{
  "campaign_count": 45,
  "campaigns": [
    {
      "activity": {
        "2026-08-14": 202,
        "2026-08-16": 199,
        "2026-08-19": 2
      },
      "anchors": {
        "registered_domains": [
          "access-divace-bridge.typedream.app",
          "app----en-bybit-sso.typedream.app",
          "app-live-ledger-wllet.typedream.app",
          "begin-faq-trezer-suite-page.typedream.app",
          "begin-hardware-trezo.typedream.app",
          "begin-ledger-support.typedream.app",
          "begin-new-trezrio-strt.typedream.app",
          "begin-trezr-start-io.typedream.app",
          "biiousdt.com",
          "biiusd.com",
          "binaccem8.com",
          "binancee2.com",
          "binancen4.com",
          "binancez5.com",
          "binccusdc.com",
          "binllusdt.com",
          "binmnxc.com",
          "binnmusdt.com",
          "binnmzcusdt.com",
          "binsiousdt.com",
          "binsxousdt.com",
          "binttusdt.com",
          "binveusdt.com",
          "binxasusdt.com",
          "binxiusdt.com",
          "binxsausdt.com",
          "binxzusdt.com",
          "binyyusdt.com",
          "binzsiousdt.com",
          "blsiusdt.com",
          "bright-secure-blokf-com-authd.typedream.app",
          "btcniox.com",
          "btcoisxaw.com",
          "btcooii.com",
          "btcsaio.com",
          "btczio.com",
          "buious.com",
          "bybaausdt.com",
          "bybaeusdt.com",
          "bybiiusdt.com",
          "bybit-login-app.typedream.app",
          "bybopusd.com",
          "bybssusdt.com",
          "cioiusd.com",
          "cioum.com",
          "ciousd.com",
          "ciovusdt.com",
          "ciuousdt.com",
          "cloud-warppe-d-ether-walle-t.typedream.app",
          "cnusx.com"
        ],
        "tags": [
          "#cryptoscam"
        ],
        "url_path_patterns": [
          "/en-us",
          "/untitled-NeN"
        ]
      },
      "confidence": "high",
      "context": "Over 400 Binance typosquat domains and typedream.app subpages spoof Ledger, Trezor, and Bybit via wallet-setup paths. Random-label bin* domains such as binancee2.com and biiusd.com form the bulk of the infrastructure alongside PaaS-hosted lure pages. Reporters phishunt_io and skocherhan flagged 403 IOCs between 2026-08-14 and 2026-08-19.",
      "enriched_count": 403,
      "families": {},
      "first_seen": "2026-08-14",
      "history": {
        "by_pattern": [],
        "domains_365d": 200,
        "first_seen_365d": "2026-03-23",
        "iocs_365d": 466,
        "iocs_before_window": 63,
        "last_seen_365d": "2026-08-19",
        "window_days": 365
      },
      "id": "tfc-8fe36f50a145",
      "ioc_count": 403,
      "ioc_count_1d": 0,
      "ioc_count_30d": 403,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-19 07:01:08",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2089970907645190365",
          "type": "domain",
          "user": "phishunt_io",
          "value": "ledger-live-login-conect-auth.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-19 07:01:08",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2089970907645190365",
          "type": "url",
          "user": "phishunt_io",
          "value": "http://ledger-live-login-conect-auth.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "welcome-begin-trezo-en.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "webpages-trzor-suite.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "web-us-en-ledger-live-wallet.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "web-trezor-io-start-app.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "web-start-trezor-io-web.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "us-io-tzore-io.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "us-conect-ledger-live-login.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "us--start-en-trazor-io-com-cdn--en.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "ttrezur-en-us.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "trezur-start-base-faqs-io.typedream.app"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-16 21:50:10",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089107474825527555",
          "type": "domain",
          "user": "skocherhan",
          "value": "trezrsite-web-us.typedream.app"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binsiousdt.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binnmzcusdt.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binnmusdt.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binmnxc.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binllusdt.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binccusdc.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binancez5.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binancen4.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binancee2.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://binaccem8.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://biiusd.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-14 13:50:15",
          "tags": [
            "#cryptoscam",
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2088261925574492649",
          "type": "url",
          "user": "skocherhan",
          "value": "http://biiousdt.com"
        }
      ],
      "last_seen": "2026-08-19",
      "member_cluster_ids": [
        "tfc-8fe36f50a145"
      ],
      "name": "Crypto phishing targeting Binance, Ledger, Trezor and Bybit",
      "related": {
        "checked_at": "2026-09-04T06:56:16Z",
        "match_count": 3,
        "matches": [
          {
            "asn": "AS13335",
            "company": "ledger",
            "domain": "ledger-live-download-sso-conect.typedream.app",
            "match": "exact"
          },
          {
            "asn": "AS13335",
            "company": "ledger",
            "domain": "ledger-live-wallet-start-conect-us-en.typedream.app",
            "match": "exact"
          },
          {
            "asn": "AS13335",
            "company": "trezor",
            "domain": "trezor-login-us-auth-start.typedream.app",
            "match": "exact"
          }
        ],
        "source": "phishunt.io"
      },
      "reporters": [
        "phishunt_io",
        "skocherhan"
      ],
      "tags": [
        "#cryptoscam",
        "#phishing"
      ],
      "targeted_brand": "Binance",
      "targeted_country": null,
      "targeted_sector": "financial-services",
      "threat_types": {
        "cryptoscam": 200,
        "phishing": 203
      },
      "ttps": [
        "T1657",
        "T1583.001",
        "T1583.006",
        "T1566.002"
      ],
      "types": {
        "domain": 202,
        "url": 201
      }
    },
    {
      "activity": {
        "2026-08-10": 140
      },
      "anchors": {
        "registered_domains": [
          "damaicn.cc",
          "jcd666.vip",
          "mahuacm.com",
          "pxb70.com",
          "qunaeer.com",
          "yijieguoji.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Six parent domains (jcd666.vip, qunaeer.com, mahuacm.com, pxb70.com, damaicn.cc, yijieguoji.com) each host dozens of subdomains cloning OKX, USDT, JD, and Alibaba platforms alongside gambling and romance-scam fronts. OKX-labeled subdomains (okx.*, okxa through okxe.*) appear across multiple parent domains, linking the clusters to a single Chinese-speaking operator. One reporter flagged all six parent domains on 2026-08-10.",
      "enriched_count": 140,
      "families": {},
      "first_seen": "2026-08-10",
      "history": {
        "by_pattern": [],
        "domains_365d": 6,
        "first_seen_365d": "2026-08-10",
        "iocs_365d": 140,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-10",
        "window_days": 365
      },
      "id": "tfc-9747b61b0a0b",
      "ioc_count": 140,
      "ioc_count_1d": 0,
      "ioc_count_30d": 140,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "zzx.jcd666.vip"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "yun.jcd666.vip"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "you.pxb70.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "yijieguoji.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "uu.mahuacm.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "tt.mahuacm.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "trxu.pxb70.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "trx.jcd666.vip"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "trx.damaicn.cc"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "tongcheng.jcd666.vip"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "tk.pxb70.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "sut.pxb70.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "soft.yijieguoji.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "slot.jcd666.vip"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "serviceapi.damaicn.cc"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "qunaeer.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "ppm.qunaeer.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "pp.qunaeer.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "pp.damaicn.cc"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "oor.yijieguoji.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "okxe.qunaeer.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "okxd.qunaeer.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "okmm.damaicn.cc"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "mxgfr.mahuacm.com"
        },
        {
          "ai": {
            "threat_type": "scam"
          },
          "date": "2026-08-10 21:17:12",
          "tags": [],
          "tweet": "https://x.com/0xb1lal/status/2086924852993073222",
          "type": "domain",
          "user": "0xb1lal",
          "value": "mxg.mahuacm.com"
        }
      ],
      "last_seen": "2026-08-10",
      "member_cluster_ids": [
        "tfc-9747b61b0a0b",
        "tfc-532aa29c68fd",
        "tfc-7bf9aaebb86a",
        "tfc-ebb27e0e9a6f",
        "tfc-8e372e5eb874",
        "tfc-fc6cddfc1519"
      ],
      "name": "Chinese-speaking OKX and USDT fraud network on six domains",
      "reporters": [
        "0xb1lal"
      ],
      "tags": [],
      "targeted_brand": "OKX",
      "targeted_country": null,
      "targeted_sector": "financial-services",
      "threat_types": {
        "scam": 140
      },
      "ttps": [
        "T1657",
        "T1583.001"
      ],
      "types": {
        "domain": 68,
        "url": 72
      }
    },
    {
      "activity": {
        "2026-08-08": 1,
        "2026-08-09": 5,
        "2026-08-11": 10,
        "2026-08-12": 64,
        "2026-08-26": 2,
        "2026-08-30": 2,
        "2026-09-01": 2,
        "2026-09-03": 2
      },
      "anchors": {
        "registered_domains": [
          "account-kakao.dynv6.net",
          "auction.dynu.net",
          "chromeupdate.mydns.vc",
          "datupdatesourcetool.online",
          "dmdoc.dynv6.net",
          "dns.army",
          "dynu.org",
          "dywkdfue.shop",
          "firstdominha.shop",
          "flewzzxsedn.mom",
          "lloizou.dynv6.net",
          "login-accounts.dynu.net",
          "login-accounts.dynv6.net",
          "nldlg.dynv6.net",
          "nstlog.store",
          "ntnmid.dynu.net",
          "ntnmid.dynuddns.com",
          "ntx-store.dynv6.net",
          "oenontuedo.homes",
          "onlygsiend.shop",
          "rhkrgun.dynu.net",
          "si1901.dynv6.net",
          "unikoreamc.dynv6.net",
          "updatesourcetool.online",
          "vnstn.dynv6.net"
        ],
        "tags": [
          "#DPRK",
          "#Kimsuky"
        ],
        "url_path_patterns": []
      },
      "confidence": "high",
      "context": "Kimsuky (DPRK-linked APT) C2 spans dynv6.net, dynu.net, and dns.army DDNS alongside operator-registered .shop, .store, and .online domains such as dywkdfue.shop and nstlog.store. Auth-themed hostnames like kakao-user.login-accounts.dynu.net and update-themed endpoints like datupdatesourcetool.online characterise the activity. A loader (geniex_crav.zip) resolves its true C2 via DNS and XOR decryption - reporters flagged 88 IOCs targeting South Korean victims between 2026-08-04 and 2026-09-03.",
      "enriched_count": 88,
      "families": {
        "Kimsuky": 2
      },
      "first_seen": "2026-08-08",
      "history": {
        "by_pattern": [],
        "domains_365d": 25,
        "first_seen_365d": "2025-10-18",
        "iocs_365d": 1919,
        "iocs_before_window": 1835,
        "last_seen_365d": "2026-09-03",
        "window_days": 365
      },
      "id": "tfc-8405633d4c70",
