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581192","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b4132ade3a61842f043b9bafc6aa6a874efd20c93b5266ab611f5d31dc783037","normalized_value":"b4132ade3a61842f043b9bafc6aa6a874efd20c93b5266ab611f5d31dc783037","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fc76bbf9-73a6-4048-ad7e-1be86dacacd6","attribute_id":"37524579","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:22.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b463b4bd78682210a7876555be1251453be68c65793d48ae640ad5fa0ced1882","normalized_value":"b463b4bd78682210a7876555be1251453be68c65793d48ae640ad5fa0ced1882","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c399be4a-da43-47ab-8a83-7f109bf4359b","attribute_id":"37523083","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162510","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","opendir","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b46f58cd9bbdcfdec0908e67229b484c6f8482523092dd627e0e97fec62e53a4","normalized_value":"b46f58cd9bbdcfdec0908e67229b484c6f8482523092dd627e0e97fec62e53a4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"35d9c610-40cd-46b1-b3bc-28da978c12f1","attribute_id":"37529012","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:42.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"TinyMet\"","tinymet","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["misp-galaxy:malpedia=\"TinyMet\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tinymet","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b46f58cd9bbdcfdec0908e67229b484c6f8482523092dd627e0e97fec62e53a4","normalized_value":"b46f58cd9bbdcfdec0908e67229b484c6f8482523092dd627e0e97fec62e53a4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"67b2194b-7741-11f1-97fa-42010aa4000a","attribute_id":"37521832","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125822","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"TinyMet payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TinyMet payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b587d049e9fae11f4fe70d5f6c9007f99483f683ee55217110094206bd6a92f2","normalized_value":"b587d049e9fae11f4fe70d5f6c9007f99483f683ee55217110094206bd6a92f2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"590c9b36-0992-407a-9992-4197f6fd5063","attribute_id":"7386065","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581323","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556","normalized_value":"b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2e2af985-9410-44be-b479-29be06f91943","attribute_id":"37752434","event_id":"61009","event_uuid":"d942d9c8-237d-455a-9940-6429c473cff1","event_info":"New Stealthy Ransomware Deployed Against Asian IT Company","event_date":"2026-07-27","attribute_timestamp":"1785124153","event_timestamp":"1785124153","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"event":["NCSA","NCSA_Research"," Ransomware","tlp:clear"],"all":[" Ransomware","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"New Stealthy Ransomware Deployed Against Asian IT Company","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b60ce046f32587bc6b87df4cd530c6728af82c482df2a3fe14c88d5fd252ca30","normalized_value":"b60ce046f32587bc6b87df4cd530c6728af82c482df2a3fe14c88d5fd252ca30","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"16dd1a81-13c0-466d-879b-c9fb13ff9e52","attribute_id":"37528406","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783044775","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b653b06393dd413224e7b31a3e1074c79a5dc691506ad460f6c93e3081dcc7ea","normalized_value":"b653b06393dd413224e7b31a3e1074c79a5dc691506ad460f6c93e3081dcc7ea","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0801ad47-6d00-4fcb-8611-18b416c386e5","attribute_id":"37528662","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783084942","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Hancitor","doc","html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Hancitor","doc","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53","normalized_value":"b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3ae61cfc-93bb-47a2-8ada-3d6949c77c47","attribute_id":"37752346","event_id":"61005","event_uuid":"efee3167-4868-4f50-b35b-565a4abec419","event_info":"Campaign Targeting Government of thailand via Hermes AI Agent & Hades","event_date":"2026-07-16","attribute_timestamp":"1784906643","event_timestamp":"1784907374","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"VShell Windows Stage 2 Payload","event_extends_uuid":"","tags":{"attribute":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"event":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"all":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"VShell Windows Stage 2 Payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53","normalized_value":"b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f5daf7bb-5f4b-41fe-bc98-e78c780241be","attribute_id":"37755157","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140402","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--438840d6-fc09-5941-a67d-0b2765d2a342","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--438840d6-fc09-5941-a67d-0b2765d2a342","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b66119ad548007e383d58987d81a200a42a89f021d0fc3b57022b91ea267bd2c","normalized_value":"b66119ad548007e383d58987d81a200a42a89f021d0fc3b57022b91ea267bd2c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7f591e25-7741-11f1-97fa-42010aa4000a","attribute_id":"37521834","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125861","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Nanocore RAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Nanocore RAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b66119ad548007e383d58987d81a200a42a89f021d0fc3b57022b91ea267bd2c","normalized_value":"b66119ad548007e383d58987d81a200a42a89f021d0fc3b57022b91ea267bd2c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9c396653-1419-455f-a604-b9f560681db7","attribute_id":"37528896","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:21.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b66119ad548007e383d58987d81a200a42a89f021d0fc3b57022b91ea267bd2c","normalized_value":"b66119ad548007e383d58987d81a200a42a89f021d0fc3b57022b91ea267bd2c","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"deb432d7-cc1d-408e-91c4-9db1edbc296f","attribute_id":"37529939","event_id":"58582","event_uuid":"6b8769a4-8845-4d75-a954-99fbbe33522f","event_info":"Nanocore host indicators [2026-07-02]","event_date":"2026-07-02","attribute_timestamp":"1783018935","event_timestamp":"1783019772","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:malware-categorization=\"Rat\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Rat\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b670441066ff868d06c682e5167b9dbc85b5323f3acfbbc044cabc0e5a594186","normalized_value":"b670441066ff868d06c682e5167b9dbc85b5323f3acfbbc044cabc0e5a594186","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"250d7f64-199b-47d3-aad1-705360e5c7af","attribute_id":"7386090","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581287","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b6fba18b6641eac47499735a0c872814b20bdc65ed491c04769d0e556d2ec40b","normalized_value":"b6fba18b6641eac47499735a0c872814b20bdc65ed491c04769d0e556d2ec40b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"965b083d-e3be-4716-9f11-302dbe1efb2e","attribute_id":"37524456","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:05.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b6fba18b6641eac47499735a0c872814b20bdc65ed491c04769d0e556d2ec40b","normalized_value":"b6fba18b6641eac47499735a0c872814b20bdc65ed491c04769d0e556d2ec40b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f309f3cb-ae60-4f7a-a43c-254fd46ea0df","attribute_id":"37523419","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146558","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b7443b0ab48d2f5786d1b6f3a580f02621e9ae5a3877ee3a44e01df13d984328","normalized_value":"b7443b0ab48d2f5786d1b6f3a580f02621e9ae5a3877ee3a44e01df13d984328","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4ad46273-6034-48d1-8ec9-3084f68fabe8","attribute_id":"37752292","event_id":"61000","event_uuid":"9307ed9a-80db-44e5-a862-1e8bf57deb45","event_info":"LabubaRAT: Masquerading as NVIDIA Software","event_date":"2026-07-24","attribute_timestamp":"1784858876","event_timestamp":"1784858947","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Analyzed LabubaRAT sample","event_extends_uuid":"","tags":{"attribute":["tlp:clear","NCSA","Masquerading","RAT","windows"],"event":["tlp:clear","NCSA","Masquerading","RAT","windows"],"all":["Masquerading","NCSA","RAT","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Analyzed LabubaRAT sample","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b7443b0ab48d2f5786d1b6f3a580f02621e9ae5a3877ee3a44e01df13d984328","normalized_value":"b7443b0ab48d2f5786d1b6f3a580f02621e9ae5a3877ee3a44e01df13d984328","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bf160c37-888f-4e77-902a-164aae22b3db","attribute_id":"37752190","event_id":"60992","event_uuid":"174a3b8c-98b2-47fc-b353-5d9bcf8faf6e","event_info":"LabubaRAT A Rust Based Remote Access Tool Masquerading as NVIDIA Software","event_date":"2026-07-22","attribute_timestamp":"1784703460","event_timestamp":"1784703460","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","RAT","tlp:clear","Create-By\"Methanon\""],"event":["NCSA","NCSA_Research","RAT","tlp:clear","Create-By\"Methanon\""],"all":["Create-By\"Methanon\"","NCSA","NCSA_Research","RAT","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"LabubaRAT A Rust Based Remote Access Tool Masquerading as NVIDIA Software","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b7443b0ab48d2f5786d1b6f3a580f02621e9ae5a3877ee3a44e01df13d984328","normalized_value":"b7443b0ab48d2f5786d1b6f3a580f02621e9ae5a3877ee3a44e01df13d984328","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cc3bc443-8123-44e8-93f7-3ed293614183","attribute_id":"37746199","event_id":"60921","event_uuid":"1a636e1d-d562-4bb2-b40d-e165978faea4","event_info":"LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software","event_date":"2026-07-16","attribute_timestamp":"1784171166","event_timestamp":"1784171168","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  ","Masquerading","NCSA","RAT","nvidia","windows","tlp:clear"],"event":["  Malware  ","Masquerading","NCSA","RAT","nvidia","windows","tlp:clear"],"all":["  Malware  ","Masquerading","NCSA","RAT","nvidia","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b757895ff266b1161a0dace31a7e3487cedaed2f0ebf89f5ce1442e9502715c5","normalized_value":"b757895ff266b1161a0dace31a7e3487cedaed2f0ebf89f5ce1442e9502715c5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"19ce5318-57eb-45d8-963c-998619053e46","attribute_id":"37528848","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783106860","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Hancitor","doc","html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Hancitor","doc","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903","normalized_value":"b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0adcad00-98ae-469d-af2d-643ac2e60d89","attribute_id":"37752426","event_id":"61008","event_uuid":"9337bf84-8d94-4826-a516-5564ea3501a8","event_info":"jscrambler npm Supply-Chain Operation","event_date":"2026-07-27","attribute_timestamp":"1785123850","event_timestamp":"1785124058","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"event":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"all":["Cybercrime","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"jscrambler npm Supply-Chain Operation","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b7d50d0406afcd2efd87bf3bf8c4211719ba9817dd2e0ad62af10c933e765e28","normalized_value":"b7d50d0406afcd2efd87bf3bf8c4211719ba9817dd2e0ad62af10c933e765e28","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7c720970-5971-49a8-88ae-ceda4bf385db","attribute_id":"37521408","event_id":"58527","event_uuid":"bb3d2aed-e7ff-4097-b022-849110a41ab8","event_info":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","event_date":"2026-07-06","attribute_timestamp":"1783319885","event_timestamp":"1783319886","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"event":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"all":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b7ec650df72dc36580fdf68d9ccbbbc4e91286c9389064570c9e61d6b1dd8bca","normalized_value":"b7ec650df72dc36580fdf68d9ccbbbc4e91286c9389064570c9e61d6b1dd8bca","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6371c71b-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521836","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176066","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b7ec650df72dc36580fdf68d9ccbbbc4e91286c9389064570c9e61d6b1dd8bca","normalized_value":"b7ec650df72dc36580fdf68d9ccbbbc4e91286c9389064570c9e61d6b1dd8bca","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7b860134-fb2d-4246-b22e-1984e95c499c","attribute_id":"37529423","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:06.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b8ac1fc0e1f6a0b04f76ea66f4f4d45c171f11486ab928d949b1c3ce104334e0","normalized_value":"b8ac1fc0e1f6a0b04f76ea66f4f4d45c171f11486ab928d949b1c3ce104334e0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fe64f435-c405-4095-ac4a-214baa6409de","attribute_id":"7386055","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581328","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b8bbe47e184340d154e1d68d8ce80b2098eaaad43fbf37ca4cf03a12cbd11b28","normalized_value":"b8bbe47e184340d154e1d68d8ce80b2098eaaad43fbf37ca4cf03a12cbd11b28","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2a758c83-1660-4246-b03b-3d5ed7e4974d","attribute_id":"37523323","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783134681","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (ConnectWise)","event_extends_uuid":"","tags":{"attribute":["ConnectWise","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ConnectWise","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (ConnectWise)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b8d9821a478f1a377095867aeb2038c464cc59ed31a4c7413ff768f2e14d3886","normalized_value":"b8d9821a478f1a377095867aeb2038c464cc59ed31a4c7413ff768f2e14d3886","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b2968ec0-9195-476e-8475-71350c2f7fb3","attribute_id":"37752466","event_id":"61011","event_uuid":"a5827ddb-b1cc-450d-9811-00a4b3a7d21a","event_info":"TikTok Videos Promise Pirated Apps, Deliver Vidar and StealC Infostealers Instead","event_date":"2026-07-27","attribute_timestamp":"1785118596","event_timestamp":"1785118597","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":[" C2"," infostealer","NCSA","Social Engineering","Tiktok","tlp:clear"],"event":[" C2"," infostealer","NCSA","Social Engineering","Tiktok","tlp:clear"],"all":[" C2"," infostealer","NCSA","Social Engineering","Tiktok","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TikTok Videos Promise Pirated Apps, Deliver Vidar and StealC Infostealers Instead","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b928e523b51187b932e48a65d36ce3d0c39ee9d409d493b90f98cf3d1e0e73b0","normalized_value":"b928e523b51187b932e48a65d36ce3d0c39ee9d409d493b90f98cf3d1e0e73b0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"af56ef27-2ea1-4550-991c-adec00d07cd0","attribute_id":"37755114","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112068","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--1cedecc5-9a06-5399-8107-b0938efd82d3","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--1cedecc5-9a06-5399-8107-b0938efd82d3","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b96de9ab78411a112bdcc308163bcd7f88c215ff57bcb58282345c316794b305","normalized_value":"b96de9ab78411a112bdcc308163bcd7f88c215ff57bcb58282345c316794b305","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"68de8227-fb0a-4ff2-a66f-028eac52c770","attribute_id":"37746192","event_id":"60920","event_uuid":"da6f8bf0-0481-4deb-8f9a-f286ff972804","event_info":"DEBULL: Storm-2372-Style Microsoft Device-Code Phishing With GraphSpy Post-Exploitation","event_date":"2026-07-08","attribute_timestamp":"1783480324","event_timestamp":"1783480325","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["Microsoft","NCSA","Phishing","attack-pattern:QR Code Phishing","session-hijacking","tlp:clear"],"event":["Microsoft","NCSA","Phishing","attack-pattern:QR Code Phishing","session-hijacking","tlp:clear"],"all":["Microsoft","NCSA","Phishing","attack-pattern:QR Code Phishing","session-hijacking","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"DEBULL: Storm-2372-Style Microsoft Device-Code Phishing With GraphSpy Post-Exploitation","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b9783c0434065058751b59f89948498ed8d08f93f6c5780cc0ce3a6d02bdf77e","normalized_value":"b9783c0434065058751b59f89948498ed8d08f93f6c5780cc0ce3a6d02bdf77e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"684790b5-7741-11f1-97fa-42010aa4000a","attribute_id":"37521839","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125823","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WannaCryptor payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WannaCryptor payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b9783c0434065058751b59f89948498ed8d08f93f6c5780cc0ce3a6d02bdf77e","normalized_value":"b9783c0434065058751b59f89948498ed8d08f93f6c5780cc0ce3a6d02bdf77e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ac3a5e25-1ff2-46e1-a5cb-9be79e5760e5","attribute_id":"37529009","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:43.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"b9fc587f695426c9dfc01123dcb372299d4f822091fba1e9570a4edaec1a3da3","normalized_value":"b9fc587f695426c9dfc01123dcb372299d4f822091fba1e9570a4edaec1a3da3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6bf24835-9b77-4911-b63e-6782df555cd5","attribute_id":"37523089","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162511","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","arm","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arm","elf","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ba04702400c9a4566c89c3d32785ac2669d3c41ecfcb6950a527eb3e1e5459dd","normalized_value":"ba04702400c9a4566c89c3d32785ac2669d3c41ecfcb6950a527eb3e1e5459dd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"087fe542-9674-4846-874e-4ef0512626e3","attribute_id":"37528504","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783061296","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ba2085d015f02bc9ab296266b8b44ceb3449842aba44b393e4a00bfe3da5508f","normalized_value":"ba2085d015f02bc9ab296266b8b44ceb3449842aba44b393e4a00bfe3da5508f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8ae1fc99-51cc-4be5-8f7e-76858628da1f","attribute_id":"37523668","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147098","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bac16a48407ea22b8905e476bbb93fc0b5ecda8bb70364094479700e33cb15d1","normalized_value":"bac16a48407ea22b8905e476bbb93fc0b5ecda8bb70364094479700e33cb15d1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3a14eb89-970b-4f60-b319-dc82ec31024f","attribute_id":"37529005","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:44.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bac16a48407ea22b8905e476bbb93fc0b5ecda8bb70364094479700e33cb15d1","normalized_value":"bac16a48407ea22b8905e476bbb93fc0b5ecda8bb70364094479700e33cb15d1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"68d3f05c-7741-11f1-97fa-42010aa4000a","attribute_id":"37521841","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125824","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Formbook payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Formbook payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bac16a48407ea22b8905e476bbb93fc0b5ecda8bb70364094479700e33cb15d1","normalized_value":"bac16a48407ea22b8905e476bbb93fc0b5ecda8bb70364094479700e33cb15d1","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"2ffd8f6f-29e3-41fa-b9a3-944ed857aa3b","attribute_id":"37529616","event_id":"58567","event_uuid":"ae1c645a-f761-4e34-b072-4eacf2062a93","event_info":"Formbook host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783105274","event_timestamp":"1783215209","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bacb8e6d037adfe4e4643c6d8b64d47c0b7eb5a2716733871e6efde97130bd62","normalized_value":"bacb8e6d037adfe4e4643c6d8b64d47c0b7eb5a2716733871e6efde97130bd62","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ca2a4f6d-7488-46f1-8dfc-0c6aeecd5ea5","attribute_id":"37523412","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146557","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bb9a5f5fe0d086e592ea23909cb1aa8baf792990c90691016da16908d01e83a4","normalized_value":"bb9a5f5fe0d086e592ea23909cb1aa8baf792990c90691016da16908d01e83a4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"715781d9-7741-11f1-97fa-42010aa4000a","attribute_id":"37521855","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125838","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"CrossRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"CrossRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bb9a5f5fe0d086e592ea23909cb1aa8baf792990c90691016da16908d01e83a4","normalized_value":"bb9a5f5fe0d086e592ea23909cb1aa8baf792990c90691016da16908d01e83a4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cf1be5e7-b6d8-4dff-aacf-a86da4ed909a","attribute_id":"37528962","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:58.