      "infra": [
        {
          "country": "KR",
          "ip_count": 1,
          "org": "AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED"
        }
      ],
      "ioc_count": 88,
      "ioc_count_1d": 2,
      "ioc_count_30d": 88,
      "ioc_count_7d": 6,
      "iocs": [
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-09-03 18:00:05",
          "tags": [
            "#APT",
            "#C2",
            "#Kimsuky",
            "#malware"
          ],
          "tweet": "https://x.com/phatomcandle/status/2095572552567669109",
          "type": "domain",
          "user": "phatomcandle",
          "value": "login-accounts.dynu.net"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-09-03 18:00:05",
          "tags": [
            "#APT",
            "#C2",
            "#Kimsuky",
            "#malware"
          ],
          "tweet": "https://x.com/phatomcandle/status/2095572552567669109",
          "type": "url",
          "user": "phatomcandle",
          "value": "http://www.login-accounts.dynu.net"
        },
        {
          "ai": {
            "family": "Kimsuky",
            "threat_type": "c2"
          },
          "date": "2026-08-30 18:00:06",
          "tags": [
            "#APT",
            "#C2",
            "#Kimsuky",
            "#malware"
          ],
          "tweet": "https://x.com/phatomcandle/status/2094123007358943281",
          "type": "domain",
          "user": "phatomcandle",
          "value": "k-store.auth-accounts.dynu.org"
        },
        {
          "ai": {
            "family": "Kimsuky",
            "threat_type": "c2"
          },
          "date": "2026-08-30 18:00:06",
          "tags": [
            "#APT",
            "#C2",
            "#Kimsuky",
            "#malware"
          ],
          "tweet": "https://x.com/phatomcandle/status/2094123007358943281",
          "type": "url",
          "user": "phatomcandle",
          "value": "http://k-store.auth-accounts.dynu.org"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "xn--cnms-kjr.dmdoc.dynv6.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "xn--acnms-gzu.dmdoc.dynv6.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "vaml.schet.dns.army"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "user-kakao.login-accounts.dynv6.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "udpate.nstlog.store"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "sunbunbest.dynu.org"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "store.unikoreamc.dynv6.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "store.si1901.dynv6.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "store.metapola.dns.army"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "store.lloizou.dynv6.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "smnoz.dynu.org"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "rhkrgun.dynu.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "ntx-store.dynv6.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "ntnmid.dynuddns.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "ntnmid.dynu.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "domain",
          "user": "skocherhan",
          "value": "nldlg.dynv6.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 18:54:06",
          "tags": [
            "#DPRK",
            "#Kimsuky"
          ],
          "tweet": "https://x.com/skocherhan/status/2087613616451121298",
          "type": "url",
          "user": "skocherhan",
          "value": "http://chromeupdate.mydns.vc"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-11 18:06:05",
          "tags": [
            "#APT",
            "#C2",
            "#DPRK",
            "#Kimsuky",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2087239144615383154",
          "type": "url",
          "user": "skocherhan",
          "value": "http://flewzzxsedn.mom"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-11 18:06:05",
          "tags": [
            "#APT",
            "#C2",
            "#DPRK",
            "#Kimsuky",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2087239144615383154",
          "type": "url",
          "user": "skocherhan",
          "value": "http://firstdominha.shop"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-11 18:06:05",
          "tags": [
            "#APT",
            "#C2",
            "#DPRK",
            "#Kimsuky",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2087239144615383154",
          "type": "url",
          "user": "skocherhan",
          "value": "http://dywkdfue.shop"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-09 11:03:10",
          "tags": [
            "#DPRK"
          ],
          "tweet": "https://x.com/skocherhan/status/2086407939158384883",
          "type": "domain",
          "user": "skocherhan",
          "value": "sam.datupdatesourcetool.online"
        }
      ],
      "last_seen": "2026-09-03",
      "member_cluster_ids": [
        "tfc-8405633d4c70",
        "tfc-d942053a3661"
      ],
      "name": "Kimsuky APT C2 infrastructure on DDNS and custom domains",
      "reporters": [
        "G60930953",
        "byrne_emmy12099",
        "phatomcandle",
        "skocherhan"
      ],
      "tags": [
        "#APT",
        "#C2",
        "#DPRK",
        "#Kimsuky",
        "#malware"
      ],
      "targeted_brand": null,
      "targeted_country": "KR",
      "targeted_sector": null,
      "threat_types": {
        "c2": 18,
        "malware": 6,
        "phishing": 64
      },
      "ttps": [
        "T1568",
        "T1071.001",
        "T1684.001",
        "T1583.001"
      ],
      "types": {
        "domain": 42,
        "ip": 1,
        "sha256": 2,
        "url": 43
      }
    },
    {
      "activity": {
        "2026-08-12": 4,
        "2026-08-17": 72,
        "2026-08-18": 4,
        "2026-08-24": 4
      },
      "anchors": {
        "registered_domains": [
          "03webzoominvite.us",
          "2oomiinvittee.com",
          "2z1alloom2.click",
          "ameliaflick.xyz",
          "candidatezoomcall.im",
          "clararise.xyz",
          "clientmeetingzoomspace.com",
          "d0c-web.org",
          "fonoon.ae",
          "gt.tc",
          "guintter.com.br",
          "hopquatet.net",
          "id3basketball.com",
          "jalallinux.ir",
          "join-01nw8900.click",
          "joinmeetlive.com",
          "khoancatbetong89.vn",
          "ngoilopviet.com",
          "nownownow.help",
          "online-interview-meeting.top",
          "relyaccessed-virtual.info",
          "requisinvitte.xyz",
          "surel.sbs",
          "uespp2.com",
          "us02webzoomus.com",
          "us03zoomwebjoin.com",
          "uss001web.com",
          "web-interviews.live",
          "zoom-meets.us",
          "zoomcallmeeting.im",
          "zoomcandidates.com",
          "zoomlive.us",
          "zoommcall.com",
          "zoommeetingg.click",
          "zoommeets.us",
          "zoomwebinviite.com",
          "zoorn-meet.com"
        ],
        "tags": [],
        "url_path_patterns": [
          "/Windows/download.php",
          "/Windows/invite.php",
          "/images/ZoomInstaller.msi",
          "/images/ZoomInstaller.msiSHAN",
          "/invite.php",
          "/zoom/Windows"
        ]
      },
      "confidence": "high",
      "context": "Multiple fake Zoom domains deliver RMM payloads via shared kit paths including /Windows/invite.php, /images/ZoomInstaller.msi, and /zoom/Windows across 80-plus domains. Payloads observed include ZoomWorkspace.exe, TraceRMM, and Agta Backup RMM signed with an EV certificate. Meeting and interview-themed domains suggest targeting of job seekers.",
      "enriched_count": 84,
      "families": {},
      "first_seen": "2026-08-12",
      "history": {
        "by_pattern": [],
        "domains_365d": 37,
        "first_seen_365d": "2025-09-08",
        "iocs_365d": 221,
        "iocs_before_window": 137,
        "last_seen_365d": "2026-08-24",
        "window_days": 365
      },
      "id": "tfc-9e6eb064d5b2",
      "ioc_count": 84,
      "ioc_count_1d": 0,
      "ioc_count_30d": 84,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 17:23:31",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/patialavii/status/2091939471877181829",
          "type": "url",
          "user": "patialavii",
          "value": "https://invite.fonoon.ae/Windows/download.php"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 17:23:31",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/patialavii/status/2091939471877181829",
          "type": "url",
          "user": "patialavii",
          "value": "https://invite.fonoon.ae"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-18 17:33:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089767634472472992",
          "type": "url",
          "user": "skocherhan",
          "value": "https://03webzoominvite.us/invite.php"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "zoomus.gt.tc"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "zoomlive.us"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "zoom.web-interviews.live"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "zoom.hopquatet.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "zoom.d0c-web.org"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "take.ameliaflick.xyz"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "requisinvitte.xyz"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "painel.guintter.com.br"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "online-interview-meeting.top"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "nownownow.help"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "ngoilopviet.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "khoancatbetong89.vn"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "joinmeetlive.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "join-01nw8900.click"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "invite.jalallinux.ir"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "invite.clararise.xyz"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "domain",
          "user": "skocherhan",
          "value": "id3basketball.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "url",
          "user": "skocherhan",
          "value": "http://clientmeetingzoomspace.com/Windows/invite.php"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "url",
          "user": "skocherhan",
          "value": "http://candidatezoomcall.im/Windows/invite.php"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "url",
          "user": "skocherhan",
          "value": "http://2z1alloom2.click/zoom/Windows/invite.php"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 16:27:04",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089388552882622939",
          "type": "url",
          "user": "skocherhan",
          "value": "http://2oomiinvittee.com/Windows/invite.php"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 17:26:34",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2087591585793855715",
          "type": "url",
          "user": "skocherhan",
          "value": "https://us02webzoomus.com/images/ZoomInstaller.msiSHA256"
        }
      ],
      "last_seen": "2026-08-24",
      "member_cluster_ids": [
        "tfc-9e6eb064d5b2",
        "tfc-24705a7b5018",
        "tfc-86cdfb6c823e"
      ],
      "name": "Fake Zoom installer phishing via typosquat domains",
      "reporters": [
        "patialavii",
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Zoom",
      "targeted_country": null,
      "targeted_sector": "technology",
      "threat_types": {
        "phishing": 84
      },
      "ttps": [
        "T1566.002",
        "T1684.001",
        "T1608.001",
        "T1583.001"
      ],
      "types": {
        "domain": 39,
        "url": 45
      }
    },
    {
      "activity": {
        "2026-08-09": 68
      },
      "anchors": {
        "registered_domains": [
          "hemenalnsanra.net",
          "hemenalsnlsa.net",
          "hemenhizlisnoclsm.net",
          "hemeniaslmenasn.net",
          "hemeniasnltamsan.net",
          "hemenislemana.net",
          "hemenislemhkatsa.net",
          "hemenislemn-sonuc.net",
          "hemenislemnal.net",
          "hemenislemnktans.net",
          "hemenislemnktasi.net",
          "hemenislemnktasna.net",
          "hemenislemnktsi.net",
          "hemenislemnoktasnin.net",
          "hemenislmkntokas.net",
          "hemenismlantans.net",
          "hemenismlnktasnati.net",
          "hemenlanlsatnas.net",
          "hemensielmnokta-islnakt.net",
          "hmnislemnktans.net",
          "hmnislemnktbas.net",
          "hmnislmbkntans.net",
          "hmnislmnkns.net",
          "hmnislmnknts.net",
          "hmnislmnktnsi.net",
          "hmnislmnkts.net",
          "hmnislmnktsan.net",
          "hmnismlntans.net",
          "sonuc-baksrnaltas.net",
          "sonuc-islemkantas.net",
          "sonuc-islemonktans.net",
          "sonuci-nnsatknasa.net",
          "sonucinlnta-nhemena.net",
          "sonucislmnktans.net"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Multiple waves of Turkish-language .net domains impersonate Turkey's MHRS central physician appointment portal. Domain prefixes include hemen-, hmnis-, islem-, and sonuc- combined with appointment-system word fragments. One reporter flagged 200-plus fake domains targeting Turkish citizens seeking medical appointments on 2026-08-09.",
      "enriched_count": 68,
      "families": {},
      "first_seen": "2026-08-09",
      "history": {
        "by_pattern": [
          {
            "domains_365d": 9,
            "first_seen_365d": "2026-08-09",
            "regex": "^hmnis[a-z]{6,9}\\.net$"
          },
          {
            "domains_365d": 6,
            "first_seen_365d": "2026-08-09",
            "regex": "^sonuc[a-z0-9-]{10,14}\\.net$"
          }
        ],
        "domains_365d": 34,
        "first_seen_365d": "2026-08-09",
        "iocs_365d": 68,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-09",
        "window_days": 365
      },
      "id": "tfc-6d1d0b38e121",
      "ioc_count": 68,
      "ioc_count_1d": 0,
      "ioc_count_30d": 68,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "domain",
          "user": "skocherhan",
          "value": "sonuci-nnsatknasa.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "domain",
          "user": "skocherhan",
          "value": "sonuc-islemkantas.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "domain",
          "user": "skocherhan",
          "value": "sonuc-baksrnaltas.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hmnislmnkts.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hmnislmnktnsi.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hmnislmnknts.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hmnislmnkns.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hmnislmbkntans.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hmnislemnktbas.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hmnislemnktans.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenislemnoktasnin.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenislemnktsi.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenislemnktasi.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenislemnktans.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenislemnal.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenislemhkatsa.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenislemana.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemeniasnltamsan.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemeniaslmenasn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenhizlisnoclsm.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenalsnlsa.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenalnsanra.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 22:41:50",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086583761274012009",
          "type": "domain",
          "user": "skocherhan",
          "value": "sonuc-islemonktans.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 22:41:50",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086583761274012009",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenislemnktasna.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 22:41:50",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086583761274012009",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hemenislemn-sonuc.net"
        }
      ],
      "last_seen": "2026-08-09",
      "member_cluster_ids": [
        "tfc-6d1d0b38e121",
        "tfc-267a534dad7f",
        "tfc-d6206dd76567"
      ],
      "name": "MHRS appointment phishing on hemen-prefixed .net domains",
      "patterns": [
        {
          "domain_count": 9,
          "domains_elsewhere_30d": 0,
          "examples": [
            "hmnislemnktans.net",
            "hmnislemnktbas.net",
            "hmnislmbkntans.net"
          ],
          "first_seen": "2026-08-09",
          "ioc_count": 18,
          "last_seen": "2026-08-09",
          "regex": "^hmnis[a-z]{6,9}\\.net$"
        },
        {
          "domain_count": 6,
          "domains_elsewhere_30d": 0,
          "examples": [
            "sonuc-baksrnaltas.net",
            "sonuc-islemkantas.net",
            "sonuc-islemonktans.net"
          ],
          "first_seen": "2026-08-09",
          "ioc_count": 12,
          "last_seen": "2026-08-09",
          "regex": "^sonuc[a-z0-9-]{10,14}\\.net$"
        }
      ],
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "MHRS",
      "targeted_country": "TR",
      "targeted_sector": "healthcare",
      "threat_types": {
        "phishing": 68
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 34,
        "url": 34
      }
    },
    {
      "activity": {
        "2026-08-17": 60
      },
      "anchors": {
        "registered_domains": [
          "mybluehost.me"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Random three-letter paired subdomains under mybluehost.me abuse compromised hosting accounts to distribute Google-themed phishing lures at scale. The uniform two-to-three-level structure (e.g. alz.rgg.mybluehost.me) suggests automated provisioning by a single operator. One reporter flagged 60 IOCs on 2026-08-17.",
      "enriched_count": 60,
      "families": {},
      "first_seen": "2026-08-17",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2025-10-13",
        "iocs_365d": 94,
        "iocs_before_window": 34,
        "last_seen_365d": "2026-08-17",
        "window_days": 365
      },
      "id": "tfc-4dd69896e7af",
      "ioc_count": 60,
      "ioc_count_1d": 0,
      "ioc_count_30d": 60,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "zir.hlf.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "yxm.smo.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "ypj.wie.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "xwf.ynd.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "xcv.chi.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "xbc.tvn.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "wkd.rgg.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "uyu.ker.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "uui.lgj.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "qzc.jiv.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "ppy.dls.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "pjn.kjz.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "pet.opx.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "ozi.xtn.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "ofu.ker.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "jbi.aey.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://zir.hlf.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://yxm.smo.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://ypj.wie.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://xwf.ynd.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://xcv.chi.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://xbc.tvn.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://wkd.rgg.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://uyu.ker.mybluehost.me"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://uui.lgj.mybluehost.me"
        }
      ],
      "last_seen": "2026-08-17",
      "member_cluster_ids": [
        "tfc-4dd69896e7af"
      ],
      "name": "Google phishing on compromised subdomains at mybluehost.me",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Google",
      "targeted_country": null,
      "targeted_sector": "technology",
      "threat_types": {
        "phishing": 60
      },
      "ttps": [
        "T1583.006",
        "T1566.002"
      ],
      "types": {
        "domain": 30,
        "url": 30
      }
    },
    {
      "activity": {
        "2026-08-09": 5,
        "2026-08-15": 20,
        "2026-08-16": 28,
        "2026-08-17": 4,
        "2026-09-03": 2
      },
      "anchors": {
        "registered_domains": [
          "20billionn.ddns.net",
          "aileen75.ddns.net",
          "billionsonlinee.ddns.net",
          "dexscreenertrade.com",
          "donta.duckdns.org",
          "fiancepsi1.duckdns.org",
          "japanaction059.duckdns.org",
          "purelog.duckdns.org",
          "remcooox.duckdns.org",
          "sermver.duckdns.org",
          "sucessful.duckdns.org",
          "superdomain8765.ddns.net",
          "ydns.eu"
        ],
        "tags": [
          "#Remcos",
          "#Xworm"
        ],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Open-directory servers on duckdns.org, ddns.net, and ydns.eu host Remcos, Xworm, and QuasarRAT payloads alongside a crypto trading lure site (dexscreenertrade.com), suggesting social engineering via a fake trading platform. Browsable directories expose staged files across DDNS domains. Two reporters flagged 59 IOCs between 2026-08-09 and 2026-09-03.",
      "enriched_count": 59,
      "families": {
        "QuasarRAT": 20,
        "Remcos": 9,
        "XWorm": 30
      },
      "first_seen": "2026-08-09",
      "history": {
        "by_pattern": [],
        "domains_365d": 13,
        "first_seen_365d": "2025-09-16",
        "iocs_365d": 136,
        "iocs_before_window": 82,
        "last_seen_365d": "2026-09-03",
        "window_days": 365
      },
      "id": "tfc-4b6108815b6f",
      "infra": [
        {
          "country": "CO",
          "ip_count": 1,
          "org": "AS3816 COLOMBIA TELECOMUNICACIONES S.A. ESP BIC"
        }
      ],
      "ioc_count": 59,
      "ioc_count_1d": 2,
      "ioc_count_30d": 59,
      "ioc_count_7d": 2,
      "iocs": [
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-09-03 20:52:10",
          "tags": [
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2095615861738361001",
          "type": "domain",
          "user": "skocherhan",
          "value": "worksodsirius.ydns.eu"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-09-03 20:52:10",
          "tags": [
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2095615861738361001",
          "type": "url",
          "user": "skocherhan",
          "value": "http://worksodsirius.ydns.eu"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 16:01:32",
          "tags": [
            "#Remcos"
          ],
          "tweet": "https://x.com/skocherhan/status/2089382126412038598",
          "type": "domain",
          "user": "skocherhan",
          "value": "sermver.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 16:01:32",
          "tags": [
            "#Remcos"
          ],
          "tweet": "https://x.com/skocherhan/status/2089382126412038598",
          "type": "url",
          "user": "skocherhan",
          "value": "http://sermver.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 16:01:32",
          "tags": [
            "#Remcos"
          ],
          "tweet": "https://x.com/skocherhan/status/2089382126412038598",
          "type": "url",
          "user": "skocherhan",
          "value": "http://donta.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 16:01:32",
          "tags": [
            "#Remcos"
          ],
          "tweet": "https://x.com/skocherhan/status/2089382126412038598",
          "type": "domain",
          "user": "skocherhan",
          "value": "donta.duckdns.org"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "domain",
          "user": "skocherhan",
          "value": "superdomain8765.ddns.net"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "domain",
          "user": "skocherhan",
          "value": "sucessful.duckdns.org"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "domain",
          "user": "skocherhan",
          "value": "stachi.ydns.eu"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "domain",
          "user": "skocherhan",
          "value": "remcooox.duckdns.org"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "url",
          "user": "skocherhan",
          "value": "http://superdomain8765.ddns.net:62699"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "url",
          "user": "skocherhan",
          "value": "http://stachi.ydns.eu:62699"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "url",
          "user": "skocherhan",