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["crossrat","misp-galaxy:malpedia=\"CrossRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["crossrat","misp-galaxy:malpedia=\"CrossRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bb9a5f5fe0d086e592ea23909cb1aa8baf792990c90691016da16908d01e83a4","normalized_value":"bb9a5f5fe0d086e592ea23909cb1aa8baf792990c90691016da16908d01e83a4","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"97240ab6-b125-4510-b71d-2e10484c546b","attribute_id":"37529642","event_id":"58570","event_uuid":"73b7ed82-0d87-402a-adfd-2462e0268878","event_info":"Remcos host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783069345","event_timestamp":"1783215210","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:malware-categorization=\"Rat\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Rat\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bba32ddeab075a5e5015eec50f5d2af364c95b848732c714aea6b6baf78f49f0","normalized_value":"bba32ddeab075a5e5015eec50f5d2af364c95b848732c714aea6b6baf78f49f0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"151c033c-60fd-4f4d-b658-ce2f114924eb","attribute_id":"37752424","event_id":"61008","event_uuid":"9337bf84-8d94-4826-a516-5564ea3501a8","event_info":"jscrambler npm Supply-Chain Operation","event_date":"2026-07-27","attribute_timestamp":"1785123850","event_timestamp":"1785124058","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"event":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"all":["Cybercrime","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"jscrambler npm Supply-Chain Operation","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bbed04bd22b2b4043a2d11fb032af16428604e96be201a9b0bc68fa3ecfcc962","normalized_value":"bbed04bd22b2b4043a2d11fb032af16428604e96be201a9b0bc68fa3ecfcc962","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7b0316e5-150b-4bed-8add-10fa903226e4","attribute_id":"37528455","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783060238","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bcb93b961d7188b32745b05b700959ba49d5b05ea870d9eeed2e2db63e8b7575","normalized_value":"bcb93b961d7188b32745b05b700959ba49d5b05ea870d9eeed2e2db63e8b7575","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d8a607c0-cff3-475b-b621-02ab0e9e4986","attribute_id":"37523197","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783128385","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Mirai","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bcdac1a2b67e2b47f8129814dca3bcf7d55404757eb09f1c3103f57da3153ec8","normalized_value":"bcdac1a2b67e2b47f8129814dca3bcf7d55404757eb09f1c3103f57da3153ec8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"13df2c70-bb96-43cc-9674-bd2bfc16d27d","attribute_id":"35015721","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558081","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"WastedLocker samples (sha256 hashes)","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WastedLocker samples (sha256 hashes)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bd7779e6100e07b3eae67bfcdc53f1f08468651240229e284cca60e2b953496b","normalized_value":"bd7779e6100e07b3eae67bfcdc53f1f08468651240229e284cca60e2b953496b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"05a7cab3-0fcb-4b25-844c-2bfa63a1cd92","attribute_id":"34370391","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581117","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bde5f995304e327d522291bf9886c987223a51a299b80ab62229fcc5e9d09f62","normalized_value":"bde5f995304e327d522291bf9886c987223a51a299b80ab62229fcc5e9d09f62","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"164d43ef-a223-441b-9848-7835ce519cf5","attribute_id":"69221","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686556","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"be5290657b25d3e8806e9fb34eb97b3689bb7698522f90963d3d2783341acca9","normalized_value":"be5290657b25d3e8806e9fb34eb97b3689bb7698522f90963d3d2783341acca9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"259e1d7b-9e7b-4a45-97b3-00ea0aa68ae0","attribute_id":"37523661","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147092","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (MaskGramStealer)","event_extends_uuid":"","tags":{"attribute":["MaskGramStealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["MaskGramStealer","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (MaskGramStealer)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"be5b469852253e4c60925777c114b46e7fca797bd21dc39b2f3774589ce0909a","normalized_value":"be5b469852253e4c60925777c114b46e7fca797bd21dc39b2f3774589ce0909a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"711aa13b-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521858","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176089","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Venus Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Venus Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"be5b469852253e4c60925777c114b46e7fca797bd21dc39b2f3774589ce0909a","normalized_value":"be5b469852253e4c60925777c114b46e7fca797bd21dc39b2f3774589ce0909a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c6875dfa-4e62-4d82-8ac8-f6a45d11662a","attribute_id":"37529432","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:29.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343","normalized_value":"bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cf8173dd-6646-4b87-b54b-49d0cf9df931","attribute_id":"37751397","event_id":"60979","event_uuid":"fea39f60-0010-477f-b097-b30d1547c5a4","event_info":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","event_date":"2026-07-17","attribute_timestamp":"1784273256","event_timestamp":"1784273257","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"event":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"all":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c02c7b9a82a75cb251b2b7307503284a408f20e689f1be30fe50173a8b6e288b","normalized_value":"c02c7b9a82a75cb251b2b7307503284a408f20e689f1be30fe50173a8b6e288b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f293b1f4-15ba-4849-8a13-bc5296d61cf5","attribute_id":"37749167","event_id":"60956","event_uuid":"36e03b09-a20c-4169-a875-b77a24ca82fd","event_info":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","event_date":"2023-03-14","attribute_timestamp":"1783685710","event_timestamp":"1783685737","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"event":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"all":["Ave Maria","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","Energy Sector ","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cyber espionage","infostealer","meterpreter","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","osint:source-type=\"blog-post\"","tlp:clear","warzonerat"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c0654c18ccb6784c34113bbd65305a35adaa0ae9290b83f05d7ad2625d638be8","normalized_value":"c0654c18ccb6784c34113bbd65305a35adaa0ae9290b83f05d7ad2625d638be8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"703de47d-145b-4dfb-b434-d2b37f1dc048","attribute_id":"37528601","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783065987","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["elf","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c0ec1488902568be9a4960c670dfa5edac0e096d106d782fa6bc26ee56793b75","normalized_value":"c0ec1488902568be9a4960c670dfa5edac0e096d106d782fa6bc26ee56793b75","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8f1e4725-c462-4804-90f4-ac609fc43140","attribute_id":"37771815","event_id":"61037","event_uuid":"7aa6269b-c2fd-4b5a-a76d-c684a98af051","event_info":"SilverFox Evolves ValleyRAT Japan","event_date":"2026-07-31","attribute_timestamp":"1785483192","event_timestamp":"1785483192","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"event":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"],"all":["\tValleyRAT","  Malware  ","China","Dll Side Loading","Manufacturing","NCSA","byovd","japan","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"SilverFox Evolves ValleyRAT Japan","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c0fdb1dd0023708a10a3d2f964ce27f36c2f024b6d5db2bbba2a896a31070223","normalized_value":"c0fdb1dd0023708a10a3d2f964ce27f36c2f024b6d5db2bbba2a896a31070223","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"52a3fae8-ade6-437f-adeb-d756c05e8018","attribute_id":"37523305","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783134671","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (ConnectWise)","event_extends_uuid":"","tags":{"attribute":["ConnectWise","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ConnectWise","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (ConnectWise)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c11aeec42a7f3c4e7895d37cf403b6900793226444dfc83ad2b85aab152e457c","normalized_value":"c11aeec42a7f3c4e7895d37cf403b6900793226444dfc83ad2b85aab152e457c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4bb2c6dd-b85c-46e9-a338-795afddc026d","attribute_id":"37523552","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146562","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c11aeec42a7f3c4e7895d37cf403b6900793226444dfc83ad2b85aab152e457c","normalized_value":"c11aeec42a7f3c4e7895d37cf403b6900793226444dfc83ad2b85aab152e457c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f2e3437f-e0cc-409a-bff8-b84e6372fb87","attribute_id":"37524433","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:12.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c1389515e42a5e2753f26f48c37d1822046af00889144b12e52d56cd6d20b4f7","normalized_value":"c1389515e42a5e2753f26f48c37d1822046af00889144b12e52d56cd6d20b4f7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9796c41f-1494-430c-b14e-07b8c8564618","attribute_id":"37528800","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783087762","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["zip","Vidar","stealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","stealer","tlp:white","type:OSINT","zip"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c1af9c6d656ba5b94c4a5a4f3e0bf58fa507df0a92772fa2242c67e5ba543277","normalized_value":"c1af9c6d656ba5b94c4a5a4f3e0bf58fa507df0a92772fa2242c67e5ba543277","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"31f4389e-ad19-4c82-b7c5-d3585824ffa5","attribute_id":"37528613","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783066133","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c21ecd18f0bbb28112240013ad42dad5c01d20927791239ada5b61e1c6f5f010","normalized_value":"c21ecd18f0bbb28112240013ad42dad5c01d20927791239ada5b61e1c6f5f010","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2e526472-41b5-4022-b7e4-ea04721d577e","attribute_id":"7386221","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581198","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c2a388115e47c2ffb0f65ec4ef28f8c961e9c37ade10b39dd920fa5909824e7f","normalized_value":"c2a388115e47c2ffb0f65ec4ef28f8c961e9c37ade10b39dd920fa5909824e7f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6ef67f25-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521878","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176085","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c2a388115e47c2ffb0f65ec4ef28f8c961e9c37ade10b39dd920fa5909824e7f","normalized_value":"c2a388115e47c2ffb0f65ec4ef28f8c961e9c37ade10b39dd920fa5909824e7f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e81b192b-964e-474f-ab87-8dee1ceaa46c","attribute_id":"37529435","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:25.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c2bd70495630ed8279de0713a010e5e55f3da29323b59ef71401b12942ba52f6","normalized_value":"c2bd70495630ed8279de0713a010e5e55f3da29323b59ef71401b12942ba52f6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f2740605-8c96-4438-9b8f-df4a81b962c1","attribute_id":"7386084","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581279","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c2cfd3d5cc6db52356661d50b0374c494c96af73cb0fea33babb9616d4453098","normalized_value":"c2cfd3d5cc6db52356661d50b0374c494c96af73cb0fea33babb9616d4453098","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0c0594e5-6bd3-4bdd-9c85-42eeb8fd2d5d","attribute_id":"37524462","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:03.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c2cfd3d5cc6db52356661d50b0374c494c96af73cb0fea33babb9616d4453098","normalized_value":"c2cfd3d5cc6db52356661d50b0374c494c96af73cb0fea33babb9616d4453098","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"63782b05-4a06-4c08-8783-ba294bd233aa","attribute_id":"37523587","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146566","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c358ce61a0a5d3f70a9acea920c98027a0c847fb23835d34d0f88fc1f534130d","normalized_value":"c358ce61a0a5d3f70a9acea920c98027a0c847fb23835d34d0f88fc1f534130d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5eaca14e-7146-42d7-9b9e-d4635878692e","attribute_id":"37532476","event_id":"58606","event_uuid":"f34db162-ecc4-440c-aa50-ccb53f0693f4","event_info":"PhantomStealer in .rar email attachment (SMTP exfil)","event_date":"2026-07-03","attribute_timestamp":"1783056960","event_timestamp":"1784166491","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"MORS_142","orgc_uuid":"11e8cd1e-4a8a-44d7-bbd3-d05f03867b7e","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["MALWARE","keylogger/infostealer","Keylogger"," Keylogger","infostealer","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","tlp:clear"," Malware"," infostealer","  Malware  ","phantom stealer","malware_name:PHANTOM STEALER","obfuscated-js"],"event":["MALWARE","keylogger/infostealer","Keylogger"," Keylogger","infostealer","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","tlp:clear"," Malware"," infostealer","  Malware  ","phantom stealer","malware_name:PHANTOM STEALER","obfuscated-js"],"all":["  Malware  "," Keylogger"," Malware"," infostealer","Keylogger","MALWARE","infostealer","keylogger/infostealer","malware_name:PHANTOM STEALER","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","obfuscated-js","phantom stealer","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"PhantomStealer in .rar email attachment (SMTP exfil)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c433957cc91e17664147cbbb9dabcee58a81747a4e4b3fdb233b6daedd8974ab","normalized_value":"c433957cc91e17664147cbbb9dabcee58a81747a4e4b3fdb233b6daedd8974ab","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5a1990d7-4bfc-4156-9a91-d37fba2b7339","attribute_id":"37523131","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125120","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0","normalized_value":"c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6d3c3918-f9a5-417c-bd9e-8cf7e2dc0dff","attribute_id":"37755404","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140537","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--64306c40-5ac0-58f5-bfe8-317db0a6c169","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--64306c40-5ac0-58f5-bfe8-317db0a6c169","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c4859db541b2bd0d266bbc44fafb5a767c862a57a3633a949dfaeebdf88ed529","normalized_value":"c4859db541b2bd0d266bbc44fafb5a767c862a57a3633a949dfaeebdf88ed529","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0c5df94f-a8d0-43b8-91f6-21b78775122b","attribute_id":"37755113","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112068","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--afa807a7-59a6-5d46-bcfc-4a52aca984cb","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--afa807a7-59a6-5d46-bcfc-4a52aca984cb","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c4a9de21aad3e71b08bfbcc827d4c242f8915e763117d254e41febe6df4807cc","normalized_value":"c4a9de21aad3e71b08bfbcc827d4c242f8915e763117d254e41febe6df4807cc","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"876bd597-bbda-4e21-8982-7725628c2ff4","attribute_id":"37755477","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785265253","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--fdedd7d6-32f7-5ac6-87a2-bd4cca7a723e","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--fdedd7d6-32f7-5ac6-87a2-bd4cca7a723e","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c","normalized_value":"c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cca3d114-697b-4cad-95cc-592e434f65ed","attribute_id":"37755403","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140536","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--b3b463aa-5c7e-5353-b316-9a723ef32be5","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--b3b463aa-5c7e-5353-b316-9a723ef32be5","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c5950c484b3fdf3f64c019c49d04232845b156b18e30198e163e2a9c14bf05c0","normalized_value":"c5950c484b3fdf3f64c019c49d04232845b156b18e30198e163e2a9c14bf05c0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3b7caf7b-ee5d-47fd-9e2b-390c9ac6cdab","attribute_id":"37523179","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783127606","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","arm","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arm","elf","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c5aed4c063d4970a03250778da8041da9e0c83d8f22d2f1994da0ad72567ebd9","normalized_value":"c5aed4c063d4970a03250778da8041da9e0c83d8f22d2f1994da0ad72567ebd9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2a70b069-0574-4453-9e74-a522c2e6d190","attribute_id":"37755438","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140556","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--3b78ec4a-f214-5566-85a6-5660d4a99e82","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--3b78ec4a-f214-5566-85a6-5660d4a99e82","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809","normalized_value":"c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"44330bf5-cb9a-448c-b1a6-945a1af7be64","attribute_id":"37755402","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140536","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--f2f9d4e8-7bba-5578-bf7f-9b3c1d846f12","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--f2f9d4e8-7bba-5578-bf7f-9b3c1d846f12","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c60ead92cd376b689d1b4450f2578b36ea0bf64f3963cfa5546279fa4424c2a5","normalized_value":"c60ead92cd376b689d1b4450f2578b36ea0bf64f3963cfa5546279fa4424c2a5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"089b9c9d-f30d-4c9a-9ed8-bf524e601b51","attribute_id":"37748491","event_id":"60948","event_uuid":"de525eea-c091-4fa7-8dc6-218ce63d53ad","event_info":"Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials","event_date":"2024-04-23","attribute_timestamp":"1783666996","event_timestamp":"1783666998","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Hash of GooseEgg binary DefragmentSrv.exe","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","OSINT","osint:source-type=\"blog-post\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","APT","Actor: APT28","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"United States\"","tlp:clear","Microsoft Corporation","windows","JavaScript","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:threat-actor=\"APT28\"","misp-galaxy:country=\"russia\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","PrintNightmare"],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","OSINT","osint:source-type=\"blog-post\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","APT","Actor: APT28","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"United States\"","tlp:clear","Microsoft Corporation","windows","JavaScript","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:threat-actor=\"APT28\"","misp-galaxy:country=\"russia\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","PrintNightmare"],"all":["APT","Actor: APT28","JavaScript","Microsoft Corporation","OSINT","PrintNightmare","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","misp-galaxy:360net-threat-actor=\"奇幻熊 - APT-C-20\"","misp-galaxy:country=\"russia\"","misp-galaxy:eset-threat-actor=\"fe6ac527-9dc1-49e7-a122-65a45d179d67\"","misp-galaxy:groups=\"STRONTIUM - Associated Group\"","misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\"","misp-galaxy:microsoft-activity-group=\"Forest Blizzard\"","misp-galaxy:microsoft-activity-group=\"STRONTIUM\"","misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-mobile-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:mitre-pre-attack-intrusion-set=\"APT28 - G0007\"","misp-galaxy:sector=\"Education\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"IT\"","misp-galaxy:sector=\"NGO\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"61986b56-e9eb-495f-97f4-4a8ac45b3837\"","misp-galaxy:target-information=\"United States\"","misp-galaxy:threat-actor=\"APT28\"","osint:source-type=\"blog-post\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Hash of GooseEgg binary DefragmentSrv.exe","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c62a539ef0b524d81b3379a21d52f1b1799f39be30c107abb80c91159c913cea","normalized_value":"c62a539ef0b524d81b3379a21d52f1b1799f39be30c107abb80c91159c913cea","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8857b166-2b35-4f12-b24c-971771353bb3","attribute_id":"37528794","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783087330","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","botnet","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","botnet","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c7195e19685ed252be9d105f817a31a475430e76c9beec4cc76d3377f784a21b","normalized_value":"c7195e19685ed252be9d105f817a31a475430e76c9beec4cc76d3377f784a21b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1e6b7a86-f5e0-48bf-ba72-d8e3776d6395","attribute_id":"37524573","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:24.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c71b437679db06f6f7bda909fdde306aa0080047fa6b3d63ba0cf0b66cdd062d","normalized_value":"c71b437679db06f6f7bda909fdde306aa0080047fa6b3d63ba0cf0b66cdd062d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"16cf83b5-7b63-4bd7-85a8-81edf15d4c22","attribute_id":"37528474","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783060466","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c725815cbb07ab5be8903e74ef8aea46ef9c25e4a3bc626ae94bfc1ae21df6e3","normalized_value":"c725815cbb07ab5be8903e74ef8aea46ef9c25e4a3bc626ae94bfc1ae21df6e3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a1bc0ca5-31c1-40f6-bc2a-a3cc62bc7679","attribute_id":"37521412","event_id":"58527","event_uuid":"bb3d2aed-e7ff-4097-b022-849110a41ab8","event_info":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","event_date":"2026-07-06","attribute_timestamp":"1783319886","event_timestamp":"1783319886","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"event":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"all":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c767bb6b6dd0b149e46b7066269b6d9fac1f9eb2dcafcec59475fd78a8af7861","normalized_value":"c767bb6b6dd0b149e46b7066269b6d9fac1f9eb2dcafcec59475fd78a8af7861","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"888248e6-912c-4a68-9652-68329b17c4b3","attribute_id":"37523594","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147089","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (njrat)","event_extends_uuid":"","tags":{"attribute":["njRat","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["njRat","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (njrat)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a","normalized_value":"c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3b18f350-aab3-49f4-b5e4-2f638e715178","attribute_id":"37523654","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147092","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (RemusStealer)","event_extends_uuid":"","tags":{"attribute":["RemusStealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["RemusStealer","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (RemusStealer)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a","normalized_value":"c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"66cb7b5b-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521882","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176071","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Venus Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Venus Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a","normalized_value":"c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b03fb5e1-1148-47e2-99a6-acdd05b880d4","attribute_id":"37529439","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:11.