          "value": "http://gu-grant-gz.ydns.eu:62699"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "url",
          "user": "skocherhan",
          "value": "http://dexscreenertrade.com"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "url",
          "user": "skocherhan",
          "value": "http://billionsonlinee.ddns.net:62699"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 18:10:04",
          "tags": [
            "#Remcos",
            "#Xworm",
            "#opendir"
          ],
          "tweet": "https://x.com/skocherhan/status/2089052085459296766",
          "type": "domain",
          "user": "skocherhan",
          "value": "gu-grant-gz.ydns.eu"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 17:59:41",
          "tags": [
            "#Remcos",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089049471472591346",
          "type": "domain",
          "user": "skocherhan",
          "value": "japan-act2.ydns.eu"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 17:59:41",
          "tags": [
            "#Remcos",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089049471472591346",
          "type": "domain",
          "user": "skocherhan",
          "value": "japan-act.ydns.eu"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 17:59:41",
          "tags": [
            "#Remcos",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089049471472591346",
          "type": "url",
          "user": "skocherhan",
          "value": "http://japan-act2.ydns.eu"
        },
        {
          "ai": {
            "family": "XWorm",
            "threat_type": "c2"
          },
          "date": "2026-08-16 17:59:41",
          "tags": [
            "#Remcos",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089049471472591346",
          "type": "url",
          "user": "skocherhan",
          "value": "http://japan-act.ydns.eu"
        },
        {
          "ai": {
            "family": "QuasarRAT",
            "threat_type": "c2"
          },
          "date": "2026-08-15 17:42:15",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088682699129024911",
          "type": "domain",
          "user": "skocherhan",
          "value": "wirroflobsny.ydns.eu"
        },
        {
          "ai": {
            "family": "QuasarRAT",
            "threat_type": "c2"
          },
          "date": "2026-08-15 17:42:15",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088682699129024911",
          "type": "domain",
          "user": "skocherhan",
          "value": "vinmporflowgroun.ydns.eu"
        },
        {
          "ai": {
            "family": "QuasarRAT",
            "threat_type": "c2"
          },
          "date": "2026-08-15 17:42:15",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088682699129024911",
          "type": "domain",
          "user": "skocherhan",
          "value": "resourcesmxuy.ydns.eu"
        },
        {
          "ai": {
            "family": "Remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-09 19:59:11",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2086542830395429325",
          "type": "sha256",
          "user": "Malwarehunterr",
          "value": "8c78a55c8bf545e0d21b8757eaa0b709b4af47b13d34a38df81045e67026bd96"
        },
        {
          "ai": {
            "family": "Remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-09 19:59:11",
          "net": {
            "country": "CO",
            "org": "AS3816 COLOMBIA TELECOMUNICACIONES S.A. ESP BIC"
          },
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2086542830395429325",
          "type": "ip",
          "user": "Malwarehunterr",
          "value": "181.237.42.61"
        }
      ],
      "last_seen": "2026-09-03",
      "member_cluster_ids": [
        "tfc-4b6108815b6f"
      ],
      "name": "Remcos and Xworm open-directory staging on DDNS providers",
      "reporters": [
        "Malwarehunterr",
        "skocherhan"
      ],
      "tags": [
        "#Remcos",
        "#Xworm",
        "#malware",
        "#opendir"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "c2": 54,
        "malware": 5
      },
      "ttps": [
        "T1588.001",
        "T1568",
        "T1608.001",
        "T1071.001"
      ],
      "types": {
        "domain": 27,
        "ip": 1,
        "md5": 1,
        "sha256": 3,
        "url": 27
      }
    },
    {
      "activity": {
        "2026-08-05": 2,
        "2026-08-10": 4,
        "2026-08-18": 2,
        "2026-08-19": 1,
        "2026-08-20": 13,
        "2026-08-24": 17,
        "2026-08-25": 16
      },
      "anchors": {
        "families": [
          "valleyrat"
        ],
        "registered_domains": [],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "ValleyRAT C2 infrastructure bucket attributed via local enrichment, covering IPs, MD5 hashes, and SHA256 hashes with no registered domains. C2 IPs include 121.127.253.206 on CTG Server Limited (HK) and 156.251.16.29 used for PNG staging. Grouping is based on malware family attribution rather than shared domain or URL patterns. Four reporters flagged indicators from 2026-08-04 to 2026-08-25.",
      "enriched_count": 55,
      "families": {
        "ValleyRAT": 55
      },
      "first_seen": "2026-08-05",
      "id": "tfc-b11700d6b3c1",
      "infra": [
        {
          "country": "HK",
          "ip_count": 3,
          "org": "AS152194 CTG Server Limited"
        },
        {
          "country": "US",
          "ip_count": 2,
          "org": "AS140869 Turing Group Limited"
        },
        {
          "country": "CN",
          "ip_count": 1,
          "org": "AS136188 NINGBO, ZHEJIANG Province, P.R.China."
        },
        {
          "country": "HK",
          "ip_count": 1,
          "org": "AS45102 Alibaba (US) Technology Co., Ltd."
        },
        {
          "country": "HK",
          "ip_count": 1,
          "org": "AS54801 Zillion Network Inc."
        },
        {
          "country": "HK",
          "ip_count": 1,
          "org": "AS979 NetLab Global"
        }
      ],
      "ioc_count": 55,
      "ioc_count_1d": 0,
      "ioc_count_30d": 55,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "c2"
          },
          "date": "2026-08-25 09:56:20",
          "tags": [],
          "tweet": "https://x.com/bomccss/status/2092189324901331195",
          "type": "sha256",
          "user": "bomccss",
          "value": "320763f4ac63a15f2a9b690c1d7adc753c3d8665b1371578f80a25417673ec95"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 09:40:49",
          "tags": [],
          "tweet": "https://x.com/bomccss/status/2092185420247482704",
          "type": "sha256",
          "user": "bomccss",
          "value": "a8f5d9a933549666b6e5070efdde08bed5b37bc492d76ed2955ce01cead662f4"
        },
        {
          "ai": {
            "family": "ValleyRat",
            "threat_type": "c2"
          },
          "date": "2026-08-25 08:21:01",
          "net": {
            "country": "HK",
            "org": "AS152194 CTG Server Limited"
          },
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092165335088783857",
          "type": "ip",
          "user": "tdatwja",
          "value": "202.146.222.95"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:25:06",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092151266436911275",
          "type": "sha256",
          "user": "tdatwja",
          "value": "da33a95b2ed28e2c50da002584eb81e4e94fe4a55e98945146842ed9e23be066"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:25:06",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092151266436911275",
          "type": "md5",
          "user": "tdatwja",
          "value": "bb7af796c8cf01e4901d7a3aba2eb4af"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:25:06",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092151266436911275",
          "type": "md5",
          "user": "tdatwja",
          "value": "5729ba4e8dfff2793e84122402cfb1d0"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:25:06",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092151266436911275",
          "type": "sha256",
          "user": "tdatwja",
          "value": "05cce219ba84d0e650fb310b42a1734c86fe8a51b0cee199c645fb9e1c59f5d0"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:14:29",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092148593406959833",
          "type": "md5",
          "user": "tdatwja",
          "value": "e3c817f7fe44cc870ecdbcbc3ea36132"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:14:29",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092148593406959833",
          "type": "sha256",
          "user": "tdatwja",
          "value": "d769fafa2b3232de9fa7153212ba287f68e745257f1c00fafb511e7a02de7adf"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:14:29",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092148593406959833",
          "type": "md5",
          "user": "tdatwja",
          "value": "bf38660a9125935658cfa3e53fdc7d65"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:14:29",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092148591091712079",
          "type": "md5",
          "user": "tdatwja",
          "value": "bdb4eb8ec9e39825f0fd90048b36a89d"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:14:29",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092148593406959833",
          "type": "sha256",
          "user": "tdatwja",
          "value": "60c06e0fa4449314da3a0a87c1a9d9577df99226f943637e06f61188e5862efa"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:14:29",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092148591091712079",
          "type": "sha256",
          "user": "tdatwja",
          "value": "5d8d20ab8008d5e8cd6ff7b44273fc4a13d30e97d1c7b295aa0786da7ac1f9e3"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:14:29",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092148591091712079",
          "type": "md5",
          "user": "tdatwja",
          "value": "4594075322ac0c9bd08828f8064aa576"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-25 07:14:29",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092148591091712079",
          "type": "sha256",
          "user": "tdatwja",
          "value": "04c9eae9f19a63e4a84da108fe6b768ab6e558c89126dbb6c35a0c383739a81f"
        },
        {
          "ai": {
            "family": "ValleyRat",
            "threat_type": "c2"
          },
          "date": "2026-08-25 07:14:28",
          "net": {
            "country": "SG",
            "org": "AS152194 CTG Server Limited"
          },
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2092148588315119958",
          "type": "ip",
          "user": "tdatwja",
          "value": "202.61.140.222"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-24 09:40:48",
          "tags": [],
          "tweet": "https://x.com/bomccss/status/2091823025868153205",
          "type": "sha256",
          "user": "bomccss",
          "value": "d01d4a086d19d7be96383aeea7538dfbf364510354d997645e6f8ec11454c50b"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-24 09:40:00",
          "tags": [],
          "tweet": "https://x.com/bomccss/status/2091822824076021954",
          "type": "sha256",
          "user": "bomccss",
          "value": "75a3ae5489d181f3b219c0d1d79ec60046f19a0e5274f30f604020ea4a1fd0a6"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-24 07:38:22",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2091792215261757850",
          "type": "sha256",
          "user": "tdatwja",
          "value": "7441c8aef0fc20a5d4feb31c7167df6bc63c64767528802b1377591d90d24282"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-24 07:31:35",
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2091790507085373910",
          "type": "sha256",
          "user": "tdatwja",
          "value": "facf78d474b66ed821288db41fa6ad8a7b6f30650eb12127cb3e9a3cc6146116"
        },
        {
          "ai": {
            "family": "ValleyRAT",
            "threat_type": "c2"
          },
          "date": "2026-08-24 07:31:34",
          "net": {
            "country": "US",
            "org": "AS140869 Turing Group Limited"
          },
          "tags": [],
          "tweet": "https://x.com/tdatwja/status/2091790504250028470",
          "type": "ip",
          "user": "tdatwja",
          "value": "170.62.130.47"
        },
        {
          "ai": {
            "family": "ValleyRat",
            "threat_type": "c2"
          },
          "date": "2026-08-24 05:39:48",
          "net": {
            "country": "CN",
            "org": "AS136188 NINGBO, ZHEJIANG Province, P.R.China."