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c892bbba158d46b0a77addb158c7c12c2c78f177b048bd48350ee9973daa0ed3","normalized_value":"c892bbba158d46b0a77addb158c7c12c2c78f177b048bd48350ee9973daa0ed3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"397da5d1-68f2-4d3b-a257-82aa6a66a6f9","attribute_id":"7386018","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581363","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd","normalized_value":"c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8b13ad8d-9af9-407c-b7cd-bd4cdf85ed4b","attribute_id":"37752427","event_id":"61008","event_uuid":"9337bf84-8d94-4826-a516-5564ea3501a8","event_info":"jscrambler npm Supply-Chain Operation","event_date":"2026-07-27","attribute_timestamp":"1785123850","event_timestamp":"1785124058","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"event":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"all":["Cybercrime","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"jscrambler npm Supply-Chain Operation","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"c971a72437d2324db042cf0157d696b60893301a30a056eeec1627146134527a","normalized_value":"c971a72437d2324db042cf0157d696b60893301a30a056eeec1627146134527a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a082a956-5c19-4fa6-97f1-c4d9aa62e66e","attribute_id":"37528812","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783088495","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Emotet","heodo","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Emotet","heodo","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ca730b8b355e44919629a958d940e77eb1b4cd0c1bbe2ab94a963222f2723f57","normalized_value":"ca730b8b355e44919629a958d940e77eb1b4cd0c1bbe2ab94a963222f2723f57","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"51805353-59f1-4770-be15-e40dfebd64eb","attribute_id":"34370343","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581070","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"cadea6f17dbee66cfb2d7aa1ed49f168f9fc201dcdd8d5b30d4e2cfdb7e069ca","normalized_value":"cadea6f17dbee66cfb2d7aa1ed49f168f9fc201dcdd8d5b30d4e2cfdb7e069ca","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"737e2ee2-7741-11f1-97fa-42010aa4000a","attribute_id":"37521884","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125841","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Nanocore RAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Nanocore RAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"cadea6f17dbee66cfb2d7aa1ed49f168f9fc201dcdd8d5b30d4e2cfdb7e069ca","normalized_value":"cadea6f17dbee66cfb2d7aa1ed49f168f9fc201dcdd8d5b30d4e2cfdb7e069ca","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fc75880f-dcd7-4bf4-bcb1-a84ccf297463","attribute_id":"37528955","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:01.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["NanoCore RAT","misp-galaxy:malpedia=\"Nanocore RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"cadea6f17dbee66cfb2d7aa1ed49f168f9fc201dcdd8d5b30d4e2cfdb7e069ca","normalized_value":"cadea6f17dbee66cfb2d7aa1ed49f168f9fc201dcdd8d5b30d4e2cfdb7e069ca","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"82c1246b-9d32-40b2-bc4e-41b5cfe03d9c","attribute_id":"37529597","event_id":"58566","event_uuid":"2db09176-7164-4ec7-b19a-7cc874aca130","event_info":"Nanocore host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783062020","event_timestamp":"1783062020","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white"],"event":["tlp:white"],"all":["kill-chain:Installation","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"cbf973cb030511d30c40beaf2c965d86c844bff5222ec8a9ff363ab2dcb61d7e","normalized_value":"cbf973cb030511d30c40beaf2c965d86c844bff5222ec8a9ff363ab2dcb61d7e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"adac4fcb-51a5-4d12-bffc-7debd35fc1b7","attribute_id":"37523706","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783152739","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["MALWARE","stealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["MALWARE","stealer","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"cc97517f80f567977300450de11e9a0be53f52657525a20b1091c99fe9e45730","normalized_value":"cc97517f80f567977300450de11e9a0be53f52657525a20b1091c99fe9e45730","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b353585d-0415-4c25-8b95-7233b2adb2de","attribute_id":"37755437","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140556","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--8c08e358-b1bc-5f19-8122-7fd4f7198887","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--8c08e358-b1bc-5f19-8122-7fd4f7198887","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ccbf818a36523c19051d066f8e5edad655a478516afc916cd915aacca80dbcd2","normalized_value":"ccbf818a36523c19051d066f8e5edad655a478516afc916cd915aacca80dbcd2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"08d31153-88e0-482c-85e2-7475d9c7469b","attribute_id":"37524518","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:43.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ccef7ca705b899fe337eda462d38216c414c0cfe41052dec102c8f6d8876ad8a","normalized_value":"ccef7ca705b899fe337eda462d38216c414c0cfe41052dec102c8f6d8876ad8a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a36bad45-91b8-4208-83f9-4674e816b5da","attribute_id":"34370355","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581082","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"cd38fa8883cdf579aa97e30356bf49b4a679e1d693edbcaf3efbe928ee27feac","normalized_value":"cd38fa8883cdf579aa97e30356bf49b4a679e1d693edbcaf3efbe928ee27feac","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a028013e-e0ab-48e0-beec-348194b995f7","attribute_id":"37751342","event_id":"59014","event_uuid":"86ac1f33-d014-4704-b3ea-2477a3cf0e54","event_info":"Hallazgos_Threat-Hunting","event_date":"2026-06-19","attribute_timestamp":"1783439275","event_timestamp":"1784063799","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"SONDA - Coomeva","orgc_uuid":"b4374700-5af8-4a26-b9cf-a5c7249e8815","threat_level_id":"1","threat_level":"high","analysis_id":"1","analysis":"ongoing","attribute_comment":"hunting_07-07-2026 Adjunto_svg_ofuscated_cpl","event_extends_uuid":"","tags":{"attribute":["tlp:white"],"event":["tlp:white"],"all":["tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"hunting_07-07-2026 Adjunto_svg_ofuscated_cpl","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"cd8d8805d96110ebeaf017938eaa8fa9dbd3dcf9eb5bf12c950f4d687ceba7e7","normalized_value":"cd8d8805d96110ebeaf017938eaa8fa9dbd3dcf9eb5bf12c950f4d687ceba7e7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"06d42c9e-137b-47b4-b557-0df50e194a60","attribute_id":"37523712","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783154486","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["sh","ua-wget","45-95-147-178","160-119-69-4","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["160-119-69-4","45-95-147-178","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ce23b56615c9b0625799dca8c83558eb1016cce8aec1919dd52d31bf646eface","normalized_value":"ce23b56615c9b0625799dca8c83558eb1016cce8aec1919dd52d31bf646eface","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"45b466e9-4d32-4226-9543-2163242c7ccc","attribute_id":"37529444","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:32.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["zloader","misp-galaxy:malpedia=\"Zloader\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["misp-galaxy:malpedia=\"Zloader\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear","zloader"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ce23b56615c9b0625799dca8c83558eb1016cce8aec1919dd52d31bf646eface","normalized_value":"ce23b56615c9b0625799dca8c83558eb1016cce8aec1919dd52d31bf646eface","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"72f195b4-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521889","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176092","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Zloader payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Zloader payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"cf3f1bceb83fa3acefbabae4bdc275347cfe03dd7fc770052a33baef204a89f7","normalized_value":"cf3f1bceb83fa3acefbabae4bdc275347cfe03dd7fc770052a33baef204a89f7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"18cbde35-6bf6-4250-8358-03763431ea46","attribute_id":"37755112","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112067","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--be9018cd-f5cc-5a6e-9b17-628ff6a91792","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--be9018cd-f5cc-5a6e-9b17-628ff6a91792","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"cf80fd95183ce1305becf6ea91d4ccfa0d87d923499d08939324d63c0ed22dc4","normalized_value":"cf80fd95183ce1305becf6ea91d4ccfa0d87d923499d08939324d63c0ed22dc4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d2cd80a6-4bc8-4a18-91a1-88c1b037838e","attribute_id":"7385963","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581401","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d09192ffa1e9e8f87e57d3d227893100add308c255c39e4b0541129d3eb28da0","normalized_value":"d09192ffa1e9e8f87e57d3d227893100add308c255c39e4b0541129d3eb28da0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1adc05af-03a4-4a23-be28-07e5e90055b6","attribute_id":"37528517","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783062601","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d0a1a0c46eb487a7461dd86c6fb6347dc42f8d0a60d85a549ae42d2f5751f7f0","normalized_value":"d0a1a0c46eb487a7461dd86c6fb6347dc42f8d0a60d85a549ae42d2f5751f7f0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2ad152f7-0012-43d8-b1fb-49db72b0ac24","attribute_id":"37528740","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082662","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d0de7f54d938e8f2f67b7ed071f8c4ad12c4634c271d5c810ebf58b1fd67f10d","normalized_value":"d0de7f54d938e8f2f67b7ed071f8c4ad12c4634c271d5c810ebf58b1fd67f10d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7262598e-c993-40aa-894d-dac6d1550bb3","attribute_id":"37746865","event_id":"60935","event_uuid":"ca70216a-9c9c-4533-b568-d69b639b093b","event_info":"CACTUS: Analyzing a Coordinated Ransomware Attack on Corporate Networks","event_date":"2024-03-06","attribute_timestamp":"1783839826","event_timestamp":"1783839834","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"MalwareBazaar: Source: https://github.com/TheRavenFile/Daily-Hunt/blob/main/Cactus%20Ransomware","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\""," Ransomware","OSINT","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Browser Bookmark Discovery - T1217\"","misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Resource Hijacking - T1496\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"File Permissions Modification - T1222\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","osint:source-type=\"blog-post\"","tlp:clear","Bitdefender SRL","Cactus Ransomware","misp-galaxy:financial-fraud=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Remote Access Software - T1219\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"","misp-galaxy:mitre-attack-pattern=\"Pass the Hash - T1550.002\"","misp-galaxy:mitre-attack-pattern=\"Linux and Mac File and Directory Permissions Modification - T1222.002\"","misp-galaxy:mitre-attack-pattern=\"Protocol Tunneling - T1572\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","misp-galaxy:mitre-attack-pattern=\"Group Policy Modification - T1484.001\"","misp-galaxy:mitre-attack-pattern=\"Malware - T1587.001\"","misp-galaxy:mitre-attack-pattern=\"Local Accounts - T1078.003\"","misp-galaxy:mitre-attack-pattern=\"Financial Theft - T1657\"","misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"","misp-galaxy:mitre-attack-pattern=\"Unsecured Credentials - T1552\"","misp-galaxy:mitre-attack-pattern=\"Use Alternate Authentication Material - T1550\"","misp-galaxy:mitre-attack-pattern=\"Domain Policy Modification - T1484\"","misp-galaxy:mitre-attack-pattern=\"Develop Capabilities - T1587\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white","Ransomware"],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\""," Ransomware","OSINT","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Browser Bookmark Discovery - T1217\"","misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Resource Hijacking - T1496\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"File Permissions Modification - T1222\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","osint:source-type=\"blog-post\"","tlp:clear","Bitdefender SRL","Cactus Ransomware","misp-galaxy:financial-fraud=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Remote Access Software - T1219\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"","misp-galaxy:mitre-attack-pattern=\"Pass the Hash - T1550.002\"","misp-galaxy:mitre-attack-pattern=\"Linux and Mac File and Directory Permissions Modification - T1222.002\"","misp-galaxy:mitre-attack-pattern=\"Protocol Tunneling - T1572\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","misp-galaxy:mitre-attack-pattern=\"Group Policy Modification - T1484.001\"","misp-galaxy:mitre-attack-pattern=\"Malware - T1587.001\"","misp-galaxy:mitre-attack-pattern=\"Local Accounts - T1078.003\"","misp-galaxy:mitre-attack-pattern=\"Financial Theft - T1657\"","misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"","misp-galaxy:mitre-attack-pattern=\"Unsecured Credentials - T1552\"","misp-galaxy:mitre-attack-pattern=\"Use Alternate Authentication Material - T1550\"","misp-galaxy:mitre-attack-pattern=\"Domain Policy Modification - T1484\"","misp-galaxy:mitre-attack-pattern=\"Develop Capabilities - T1587\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white","Ransomware"],"all":[" Ransomware","Bitdefender SRL","Cactus Ransomware","OSINT","Ransomware","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","misp-galaxy:financial-fraud=\"Ransomware\"","misp-galaxy:mitre-attack-pattern=\"Browser Bookmark Discovery - T1217\"","misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"","misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"","misp-galaxy:mitre-attack-pattern=\"Develop Capabilities - T1587\"","misp-galaxy:mitre-attack-pattern=\"Domain Policy Modification - T1484\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"","misp-galaxy:mitre-attack-pattern=\"File Permissions Modification - T1222\"","misp-galaxy:mitre-attack-pattern=\"Financial Theft - T1657\"","misp-galaxy:mitre-attack-pattern=\"Group Policy Modification - T1484.001\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"","misp-galaxy:mitre-attack-pattern=\"Linux and Mac File and Directory Permissions Modification - T1222.002\"","misp-galaxy:mitre-attack-pattern=\"Local Accounts - T1078.003\"","misp-galaxy:mitre-attack-pattern=\"Malware - T1587.001\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Pass the Hash - T1550.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"","misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"","misp-galaxy:mitre-attack-pattern=\"Protocol Tunneling - T1572\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Remote Access Software - T1219\"","misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"Resource Hijacking - T1496\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Server Software Component - T1505\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Unsecured Credentials - T1552\"","misp-galaxy:mitre-attack-pattern=\"Use Alternate Authentication Material - T1550\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","ncsc-nl-ndn:feed=\"selected\"","osint:source-type=\"blog-post\"","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"MalwareBazaar: Source: https://github.com/TheRavenFile/Daily-Hunt/blob/main/Cactus%20Ransomware","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2","normalized_value":"d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2","attribute_type":"sha256","category":"Artifacts dropped","attribute_uuid":"3bcb475c-7a11-4a48-92e0-6819f64a81c1","attribute_id":"37752347","event_id":"61005","event_uuid":"efee3167-4868-4f50-b35b-565a4abec419","event_info":"Campaign Targeting Government of thailand via Hermes AI Agent & Hades","event_date":"2026-07-16","attribute_timestamp":"1784906644","event_timestamp":"1784907374","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Hades Custom Go Implant (Linux ELF binary: multipathd_04d0)","event_extends_uuid":"","tags":{"attribute":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"event":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"all":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Hades Custom Go Implant (Linux ELF binary: multipathd_04d0)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2","normalized_value":"d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2fb8b406-31c9-496d-8e33-4a02b13572ee","attribute_id":"37755156","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140402","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--02923d2e-1a29-5d29-921c-3de75bcaa620","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--02923d2e-1a29-5d29-921c-3de75bcaa620","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d267adf0296ae16863b33045222c6354b28716e0277857f22f98282447c23e53","normalized_value":"d267adf0296ae16863b33045222c6354b28716e0277857f22f98282447c23e53","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5023ff41-722e-43e0-b068-1fd3e73a6553","attribute_id":"7386035","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581344","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d284841b717f1ced21ea84cd6a6b6b620daaf7c6f12f8b1f16525ada570f7d82","normalized_value":"d284841b717f1ced21ea84cd6a6b6b620daaf7c6f12f8b1f16525ada570f7d82","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"625c32ae-807b-429d-b783-c2f075da8cae","attribute_id":"37529448","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:21.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d284841b717f1ced21ea84cd6a6b6b620daaf7c6f12f8b1f16525ada570f7d82","normalized_value":"d284841b717f1ced21ea84cd6a6b6b620daaf7c6f12f8b1f16525ada570f7d82","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6c98f039-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521898","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176081","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WannaCryptor payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WannaCryptor payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d2a961569e9ce75e16e24f1ce9614e45a83ce50d90dc0af52347cffb33e30509","normalized_value":"d2a961569e9ce75e16e24f1ce9614e45a83ce50d90dc0af52347cffb33e30509","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d6008096-3c20-404e-8057-7782b6437942","attribute_id":"37523029","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783168543","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","arm","geofenced","USA","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","USA","arm","elf","geofenced","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d365700f7b92b99111394dc199b782a237e5aeaf9f0544875b5071a9b3cb9a34","normalized_value":"d365700f7b92b99111394dc199b782a237e5aeaf9f0544875b5071a9b3cb9a34","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7ec94e8b-7741-11f1-97fa-42010aa4000a","attribute_id":"37521900","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125860","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WebMonitor RAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WebMonitor RAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d365700f7b92b99111394dc199b782a237e5aeaf9f0544875b5071a9b3cb9a34","normalized_value":"d365700f7b92b99111394dc199b782a237e5aeaf9f0544875b5071a9b3cb9a34","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"df4b2a14-06c9-4d49-846a-d7affe656f1a","attribute_id":"37528899","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:20.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WebMonitor RAT\"","WebMonitor RAT","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WebMonitor RAT","misp-galaxy:malpedia=\"WebMonitor RAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d38e05a6fea310e778a8b1e623ee9b00f430ee76622f7a66cd0ca538fcaa1613","normalized_value":"d38e05a6fea310e778a8b1e623ee9b00f430ee76622f7a66cd0ca538fcaa1613","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9a67b7b4-5aea-431c-94a1-7f89fe8997b9","attribute_id":"37755241","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140442","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--3b5a4e6e-9ba0-59f7-a1f8-3045a43092ce","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--3b5a4e6e-9ba0-59f7-a1f8-3045a43092ce","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d4951b8ee5c2abb79b47c9038b0a85b4ae4b4af7b895ad64fd19a5b07512b50f","normalized_value":"d4951b8ee5c2abb79b47c9038b0a85b4ae4b4af7b895ad64fd19a5b07512b50f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1ee0a2e3-e0fb-4b45-8d28-b31bc8717330","attribute_id":"37528782","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783086973","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d4a49f70b86d27a9b2f29d1874bc1407d38d98ef93267a52775948079fb96f13","normalized_value":"d4a49f70b86d27a9b2f29d1874bc1407d38d98ef93267a52775948079fb96f13","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b53b8560-a0be-4269-8ce1-98ee4e8be2eb","attribute_id":"37528553","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783063210","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","PowerPC","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","PowerPC","elf","gafgyt","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d4d249c621b5c27fd96505d041674ea472d5dec0a7730b44324c8af6a7fb7f0a","normalized_value":"d4d249c621b5c27fd96505d041674ea472d5dec0a7730b44324c8af6a7fb7f0a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c560d836-fad2-4209-9572-9135e3ea5b78","attribute_id":"37755239","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140442","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--71c71183-ad94-5130-9884-a197693e430f","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--71c71183-ad94-5130-9884-a197693e430f","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d4eb4ff02df659fdeec17d36b77084627469623bb3c7d16383d257404b52d1c3","normalized_value":"d4eb4ff02df659fdeec17d36b77084627469623bb3c7d16383d257404b52d1c3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6959f78e-4dac-494d-8f1f-20a40736ac9a","attribute_id":"37752154","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d5590802bf0926ac30d8e31c0911439c35aead82bf17771cfd1f9a785a7bf143","normalized_value":"d5590802bf0926ac30d8e31c0911439c35aead82bf17771cfd1f9a785a7bf143","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"11c64b1a-53a7-49ab-a6c7-4c87fd9b99c3","attribute_id":"37755284","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140467","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--1229390c-bb9e-5158-94ab-fd43b758b72e","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--1229390c-bb9e-5158-94ab-fd43b758b72e","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d5cb4f58ddb01761d6e9185e9bd6b856d1cd10f87b3ef33d473bdeaf5fe2327f","normalized_value":"d5cb4f58ddb01761d6e9185e9bd6b856d1cd10f87b3ef33d473bdeaf5fe2327f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bbcea384-107e-4a8f-87bd-7da95dfa8149","attribute_id":"37523688","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783149931","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["zip","SmartLoader","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["SmartLoader","tlp:white","type:OSINT","zip"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d6ac21a409f35a80ba9ccfe58ae1ae32883e44ecc724e4ae8289e7465ab2cf40","normalized_value":"d6ac21a409f35a80ba9ccfe58ae1ae32883e44ecc724e4ae8289e7465ab2cf40","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cc8c0e1c-a75d-46a1-b6da-f868717f9889","attribute_id":"37746517","event_id":"60929","event_uuid":"f6732da4-728c-4bb6-8eae-2b34f20b075e","event_info":"TinyTurla Next Generation - Turla APT spies on Polish NGOs","event_date":"2024-02-16","attribute_timestamp":"1783839751","event_timestamp":"1783839753","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"0","analysis":"initial","attribute_comment":"TinyTurla-NG (TTNG) backdoor hash.","event_extends_uuid":"","tags":{"attribute":["Backdoor","admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","Turla","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","Backdoor","Powershell","OSINT","osint:source-type=\"blog-post\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Indicator Removal from Tools - T1027.005\"","misp-galaxy:mitre-attack-pattern=\"Rundll32 - T1218.011\"","windows","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"","misp-galaxy:360net-threat-actor=\"Turla - APT-C-29\"","misp-galaxy:country=\"poland\"","misp-galaxy:malpedia=\"TinyTurla\"","misp-galaxy:mitre-malware=\"TinyTurla - S0668\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","Turla","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","Backdoor","Powershell","OSINT","osint:source-type=\"blog-post\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Indicator Removal from Tools - T1027.005\"","misp-galaxy:mitre-attack-pattern=\"Rundll32 - T1218.011\"","windows","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"","misp-galaxy:360net-threat-actor=\"Turla - APT-C-29\"","misp-galaxy:country=\"poland\"","misp-galaxy:malpedia=\"TinyTurla\"","misp-galaxy:mitre-malware=\"TinyTurla - S0668\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white"],"all":["Backdoor","OSINT","Powershell","Turla","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:360net-threat-actor=\"Turla - APT-C-29\"","misp-galaxy:country=\"poland\"","misp-galaxy:malpedia=\"TinyTurla\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Execution through Module Load - T1129\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Indicator Removal from Tools - T1027.005\"","misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"","misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"","misp-galaxy:mitre-attack-pattern=\"Rundll32 - T1218.011\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-malware=\"TinyTurla - S0668\"","ncsc-nl-ndn:feed=\"selected\"","osint:source-type=\"blog-post\"","tlp:clear","tlp:white","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"TinyTurla-NG (TTNG) backdoor hash.","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d718ba03a97cf133f7cb87f6d9b7d22aecfb900c95d12e963d30af3b640fa52f","normalized_value":"d718ba03a97cf133f7cb87f6d9b7d22aecfb900c95d12e963d30af3b640fa52f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2ba2aa17-07f8-421f-b0ea-90d4b241f9da","attribute_id":"37523342","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146430","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d7c75c5258ea8467690ec1f710415e7f8234491d4873566515f15fb7e5e729a2","normalized_value":"d7c75c5258ea8467690ec1f710415e7f8234491d4873566515f15fb7e5e729a2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a659c603-88dc-4a3b-800b-79070e540c96","attribute_id":"37528461","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783060376","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","botnet","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","botnet","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d90168d1f3568b5909d2e14288300ede298f6c663b51e883e7eb5d8d70277423","normalized_value":"d90168d1f3568b5909d2e14288300ede298f6c663b51e883e7eb5d8d70277423","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5830fee2-29f3-48b0-9347-323d2e7323d9","attribute_id":"34370358","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581084","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d9223382acec8ee90c20f7bc6104706d35fcfdd09e760acefc54ab91619f761d","normalized_value":"d9223382acec8ee90c20f7bc6104706d35fcfdd09e760acefc54ab91619f761d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4020543f-dfbb-45b0-964c-5983cf0c64b0","attribute_id":"37523095","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162510","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","x86","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","opendir","tlp:white","type:OSINT","ua-wget","x86"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d95f9c5d82b08b395304374db0f7db3024a0fd9c5d91ccd53dd0f7661ae02bfa","normalized_value":"d95f9c5d82b08b395304374db0f7db3024a0fd9c5d91ccd53dd0f7661ae02bfa","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"202d90cb-1527-4fd6-84f8-6267256d18d8","attribute_id":"37528316","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783040569","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d9d6fc3085dd822f258601164ecb21f318822a63ca0360aead9201bcee49ed04","normalized_value":"d9d6fc3085dd822f258601164ecb21f318822a63ca0360aead9201bcee49ed04","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8bf6ca3d-624c-4ddc-8a1b-030e0e7b0d75","attribute_id":"37524496","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:50.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["xworm","misp-galaxy:malpedia=\"XWorm\"","misp-galaxy:mandiant-malware-family=\"2c11edb3-e227-4a8f-b5d8-1b9eb7c9e378\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["misp-galaxy:malpedia=\"XWorm\"","misp-galaxy:mandiant-malware-family=\"2c11edb3-e227-4a8f-b5d8-1b9eb7c9e378\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear","xworm"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"d9f15a43821328bf482e2945ff9da40fa05f382777819d8e9fa3aaae8704862d","normalized_value":"d9f15a43821328bf482e2945ff9da40fa05f382777819d8e9fa3aaae8704862d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7ceb3511-8dec-4a46-88a3-cbb3166d5752","attribute_id":"37524526","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:40.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"da0f35b3d900c47c5afc73503639efd545cae4c2a380b706cf512f63ece6ff45","normalized_value":"da0f35b3d900c47c5afc73503639efd545cae4c2a380b706cf512f63ece6ff45","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dc972a49-3a01-46b4-be21-04435971ecd2","attribute_id":"37523065","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162510","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","arc","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","arc","elf","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"da258307c61058016d7e553c07f00dcc06c119ce40536db59d4f726c16d32fb2","normalized_value":"da258307c61058016d7e553c07f00dcc06c119ce40536db59d4f726c16d32fb2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e113e7a2-2f2b-422d-9833-f3fe703dedb2","attribute_id":"37523161","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126413","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","gafgyt","opendir","elf","sparc","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","gafgyt","opendir","sparc","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"db9a6efd5d64ba0ba1783c51b6d430873518fa032bf5265c6837c7674321e183","normalized_value":"db9a6efd5d64ba0ba1783c51b6d430873518fa032bf5265c6837c7674321e183","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a48c4c0c-0e67-4c2a-a577-15ea3cd0eaed","attribute_id":"37749168","event_id":"60956","event_uuid":"36e03b09-a20c-4169-a875-b77a24ca82fd","event_info":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","event_date":"2023-03-14","attribute_timestamp":"1783685711","event_timestamp":"1783685737","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"event":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"all":["Ave Maria","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","Energy Sector ","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cyber espionage","infostealer","meterpreter","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","osint:source-type=\"blog-post\"","tlp:clear","warzonerat"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"dbae7bc63cff2e9500a524928dc5139aff58c8c2241d9fbed43b464a3ab81ce3","normalized_value":"dbae7bc63cff2e9500a524928dc5139aff58c8c2241d9fbed43b464a3ab81ce3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c8e2e38a-59e8-40c9-9904-b55a9e90087d","attribute_id":"37528443","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783057019","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","mips","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","mips","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"dbbb8a11a239da11cbaf99f847a2d032f34d3b522e13b0fd4ef7b2649da7123b","normalized_value":"dbbb8a11a239da11cbaf99f847a2d032f34d3b522e13b0fd4ef7b2649da7123b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d04b75d7-4c34-4b01-ae27-97214ec16973","attribute_id":"37755155","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140401","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--9974b1fd-b3c9-598c-9c8a-2c04da76573c","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--9974b1fd-b3c9-598c-9c8a-2c04da76573c","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"dcfd33a5ed6c86fde6216ee270884e6a977e0daed7db7077ae0b1c7fbe3af860","normalized_value":"dcfd33a5ed6c86fde6216ee270884e6a977e0daed7db7077ae0b1c7fbe3af860","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1521a0b9-b781-4bfc-b15b-ae09046a78a7","attribute_id":"37529459","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:24.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["QuantLoader","misp-galaxy:malpedia=\"QuantLoader\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["QuantLoader","misp-galaxy:malpedia=\"QuantLoader\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"dcfd33a5ed6c86fde6216ee270884e6a977e0daed7db7077ae0b1c7fbe3af860","normalized_value":"dcfd33a5ed6c86fde6216ee270884e6a977e0daed7db7077ae0b1c7fbe3af860","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6e52c653-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521910","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176084","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"QuantLoader payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"QuantLoader payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402","normalized_value":"dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"221b8737-9a7f-4518-a9f3-77c79b312ff7","attribute_id":"37528971","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:55.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402","normalized_value":"dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6f8a8502-7741-11f1-97fa-42010aa4000a","attribute_id":"37521911","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125835","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Stealc payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Stealc payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402","normalized_value":"dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e85f6740-8a17-4524-b6d5-cf2bcd32b46b","attribute_id":"37528656","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783081628","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Stealc)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Stealc)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"dd5d4cf9422b6e4514d49a3ec542cffb682be8a24079010cda689afbb44ac0f4","normalized_value":"dd5d4cf9422b6e4514d49a3ec542cffb682be8a24079010cda689afbb44ac0f4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c7c17ac0-1df4-4be6-92ad-c19196e60a63","attribute_id":"7386091","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581289","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ddeb109a97e3689b63d4ee848d4c23b0646c8070badebcc852577be0b64c7397","normalized_value":"ddeb109a97e3689b63d4ee848d4c23b0646c8070badebcc852577be0b64c7397","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7c69e4ed-4858-40c3-9517-85a9c6554fcf","attribute_id":"37749125","event_id":"60956","event_uuid":"36e03b09-a20c-4169-a875-b77a24ca82fd","event_info":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","event_date":"2023-03-14","attribute_timestamp":"1783685694","event_timestamp":"1783685737","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"event":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"all":["Ave Maria","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","Energy Sector ","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cyber espionage","infostealer","meterpreter","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","osint:source-type=\"blog-post\"","tlp:clear","warzonerat"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"de40109b05faaca5c2715008b6d1af0ab53652a424346ff4ee2ade44c76b8c41","normalized_value":"de40109b05faaca5c2715008b6d1af0ab53652a424346ff4ee2ade44c76b8c41","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8e4c0dda-0d05-4975-b9fa-4671db2cdb2a","attribute_id":"37523227","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783129568","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","botnet","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","botnet","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"de53ebcda1d083a7d3ebe4fa44d8236c785a8bc5ee816af93c43b6d9cf11c6e5","normalized_value":"de53ebcda1d083a7d3ebe4fa44d8236c785a8bc5ee816af93c43b6d9cf11c6e5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e0e1dc40-b0dc-4bea-9b8e-8359479debf0","attribute_id":"37528583","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783064225","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"de9a0df59d81ab578f1eb1238c6caae3a718e4f35a368149656915aa15059e37","normalized_value":"de9a0df59d81ab578f1eb1238c6caae3a718e4f35a368149656915aa15059e37","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d593f930-a60b-476b-a203-53dac3247c00","attribute_id":"37528704","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082546","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"def580734d7194d862e5dac7d48980c392ba93ce5bf85c37f664666b61f83899","normalized_value":"def580734d7194d862e5dac7d48980c392ba93ce5bf85c37f664666b61f83899","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4cd05429-b483-47ea-af9a-053f4f8bf4c8","attribute_id":"37529463","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:26.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"def580734d7194d862e5dac7d48980c392ba93ce5bf85c37f664666b61f83899","normalized_value":"def580734d7194d862e5dac7d48980c392ba93ce5bf85c37f664666b61f83899","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6f9fdab0-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521914","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176086","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Vidar payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vidar payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"df75defc7bde078faefcb2c1c32f16c141337a1583bd0bc14f6d93c135d34289","normalized_value":"df75defc7bde078faefcb2c1c32f16c141337a1583bd0bc14f6d93c135d34289","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"913f5c10-a01e-473a-921d-a4270f7e8ca6","attribute_id":"37749180","event_id":"60956","event_uuid":"36e03b09-a20c-4169-a875-b77a24ca82fd","event_info":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","event_date":"2023-03-14","attribute_timestamp":"1783685720","event_timestamp":"1783685737","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"event":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"all":["Ave Maria","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","Energy Sector ","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cyber espionage","infostealer","meterpreter","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","osint:source-type=\"blog-post\"","tlp:clear","warzonerat"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e031de762e54fe17c46c8a1936eba20787368ad79f046d762542ca487d7ec3d2","normalized_value":"e031de762e54fe17c46c8a1936eba20787368ad79f046d762542ca487d7ec3d2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3dd9a9d9-bd43-4e0c-8448-403122e47fb4","attribute_id":"37528577","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783064213","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e061a76a42aead05e3cf7161b65a73fb8e6f074a0a2aba1b3817eae9ef659491","normalized_value":"e061a76a42aead05e3cf7161b65a73fb8e6f074a0a2aba1b3817eae9ef659491","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"69f3ae45-7741-11f1-97fa-42010aa4000a","attribute_id":"37521924","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125825","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"X-Agent payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"X-Agent payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e061a76a42aead05e3cf7161b65a73fb8e6f074a0a2aba1b3817eae9ef659491","normalized_value":"e061a76a42aead05e3cf7161b65a73fb8e6f074a0a2aba1b3817eae9ef659491","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e74f5050-3880-4c52-80da-f01206648f9c","attribute_id":"37529004","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:45.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["X-Agent","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["X-Agent","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e069bcd473c83b937db46243dd53e8856b5be6d0ade880c0ec61107054a7e32e","normalized_value":"e069bcd473c83b937db46243dd53e8856b5be6d0ade880c0ec61107054a7e32e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b62a22c9-2042-4655-a3aa-270a3ac0570c","attribute_id":"34370334","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581062","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e0d9ebe414aca4f6d28b0f1631a969f9190b6fb2cf5599b99ccfc6b7916ed8b3","normalized_value":"e0d9ebe414aca4f6d28b0f1631a969f9190b6fb2cf5599b99ccfc6b7916ed8b3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"53e36361-38ca-42e4-b87e-4e7988f0e15b","attribute_id":"69109","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686503","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e0fc365c042e708c8d04b5431238958586194cc4a8cbe069411a26dcfcc4e9b6","normalized_value":"e0fc365c042e708c8d04b5431238958586194cc4a8cbe069411a26dcfcc4e9b6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c8233ee2-828a-4247-bc8f-8a6574f13efb","attribute_id":"37752332","event_id":"61004","event_uuid":"f55757e1-7aef-484b-9552-2ca3b6b7d0d8","event_info":"Banking Rewards Malware Campaign","event_date":"2026-07-24","attribute_timestamp":"1784881857","event_timestamp":"1784881991","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"event":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"all":[" trojan","BANKING TROJAN","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Banking Rewards Malware Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e167717c47bc2776217b5cd16fe7ad8a7228d626b3a452b2c8664f9c1c057b66","normalized_value":"e167717c47bc2776217b5cd16fe7ad8a7228d626b3a452b2c8664f9c1c057b66","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"530bf2bf-011c-422d-a90d-a0356a48ae83","attribute_id":"7386047","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581336","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e1c10f2f589e87f30f352da81a501a0257471314bbb16bdc872ea55c1e81b51b","normalized_value":"e1c10f2f589e87f30f352da81a501a0257471314bbb16bdc872ea55c1e81b51b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4c542b0f-8516-44c6-9aee-71e180bf68ec","attribute_id":"37523730","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783168688","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["elf","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e2340ace8e74203f9a0e9bb72ef73964d6adcc34ff6d3d0928613bd38770cc6a","normalized_value":"e2340ace8e74203f9a0e9bb72ef73964d6adcc34ff6d3d0928613bd38770cc6a","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"282c411a-4e91-498b-b45f-36ebd125ca91","attribute_id":"37529612","event_id":"58567","event_uuid":"ae1c645a-f761-4e34-b072-4eacf2062a93","event_info":"Formbook host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783102071","event_timestamp":"1783215209","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e2f0c2d4c1552cd81fa012043e4a5ac832582b639b7b6b7eccc0c4802d7a8ad8","normalized_value":"e2f0c2d4c1552cd81fa012043e4a5ac832582b639b7b6b7eccc0c4802d7a8ad8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a4dc5436-3b42-46d7-aa2f-cd01723682df","attribute_id":"37752142","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529371","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e3137135f4ad5ecdc7900a619d7f1b88ba252b963b38ae9a156299cc9bce92a1","normalized_value":"e3137135f4ad5ecdc7900a619d7f1b88ba252b963b38ae9a156299cc9bce92a1","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a2c7c0c3-008d-41c3-b355-d9b39d2331c5","attribute_id":"35285993","event_id":"54507","event_uuid":"234daefa-6a93-4240-80b8-23582ad75013","event_info":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","event_date":"2021-07-30","attribute_timestamp":"1783639110","event_timestamp":"1783639112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["tlp:white","threat-report"],"event":["tlp:white","threat-report"],"all":["threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e314484b3b7f5767bed58b5a6f1ecb51f8ad00825c824ec5c7f0150da05360cd","normalized_value":"e314484b3b7f5767bed58b5a6f1ecb51f8ad00825c824ec5c7f0150da05360cd","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"fbdcc398-467c-45f5-b211-1aa115be3e2e","attribute_id":"37529609","event_id":"58567","event_uuid":"ae1c645a-f761-4e34-b072-4eacf2062a93","event_info":"Formbook host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783102007","event_timestamp":"1783215209","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","stone:malware-categorization=\"Stealer\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Stealer\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e3bf41de3a7edf556d43b6196652aa036e48a602bb3f7c98af9dae992222a8eb","normalized_value":"e3bf41de3a7edf556d43b6196652aa036e48a602bb3f7c98af9dae992222a8eb","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e6fbaa46-85eb-47b0-a98a-20975aeb4d4f","attribute_id":"35015722","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558083","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"WastedLocker samples (sha256 hashes)","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WastedLocker samples (sha256 hashes)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e3e75e15fd7f6a8233e33c8a8e127cee36706025451644cf8618a0876fd0e95f","normalized_value":"e3e75e15fd7f6a8233e33c8a8e127cee36706025451644cf8618a0876fd0e95f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"8c9486a9-a116-4772-bf88-5a453e78c445","attribute_id":"7386014","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581360","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e3ec5926a167d6e3359f98cdfb7ac3b2cce97652843056505d02e6d2898573c6","normalized_value":"e3ec5926a167d6e3359f98cdfb7ac3b2cce97652843056505d02e6d2898573c6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"193a6cfc-539e-4f82-9192-9615f477af4a","attribute_id":"37521404","event_id":"58527","event_uuid":"bb3d2aed-e7ff-4097-b022-849110a41ab8","event_info":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","event_date":"2026-07-06","attribute_timestamp":"1783319883","event_timestamp":"1783319886","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"event":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"],"all":["  Malware  ","Masquerading","NCSA","Phishing","lure","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e4d6f88789bab6b4646c872227ee03a81bed1532bb1b9953ef98b8535678886b","normalized_value":"e4d6f88789bab6b4646c872227ee03a81bed1532bb1b9953ef98b8535678886b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"292fa33b-1387-4aaa-862b-8c430641b8e0","attribute_id":"37523405","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146556","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e528cebef94e85d492a0dc4ccdb860e8b35523b1ac014b7879b587825c4610c8","normalized_value":"e528cebef94e85d492a0dc4ccdb860e8b35523b1ac014b7879b587825c4610c8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e46336b5-5f38-4788-b633-eacdbfa439b8","attribute_id":"37523059","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783162511","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","PowerPC","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","PowerPC","elf","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e5b81fb1398dfa674f787ac54a6f9609c18690de81332a3f8ccfaac8a313d5ac","normalized_value":"e5b81fb1398dfa674f787ac54a6f9609c18690de81332a3f8ccfaac8a313d5ac","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"89b28d5b-6f8b-48b3-aa92-d0c2cd77110f","attribute_id":"37529558","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101986","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e5ebe4d8925853fc1f233a5a6f7aa29fd8a7fa3a8ad27471c7d525a70f4461b6","normalized_value":"e5ebe4d8925853fc1f233a5a6f7aa29fd8a7fa3a8ad27471c7d525a70f4461b6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3783937d-05bc-4a29-a340-2c61af46dd91","attribute_id":"69179","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686542","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e5f3ef69a534260e899a36cec459440dc572388defd8f1d98760d31c700f42d5","normalized_value":"e5f3ef69a534260e899a36cec459440dc572388defd8f1d98760d31c700f42d5","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"53cb24f0-bf82-4498-a842-74ceecebd6aa","attribute_id":"37025679","event_id":"56910","event_uuid":"53be7197-1af5-4a19-96c3-a7c48ab0af68","event_info":"HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine","event_date":"2022-02-24","attribute_timestamp":"1783792825","event_timestamp":"1783792825","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSC-NL","orgc_uuid":"5697b0c4-9474-4336-b675-28140a950b0b","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"Merged from event 50051","event_extends_uuid":"","tags":{"attribute":["ncsc-nl-ndn:feed=\"selected\"","tlp:white","HermeticWiper","misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Create or Modify System Process - T1543\"","misp-galaxy:mitre-attack-pattern=\"Disk Wipe - T1561\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Shutdown/Reboot - T1529\"","misp-galaxy:target-information=\"Ukraine\"","misp-galaxy:sector=\"Government, Administration\""],"event":["ncsc-nl-ndn:feed=\"selected\"","tlp:white","HermeticWiper","misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Create or Modify System Process - T1543\"","misp-galaxy:mitre-attack-pattern=\"Disk Wipe - T1561\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Shutdown/Reboot - T1529\"","misp-galaxy:target-information=\"Ukraine\"","misp-galaxy:sector=\"Government, Administration\""],"all":["HermeticWiper","misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"","misp-galaxy:mitre-attack-pattern=\"Create or Modify System Process - T1543\"","misp-galaxy:mitre-attack-pattern=\"Disk Wipe - T1561\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"","misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Shutdown/Reboot - T1529\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:target-information=\"Ukraine\"","ncsc-nl-ndn:feed=\"selected\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Merged from event 50051","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e65ee878453d6fa2005f27ad16ecab564cf371992db9e058d8bdd78bde54a99a","normalized_value":"e65ee878453d6fa2005f27ad16ecab564cf371992db9e058d8bdd78bde54a99a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e8977870-1bf5-4587-b236-f8835320cde6","attribute_id":"37523149","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125351","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","elf","m68k","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","m68k","opendir","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e6b15512909dad441e5da10f301d6369f333a5b51ad94f3504e9e6ef12dade3a","normalized_value":"e6b15512909dad441e5da10f301d6369f333a5b51ad94f3504e9e6ef12dade3a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"17515aaf-6045-4f72-bc02-bc9457a54cd5","attribute_id":"37528995","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:48.