          },
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2091762376613802195",
          "type": "ip",
          "user": "skocherhan",
          "value": "110.42.106.225"
        },
        {
          "ai": {
            "family": "ValleyRat",
            "threat_type": "c2"
          },
          "date": "2026-08-24 03:17:54",
          "net": {
            "country": "HK",
            "org": "AS45102 Alibaba (US) Technology Co., Ltd."
          },
          "tags": [
            "#C2"
          ],
          "tweet": "https://x.com/skocherhan/status/2091726665713893539",
          "type": "ip",
          "user": "skocherhan",
          "value": "47.243.155.133"
        },
        {
          "ai": {
            "family": "ValleyRat",
            "threat_type": "c2"
          },
          "date": "2026-08-24 03:03:06",
          "net": {
            "country": "HK",
            "org": "AS152194 CTG Server Limited"
          },
          "tags": [],
          "tweet": "https://x.com/bomccss/status/2091722942363455705",
          "type": "ip",
          "user": "bomccss",
          "value": "202.146.222.95"
        },
        {
          "ai": {
            "family": "ValleyRat",
            "threat_type": "c2"
          },
          "date": "2026-08-24 03:02:20",
          "net": {
            "country": "SG",
            "org": "AS152194 CTG Server Limited"
          },
          "tags": [],
          "tweet": "https://x.com/bomccss/status/2091722749144424639",
          "type": "ip",
          "user": "bomccss",
          "value": "202.61.140.222"
        }
      ],
      "last_seen": "2026-08-25",
      "member_cluster_ids": [
        "tfc-b11700d6b3c1"
      ],
      "name": "ValleyRAT C2 infrastructure - IPs and hashes",
      "reporters": [
        "bomccss",
        "skocherhan",
        "tdatwja"
      ],
      "tags": [
        "#C2"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "c2": 16,
        "malware": 39
      },
      "ttps": [
        "T1071.001"
      ],
      "types": {
        "ip": 15,
        "md5": 14,
        "sha256": 26
      }
    },
    {
      "activity": {
        "2026-08-09": 50,
        "2026-08-19": 2
      },
      "anchors": {
        "registered_domains": [
          "b-cdn.net"
        ],
        "tags": [],
        "url_path_patterns": [
          "/folders/index"
        ]
      },
      "confidence": "medium",
      "context": "UUID-pattern subdomains under b-cdn.net (Bunny CDN) serve phishing pages at a /folders/index path. Consistent UUID-style labels across 26 domains suggest automated provisioning by a single operator abusing the CDN service. Two reporters flagged 52 IOCs between 2026-08-09 and 2026-08-19.",
      "enriched_count": 52,
      "families": {},
      "first_seen": "2026-08-09",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2025-11-25",
        "iocs_365d": 68,
        "iocs_before_window": 16,
        "last_seen_365d": "2026-08-19",
        "window_days": 365
      },
      "id": "tfc-259d7f5fa570",
      "ioc_count": 52,
      "ioc_count_1d": 0,
      "ioc_count_30d": 52,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-19 05:17:49",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Kb4Threatlabs/status/2089944905661771919",
          "type": "url",
          "user": "Kb4Threatlabs",
          "value": "http://folders-them9782-safe-empty-files-9w478262.b-cdn.net/folders/index"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-19 05:17:49",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Kb4Threatlabs/status/2089944905661771919",
          "type": "domain",
          "user": "Kb4Threatlabs",
          "value": "folders-them9782-safe-empty-files-9w478262.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://f13682ae-e.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://ecd31356-d.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://eb289d5c-5.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://e74678f4-f.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://d871d5f2-6.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://d28c4902-a.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://ce2dcdb7-3.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://b5080e3d-6.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://a7f3c362-9.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://a6cfe784-e.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://9fde8fe7-9.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://838466ca-e.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://7d3e329f-5.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://7979b423-2.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://7640450a-b.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://74ed77fc-8.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://6dedb6bd-3.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://62ce61f5-9.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://604da060-7.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://485e02db-a.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://35c195e4-7.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://2a0aabb0-e.b-cdn.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 23:18:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086592966127177859",
          "type": "url",
          "user": "skocherhan",
          "value": "http://29c02a5b-e.b-cdn.net"
        }
      ],
      "last_seen": "2026-08-19",
      "member_cluster_ids": [
        "tfc-259d7f5fa570"
      ],
      "name": "Phishing pages on Bunny CDN pull-zone subdomains",
      "reporters": [
        "Kb4Threatlabs",
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "phishing": 52
      },
      "ttps": [
        "T1583.006",
        "T1566.002"
      ],
      "types": {
        "domain": 26,
        "url": 26
      }
    },
    {
      "activity": {
        "2026-08-10": 2,
        "2026-08-13": 2,
        "2026-08-15": 4,
        "2026-08-16": 2,
        "2026-08-17": 4,
        "2026-08-18": 4,
        "2026-08-19": 2,
        "2026-08-20": 2,
        "2026-08-21": 4,
        "2026-08-22": 8,
        "2026-08-24": 2,
        "2026-08-26": 6,
        "2026-08-28": 4,
        "2026-08-31": 2
      },
      "anchors": {
        "registered_domains": [
          "aspen-92.com",
          "aspencore18.com",
          "canvas-35.com",
          "chisel-84.com",
          "claude-macos-app.com",
          "cli-guides.com",
          "cli-stack.com",
          "codex-notes.com",
          "leaf68.com",
          "leap39.com",
          "neststudio16.com",
          "opalblueprint10.com",
          "parentpreneurx.com",
          "perchframe15.com",
          "pine63.com",
          "quest-22.com",
          "quill-flint.com",
          "raster-80.com",
          "shoretapestry.com",
          "stride25.com",
          "trekmesh15.com"
        ],
        "tags": [
          "#ClickFix",
          "#malvertising"
        ],
        "url_path_patterns": [
          "/curl/NtgqsiNufvy"
        ]
      },
      "confidence": "medium",
      "context": "ClickFix lures on domains including trekmesh15.com, aspen-92.com, and claude-macos-app.com redirect malvertising victims to MacSync Stealer payloads delivered via /curl/ path variants. Domains mimic software brands - Claude AI, Homebrew, CLI tools - and generic business names across multiple TLDs. Four researchers reported 48 IOCs between 2026-08-10 and 2026-08-31.",
      "enriched_count": 48,
      "families": {
        "MacSync Stealer": 4
      },
      "first_seen": "2026-08-10",
      "history": {
        "by_pattern": [],
        "domains_365d": 21,
        "first_seen_365d": "2026-08-10",
        "iocs_365d": 48,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-31",
        "window_days": 365
      },
      "id": "tfc-fb11464dfed7",
      "ioc_count": 48,
      "ioc_count_1d": 0,
      "ioc_count_30d": 48,
      "ioc_count_7d": 6,
      "iocs": [
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-31 11:57:12",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2094394067732033779",
          "type": "domain",
          "user": "masaomi346",
          "value": "pine63.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-28 09:24:21",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2093268438403919987",
          "type": "domain",
          "user": "masaomi346",
          "value": "stride25.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-28 09:24:21",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2093268438403919987",
          "type": "url",
          "user": "masaomi346",
          "value": "https://cli-stack.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-26 12:35:47",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2092591838775705648",
          "type": "domain",
          "user": "masaomi346",
          "value": "opalblueprint10.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-26 12:35:47",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2092591838775705648",
          "type": "url",
          "user": "masaomi346",
          "value": "https://claude-macos-app.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-26 12:20:51",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2092588079609696498",
          "type": "domain",
          "user": "masaomi346",
          "value": "leaf68.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-24 07:42:46",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2091793322151194975",
          "type": "domain",
          "user": "masaomi346",
          "value": "raster-80.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-22 09:52:05",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2091101089705971718",
          "type": "url",
          "user": "masaomi346",
          "value": "http://canvas-35.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-22 09:47:08",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/TheM3gatr0n/status/2091099845285330991",
          "type": "domain",
          "user": "TheM3gatr0n",
          "value": "quest-22.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-22 09:47:08",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/TheM3gatr0n/status/2091099845285330991",
          "type": "url",
          "user": "TheM3gatr0n",
          "value": "https://quest-22.com/curl/44tgqsi3ufvy/wv242quj7idscf3dze4.dat"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-22 09:41:46",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2091098495105314893",
          "type": "domain",
          "user": "masaomi346",
          "value": "perchframe15.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-22 09:41:46",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2091098495105314893",
          "type": "url",
          "user": "masaomi346",
          "value": "https://cli-guides.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-21 12:25:15",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2090777247179489573",
          "type": "domain",
          "user": "masaomi346",
          "value": "quill-flint.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-21 12:25:15",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2090777247179489573",
          "type": "url",
          "user": "masaomi346",
          "value": "https://codex-notes.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-20 00:51:55",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2090240377358102881",
          "type": "domain",
          "user": "masaomi346",
          "value": "leap39.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-19 19:58:50",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2090166619435683931",
          "type": "domain",
          "user": "skocherhan",
          "value": "quest-22.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-19 19:58:50",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2090166619435683931",
          "type": "url",
          "user": "skocherhan",
          "value": "http://quest-22.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-18 12:36:09",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2089692827701973179",
          "type": "domain",
          "user": "masaomi346",
          "value": "parentpreneurx.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-18 12:36:09",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2089692827701973179",
          "type": "domain",
          "user": "masaomi346",
          "value": "neststudio16.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-17 10:00:29",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2089291267436077496",
          "type": "domain",
          "user": "masaomi346",
          "value": "shoretapestry.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-16 12:43:32",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2088969908919091619",
          "type": "url",
          "user": "masaomi346",
          "value": "http://chisel-84.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-15 07:29:06",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2088528394661310925",
          "type": "url",
          "user": "masaomi346",
          "value": "http://aspencore18.com"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-15 07:18:30",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2088525725590859882",
          "type": "url",
          "user": "masaomi346",
          "value": "http://aspen-92.com"
        },
        {
          "ai": {
            "family": "MacSync Stealer",
            "threat_type": "malware"
          },
          "date": "2026-08-13 03:15:41",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2087739841060696382",
          "type": "domain",
          "user": "masaomi346",
          "value": "trekmesh15.com"
        },
        {
          "ai": {
            "family": "MacSync Stealer",
            "threat_type": "malware"
          },
          "date": "2026-08-13 03:15:41",
          "tags": [
            "#infostealer",
            "#malvertising",
            "#malware"
          ],
          "tweet": "https://x.com/masaomi346/status/2087739841060696382",
          "type": "url",
          "user": "masaomi346",
          "value": "http://trekmesh15.com"
        }
      ],
      "last_seen": "2026-08-31",
      "member_cluster_ids": [
        "tfc-fb11464dfed7"
      ],
      "name": "ClickFix malvertising with infostealer via /curl/ paths",
      "reporters": [
        "HusseiN98D",
        "TheM3gatr0n",
        "masaomi346",
        "skocherhan"
      ],
      "tags": [
        "#ClickFix",
        "#infostealer",
        "#malvertising",
        "#malware"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "malware": 48
      },
      "ttps": [
        "T1204.004",
        "T1583.008",
        "T1583.001",
        "T1608.001"
      ],
      "types": {
        "domain": 24,
        "url": 24
      }
    },
    {
      "activity": {
        "2026-08-17": 38
      },
      "anchors": {
        "registered_domains": [
          "posmasters.lk"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Dozens of subdomains on posmasters.lk, a compromised domain, host Google-branded phishing pages with labels ranging from business names to project identifiers, suggesting automated provisioning on a hijacked site. The pattern mirrors a concurrent campaign abusing mybluehost.me for the same Google lure type. One reporter flagged 38 IOCs on 2026-08-17.",
      "enriched_count": 38,
      "families": {},
      "first_seen": "2026-08-17",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-17",
        "iocs_365d": 38,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-17",
        "window_days": 365
      },
      "id": "tfc-daa2fe3e2667",
      "ioc_count": 38,
      "ioc_count_1d": 0,
      "ioc_count_30d": 38,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "titanium-art.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "thakshila-mobile.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "techview.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "snc.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "projectp.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "paintshop.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "oneelia.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "nmkr.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "medkin.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "laundry.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "domain",
          "user": "skocherhan",
          "value": "jfcg.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://titanium-art.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://thakshila-mobile.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://techview.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://snc.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://projectp.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://paintshop.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://oneelia.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://nmkr.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://medkin.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://laundry.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://jfcg.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://henz.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://farhan.posmasters.lk"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 21:14:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089460918170366153",
          "type": "url",
          "user": "skocherhan",
          "value": "http://esrpos.posmasters.lk"
        }
      ],
      "last_seen": "2026-08-17",
      "member_cluster_ids": [
        "tfc-daa2fe3e2667"
      ],
      "name": "Google phishing on compromised subdomains at posmasters.lk",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Google",
      "targeted_country": null,
      "targeted_sector": "technology",
      "threat_types": {
        "phishing": 38
      },
      "ttps": [
        "T1566.002"
      ],
      "types": {
        "domain": 19,
        "url": 19
      }
    },
    {
      "activity": {
        "2026-08-05": 1,
        "2026-08-14": 10,
        "2026-08-17": 21
      },
      "anchors": {
        "registered_domains": [
          "0306sendrat.duckdns.org",
          "08yvh4.com",
          "0906envdcrat.duckdns.org",
          "100blackmenofsanantonio.org",
          "andresherrerapi66.gleeze.com",
          "app-bitmoon.fun",
          "connect-bitmoon.fun",
          "github.com",
          "portal-bitmoon.fun",
          "qq8875.online",
          "rewards-bitmoon.fun",
          "sharjahaquarium.com",
          "trade-bitmoon.fun",
          "verify-bitmoon.fun"
        ],
        "tags": [
          "#AsyncRAT",
          "#Dcrat",
          "#Xworm"
        ],
        "url_path_patterns": [
          "/jhfgdafsdgsfhdgjfhk"
        ]
      },
      "confidence": "medium",
      "context": "DcRat, AsyncRAT, and XWorm C2 infrastructure spans bitmoon-themed domains (app-bitmoon.fun, trade-bitmoon.fun, verify-bitmoon.fun), a gleeze.com subdomain, DuckDNS nodes, and a GitHub repository. The bitmoon cluster suggests a fake crypto platform used as a social-engineering lure. Enrichment attributes 31 DcRat and 3 AsyncRAT samples to this infrastructure.",
      "enriched_count": 32,
      "families": {
        "AsyncRAT": 1,
        "dcrat": 31
      },
      "first_seen": "2026-08-05",
      "history": {
        "by_pattern": [],
        "domains_365d": 14,
        "first_seen_365d": "2025-09-08",
        "iocs_365d": 196,
        "iocs_before_window": 149,
        "last_seen_365d": "2026-08-24",
        "window_days": 365
      },
      "id": "tfc-5d3456bc193c",
      "infra": [
        {
          "country": "DE",
          "ip_count": 1,
          "org": "AS202412 Omegatech LTD"
        },
        {
          "country": "NL",
          "ip_count": 1,
          "org": "AS212477 RoyaleHosting BV"
        }
      ],
      "ioc_count": 32,
      "ioc_count_1d": 0,
      "ioc_count_30d": 32,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "domain",
          "user": "skocherhan",
          "value": "verify-bitmoon.fun"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "domain",
          "user": "skocherhan",
          "value": "trade-bitmoon.fun"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "domain",
          "user": "skocherhan",
          "value": "sharjahaquarium.com"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "domain",
          "user": "skocherhan",
          "value": "rewards-bitmoon.fun"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "domain",
          "user": "skocherhan",
          "value": "portal-bitmoon.fun"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "url",
          "user": "skocherhan",
          "value": "http://portal-bitmoon.fun"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "url",
          "user": "skocherhan",
          "value": "http://github.com/jhfgdafsdgsfhdgjfhk"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "url",
          "user": "skocherhan",
          "value": "http://connect-bitmoon.fun"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "url",
          "user": "skocherhan",
          "value": "http://app-bitmoon.fun"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "url",
          "user": "skocherhan",
          "value": "http://andresherrerapi66.gleeze.com"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "url",
          "user": "skocherhan",
          "value": "http://78.17.71.8:5025"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "domain",
          "user": "skocherhan",
          "value": "connect-bitmoon.fun"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "domain",
          "user": "skocherhan",
          "value": "app-bitmoon.fun"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "domain",
          "user": "skocherhan",
          "value": "andresherrerapi66.gleeze.com"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "malware"
          },
          "date": "2026-08-17 19:15:27",
          "net": {
            "country": "NL",
            "org": "AS212477 RoyaleHosting BV"
          },
          "tags": [
            "#AsyncRAT",
            "#Dcrat",
            "#Xworm"
          ],
          "tweet": "https://x.com/skocherhan/status/2089430925595619565",
          "type": "ip",
          "user": "skocherhan",
          "value": "78.17.71.8"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "c2"
          },
          "date": "2026-08-14 13:13:15",
          "tags": [
            "#Dcrat"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2088252611208061382",
          "type": "url",
          "user": "teamcymru_S2",
          "value": "http://100blackmenofsanantonio.org"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "c2"
          },
          "date": "2026-08-14 13:13:15",
          "tags": [
            "#Dcrat"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2088252611208061382",
          "type": "url",
          "user": "teamcymru_S2",
          "value": "http://1.qq8875.online"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "c2"
          },
          "date": "2026-08-14 13:13:15",
          "tags": [
            "#Dcrat"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2088252611208061382",
          "type": "url",
          "user": "teamcymru_S2",
          "value": "http://0906envdcrat.duckdns.org"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "c2"
          },
          "date": "2026-08-14 13:13:15",
          "tags": [
            "#Dcrat"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2088252611208061382",
          "type": "url",
          "user": "teamcymru_S2",
          "value": "http://08yvh4.com"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "c2"
          },
          "date": "2026-08-14 13:13:15",
          "tags": [
            "#Dcrat"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2088252611208061382",
          "type": "url",
          "user": "teamcymru_S2",
          "value": "http://0306sendrat.duckdns.org"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "c2"
          },
          "date": "2026-08-14 13:13:15",
          "tags": [
            "#Dcrat"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2088252611208061382",
          "type": "domain",
          "user": "teamcymru_S2",
          "value": "100blackmenofsanantonio.org"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "c2"
          },
          "date": "2026-08-14 13:13:15",
          "tags": [
            "#Dcrat"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2088252611208061382",
          "type": "domain",
          "user": "teamcymru_S2",
          "value": "1.qq8875.online"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "c2"
          },
          "date": "2026-08-14 13:13:15",
          "tags": [
            "#Dcrat"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2088252611208061382",
          "type": "domain",
          "user": "teamcymru_S2",
          "value": "0906envdcrat.duckdns.org"
        },
        {
          "ai": {
            "family": "dcrat",
            "threat_type": "c2"
          },
          "date": "2026-08-14 13:13:15",
          "tags": [
            "#Dcrat"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2088252611208061382",
          "type": "domain",
          "user": "teamcymru_S2",
          "value": "08yvh4.com"
        },
        {
          "ai": {
            "family": "AsyncRAT",
            "threat_type": "malware"
          },
          "date": "2026-08-05 17:30:00",
          "tags": [],
          "tweet": "https://x.com/bomccss/status/2085055822833566010",
          "type": "sha256",
          "user": "bomccss",
          "value": "47c4077decff58ceefe85ccf98d172456d8b3f9aab7f6bf8ce237ff67c718880"
        }
      ],
      "last_seen": "2026-08-17",
      "member_cluster_ids": [
        "tfc-5d3456bc193c"
      ],
      "name": "DcRat and AsyncRAT C2 on bitmoon-themed and DDNS domains",
      "reporters": [
        "bomccss",
        "skocherhan",
        "teamcymru_S2"
      ],
      "tags": [
        "#AsyncRAT",
        "#Dcrat",
        "#Xworm"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "c2": 10,
        "malware": 22
      },
      "ttps": [
        "T1588.001",
        "T1071.001",
        "T1102",
        "T1583.001"
      ],
      "types": {
        "domain": 13,
        "ip": 2,
        "sha256": 1,
        "url": 16
      }
    },
    {
      "activity": {