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["crossrat","misp-galaxy:malpedia=\"CrossRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["crossrat","misp-galaxy:malpedia=\"CrossRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e6b15512909dad441e5da10f301d6369f333a5b51ad94f3504e9e6ef12dade3a","normalized_value":"e6b15512909dad441e5da10f301d6369f333a5b51ad94f3504e9e6ef12dade3a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6bb19170-7741-11f1-97fa-42010aa4000a","attribute_id":"37521931","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125828","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"CrossRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"CrossRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e6b15512909dad441e5da10f301d6369f333a5b51ad94f3504e9e6ef12dade3a","normalized_value":"e6b15512909dad441e5da10f301d6369f333a5b51ad94f3504e9e6ef12dade3a","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"3a58c5c5-09a7-4e23-ad43-9620321e2cd3","attribute_id":"37529652","event_id":"58570","event_uuid":"73b7ed82-0d87-402a-adfd-2462e0268878","event_info":"Remcos host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101732","event_timestamp":"1783215210","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:malware-categorization=\"Rat\"","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Rat\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14","normalized_value":"e6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1d3a50a2-ac74-4ef2-a06f-8dc31b973415","attribute_id":"37752159","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e748047da112f7ac0ff84f1adbad5d4a83dfd857a852a7b626a5a41e54a85325","normalized_value":"e748047da112f7ac0ff84f1adbad5d4a83dfd857a852a7b626a5a41e54a85325","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"0465e7cc-0b7a-45cb-b2f0-131173747031","attribute_id":"37529589","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783102068","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e74cf40d9df390976e11bad98f81df248c14b6e5a45c889b05095fb66117a83b","normalized_value":"e74cf40d9df390976e11bad98f81df248c14b6e5a45c889b05095fb66117a83b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"69f88c1b-607c-4b77-8470-b2058366cb15","attribute_id":"37524499","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:49.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e74cf40d9df390976e11bad98f81df248c14b6e5a45c889b05095fb66117a83b","normalized_value":"e74cf40d9df390976e11bad98f81df248c14b6e5a45c889b05095fb66117a83b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a11d19ff-8ac4-4fe5-a2da-1c5764f97f7c","attribute_id":"37523426","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e78ddc9d7f9284de7b46e27081854751c77e9cad515db9d0cdb17e007629848d","normalized_value":"e78ddc9d7f9284de7b46e27081854751c77e9cad515db9d0cdb17e007629848d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7b084c45-6bb2-4eb1-9089-c532a9a6e127","attribute_id":"37523773","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176451","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["html","censys","ClickFix","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["ClickFix","censys","html","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e7a6925f0fe03108b965a3cf9f2fe1204add376ecde68bafd872e9d828d762e9","normalized_value":"e7a6925f0fe03108b965a3cf9f2fe1204add376ecde68bafd872e9d828d762e9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"4371d583-7e9c-4d10-a1d7-a3b48abce2a7","attribute_id":"34370385","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581111","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268","normalized_value":"e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2944403e-c48c-4b91-9836-677a84c5f805","attribute_id":"37752179","event_id":"60991","event_uuid":"58e75ed8-2394-41b3-a563-2324bec70d3a","event_info":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","event_date":"2026-07-22","attribute_timestamp":"1784691371","event_timestamp":"1784691372","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"event":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"],"all":[" C2","NCSA","WebDav","dropper","lnk","spoofing","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e8c5c0b70d45a5dc80d678ed7102abf9882efb9cbc2cff20f171d60d5205051d","normalized_value":"e8c5c0b70d45a5dc80d678ed7102abf9882efb9cbc2cff20f171d60d5205051d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"ad4ecff4-200f-4e20-b37b-b1539863fc55","attribute_id":"7386024","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581352","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"e957e67ed9787dc7941454ebba020699013e0a0cc00a99c36960a71bc6ab44f7","normalized_value":"e957e67ed9787dc7941454ebba020699013e0a0cc00a99c36960a71bc6ab44f7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"168af711-bb90-4de9-9f3b-61e071c0a538","attribute_id":"37524576","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:23.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ea1574595f87171c26f483df77dec52b0c5c73dd37f4dd554944cd6a8b484d17","normalized_value":"ea1574595f87171c26f483df77dec52b0c5c73dd37f4dd554944cd6a8b484d17","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d2d46e0b-3e45-4bf8-a045-80d778e3d934","attribute_id":"35286117","event_id":"54507","event_uuid":"234daefa-6a93-4240-80b8-23582ad75013","event_info":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","event_date":"2021-07-30","attribute_timestamp":"1783639111","event_timestamp":"1783639112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["tlp:white","threat-report"],"event":["tlp:white","threat-report"],"all":["threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"MAR-10339606.r1.v1: Pulse Secure -> Malware Analysis Report (AR21-236E)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ea22b3e9ecdfd06fae74483deb9ef0245aefdc72f99120ae6525c0eaf37de32e","normalized_value":"ea22b3e9ecdfd06fae74483deb9ef0245aefdc72f99120ae6525c0eaf37de32e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"68ca8f74-3fe5-4e13-8264-3cae4f5ede2d","attribute_id":"37746985","event_id":"60937","event_uuid":"0f810383-867c-42c6-ba59-2c5e4cfacbce","event_info":"Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage Campaign","event_date":"2024-02-19","attribute_timestamp":"1783792850","event_timestamp":"1783918916","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"146e7f08-0c70-4ec2-a055-ea3f402afd1e","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","APT","Recorded Future","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Ukraine\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Credential Access - T1212\"","misp-galaxy:mitre-attack-pattern=\"Input Capture - T1056\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Email Collection - T1114\"","stix-ttp:victim-targeting=\"government-international-organizations-sector\"","misp-galaxy:region=\"150 - Europe\"","misp-galaxy:sector=\"Academia - University\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"Czech Republic\"","misp-galaxy:target-information=\"France\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"United Kingdom\"","tlp:clear","cyber espionage","misp-galaxy:target-information=\"Georgia\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Non-Standard Port - T1571\"","social-engineering-attack-vectors:non-technical=\"pretexting-impersonation\"","misp-galaxy:target-information=\"Belgium\"","belgium","cert-ist:threat_targeted_region=\"Ukraine\"","georgia","poland"],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","APT","Recorded Future","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Ukraine\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Credential Access - T1212\"","misp-galaxy:mitre-attack-pattern=\"Input Capture - T1056\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Email Collection - T1114\"","stix-ttp:victim-targeting=\"government-international-organizations-sector\"","misp-galaxy:region=\"150 - Europe\"","misp-galaxy:sector=\"Academia - University\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"Czech Republic\"","misp-galaxy:target-information=\"France\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"United Kingdom\"","tlp:clear","cyber espionage","misp-galaxy:target-information=\"Georgia\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Non-Standard Port - T1571\"","social-engineering-attack-vectors:non-technical=\"pretexting-impersonation\"","misp-galaxy:target-information=\"Belgium\"","belgium","cert-ist:threat_targeted_region=\"Ukraine\"","georgia","poland"],"all":["APT","Recorded Future","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","belgium","cert-ist:threat_targeted_region=\"Ukraine\"","cyber espionage","georgia","misp-galaxy:mitre-attack-pattern=\"Email Collection - T1114\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Credential Access - T1212\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Input Capture - T1056\"","misp-galaxy:mitre-attack-pattern=\"Non-Standard Port - T1571\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:region=\"150 - Europe\"","misp-galaxy:sector=\"Academia - University\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:target-information=\"Belgium\"","misp-galaxy:target-information=\"Czech Republic\"","misp-galaxy:target-information=\"France\"","misp-galaxy:target-information=\"Georgia\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Ukraine\"","misp-galaxy:target-information=\"United Kingdom\"","poland","social-engineering-attack-vectors:non-technical=\"pretexting-impersonation\"","stix-ttp:victim-targeting=\"government-international-organizations-sector\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ea310cc4fd4e8669e014ff417286da5edf2d3bef20abfb0a4f4951afe260d33d","normalized_value":"ea310cc4fd4e8669e014ff417286da5edf2d3bef20abfb0a4f4951afe260d33d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6f8bf2c6-4353-493e-a810-2771bb323aec","attribute_id":"35015660","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558036","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Hades Ransomware\r\nSHA256","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Hades Ransomware\r\nSHA256","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ea7822eac6cecef7746c606b862b4d3034856caf754c4cf69533662637905328","normalized_value":"ea7822eac6cecef7746c606b862b4d3034856caf754c4cf69533662637905328","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3cf97070-ec68-4a70-a478-c633fd96068f","attribute_id":"37755349","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140504","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--d10f5565-26df-59c0-b85f-c213972b07b4","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--d10f5565-26df-59c0-b85f-c213972b07b4","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eacea4983eb01cabe9f621d7b28ae37cbc3e801106575272795e025de1064a29","normalized_value":"eacea4983eb01cabe9f621d7b28ae37cbc3e801106575272795e025de1064a29","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7d07793a-7741-11f1-97fa-42010aa4000a","attribute_id":"37521933","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125857","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"XenoRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"XenoRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eacea4983eb01cabe9f621d7b28ae37cbc3e801106575272795e025de1064a29","normalized_value":"eacea4983eb01cabe9f621d7b28ae37cbc3e801106575272795e025de1064a29","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"891f0473-7095-41ca-bdb7-425edb2bcb76","attribute_id":"37528909","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:17.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["XenoRAT","misp-galaxy:mandiant-malware-family=\"17f01159-f29c-4320-a409-3a4f68523864\"","misp-galaxy:malpedia=\"XenoRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["XenoRAT","misp-galaxy:malpedia=\"XenoRAT\"","misp-galaxy:mandiant-malware-family=\"17f01159-f29c-4320-a409-3a4f68523864\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eb1470786fda58fc8291e099c7fcd5d36a04de85d1f6fe8683c1950b7119314e","normalized_value":"eb1470786fda58fc8291e099c7fcd5d36a04de85d1f6fe8683c1950b7119314e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cf257d7f-10af-4963-9f8b-b256cf2747b0","attribute_id":"7386240","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581182","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eb4c2dc7db21d6a8a889c74c7b90eaac0e095205063ae3e348a400e253c6bdd8","normalized_value":"eb4c2dc7db21d6a8a889c74c7b90eaac0e095205063ae3e348a400e253c6bdd8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"65474ccb-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521934","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176069","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"MaskGramStealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"MaskGramStealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eb4c2dc7db21d6a8a889c74c7b90eaac0e095205063ae3e348a400e253c6bdd8","normalized_value":"eb4c2dc7db21d6a8a889c74c7b90eaac0e095205063ae3e348a400e253c6bdd8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6ea5d61f-259b-417d-83b8-361f743c6f4f","attribute_id":"37523607","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783147090","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (MaskGramStealer)","event_extends_uuid":"","tags":{"attribute":["MaskGramStealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["MaskGramStealer","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (MaskGramStealer)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eb4c2dc7db21d6a8a889c74c7b90eaac0e095205063ae3e348a400e253c6bdd8","normalized_value":"eb4c2dc7db21d6a8a889c74c7b90eaac0e095205063ae3e348a400e253c6bdd8","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"792b1445-6aca-4d44-a243-a145116d964d","attribute_id":"37529469","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:09.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["MaskGramStealer","misp-galaxy:malpedia=\"MaskGramStealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["MaskGramStealer","misp-galaxy:malpedia=\"MaskGramStealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eb4e1394d537d8eba509dd5c57e7aaf4c1df57715c7161330012a11f6202af84","normalized_value":"eb4e1394d537d8eba509dd5c57e7aaf4c1df57715c7161330012a11f6202af84","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"bc1823cd-7126-4c55-a13b-73e15e755a31","attribute_id":"37755104","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112062","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--d512c05e-78aa-5c5b-8469-fccbb7e8904d","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--d512c05e-78aa-5c5b-8469-fccbb7e8904d","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eb4e1394d537d8eba509dd5c57e7aaf4c1df57715c7161330012a11f6202af84","normalized_value":"eb4e1394d537d8eba509dd5c57e7aaf4c1df57715c7161330012a11f6202af84","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dd55a7df-fb9f-4f72-bd56-8a125d64e238","attribute_id":"37752219","event_id":"60993","event_uuid":"297956e5-c56a-4239-b35f-693d8c117afd","event_info":"148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet","event_date":"2026-07-22","attribute_timestamp":"1784703380","event_timestamp":"1784703385","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","Cybercrime","tlp:clear","proxy","Create-By\"Methanon\""],"event":["NCSA","NCSA_Research","Cybercrime","tlp:clear","proxy","Create-By\"Methanon\""],"all":["Create-By\"Methanon\"","Cybercrime","NCSA","NCSA_Research","proxy","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ebdd2ac5c447807ff3218ae4fe747a681dc1097b64025452acbf7faa1fb17ca4","normalized_value":"ebdd2ac5c447807ff3218ae4fe747a681dc1097b64025452acbf7faa1fb17ca4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"efac50ba-282a-4583-b6db-8f4d46c21152","attribute_id":"37524444","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:09.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ebdd2ac5c447807ff3218ae4fe747a681dc1097b64025452acbf7faa1fb17ca4","normalized_value":"ebdd2ac5c447807ff3218ae4fe747a681dc1097b64025452acbf7faa1fb17ca4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f4de4f0d-65f5-4fd5-91fd-32e0c6478c87","attribute_id":"37523482","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ebe7c0a067c87ada62581531981365304364f4675be7cde328201395e942af9c","normalized_value":"ebe7c0a067c87ada62581531981365304364f4675be7cde328201395e942af9c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"d471ba05-dd2b-40e7-b5fd-2648c4226ac8","attribute_id":"37746631","event_id":"60932","event_uuid":"ae102ba0-f797-4201-b557-0fb163a9e03f","event_info":"Unmasking the Hidden Threat: Inside a Sophisticated Excel-Based Attack Delivering Fileless Remcos RAT","event_date":"2024-09-12","attribute_timestamp":"1783581638","event_timestamp":"1784392758","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Template Injection - T1221\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Third-party Software - T1072\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Execution through API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\""," Agent Tesla","FormBook","GuLoader","OSINT","Remcos","RevengeRAT","SnakeKeylogger","excel","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Technology\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Mshta - T1218.005\"","misp-galaxy:mitre-attack-pattern=\"Steganography - T1027.003\"","misp-galaxy:mitre-attack-pattern=\"Shortcut Modification - T1547.009\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities - T1127\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities Proxy Execution - T1127\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\""," RemcosRAT","FinFisher.Botnet","finspy","LatentBot","misp-galaxy:country=\"australia\"","misp-galaxy:country=\"belgium\"","misp-galaxy:country=\"canada\"","misp-galaxy:country=\"germany\"","misp-galaxy:country=\"japan\"","misp-galaxy:country=\"south korea\"","misp-galaxy:country=\"united states of america\"","Agent Tesla","RemcosRAT"],"event":["admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Template Injection - T1221\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Third-party Software - T1072\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Execution through API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\""," Agent Tesla","FormBook","GuLoader","OSINT","Remcos","RevengeRAT","SnakeKeylogger","excel","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Technology\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Mshta - T1218.005\"","misp-galaxy:mitre-attack-pattern=\"Steganography - T1027.003\"","misp-galaxy:mitre-attack-pattern=\"Shortcut Modification - T1547.009\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities - T1127\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities Proxy Execution - T1127\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\""," RemcosRAT","FinFisher.Botnet","finspy","LatentBot","misp-galaxy:country=\"australia\"","misp-galaxy:country=\"belgium\"","misp-galaxy:country=\"canada\"","misp-galaxy:country=\"germany\"","misp-galaxy:country=\"japan\"","misp-galaxy:country=\"south korea\"","misp-galaxy:country=\"united states of america\"","Agent Tesla","RemcosRAT"],"all":[" Agent Tesla"," RemcosRAT","Agent Tesla","FinFisher.Botnet","FormBook","GuLoader","LatentBot","OSINT","Remcos","RemcosRAT","RevengeRAT","SnakeKeylogger","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","excel","finspy","misp-galaxy:country=\"australia\"","misp-galaxy:country=\"belgium\"","misp-galaxy:country=\"canada\"","misp-galaxy:country=\"germany\"","misp-galaxy:country=\"japan\"","misp-galaxy:country=\"south korea\"","misp-galaxy:country=\"united states of america\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"","misp-galaxy:mitre-attack-pattern=\"Execution through API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Mshta - T1218.005\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Shortcut Modification - T1547.009\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Steganography - T1027.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Template Injection - T1221\"","misp-galaxy:mitre-attack-pattern=\"Third-party Software - T1072\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities - T1127\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities Proxy Execution - T1127\"","misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Technology\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Unmasking the Hidden Threat: Inside a Sophisticated Excel-Based Attack Delivering Fileless Remcos RAT","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ec35c76ad2c8192f09c02eca1f263b406163470ca8438d054db7adcf5bfc0597","normalized_value":"ec35c76ad2c8192f09c02eca1f263b406163470ca8438d054db7adcf5bfc0597","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"3116dcc6-ad9b-4b6a-b32c-50bdbcb0ae21","attribute_id":"7386093","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581291","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ec59758993501d25047672e4c46d33d7489012bf3936832af18896fb1bbef109","normalized_value":"ec59758993501d25047672e4c46d33d7489012bf3936832af18896fb1bbef109","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c0686380-3921-4d4d-bab2-700c9d0e30a4","attribute_id":"37524466","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:00.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ec59758993501d25047672e4c46d33d7489012bf3936832af18896fb1bbef109","normalized_value":"ec59758993501d25047672e4c46d33d7489012bf3936832af18896fb1bbef109","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dbd94513-0493-47d6-8a48-019d8d86a2b6","attribute_id":"37523503","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146560","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2","normalized_value":"ec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5be27052-35b5-4cef-b1aa-8dfbaaa8d653","attribute_id":"37755154","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140401","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--4254dae8-38b0-5860-b65b-91db69c3ff36","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--4254dae8-38b0-5860-b65b-91db69c3ff36","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2","normalized_value":"ec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b45c4964-bcca-4ba6-97b6-57eb3f02b4d2","attribute_id":"37752345","event_id":"61005","event_uuid":"efee3167-4868-4f50-b35b-565a4abec419","event_info":"Campaign Targeting Government of thailand via Hermes AI Agent & Hades","event_date":"2026-07-16","attribute_timestamp":"1784906643","event_timestamp":"1784907374","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"VShell Linux Stage 2 Payload","event_extends_uuid":"","tags":{"attribute":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"event":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"],"all":["NCSA","misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"","misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"","misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"","misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Scheduled Task/Job - T1053\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"VShell Linux Stage 2 Payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ecafb11a4c92905e8e00f586411412d8c17b3f7ed1175c07ee2464a1d88521e7","normalized_value":"ecafb11a4c92905e8e00f586411412d8c17b3f7ed1175c07ee2464a1d88521e7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"48a2c458-6465-4ef5-b3bc-686da871eee0","attribute_id":"37528292","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783037598","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ed0632acb266a4ec3f51dd803c8025bccd654e53c64eb613e203c590897079b3","normalized_value":"ed0632acb266a4ec3f51dd803c8025bccd654e53c64eb613e203c590897079b3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"96e26c21-9e23-4308-b4c6-9b704e3b8455","attribute_id":"35015723","event_id":"54291","event_uuid":"14cc8767-167c-4cf4-88f6-364c36bfbcf9","event_info":"Evil Corp - A Threat Actor with Multiple Alter Egos","event_date":"2021-06-24","attribute_timestamp":"1783558086","event_timestamp":"1783558089","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"WastedLocker samples (sha256 hashes)","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"event":["misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:threat-actor=\"TA505\""," Ransomware","threat-report","ta505","tlp:white","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:malpedia=\"WastedLocker\"","Ransomware"],"all":[" Ransomware","Ransomware","misp-galaxy:malpedia=\"Cobalt Strike\"","misp-galaxy:malpedia=\"WastedLocker\"","misp-galaxy:mitre-attack-pattern=\"Conduct social engineering - T1249\"","misp-galaxy:mitre-attack-pattern=\"DNS poisoning - T1382\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Unauthorized user introduces compromise delivery mechanism - T1387\"","misp-galaxy:mitre-enterprise-attack-tool=\"Cobalt Strike - S0154\"","misp-galaxy:mitre-intrusion-set=\"TA505 - G0092\"","misp-galaxy:mitre-malware=\"Ursnif - S0386\"","misp-galaxy:ransomware=\"Hades\"","misp-galaxy:sector=\"Communication equipment\"","misp-galaxy:sector=\"Electronic\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"News - Media\"","misp-galaxy:sector=\"Technology\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"Evil Corp\"","misp-galaxy:threat-actor=\"TA505\"","ta505","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WastedLocker samples (sha256 hashes)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ed3171b8abf77dcc65bb6801c784a3a5adf671332fa0ad38b81c5fd87005bcf3","normalized_value":"ed3171b8abf77dcc65bb6801c784a3a5adf671332fa0ad38b81c5fd87005bcf3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"075f9e93-832d-4610-ab32-80896c3ce46a","attribute_id":"37528957","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:00.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Creal Stealer","misp-galaxy:malpedia=\"Creal Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Creal Stealer","misp-galaxy:malpedia=\"Creal Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ed3171b8abf77dcc65bb6801c784a3a5adf671332fa0ad38b81c5fd87005bcf3","normalized_value":"ed3171b8abf77dcc65bb6801c784a3a5adf671332fa0ad38b81c5fd87005bcf3","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7292d333-7741-11f1-97fa-42010aa4000a","attribute_id":"37521936","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125840","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Creal Stealer payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Creal Stealer payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"edba574bd742a61fa55e6be554bffbe6b8548d57e9cd4bdd37c1fd0380125af9","normalized_value":"edba574bd742a61fa55e6be554bffbe6b8548d57e9cd4bdd37c1fd0380125af9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"530dd4ef-80b7-408c-a52a-06f7fce7c3f1","attribute_id":"37528449","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783057576","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["MALWARE","stealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["MALWARE","stealer","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eded86eb5c664d712b1393001d997338d122e53b15885adc4c89d2421a412f64","normalized_value":"eded86eb5c664d712b1393001d997338d122e53b15885adc4c89d2421a412f64","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a37157ad-5476-47f1-a738-e2f62abb8729","attribute_id":"37523531","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146561","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eded86eb5c664d712b1393001d997338d122e53b15885adc4c89d2421a412f64","normalized_value":"eded86eb5c664d712b1393001d997338d122e53b15885adc4c89d2421a412f64","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fa5609f7-b508-47dd-8f6d-6d5f860ef1ce","attribute_id":"37524487","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:53.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ee0e3b3489ea0dd06f2af0b969e480c4fc6f2755cf4016dcba5d1299ac74f84e","normalized_value":"ee0e3b3489ea0dd06f2af0b969e480c4fc6f2755cf4016dcba5d1299ac74f84e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6efdc8d7-7741-11f1-97fa-42010aa4000a","attribute_id":"37521937","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125834","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"VENON payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"VENON payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ee0e3b3489ea0dd06f2af0b969e480c4fc6f2755cf4016dcba5d1299ac74f84e","normalized_value":"ee0e3b3489ea0dd06f2af0b969e480c4fc6f2755cf4016dcba5d1299ac74f84e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cf6c2527-9308-4f48-82f6-a82e8a3ceddb","attribute_id":"37528975","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:54.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["VENON","misp-galaxy:malpedia=\"VENON\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["VENON","misp-galaxy:malpedia=\"VENON\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ee31cfe74796debd9d023c1897f33f5eb6ade5feb9d991b8c126e4fb1b83f590","normalized_value":"ee31cfe74796debd9d023c1897f33f5eb6ade5feb9d991b8c126e4fb1b83f590","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"88451b67-62ff-477f-a21a-44015fb9eef3","attribute_id":"37523694","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783150343","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["MALWARE","stealer","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["MALWARE","stealer","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ee531cd7011cb5c2625d40892b70cf7e3860dbb92648391068e1f340e5d6c47f","normalized_value":"ee531cd7011cb5c2625d40892b70cf7e3860dbb92648391068e1f340e5d6c47f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7632a605-3026-4f8d-a950-bde7f13fe33d","attribute_id":"7386012","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581357","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ee9dd2a180aea75af5c0eda16b83681c0a5fed451bfad6d5b3af85c3b62fa210","normalized_value":"ee9dd2a180aea75af5c0eda16b83681c0a5fed451bfad6d5b3af85c3b62fa210","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"2caa8582-55d3-4e4b-8a72-e4d104ffb9e2","attribute_id":"37755111","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112066","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--8c93086e-0436-5887-bf10-faa75b063fab","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--8c93086e-0436-5887-bf10-faa75b063fab","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eeb2d44d0f86670ac2ee5e0b7aa44ec41b7be9962359f59ac21f736d7b0e7889","normalized_value":"eeb2d44d0f86670ac2ee5e0b7aa44ec41b7be9962359f59ac21f736d7b0e7889","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"79033d55-7741-11f1-97fa-42010aa4000a","attribute_id":"37521938","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125851","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"ValleyRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"ValleyRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eeb2d44d0f86670ac2ee5e0b7aa44ec41b7be9962359f59ac21f736d7b0e7889","normalized_value":"eeb2d44d0f86670ac2ee5e0b7aa44ec41b7be9962359f59ac21f736d7b0e7889","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"970d7620-d6c5-425a-a200-6b91b88b0ca3","attribute_id":"37528925","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:11.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ValleyRAT","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","misp-galaxy:malpedia=\"ValleyRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["ValleyRAT","misp-galaxy:malpedia=\"ValleyRAT\"","misp-galaxy:mandiant-malware-family=\"d3958a16-20ef-43cf-8468-00dbbbc654d2\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"eef4175da3a166ebbc6d5b8d81b569438e6f4c92a3ca42370efd1fef31fb3ca9","normalized_value":"eef4175da3a166ebbc6d5b8d81b569438e6f4c92a3ca42370efd1fef31fb3ca9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"60545f19-d9ea-4ebc-b91a-b916ca6ac41e","attribute_id":"34891762","event_id":"54097","event_uuid":"3dd38b8c-5338-4ec6-98a1-084f56a8680c","event_info":"Malware Analysis Report (AR21-102A) MAR-10331466-1.v1: China Chopper Webshell","event_date":"2021-03-26","attribute_timestamp":"1783743717","event_timestamp":"1783743718","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["tlp:white","misp-galaxy:mitre-malware=\"China Chopper - S0020\"","misp-galaxy:tool=\"China Chopper\"","misp-galaxy:threat-actor=\"Hafnium\"","threat-report"],"event":["tlp:white","misp-galaxy:mitre-malware=\"China Chopper - S0020\"","misp-galaxy:tool=\"China Chopper\"","misp-galaxy:threat-actor=\"Hafnium\"","threat-report"],"all":["misp-galaxy:mitre-malware=\"China Chopper - S0020\"","misp-galaxy:threat-actor=\"Hafnium\"","misp-galaxy:tool=\"China Chopper\"","threat-report","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware Analysis Report (AR21-102A) MAR-10331466-1.v1: China Chopper Webshell","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ef8fb137711aba179550d97b4dacda5644d17482b64e142934f429306044ce6b","normalized_value":"ef8fb137711aba179550d97b4dacda5644d17482b64e142934f429306044ce6b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b729fc3c-e435-43c7-9b03-d6c7a3a7b1df","attribute_id":"37524545","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:34.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"efc81267da3ad48cc779e9aed8f9232504ed7c85abf3958a87ba2ae68056ae23","normalized_value":"efc81267da3ad48cc779e9aed8f9232504ed7c85abf3958a87ba2ae68056ae23","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"88ef049c-8976-4b9a-b8fe-2ed367777ba8","attribute_id":"37752331","event_id":"61004","event_uuid":"f55757e1-7aef-484b-9552-2ca3b6b7d0d8","event_info":"Banking Rewards Malware Campaign","event_date":"2026-07-24","attribute_timestamp":"1784881856","event_timestamp":"1784881991","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"event":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"all":[" trojan","BANKING TROJAN","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Banking Rewards Malware Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"effae3acf9a49462ddead02a7d382a899367af22271cc9b7564c7be0e3a75505","normalized_value":"effae3acf9a49462ddead02a7d382a899367af22271cc9b7564c7be0e3a75505","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"2fc7ff6f-b94d-411a-9ad2-c48cbcdaad53","attribute_id":"37529620","event_id":"58567","event_uuid":"ae1c645a-f761-4e34-b072-4eacf2062a93","event_info":"Formbook host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783105335","event_timestamp":"1783215209","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f0163235356db1417f35409ec428f89392940c08bab8947acf9ccf1372f71946","normalized_value":"f0163235356db1417f35409ec428f89392940c08bab8947acf9ccf1372f71946","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6f2b8f59-2b4d-4c75-b0c9-c7842fe5dfd0","attribute_id":"37528510","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783062182","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f017efe36ccdbfee1fc834eb6cdbe02890edc845a2245a334a2ecaea825c6547","normalized_value":"f017efe36ccdbfee1fc834eb6cdbe02890edc845a2245a334a2ecaea825c6547","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"66869900-67bd-406f-bc1a-28c5d033d69b","attribute_id":"37528498","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783060860","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f11057ab58bef936d98ba189829c64260a6a540cdaa046f93613138e820c98c6","normalized_value":"f11057ab58bef936d98ba189829c64260a6a540cdaa046f93613138e820c98c6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"532b5874-da29-47b6-9fcf-f6837e56f31f","attribute_id":"37755495","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785351647","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--6c96119b-950c-57b8-813e-05356f6d4a0a","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--6c96119b-950c-57b8-813e-05356f6d4a0a","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f1728125f37ca8738b19b418a3fe896e9bdcde5aed6559db3eea55f4e17602c4","normalized_value":"f1728125f37ca8738b19b418a3fe896e9bdcde5aed6559db3eea55f4e17602c4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"65491eb2-c969-4bc1-9a29-f53dfa44b21c","attribute_id":"34370340","event_id":"51908","event_uuid":"9bdd433b-de5c-4bfe-92b8-2bd29eed6382","event_info":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","event_date":"2021-02-08","attribute_timestamp":"1783581067","event_timestamp":"1783581126","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"event":["misp-galaxy:threat-actor=\"Domestic Kitten\"","APT","threat-report","tlp:white","veris:actor:motive=\"Espionage\""],"all":["APT","misp-galaxy:threat-actor=\"Domestic Kitten\"","threat-report","tlp:white","veris:actor:motive=\"Espionage\""]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Domestic Kitten – An Inside Look at the Iranian Surveillance Operations","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f193b47f2739aaa35c0ecec5d2731dc7d343c200340015e4a2bff663c3041512","normalized_value":"f193b47f2739aaa35c0ecec5d2731dc7d343c200340015e4a2bff663c3041512","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"779c9614-1b15-4406-a624-ce0dc1a22f94","attribute_id":"37524523","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:41.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Venus Stealer","misp-galaxy:malpedia=\"Venus Stealer\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f2215e1a848bc5a5d172745201ea428b1d16fee7c814c5c5180a94a134592e86","normalized_value":"f2215e1a848bc5a5d172745201ea428b1d16fee7c814c5c5180a94a134592e86","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"750d1149-7dce-4011-b277-1eb0e9f3f542","attribute_id":"7386000","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581374","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f23e6b705868c3d3a6615be240bfa23620b0b873fd17b12a9481f7580a18ec75","normalized_value":"f23e6b705868c3d3a6615be240bfa23620b0b873fd17b12a9481f7580a18ec75","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"71cb2192-c1ce-452f-92d0-6e22abdaca1c","attribute_id":"37524508","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:46.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f23e6b705868c3d3a6615be240bfa23620b0b873fd17b12a9481f7580a18ec75","normalized_value":"f23e6b705868c3d3a6615be240bfa23620b0b873fd17b12a9481f7580a18ec75","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"eca9e1b5-249a-46fc-b834-362adbc64d31","attribute_id":"37523398","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146557","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f298725e197f974b7a8407c5d79114a4ac322c573813d543141ccf1d9119dd8b","normalized_value":"f298725e197f974b7a8407c5d79114a4ac322c573813d543141ccf1d9119dd8b","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"637c62ca-8548-48bc-8973-e4e53a3aba62","attribute_id":"7386239","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581184","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f2bbba1ea0f34b262f158ff31e00d39d89bbc471d04e8fca60a034cabe18e4f4","normalized_value":"f2bbba1ea0f34b262f158ff31e00d39d89bbc471d04e8fca60a034cabe18e4f4","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"22ef57c7-18c2-49ba-9335-a633f85ee562","attribute_id":"25410","event_id":"312","event_uuid":"3057b723-5fae-476d-b162-b0a1a9a63ac2","event_info":"Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System","event_date":"2025-08-28","attribute_timestamp":"1783667014","event_timestamp":"1783667101","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Trusted Relationship - T1199\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Network Sniffing - T1040\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Network Configuration Discovery - T1016\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"Archive Collected Data - T1560\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","APT","osint:source-type=\"technical-report\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"Telecoms\"","misp-galaxy:sector=\"Transport\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Active Scanning - T1595\"","misp-galaxy:mitre-attack-pattern=\"Network Topology - T1590.004\"","misp-galaxy:mitre-attack-pattern=\"Virtual Private Server - T1583.003\"","misp-galaxy:mitre-attack-pattern=\"Network Devices - T1584.008\"","misp-galaxy:mitre-attack-pattern=\"Exploits - T1588.005\"","misp-galaxy:mitre-attack-pattern=\"Tool - T1588.002\"","misp-galaxy:mitre-attack-pattern=\"System Services - T1569\"","misp-galaxy:mitre-attack-pattern=\"Container Administration Command - T1609\"","misp-galaxy:mitre-attack-pattern=\"Python - T1059.006\"","misp-galaxy:mitre-attack-pattern=\"Network Device CLI - T1059.008\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1136.001\"","misp-galaxy:mitre-attack-pattern=\"Container Service - T1543.005\"","misp-galaxy:mitre-attack-pattern=\"SSH Authorized Keys - T1098.004\"","misp-galaxy:mitre-attack-pattern=\"Password Cracking - T1110.002\"","misp-galaxy:mitre-attack-pattern=\"Command Obfuscation - T1027.010\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify System Firewall - T1562.004\"","misp-galaxy:mitre-attack-pattern=\"Deploy Container - T1610\"","misp-galaxy:mitre-attack-pattern=\"Indicator Removal - T1070\"","misp-galaxy:mitre-attack-pattern=\"Clear Persistence - T1070.009\"","misp-galaxy:mitre-attack-pattern=\"Network Boundary Bridging - T1599\"","misp-galaxy:mitre-attack-pattern=\"Modify Authentication Process - T1556\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"SSH - T1021.004\"","misp-galaxy:mitre-attack-pattern=\"SNMP (MIB Dump) - T1602.001\"","misp-galaxy:mitre-attack-pattern=\"Network Device Configuration Dump - T1602.002\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Multi-hop Proxy - T1090.003\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Non-Standard Port - T1571\"","misp-galaxy:mitre-attack-pattern=\"Protocol Tunneling - T1572\"","misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Unencrypted Non-C2 Protocol - T1048.003\"","CISA","cross-platform","cyber espionage","ssh","misp-galaxy:threat-actor=\"GhostEmperor\""],"event":["admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Trusted Relationship - T1199\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Network Sniffing - T1040\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Network Configuration Discovery - T1016\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"Archive Collected Data - T1560\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","APT","osint:source-type=\"technical-report\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"Telecoms\"","misp-galaxy:sector=\"Transport\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Active Scanning - T1595\"","misp-galaxy:mitre-attack-pattern=\"Network Topology - T1590.004\"","misp-galaxy:mitre-attack-pattern=\"Virtual Private Server - T1583.003\"","misp-galaxy:mitre-attack-pattern=\"Network Devices - T1584.008\"","misp-galaxy:mitre-attack-pattern=\"Exploits - T1588.005\"","misp-galaxy:mitre-attack-pattern=\"Tool - T1588.002\"","misp-galaxy:mitre-attack-pattern=\"System Services - T1569\"","misp-galaxy:mitre-attack-pattern=\"Container Administration Command - T1609\"","misp-galaxy:mitre-attack-pattern=\"Python - T1059.006\"","misp-galaxy:mitre-attack-pattern=\"Network Device CLI - T1059.008\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1136.001\"","misp-galaxy:mitre-attack-pattern=\"Container Service - T1543.005\"","misp-galaxy:mitre-attack-pattern=\"SSH Authorized Keys - T1098.004\"","misp-galaxy:mitre-attack-pattern=\"Password Cracking - T1110.002\"","misp-galaxy:mitre-attack-pattern=\"Command Obfuscation - T1027.010\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify System Firewall - T1562.004\"","misp-galaxy:mitre-attack-pattern=\"Deploy Container - T1610\"","misp-galaxy:mitre-attack-pattern=\"Indicator Removal - T1070\"","misp-galaxy:mitre-attack-pattern=\"Clear Persistence - T1070.009\"","misp-galaxy:mitre-attack-pattern=\"Network Boundary Bridging - T1599\"","misp-galaxy:mitre-attack-pattern=\"Modify Authentication Process - T1556\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"SSH - T1021.004\"","misp-galaxy:mitre-attack-pattern=\"SNMP (MIB Dump) - T1602.001\"","misp-galaxy:mitre-attack-pattern=\"Network Device Configuration Dump - T1602.002\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Multi-hop Proxy - T1090.003\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Non-Standard Port - T1571\"","misp-galaxy:mitre-attack-pattern=\"Protocol Tunneling - T1572\"","misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Unencrypted Non-C2 Protocol - T1048.003\"","CISA","cross-platform","cyber espionage","ssh","misp-galaxy:threat-actor=\"GhostEmperor\""],"all":["APT","CISA","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cross-platform","cyber