        "2026-08-15": 32
      },
      "anchors": {
        "registered_domains": [
          "trust-wazirx.com",
          "trustsewallet.com",
          "trustsupportt.com",
          "trustupgradewallet.com",
          "trustwalletsrestore.com",
          "trustwalllet.com",
          "trustyourcrypt.com",
          "trustyourcrypto.com",
          "wallet-accountnotice.com",
          "wallet-accountrewards.com",
          "wallet-accountsecurity.com",
          "walletsreward.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Two clusters of domains impersonate TrustWallet and MetaMask cryptocurrency wallets to steal seed phrases via fraudulent airdrop lures. The first uses trust-prefixed registered domains (trustwallet*, trustyourcrypt*, trust-wazirx.com); the second uses wallet-account* and walletsreward.com with trust.* subdomains hosting the same lure. Both clusters were reported by the same researcher on 2026-08-15.",
      "enriched_count": 32,
      "families": {},
      "first_seen": "2026-08-15",
      "history": {
        "by_pattern": [],
        "domains_365d": 12,
        "first_seen_365d": "2026-08-15",
        "iocs_365d": 32,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-15",
        "window_days": 365
      },
      "id": "tfc-68f958e45bca",
      "ioc_count": 32,
      "ioc_count_1d": 0,
      "ioc_count_30d": 32,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trustwalletsrestore.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trustupgradewallet.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trustsupportt.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trustsewallet.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trusts-crypto.walletsreward.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trust.walletsreward.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trust.wallet-accountsecurity.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trust.wallet-accountrewards.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trust.wallet-accountnotice.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trust-wazirx.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "domain",
          "user": "skocherhan",
          "value": "trust-crypto.walletsreward.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://trustwalletsrestore.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://trustupgradewallet.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://trustsupportt.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://trustsewallet.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://trusts-crypto.walletsreward.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://trust.walletsreward.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://trust.wallet-accountnotice.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://trust-wazirx.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://trust-crypto.walletsreward.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://claim.trustwalllet.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://claim-trusts.walletsreward.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://claim-trust.walletsreward.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://authenticate.trustyourcrypto.com"
        },
        {
          "ai": {
            "threat_type": "cryptoscam"
          },
          "date": "2026-08-15 20:42:06",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2088727959175614655",
          "type": "url",
          "user": "skocherhan",
          "value": "http://authenticate.trustyourcrypt.com"
        }
      ],
      "last_seen": "2026-08-15",
      "member_cluster_ids": [
        "tfc-68f958e45bca",
        "tfc-6b81adc7e438"
      ],
      "name": "TrustWallet and crypto wallet seed-phrase phishing",
      "reporters": [
        "skocherhan"
      ],
      "tags": [],
      "targeted_brand": "TrustWallet",
      "targeted_country": null,
      "targeted_sector": "financial-services",
      "threat_types": {
        "cryptoscam": 32
      },
      "ttps": [
        "T1657",
        "T1684.001",
        "T1583.001"
      ],
      "types": {
        "domain": 16,
        "url": 16
      }
    },
    {
      "activity": {
        "2026-08-25": 2,
        "2026-08-27": 4,
        "2026-08-29": 6,
        "2026-08-30": 4,
        "2026-09-01": 8,
        "2026-09-02": 6,
        "2026-09-03": 2
      },
      "anchors": {
        "registered_domains": [
          "budgetweddingplanner.info",
          "figurmanager.com",
          "financialmarkets.info",
          "horizonpeak.shop",
          "jeffersongraphicsllc.com",
          "jessicaleeinc.com",
          "schoolgirstrikers.info"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Freshly registered random-name domains deliver fake cloud-storage quota, suspension, and device-protection warnings routing victim clicks to attacker infrastructure. jeffersongraphicsllc.com links directly to financialmarkets.info, confirming a shared backend across at least seven sender domains. TKemmerling reported IOCs across figurmanager.com, schoolgirstrikers.info, horizonpeak.shop, budgetweddingplanner.info, and related domains between 2026-08-25 and 2026-09-03.",
      "enriched_count": 32,
      "families": {},
      "first_seen": "2026-08-25",
      "history": {
        "by_pattern": [],
        "domains_365d": 7,
        "first_seen_365d": "2026-08-25",
        "iocs_365d": 32,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-03",
        "window_days": 365
      },
      "id": "tfc-8b21dd67cb9f",
      "ioc_count": 32,
      "ioc_count_1d": 2,
      "ioc_count_30d": 32,
      "ioc_count_7d": 26,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-03 19:49:21",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095600052068553203",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://budgetweddingplanner.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-03 19:49:21",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095600052068553203",
          "type": "domain",
          "user": "TKemmerling",
          "value": "budgetweddingplanner.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 14:08:46",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095151953026457791",
          "type": "domain",
          "user": "TKemmerling",
          "value": "jessicaleeinc.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 14:08:46",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095151953026457791",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://jessicaleeinc.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 04:07:27",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095000627382501829",
          "type": "domain",
          "user": "TKemmerling",
          "value": "jeffersongraphicsllc.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 04:07:27",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095000627382501829",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://jeffersongraphicsllc.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 03:00:48",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094983856529326218",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://horizonpeak.shop"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 03:00:48",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094983856529326218",
          "type": "domain",
          "user": "TKemmerling",
          "value": "horizonpeak.shop"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 14:34:42",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094796091728474388",
          "type": "domain",
          "user": "TKemmerling",
          "value": "jessicaleeinc.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 14:33:44",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094795847594828215",
          "type": "domain",
          "user": "TKemmerling",
          "value": "jeffersongraphicsllc.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 14:33:44",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094795847594828215",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://financialmarkets.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 14:33:44",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094795847594828215",
          "type": "domain",
          "user": "TKemmerling",
          "value": "financialmarkets.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 03:08:08",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094623313700303145",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://budgetweddingplanner.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:16:16",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096877092495704",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://horizonpeak.shop"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:16:16",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096877092495704",
          "type": "domain",
          "user": "TKemmerling",
          "value": "horizonpeak.shop"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:16:03",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096823338291575",
          "type": "domain",
          "user": "TKemmerling",
          "value": "schoolgirstrikers.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:16:03",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096823338291575",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://schoolgirstrikers.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:57:14",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533407561359704",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://figurmanager.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:57:14",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533407561359704",
          "type": "domain",
          "user": "TKemmerling",
          "value": "figurmanager.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:57:08",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533379195244819",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://horizonpeak.shop"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:56:48",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533296760332662",
          "type": "domain",
          "user": "TKemmerling",
          "value": "schoolgirstrikers.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 00:22:10",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092769604116549868",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://financialmarkets.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 00:22:10",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092769604116549868",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://figurmanager.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 00:22:10",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092769604116549868",
          "type": "domain",
          "user": "TKemmerling",
          "value": "financialmarkets.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 13:46:24",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092247222259941826",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://financialmarkets.info"
        }
      ],
      "last_seen": "2026-09-03",
      "member_cluster_ids": [
        "tfc-8b21dd67cb9f",
        "tfc-51f5603e6046",
        "tfc-b911e8d321c7",
        "tfc-b00feaa7092d",
        "tfc-6f9affa8dd1e",
        "tfc-c215b9b09fc9",
        "tfc-38face3f9c3f"
      ],
      "name": "Fake cloud-storage warning phishing on random-name domains",
      "reporters": [
        "TKemmerling"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "phishing": 32
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 16,
        "url": 16
      }
    },
    {
      "activity": {
        "2026-08-07": 7,
        "2026-08-17": 21
      },
      "anchors": {
        "registered_domains": [
          "025sep.duckdns.org",
          "11243debestreeeemcoxxxx.duckdns.org",
          "careerlongprofit.duckdns.org",
          "cinnamonthai.com",
          "comeforreealz.duckdns.org",
          "hurtomtracker.live",
          "t0loka.live"
        ],
        "tags": [
          "#RemcosRAT"
        ],
        "url_path_patterns": [
          "/cgi-bins/N.N_N_N.exe"
        ]
      },
      "confidence": "medium",
      "context": "RemcosRAT malspam in Italy uses a quote-request lure with payload hosted at cinnamonthai.com/cgi-bins/ and C2 across DuckDNS nodes (025sep.duckdns.org, comeforreealz.duckdns.org) and direct IPs. The /cgi-bins/ path with OS-bitness-tagged filenames (e.g. 05.08_8080_64.exe) is consistent with automated payload hosting. Two reporters flagged 31 IOCs between 2026-08-03 and 2026-08-17.",
      "enriched_count": 28,
      "families": {
        "remcos": 28
      },
      "first_seen": "2026-08-07",
      "history": {
        "by_pattern": [],
        "domains_365d": 7,
        "first_seen_365d": "2026-08-07",
        "iocs_365d": 14,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-17",
        "window_days": 365
      },
      "id": "tfc-28e7dbbfd061",
      "infra": [
        {
          "country": "SI",
          "ip_count": 2,
          "org": "AS197769 VPS Dedicated LLC"
        },
        {
          "country": "NL",
          "ip_count": 2,
          "org": "AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP"