espionage","misp-galaxy:mitre-attack-pattern=\"Active Scanning - T1595\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Archive Collected Data - T1560\"","misp-galaxy:mitre-attack-pattern=\"Clear Persistence - T1070.009\"","misp-galaxy:mitre-attack-pattern=\"Command Obfuscation - T1027.010\"","misp-galaxy:mitre-attack-pattern=\"Container Administration Command - T1609\"","misp-galaxy:mitre-attack-pattern=\"Container Service - T1543.005\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Deploy Container - T1610\"","misp-galaxy:mitre-attack-pattern=\"Disable or Modify System Firewall - T1562.004\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Unencrypted Non-C2 Protocol - T1048.003\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"Exploits - T1588.005\"","misp-galaxy:mitre-attack-pattern=\"Indicator Removal - T1070\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1136.001\"","misp-galaxy:mitre-attack-pattern=\"Modify Authentication Process - T1556\"","misp-galaxy:mitre-attack-pattern=\"Multi-hop Proxy - T1090.003\"","misp-galaxy:mitre-attack-pattern=\"Network Boundary Bridging - T1599\"","misp-galaxy:mitre-attack-pattern=\"Network Device CLI - T1059.008\"","misp-galaxy:mitre-attack-pattern=\"Network Device Configuration Dump - T1602.002\"","misp-galaxy:mitre-attack-pattern=\"Network Devices - T1584.008\"","misp-galaxy:mitre-attack-pattern=\"Network Sniffing - T1040\"","misp-galaxy:mitre-attack-pattern=\"Network Topology - T1590.004\"","misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"","misp-galaxy:mitre-attack-pattern=\"Non-Standard Port - T1571\"","misp-galaxy:mitre-attack-pattern=\"OS Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Password Cracking - T1110.002\"","misp-galaxy:mitre-attack-pattern=\"Protocol Tunneling - T1572\"","misp-galaxy:mitre-attack-pattern=\"Proxy - T1090\"","misp-galaxy:mitre-attack-pattern=\"Python - T1059.006\"","misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"","misp-galaxy:mitre-attack-pattern=\"SNMP (MIB Dump) - T1602.001\"","misp-galaxy:mitre-attack-pattern=\"SSH - T1021.004\"","misp-galaxy:mitre-attack-pattern=\"SSH Authorized Keys - T1098.004\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Network Configuration Discovery - T1016\"","misp-galaxy:mitre-attack-pattern=\"System Services - T1569\"","misp-galaxy:mitre-attack-pattern=\"Tool - T1588.002\"","misp-galaxy:mitre-attack-pattern=\"Trusted Relationship - T1199\"","misp-galaxy:mitre-attack-pattern=\"Virtual Private Server - T1583.003\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Military\"","misp-galaxy:sector=\"Telecoms\"","misp-galaxy:sector=\"Transport\"","misp-galaxy:threat-actor=\"GhostEmperor\"","osint:source-type=\"technical-report\"","ssh","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f371d7ac791a65baff290a230a59211d08248c69829f5b7e7c008c6dd3819dc1","normalized_value":"f371d7ac791a65baff290a230a59211d08248c69829f5b7e7c008c6dd3819dc1","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"8a9bcca9-f513-4c5c-babc-b434615ece01","attribute_id":"37521462","event_id":"58543","event_uuid":"c4505b05-707b-43d6-be9e-7280c9f43b72","event_info":"Nanocore host indicators [2026-07-04]","event_date":"2026-07-04","attribute_timestamp":"1783188009","event_timestamp":"1783208131","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","stone:malware-categorization=\"Rat\"","tlp:white","tlp:clear","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","tlp:clear","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","misp-galaxy:mitre-attack-pattern=\"Execution - TA0002\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","stone:false-positive=\"medium-risk\"","stone:incident-classification=\"Malware\"","stone:malware-categorization=\"Rat\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f37d19918ca9a92945198b23ab4e10be7d681e4aa1f8dfd1b0905482a006e7dd","normalized_value":"f37d19918ca9a92945198b23ab4e10be7d681e4aa1f8dfd1b0905482a006e7dd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"824df18f-7741-11f1-97fa-42010aa4000a","attribute_id":"37521947","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125866","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"CrossRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"CrossRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f37d19918ca9a92945198b23ab4e10be7d681e4aa1f8dfd1b0905482a006e7dd","normalized_value":"f37d19918ca9a92945198b23ab4e10be7d681e4aa1f8dfd1b0905482a006e7dd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"deef6bfe-e861-4233-89a3-11ac1edf79a6","attribute_id":"37528881","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:26.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["crossrat","misp-galaxy:malpedia=\"CrossRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["crossrat","misp-galaxy:malpedia=\"CrossRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f3bbf19f96f7ad2c8f8b36a0ba4354ea134a54392e6ebaa28b922d3f9f09d74f","normalized_value":"f3bbf19f96f7ad2c8f8b36a0ba4354ea134a54392e6ebaa28b922d3f9f09d74f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"aa8460ae-f7e2-4bdc-857d-f640519aa3c5","attribute_id":"37523761","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783174847","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f3c837323c135a7d7ed9d03f856c81463abb80174211117f4bda193a55f1b78e","normalized_value":"f3c837323c135a7d7ed9d03f856c81463abb80174211117f4bda193a55f1b78e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"46071652-7c6e-4942-9349-1609a13fe8ef","attribute_id":"825524","event_id":"1538","event_uuid":"d111d331-0c25-404b-b5b5-8ccf73753aea","event_info":"Travel Themed Phishing URLs Set to Prey on Eager Travelers","event_date":"2021-09-16","attribute_timestamp":"1783580592","event_timestamp":"1783580592","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["threat-report","tlp:white","Dridex","MalSpam","misp-galaxy:mitre-attack-pattern=\"Brute Force - T1110\"","misp-galaxy:mitre-attack-pattern=\"Create Account - T1136\"","misp-galaxy:mitre-attack-pattern=\"Drive-by Compromise - T1189\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"","misp-galaxy:mitre-attack-pattern=\"System Service Discovery - T1007\"","misp-galaxy:mitre-malware=\"Dridex - S0384\"","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Travel\"","cert-ist:attack_vector=\"Phishing\"","cert-ist:threat_type=\"phishing\"","cert-ist:enriched","cert-ist:ioc_accuracy=\"medium\"","misp-galaxy:tool=\"Dridex\"","misp-galaxy:banker=\"Dridex\"","misp-galaxy:malpedia=\"Dridex\"","tlp:clear"],"event":["threat-report","tlp:white","Dridex","MalSpam","misp-galaxy:mitre-attack-pattern=\"Brute Force - T1110\"","misp-galaxy:mitre-attack-pattern=\"Create Account - T1136\"","misp-galaxy:mitre-attack-pattern=\"Drive-by Compromise - T1189\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"","misp-galaxy:mitre-attack-pattern=\"System Service Discovery - T1007\"","misp-galaxy:mitre-malware=\"Dridex - S0384\"","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Travel\"","cert-ist:attack_vector=\"Phishing\"","cert-ist:threat_type=\"phishing\"","cert-ist:enriched","cert-ist:ioc_accuracy=\"medium\"","misp-galaxy:tool=\"Dridex\"","misp-galaxy:banker=\"Dridex\"","misp-galaxy:malpedia=\"Dridex\"","tlp:clear"],"all":["Dridex","MalSpam","cert-ist:attack_vector=\"Phishing\"","cert-ist:enriched","cert-ist:ioc_accuracy=\"medium\"","cert-ist:threat_type=\"phishing\"","misp-galaxy:banker=\"Dridex\"","misp-galaxy:malpedia=\"Dridex\"","misp-galaxy:mitre-attack-pattern=\"Brute Force - T1110\"","misp-galaxy:mitre-attack-pattern=\"Create Account - T1136\"","misp-galaxy:mitre-attack-pattern=\"Drive-by Compromise - T1189\"","misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"","misp-galaxy:mitre-attack-pattern=\"System Service Discovery - T1007\"","misp-galaxy:mitre-malware=\"Dridex - S0384\"","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Defense\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Travel\"","misp-galaxy:tool=\"Dridex\"","threat-report","tlp:clear","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Travel Themed Phishing URLs Set to Prey on Eager Travelers","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f3d8916b99d7e6301a885b2ec4aaf9635f1713464c53b1604d3b4e1abd673c36","normalized_value":"f3d8916b99d7e6301a885b2ec4aaf9635f1713464c53b1604d3b4e1abd673c36","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fc6c07c7-8021-4769-9554-f57d61bcf4d4","attribute_id":"37749166","event_id":"60956","event_uuid":"36e03b09-a20c-4169-a875-b77a24ca82fd","event_info":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","event_date":"2023-03-14","attribute_timestamp":"1783685709","event_timestamp":"1783685737","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"event":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"all":["Ave Maria","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","Energy Sector ","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cyber espionage","infostealer","meterpreter","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","osint:source-type=\"blog-post\"","tlp:clear","warzonerat"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f430b41d9a1bd7049a0d7ad0626c2e8c9f14dd1066b73fba4b9cdad17544b6cc","normalized_value":"f430b41d9a1bd7049a0d7ad0626c2e8c9f14dd1066b73fba4b9cdad17544b6cc","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7abb8d60-e1ca-4b5b-8926-07e437502449","attribute_id":"37528400","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783043908","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f583571ccb563a05415d5fe9dd67b369d9e5e01ce71f113633552a869720867b","normalized_value":"f583571ccb563a05415d5fe9dd67b369d9e5e01ce71f113633552a869720867b","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"2b536f8a-9349-409e-aa16-4a58226eace6","attribute_id":"37529573","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101997","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f5b43a3803a8149dda677d208ba7ef5e0aa33640bcd3dd58924355f4fc54be99","normalized_value":"f5b43a3803a8149dda677d208ba7ef5e0aa33640bcd3dd58924355f4fc54be99","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"19547959-7ef2-43e1-a299-0c18f8b50ad1","attribute_id":"37529015","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:41.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f5b43a3803a8149dda677d208ba7ef5e0aa33640bcd3dd58924355f4fc54be99","normalized_value":"f5b43a3803a8149dda677d208ba7ef5e0aa33640bcd3dd58924355f4fc54be99","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6717303c-7741-11f1-97fa-42010aa4000a","attribute_id":"37521950","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125821","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"WannaCryptor payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"WannaCryptor payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f65a25e37c7abc88d641e13004c4e5523502b4568cfcf6713f4f50e34f23e770","normalized_value":"f65a25e37c7abc88d641e13004c4e5523502b4568cfcf6713f4f50e34f23e770","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"136438d6-866e-4ab5-bc66-1d9f8f293130","attribute_id":"37524536","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:37.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Redosdru","misp-galaxy:malpedia=\"Redosdru\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Redosdru","misp-galaxy:malpedia=\"Redosdru\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f681e8f26091a2a5ed40f477340a06140bbee4fa91eb5fe5a71b40da43affb46","normalized_value":"f681e8f26091a2a5ed40f477340a06140bbee4fa91eb5fe5a71b40da43affb46","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1f78123d-285c-4e26-924c-84f2a6006105","attribute_id":"37746622","event_id":"60932","event_uuid":"ae102ba0-f797-4201-b557-0fb163a9e03f","event_info":"Unmasking the Hidden Threat: Inside a Sophisticated Excel-Based Attack Delivering Fileless Remcos RAT","event_date":"2024-09-12","attribute_timestamp":"1783581636","event_timestamp":"1784392758","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Template Injection - T1221\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Third-party Software - T1072\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Execution through API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\""," Agent Tesla","FormBook","GuLoader","OSINT","Remcos","RevengeRAT","SnakeKeylogger","excel","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Technology\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Mshta - T1218.005\"","misp-galaxy:mitre-attack-pattern=\"Steganography - T1027.003\"","misp-galaxy:mitre-attack-pattern=\"Shortcut Modification - T1547.009\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities - T1127\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities Proxy Execution - T1127\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\""," RemcosRAT","FinFisher.Botnet","finspy","LatentBot","misp-galaxy:country=\"australia\"","misp-galaxy:country=\"belgium\"","misp-galaxy:country=\"canada\"","misp-galaxy:country=\"germany\"","misp-galaxy:country=\"japan\"","misp-galaxy:country=\"south korea\"","misp-galaxy:country=\"united states of america\"","Agent Tesla","RemcosRAT"],"event":["admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Template Injection - T1221\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Third-party Software - T1072\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Execution through API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\""," Agent Tesla","FormBook","GuLoader","OSINT","Remcos","RevengeRAT","SnakeKeylogger","excel","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Technology\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Mshta - T1218.005\"","misp-galaxy:mitre-attack-pattern=\"Steganography - T1027.003\"","misp-galaxy:mitre-attack-pattern=\"Shortcut Modification - T1547.009\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities - T1127\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities Proxy Execution - T1127\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\""," RemcosRAT","FinFisher.Botnet","finspy","LatentBot","misp-galaxy:country=\"australia\"","misp-galaxy:country=\"belgium\"","misp-galaxy:country=\"canada\"","misp-galaxy:country=\"germany\"","misp-galaxy:country=\"japan\"","misp-galaxy:country=\"south korea\"","misp-galaxy:country=\"united states of america\"","Agent Tesla","RemcosRAT"],"all":[" Agent Tesla"," RemcosRAT","Agent Tesla","FinFisher.Botnet","FormBook","GuLoader","LatentBot","OSINT","Remcos","RemcosRAT","RevengeRAT","SnakeKeylogger","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","excel","finspy","misp-galaxy:country=\"australia\"","misp-galaxy:country=\"belgium\"","misp-galaxy:country=\"canada\"","misp-galaxy:country=\"germany\"","misp-galaxy:country=\"japan\"","misp-galaxy:country=\"south korea\"","misp-galaxy:country=\"united states of america\"","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"","misp-galaxy:mitre-attack-pattern=\"Execution through API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"","misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Mshta - T1218.005\"","misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Shortcut Modification - T1547.009\"","misp-galaxy:mitre-attack-pattern=\"Software Deployment Tools - T1072\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Standard Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Steganography - T1027.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Language Discovery - T1614.001\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Template Injection - T1221\"","misp-galaxy:mitre-attack-pattern=\"Third-party Software - T1072\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities - T1127\"","misp-galaxy:mitre-attack-pattern=\"Trusted Developer Utilities Proxy Execution - T1127\"","misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"","misp-galaxy:sector=\"Bank\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Manufacturing\"","misp-galaxy:sector=\"Technology\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Unmasking the Hidden Threat: Inside a Sophisticated Excel-Based Attack Delivering Fileless Remcos RAT","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f770e3955872fbb611e7a8bc154efc34b2e363493847c3f211da72214fb2c4e6","normalized_value":"f770e3955872fbb611e7a8bc154efc34b2e363493847c3f211da72214fb2c4e6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7becd7b1-7741-11f1-97fa-42010aa4000a","attribute_id":"37521955","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125856","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"RatonRAT payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"RatonRAT payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f770e3955872fbb611e7a8bc154efc34b2e363493847c3f211da72214fb2c4e6","normalized_value":"f770e3955872fbb611e7a8bc154efc34b2e363493847c3f211da72214fb2c4e6","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"c476cfe8-6c8f-4da3-ad14-cb1a2d13a716","attribute_id":"37528910","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:16.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["ratonrat","misp-galaxy:malpedia=\"RatonRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["misp-galaxy:malpedia=\"RatonRAT\"","osint:source-type=\"block-or-filter-list\"","ratonrat","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f78319fcb16312d69c6d2e42689254dff3cb875315f7b2111f5c3d2b4947ab50","normalized_value":"f78319fcb16312d69c6d2e42689254dff3cb875315f7b2111f5c3d2b4947ab50","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"61506f3f-e104-4f24-a72f-b285130825bf","attribute_id":"69151","event_id":"840","event_uuid":"43ada241-ed57-4303-85a5-4caa53e6f5ef","event_info":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","event_date":"2024-11-08","attribute_timestamp":"1783686530","event_timestamp":"1784305112","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"event":["admiralty-scale:source-reliability=\"c\"","admiralty-scale:information-credibility=\"3\"","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\""," RemcosRAT","GuLoader"," powershell","OSINT","osint:source-type=\"technical-report\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","windows","RemcosRAT","Powershell"],"all":[" RemcosRAT"," powershell","GuLoader","OSINT","Powershell","RemcosRAT","admiralty-scale:information-credibility=\"3\"","admiralty-scale:source-reliability=\"c\"","misp-galaxy:mitre-attack-pattern=\"Debugger Evasion - T1622\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"","misp-galaxy:mitre-attack-pattern=\"Junk Data - T1001.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"","misp-galaxy:mitre-attack-pattern=\"Remote File Copy - T1105\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Time Based Evasion - T1497.003\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:target-information=\"Germany\"","misp-galaxy:target-information=\"Kazakhstan\"","misp-galaxy:target-information=\"Poland\"","misp-galaxy:target-information=\"Romania\"","osint:source-type=\"technical-report\"","tlp:clear","windows"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"GuLoader: Evolving Tactics in Latest Campaign Targeting European Industry","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f7ccf101a530bb40dc57ca98993cd3be54915518ba6af090a6b818ccf847d994","normalized_value":"f7ccf101a530bb40dc57ca98993cd3be54915518ba6af090a6b818ccf847d994","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"39d56613-6499-4d74-be4e-e030bd29c1ad","attribute_id":"37528565","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783064129","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["zip","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT","zip"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f8183b625153b4b06f974c697d52a2d273a4e7d981f4f33e8ff27c203653f600","normalized_value":"f8183b625153b4b06f974c697d52a2d273a4e7d981f4f33e8ff27c203653f600","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"094dbd34-b019-48c4-9e3a-ad8153899d4d","attribute_id":"37528370","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783043432","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","elf","mips","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","elf","mips","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0","normalized_value":"f8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"99d3c530-44e8-400a-9c70-9efad83e7c67","attribute_id":"37755194","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140424","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--051741a9-8642-5f47-bd04-bf16e229101d","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--051741a9-8642-5f47-bd04-bf16e229101d","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f93209fccd0c452b8b5dc9db46341281344156bbedd23a47d2d551f80f460534","normalized_value":"f93209fccd0c452b8b5dc9db46341281344156bbedd23a47d2d551f80f460534","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0d84942f-6d1c-4042-9884-020f055625db","attribute_id":"7385976","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581392","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f966b81a9ed9c9f025cb92f12cf4839a2ff37b8ca14133ae214a4f88c0efc56a","normalized_value":"f966b81a9ed9c9f025cb92f12cf4839a2ff37b8ca14133ae214a4f88c0efc56a","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a684eb71-408d-4790-982c-c8994607d6e3","attribute_id":"37523221","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783128917","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload","event_extends_uuid":"","tags":{"attribute":["Mirai","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"f9e91a2fcffaeae978fa7abf8bdcb7ee79270f97385e22d70e7182a969af1fac","normalized_value":"f9e91a2fcffaeae978fa7abf8bdcb7ee79270f97385e22d70e7182a969af1fac","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"5181b37e-cd4c-4673-b06d-67ae5a6c3c91","attribute_id":"37528619","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783066351","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Mirai)","event_extends_uuid":"","tags":{"attribute":["Mirai","opendir","sh","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Mirai","opendir","sh","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Mirai)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fadbb8061715128bebecf7bc59132b6bb04fe8cc39b965aa5b8722dffe28d7e7","normalized_value":"fadbb8061715128bebecf7bc59132b6bb04fe8cc39b965aa5b8722dffe28d7e7","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9f4f43d9-8732-4fc0-aac2-ac2404a8eaf9","attribute_id":"37752149","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fb43c4191c40f159167a98a4ac20bf23ae66a8ec27a919f703e953933e22a266","normalized_value":"fb43c4191c40f159167a98a4ac20bf23ae66a8ec27a919f703e953933e22a266","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"22fbe47d-3b91-4082-983b-1614b37731ee","attribute_id":"37752330","event_id":"61004","event_uuid":"f55757e1-7aef-484b-9552-2ca3b6b7d0d8","event_info":"Banking Rewards Malware Campaign","event_date":"2026-07-24","attribute_timestamp":"1784881856","event_timestamp":"1784881991","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"event":["NCSA","NCSA_Research"," trojan","BANKING TROJAN","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\""],"all":[" trojan","BANKING TROJAN","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"","misp-galaxy:mitre-attack-pattern=\"Boot or Logon Autostart Execution - T1547\"","misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"","misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Masquerade Account Name - T1036.010\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing via Service - T1566.003\"","misp-galaxy:mitre-attack-pattern=\"Stage Capabilities - T1608\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"User Execution - T1204\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Banking Rewards Malware Campaign","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fb913ba0ad2ee1d28ed55ac637d770a196ec0fac8d865f106a45338f95757557","normalized_value":"fb913ba0ad2ee1d28ed55ac637d770a196ec0fac8d865f106a45338f95757557","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"da67ab6f-4eff-4a5a-8996-0f97096e07e3","attribute_id":"37528710","event_id":"58562","event_uuid":"b7ca4266-d7ab-4860-9776-8ffa8bb8b7ab","event_info":"URLhaus IOCs for 2026-07-03","event_date":"2026-07-03","attribute_timestamp":"1783082546","event_timestamp":"1783124124","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Gafgyt)","event_extends_uuid":"","tags":{"attribute":["gafgyt","elf","ua-wget","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["elf","gafgyt","tlp:white","type:OSINT","ua-wget"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Gafgyt)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fb94b2caee2c40635448a98ba0118421e19a400e74ccff73315f8fa42351f53f","normalized_value":"fb94b2caee2c40635448a98ba0118421e19a400e74ccff73315f8fa42351f53f","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"cced663b-558e-47c0-bc3b-c6081d4b7aea","attribute_id":"37755436","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140555","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--3c31b83d-1681-55e4-9ee4-be9078d0dabb","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--3c31b83d-1681-55e4-9ee4-be9078d0dabb","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fbbb5b74e9d1d24d79f9ca7f8dc44dac9ea7663d666ee829bc5e2d2cbcec3174","normalized_value":"fbbb5b74e9d1d24d79f9ca7f8dc44dac9ea7663d666ee829bc5e2d2cbcec3174","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"696088df-7741-11f1-97fa-42010aa4000a","attribute_id":"37521958","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125824","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Formbook payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Formbook payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fbbb5b74e9d1d24d79f9ca7f8dc44dac9ea7663d666ee829bc5e2d2cbcec3174","normalized_value":"fbbb5b74e9d1d24d79f9ca7f8dc44dac9ea7663d666ee829bc5e2d2cbcec3174","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"fffebdbf-1133-419a-9a36-ca626cc80899","attribute_id":"37529008","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:44.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["FormBook","misp-galaxy:malpedia=\"Formbook\"","misp-galaxy:malpedia=\"XLoader\"","misp-galaxy:mandiant-malware-family=\"5134b4c1-6956-4a5e-b09f-6cd16cad3e42\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fbbb5b74e9d1d24d79f9ca7f8dc44dac9ea7663d666ee829bc5e2d2cbcec3174","normalized_value":"fbbb5b74e9d1d24d79f9ca7f8dc44dac9ea7663d666ee829bc5e2d2cbcec3174","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"008a171c-7275-48d9-bf73-e910e3814755","attribute_id":"37529624","event_id":"58567","event_uuid":"ae1c645a-f761-4e34-b072-4eacf2062a93","event_info":"Formbook host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783105408","event_timestamp":"1783215209","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd","normalized_value":"fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f52ddc2e-1628-4a1a-827a-ea4f0e8db433","attribute_id":"37752425","event_id":"61008","event_uuid":"9337bf84-8d94-4826-a516-5564ea3501a8","event_info":"jscrambler npm Supply-Chain Operation","event_date":"2026-07-27","attribute_timestamp":"1785123850","event_timestamp":"1785124058","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"event":["NCSA","NCSA_Research","Cybercrime","tlp:clear","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\""],"all":["Cybercrime","NCSA","NCSA_Research","misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"","misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"","misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"","misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"","misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"","misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"","misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"","misp-galaxy:mitre-attack-pattern=\"Password Managers - T1555.005\"","misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"","misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"","misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"","misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"","misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"","misp-galaxy:mitre-enterprise-attack-attack-pattern=\"Obfuscated Files or Information - T1027\"","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"jscrambler npm Supply-Chain Operation","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fc772ded09936960f85abe63e2162ac141d072eeb60d3f5a4c0e47f249c9b6a9","normalized_value":"fc772ded09936960f85abe63e2162ac141d072eeb60d3f5a4c0e47f249c9b6a9","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"f91d0f57-ea33-4fb7-a609-2e74143c22cf","attribute_id":"37524554","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:31.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"WannaCryptor\"","WannaCryptor","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["WannaCryptor","misp-galaxy:malpedia=\"WannaCryptor\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fc99609172910a8fad9522b374f8bae21e5805abdf052a49029edb53620a8e8c","normalized_value":"fc99609172910a8fad9522b374f8bae21e5805abdf052a49029edb53620a8e8c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"1b519e82-3a3e-4819-a1bb-614cb5ce90fb","attribute_id":"37529164","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783149779","event_timestamp":"1783231919","first_seen":"2026-07-04T05:10:21.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n100","event_extends_uuid":"","tags":{"attribute":["dropper","Android","apk ","craxsrat","misp-galaxy:mandiant-malware-family=\"f5acf861-c801-4961-9154-f3dcabc198e4\"","SafeRussia","misp-galaxy:malpedia=\"CraxsRAT\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Android","SafeRussia","apk ","craxsrat","dropper","misp-galaxy:malpedia=\"CraxsRAT\"","misp-galaxy:mandiant-malware-family=\"f5acf861-c801-4961-9154-f3dcabc198e4\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n100","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fc99609172910a8fad9522b374f8bae21e5805abdf052a49029edb53620a8e8c","normalized_value":"fc99609172910a8fad9522b374f8bae21e5805abdf052a49029edb53620a8e8c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"99d512e3-7705-11f1-97fa-42010aa4000a","attribute_id":"37521961","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783149021","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"CraxsRAT payload (confidence level: 100%)","event_extends_uuid":"","tags":{"attribute":["dropper","Android","apk ","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Android","apk ","dropper","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"CraxsRAT payload (confidence level: 100%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fcd8643dff51723d1250496b2a8e10d69fb6e2eb4c01c30cbad32bbf54c9ce51","normalized_value":"fcd8643dff51723d1250496b2a8e10d69fb6e2eb4c01c30cbad32bbf54c9ce51","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"08472233-5687-44c5-89ac-a9bca7a8ff92","attribute_id":"37524424","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:23:15.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["misp-galaxy:malpedia=\"vidar\"","Vidar","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Vidar","misp-galaxy:malpedia=\"vidar\"","misp-galaxy:mandiant-malware-family=\"3861af6f-780c-4b5f-961f-14852a4106e7\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fcd8643dff51723d1250496b2a8e10d69fb6e2eb4c01c30cbad32bbf54c9ce51","normalized_value":"fcd8643dff51723d1250496b2a8e10d69fb6e2eb4c01c30cbad32bbf54c9ce51","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"b944a2c6-fe19-4f6d-ae58-cb998c1a6b72","attribute_id":"37523580","event_id":"58548","event_uuid":"820fa53a-74c7-4ec0-9817-8c2be9e3cf21","event_info":"URLhaus IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783146566","event_timestamp":"1783210524","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Malware payload (Vidar)","event_extends_uuid":"","tags":{"attribute":["Vidar","tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["Vidar","tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malware payload (Vidar)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fd01262bd56510088b9ddfe58ca101abb98575f3c0259b480a31b917aa73bc56","normalized_value":"fd01262bd56510088b9ddfe58ca101abb98575f3c0259b480a31b917aa73bc56","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"366a03bc-4852-44c1-b105-fc1253d00de2","attribute_id":"37752277","event_id":"60998","event_uuid":"5d50bb0c-c021-4540-808f-bbd176218e0d","event_info":"Malicious GitHub Campaign Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer","event_date":"2026-07-22","attribute_timestamp":"1784704450","event_timestamp":"1784704564","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research","malicious","tlp:clear","  Malware  "," infostealer"],"event":["NCSA","NCSA_Research","malicious","tlp:clear","  Malware  "," infostealer"],"all":["  Malware  "," infostealer","NCSA","NCSA_Research","malicious","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Malicious GitHub Campaign Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fd2ac3a761f66dc6954014532795f9108f65739f23e4b294d4563673b7996881","normalized_value":"fd2ac3a761f66dc6954014532795f9108f65739f23e4b294d4563673b7996881","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"970e1376-c5c7-4b04-9b57-e41811639072","attribute_id":"37755110","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1784112066","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--1e71a47e-1ee4-58e3-854e-8f735740e5b1","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--1e71a47e-1ee4-58e3-854e-8f735740e5b1","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fd2d5ada1da9e1088e3ad645543dcdf407a1996be32041c4fd64e15591962577","normalized_value":"fd2d5ada1da9e1088e3ad645543dcdf407a1996be32041c4fd64e15591962577","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"6e6ee346-7741-11f1-97fa-42010aa4000a","attribute_id":"37521962","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125833","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Stealc payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Stealc payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fd2d5ada1da9e1088e3ad645543dcdf407a1996be32041c4fd64e15591962577","normalized_value":"fd2d5ada1da9e1088e3ad645543dcdf407a1996be32041c4fd64e15591962577","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"a2d70157-ddf1-48d8-8152-8c9af7e605ff","attribute_id":"37528978","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:43:53.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Stealc","misp-galaxy:malpedia=\"Stealc\"","misp-galaxy:mandiant-malware-family=\"fbc478bb-a58b-4e92-85cd-ce0b40981cad\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fd3489f6067ef7ca3999776205839424cb7349134baaeb693abcecaa2c5bf913","normalized_value":"fd3489f6067ef7ca3999776205839424cb7349134baaeb693abcecaa2c5bf913","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"9ab339d6-cc04-410a-b4c7-1327620c6099","attribute_id":"7385981","event_id":"34124","event_uuid":"48e15610-a505-4067-8dec-4627e36bcbe7","event_info":"Combined IOCs Netwalk/Netwalker Ransomware","event_date":"2020-10-14","attribute_timestamp":"1783581388","event_timestamp":"1783581502","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","event_extends_uuid":"","tags":{"attribute":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"event":["tlp:white","Ransomware","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","NetWalker "],"all":["NetWalker ","Ransomware","misp-galaxy:mitre-attack-pattern=\"Credential Dumping - T1003\"","misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"","misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"","misp-galaxy:mitre-attack-pattern=\"Network Service Scanning - T1046\"","misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"","misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"","misp-galaxy:mitre-attack-pattern=\"Windows Management Instrumentation - T1047\"","misp-galaxy:sector=\"Energy\"","misp-galaxy:sector=\"Finance\"","misp-galaxy:sector=\"Government, Administration\"","misp-galaxy:sector=\"Health\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Enriched via the openiocimport module MalwareBazaar: Zero2Automated Course","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fd7fe71185a70f281545a815fce9837453450bb29031954dd2301fe4da99250d","normalized_value":"fd7fe71185a70f281545a815fce9837453450bb29031954dd2301fe4da99250d","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"75baef48-6772-4a6b-96bc-79fa26bcbdfa","attribute_id":"37749178","event_id":"60956","event_uuid":"36e03b09-a20c-4169-a875-b77a24ca82fd","event_info":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","event_date":"2023-03-14","attribute_timestamp":"1783685717","event_timestamp":"1783685737","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"Centre for Cyber security Belgium","orgc_uuid":"5cf66e53-b5f8-43e7-be9a-49880a3b4631","threat_level_id":"1","threat_level":"high","analysis_id":"0","analysis":"initial","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"event":["osint:source-type=\"blog-post\"","admiralty-scale:source-reliability=\"b\"","admiralty-scale:information-credibility=\"2\"","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","warzonerat","meterpreter","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","infostealer","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","tlp:clear","cyber espionage","Energy Sector ","Ave Maria","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\""],"all":["Ave Maria","Ave Maria RAT","AveMairaRAT","AveMaria","AveMariaRAT","Energy Sector ","Loda","LodaRAT","WarzonaRAT","Warzone","Warzone RAT","admiralty-scale:information-credibility=\"2\"","admiralty-scale:source-reliability=\"b\"","cyber espionage","infostealer","meterpreter","misp-galaxy:mitre-attack-pattern=\"Credentials - T1589.001\"","misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"","misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"","misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"","misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"","misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"","misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"","misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"","misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"","osint:source-type=\"blog-post\"","tlp:clear","warzonerat"]},"tlp":"TLP:CLEAR","confidence":"medium","sightings_count":0,"recommended_action":"detect_or_block","reason":"Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939","normalized_value":"fd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"dcf27e24-6349-43b6-ab91-65ecf99d5b9a","attribute_id":"37755193","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140423","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--e28f27f7-e777-54d7-8e88-4ab659011909","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--e28f27f7-e777-54d7-8e88-4ab659011909","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"fd834934b8de230554ae62d2c8607b1d5ada181d34140085ccf55560c4b92d18","normalized_value":"fd834934b8de230554ae62d2c8607b1d5ada181d34140085ccf55560c4b92d18","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e33b4406-e508-4d25-8c45-200d9714ebef","attribute_id":"37524570","event_id":"58550","event_uuid":"a142ee5b-e60c-43b2-9d45-d52e88246c9f","event_info":"Daily Incremental ThreatFox Import - 2026-07-05","event_date":"2026-07-05","attribute_timestamp":"1783269183","event_timestamp":"1784390661","first_seen":"2026-07-05T14:22:25.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Kuiper","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ff5e55cdf68dcf74022d806dfa3a4e5f55780cabd255b63cde7cf00d78d7f96f","normalized_value":"ff5e55cdf68dcf74022d806dfa3a4e5f55780cabd255b63cde7cf00d78d7f96f","attribute_type":"sha256","category":"Payload installation","attribute_uuid":"a250a7b8-dbd1-4638-b09e-0946328fa099","attribute_id":"37529577","event_id":"58565","event_uuid":"3935efbf-a913-4c9d-819d-0d7df57f67e3","event_info":"AgentTesla host indicators [2026-07-03]","event_date":"2026-07-03","attribute_timestamp":"1783101999","event_timestamp":"1783213145","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"StoneCo","orgc_uuid":"2cec48ab-66a6-4ef9-9879-954f525dc54a","threat_level_id":"2","threat_level":"medium","analysis_id":"2","analysis":"completed","attribute_comment":"Source: MalwareBazaar","event_extends_uuid":"","tags":{"attribute":["kill-chain:Installation","tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"event":["tlp:white","stone:source=\"OSINT\"","stone:incident-classification=\"Malware\"","stone:threat-level=\"medium-risk\""],"all":["kill-chain:Installation","stone:incident-classification=\"Malware\"","stone:source=\"OSINT\"","stone:threat-level=\"medium-risk\"","tlp:white"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Source: MalwareBazaar","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ff662b60f6a142f99292fbdd65dd1ccd79dc9628686ddf5935c92f7fb1b62a81","normalized_value":"ff662b60f6a142f99292fbdd65dd1ccd79dc9628686ddf5935c92f7fb1b62a81","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"834bc490-c446-44c8-9182-64ecbf2524fe","attribute_id":"37755153","event_id":"61026","event_uuid":"6cb94c67-172c-436e-bf15-8bf6bee32566","event_info":"CTM360 Collection: IOC's TLP:WHITE","event_date":"2026-07-15","attribute_timestamp":"1785140400","event_timestamp":"1785351655","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CTM360","orgc_uuid":"7d2546a4-bcdc-48fd-a20f-d3d4c37b4620","threat_level_id":"3","threat_level":"low","analysis_id":"1","analysis":"ongoing","attribute_comment":"stix_id:indicator--ae322e87-ea1a-50ea-9bfa-63683d9f0eab","event_extends_uuid":"","tags":{"attribute":["source:ctm360","tlp:clear","source:ctm360","tlp:clear"],"event":["source:ctm360","tlp:clear"],"all":["source:ctm360","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"stix_id:indicator--ae322e87-ea1a-50ea-9bfa-63683d9f0eab","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3e","normalized_value":"ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3e","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"e3c9cb18-8c69-4ca8-9555-a84b413389a2","attribute_id":"37751398","event_id":"60979","event_uuid":"fea39f60-0010-477f-b097-b30d1547c5a4","event_info":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","event_date":"2026-07-17","attribute_timestamp":"1784273256","event_timestamp":"1784273257","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"event":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"],"all":["  Malware  "," C2"," ClickFix","MaaS","NCSA","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ff825f043105b50df62b498b65c6c7632f2e7aab5efff1cdca49400e38bd2943","normalized_value":"ff825f043105b50df62b498b65c6c7632f2e7aab5efff1cdca49400e38bd2943","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"79af651f-7741-11f1-97fa-42010aa4000a","attribute_id":"37521964","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783125852","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"Prometei payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Prometei payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ff825f043105b50df62b498b65c6c7632f2e7aab5efff1cdca49400e38bd2943","normalized_value":"ff825f043105b50df62b498b65c6c7632f2e7aab5efff1cdca49400e38bd2943","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"7a59aa3e-20b5-4ddc-8da2-80d020500479","attribute_id":"37528922","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783126380","event_timestamp":"1783231919","first_seen":"2026-07-03T22:44:12.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["Prometei","misp-galaxy:malpedia=\"Prometei\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["Prometei","misp-galaxy:malpedia=\"Prometei\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ffa6334625c7613e5a3b8817c742e43a2e9447fcaae7305e3eeaf0be5eb4ea70","normalized_value":"ffa6334625c7613e5a3b8817c742e43a2e9447fcaae7305e3eeaf0be5eb4ea70","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"46799d70-d1f3-4a4d-b3a5-6d22dce8a887","attribute_id":"37529482","event_id":"58563","event_uuid":"2847b718-803a-43f5-b62c-78669d1f2627","event_info":"Daily Incremental ThreatFox Import - 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176776","event_timestamp":"1783231919","first_seen":"2026-07-04T12:41:54.000000+00:00","last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"CERT-Bayern","orgc_uuid":"55f6ea63-a22c-40cc-a1d1-483b950d210f","threat_level_id":"3","threat_level":"low","analysis_id":"2","analysis":"completed","attribute_comment":"payload\n95","event_extends_uuid":"","tags":{"attribute":["xworm","misp-galaxy:malpedia=\"XWorm\"","misp-galaxy:mandiant-malware-family=\"2c11edb3-e227-4a8f-b5d8-1b9eb7c9e378\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"event":["osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear"],"all":["misp-galaxy:malpedia=\"XWorm\"","misp-galaxy:mandiant-malware-family=\"2c11edb3-e227-4a8f-b5d8-1b9eb7c9e378\"","osint:source-type=\"block-or-filter-list\"","source:threatfox.abuse.ch","tlp:clear","xworm"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"payload\n95","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ffa6334625c7613e5a3b8817c742e43a2e9447fcaae7305e3eeaf0be5eb4ea70","normalized_value":"ffa6334625c7613e5a3b8817c742e43a2e9447fcaae7305e3eeaf0be5eb4ea70","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"804a00e2-77b6-11f1-97fa-42010aa4000a","attribute_id":"37521965","event_id":"58544","event_uuid":"afd2384d-11f9-429e-a963-77d6833f4c1a","event_info":"ThreatFox IOCs for 2026-07-04","event_date":"2026-07-04","attribute_timestamp":"1783176114","event_timestamp":"1783209786","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"threatfox","orgc_uuid":"9b086132-8588-49ed-97fd-8578a777822c","threat_level_id":"2","threat_level":"medium","analysis_id":"1","analysis":"ongoing","attribute_comment":"XWorm payload (confidence level: 95%)","event_extends_uuid":"","tags":{"attribute":["tlp:white","type:OSINT"],"event":["tlp:white","type:OSINT"],"all":["tlp:white","type:OSINT"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"XWorm payload (confidence level: 95%)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
{"schema_version":"1.0","feed":"hash","observable_value":"ffb9eb47cc0cb2f43e04a10dc84df13d04bca1ebacbe47fad0b669728de2f59c","normalized_value":"ffb9eb47cc0cb2f43e04a10dc84df13d04bca1ebacbe47fad0b669728de2f59c","attribute_type":"sha256","category":"Payload delivery","attribute_uuid":"0ea6e81b-24b2-4136-864b-a820648847c8","attribute_id":"37752155","event_id":"60988","event_uuid":"435b3789-3be8-4d6e-998e-a894f87fcedf","event_info":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","event_date":"2026-07-20","attribute_timestamp":"1784529372","event_timestamp":"1784557812","first_seen":null,"last_seen":null,"to_ids":true,"deleted":false,"disable_correlation":false,"distribution":"5","sharing_group_id":"0","orgc_name":"NCSA","orgc_uuid":"24c76f03-ca54-4c1a-b9eb-edfbc2494ecc","threat_level_id":"1","threat_level":"high","analysis_id":"2","analysis":"completed","attribute_comment":"","event_extends_uuid":"","tags":{"attribute":["NCSA","NCSA_Research"," trojan","tlp:clear"],"event":["NCSA","NCSA_Research"," trojan","tlp:clear"],"all":[" trojan","NCSA","NCSA_Research","tlp:clear"]},"tlp":"TLP:CLEAR","confidence":null,"sightings_count":0,"recommended_action":"detect_or_block","reason":"Threat Actor Targets Banking Users in Spain and Portugal with Ousaban Malware [ Javali (Ousaban)","source":"NCSA MISP","exported_at":"2026-08-01T18:30:01Z"}