        },
        {
          "country": "TR",
          "ip_count": 2,
          "org": "AS44382 Fiba Cloud Operation Company, LLC"
        },
        {
          "country": "US",
          "ip_count": 1,
          "org": "AS40676 Psychz Networks"
        },
        {
          "country": "LV",
          "ip_count": 1,
          "org": "AS52048 SIA RixHost"
        }
      ],
      "ioc_count": 28,
      "ioc_count_1d": 0,
      "ioc_count_30d": 28,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "domain",
          "user": "teamcymru_S2",
          "value": "t0loka.live"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "domain",
          "user": "teamcymru_S2",
          "value": "hurtomtracker.live"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "url",
          "user": "teamcymru_S2",
          "value": "http://t0loka.live:7312"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "url",
          "user": "teamcymru_S2",
          "value": "http://hurtomtracker.live:2428"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "sha256",
          "user": "teamcymru_S2",
          "value": "d68810f29a58f09db1f036393cfc52c6b0934e7089077bc90a38fdece78489d9"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "sha256",
          "user": "teamcymru_S2",
          "value": "83726f65084b85630aa0bd7b1808d4941484065991f58f1789ad819cd004cf4e"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "sha256",
          "user": "teamcymru_S2",
          "value": "5be83ef1061cc0e3addb28146c4117989180e6f3b54248e3f3b9aa22884d9445"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "net": {
            "country": "NL",
            "org": "AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP"
          },
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "194.87.31.229"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "net": {
            "country": "NL",
            "org": "AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP"
          },
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "194.87.31.181"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-17 17:16:14",
          "tags": [
            "#RemcosRAT",
            "#malware"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089400926507274706",
          "type": "sha256",
          "user": "teamcymru_S2",
          "value": "0fc5b813c114443d20a4bb88adcff5dbd010f45bb4bb4fa2f5e825b85606730b"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 15:13:09",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089369951635136673",
          "type": "url",
          "user": "teamcymru_S2",
          "value": "http://11243debestreeeemcoxxxx.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 15:13:09",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089369951635136673",
          "type": "url",
          "user": "teamcymru_S2",
          "value": "http://025sep.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 15:13:09",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089369951635136673",
          "type": "domain",
          "user": "teamcymru_S2",
          "value": "11243debestreeeemcoxxxx.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 15:13:09",
          "net": {
            "country": "LV",
            "org": "AS52048 SIA RixHost"
          },
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089369951635136673",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "109.248.151.11"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 15:13:09",
          "net": {
            "country": "US",
            "org": "AS40676 Psychz Networks"
          },
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089369951635136673",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "108.181.253.47"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 15:13:09",
          "net": {
            "country": "TR",
            "org": "AS44382 Fiba Cloud Operation Company, LLC"
          },
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089369951635136673",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "103.83.86.48"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 15:13:09",
          "net": {
            "country": "TR",
            "org": "AS44382 Fiba Cloud Operation Company, LLC"
          },
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089369951635136673",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "103.83.86.143"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 15:13:09",
          "net": {
            "country": "SI",
            "org": "AS197769 VPS Dedicated LLC"
          },
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089369951635136673",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "102.220.160.105"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "c2"
          },
          "date": "2026-08-17 15:13:09",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2089369951635136673",
          "type": "domain",
          "user": "teamcymru_S2",
          "value": "025sep.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-07 07:53:00",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/D3LabIT/status/2085635481727897848",
          "type": "url",
          "user": "D3LabIT",
          "value": "http://comeforreealz.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-07 07:53:00",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/D3LabIT/status/2085635481727897848",
          "type": "url",
          "user": "D3LabIT",
          "value": "http://cinnamonthai.com/cgi-bins/05.08_8080_64.exe"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-07 07:53:00",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/D3LabIT/status/2085635481727897848",
          "type": "url",
          "user": "D3LabIT",
          "value": "http://careerlongprofit.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-07 07:53:00",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/D3LabIT/status/2085635481727897848",
          "type": "domain",
          "user": "D3LabIT",
          "value": "comeforreealz.duckdns.org"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-07 07:53:00",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/D3LabIT/status/2085635481727897848",
          "type": "domain",
          "user": "D3LabIT",
          "value": "cinnamonthai.com"
        },
        {
          "ai": {
            "family": "remcos",
            "threat_type": "malware"
          },
          "date": "2026-08-07 07:53:00",
          "tags": [
            "#RemcosRAT"
          ],
          "tweet": "https://x.com/D3LabIT/status/2085635481727897848",
          "type": "md5",
          "user": "D3LabIT",
          "value": "c5572f461bcc603de50104ec6c245098"
        }
      ],
      "last_seen": "2026-08-17",
      "member_cluster_ids": [
        "tfc-28e7dbbfd061"
      ],
      "name": "RemcosRAT Italian malspam staged on cinnamonthai.com",
      "reporters": [
        "D3LabIT",
        "teamcymru_S2"
      ],
      "tags": [
        "#RemcosRAT",
        "#malware"
      ],
      "targeted_brand": null,
      "targeted_country": "IT",
      "targeted_sector": null,
      "threat_types": {
        "c2": 10,
        "malware": 18
      },
      "ttps": [
        "T1588.001",
        "T1608.001",
        "T1568",
        "T1583.001"
      ],
      "types": {
        "domain": 7,
        "ip": 8,
        "md5": 1,
        "sha256": 5,
        "url": 7
      }
    },
    {
      "activity": {
        "2026-08-08": 14,
        "2026-08-10": 6
      },
      "anchors": {
        "registered_domains": [
          "tmallartist.com",
          "tmallbounty.com",
          "tmallhappiness.com",
          "tmallnetwork.com",
          "tmallpeaceful.com",
          "tmallplanet.com",
          "tmallpleasure.com",
          "tmallserene.com",
          "tmallsinger.com",
          "tmallstarlight.com"
        ],
        "tags": [],
        "url_path_patterns": [
          "/page/xvfhptkuqu"
        ]
      },
      "confidence": "medium",
      "context": "Phishing emails impersonating Japan's Ministry of Health, Labour and Welfare use tmall-prefixed .com domains (tmallpeaceful.com, tmallartist.com, tmallserene.com) with a CAPTCHA redirect chain landing at keeed.top/jp/. The consistent tmall- naming with abstract English suffixes across 10 domains suggests bulk registration by a single operator. Two reporters flagged 20 IOCs between 2026-08-08 and 2026-08-10.",
      "enriched_count": 20,
      "families": {},
      "first_seen": "2026-08-08",
      "history": {
        "by_pattern": [
          {
            "domains_365d": 10,
            "first_seen_365d": "2026-08-08",
            "regex": "^tmall[a-z]{6,9}\\.com$"
          }
        ],
        "domains_365d": 10,
        "first_seen_365d": "2026-08-08",
        "iocs_365d": 20,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-10",
        "window_days": 365
      },
      "id": "tfc-e84984d4d401",
      "ioc_count": 20,
      "ioc_count_1d": 0,
      "ioc_count_30d": 20,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-10 02:08:15",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086635708375028154",
          "type": "domain",
          "user": "skocherhan",
          "value": "tmallsinger.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-10 02:08:15",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086635708375028154",
          "type": "domain",
          "user": "skocherhan",
          "value": "tmallhappiness.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-10 02:08:15",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086635708375028154",
          "type": "domain",
          "user": "skocherhan",
          "value": "tmallartist.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-10 02:08:15",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086635708375028154",
          "type": "url",
          "user": "skocherhan",
          "value": "http://tmallsinger.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-10 02:08:15",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086635708375028154",
          "type": "url",
          "user": "skocherhan",
          "value": "http://tmallhappiness.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-10 02:08:15",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086635708375028154",
          "type": "url",
          "user": "skocherhan",
          "value": "http://tmallartist.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "domain",
          "user": "skocherhan",
          "value": "tmallstarlight.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "domain",
          "user": "skocherhan",
          "value": "tmallserene.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "domain",
          "user": "skocherhan",
          "value": "tmallpleasure.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "domain",
          "user": "skocherhan",
          "value": "tmallplanet.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "domain",
          "user": "skocherhan",
          "value": "tmallnetwork.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "domain",
          "user": "skocherhan",
          "value": "tmallbounty.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "url",
          "user": "skocherhan",
          "value": "http://tmallstarlight.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "url",
          "user": "skocherhan",
          "value": "http://tmallserene.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "url",
          "user": "skocherhan",
          "value": "http://tmallpleasure.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "url",
          "user": "skocherhan",
          "value": "http://tmallplanet.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "url",
          "user": "skocherhan",
          "value": "http://tmallnetwork.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 21:14:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2086199495507730922",
          "type": "url",
          "user": "skocherhan",
          "value": "http://tmallbounty.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 12:37:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/harugasumi/status/2086069278303027634",
          "type": "domain",
          "user": "harugasumi",
          "value": "tmallpeaceful.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 12:37:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/harugasumi/status/2086069278303027634",
          "type": "url",
          "user": "harugasumi",
          "value": "https://tmallpeaceful.com/page/xvfhptkuqu"
        }
      ],
      "last_seen": "2026-08-10",
      "member_cluster_ids": [
        "tfc-e84984d4d401"
      ],
      "name": "Japan labor ministry phishing on tmall-prefixed domains",
      "patterns": [
        {
          "domain_count": 10,
          "domains_elsewhere_30d": 0,
          "examples": [
            "tmallartist.com",
            "tmallbounty.com",
            "tmallhappiness.com"
          ],
          "first_seen": "2026-08-08",
          "ioc_count": 20,
          "last_seen": "2026-08-10",
          "regex": "^tmall[a-z]{6,9}\\.com$"
        }
      ],
      "reporters": [
        "harugasumi",
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Japan Ministry of Health, Labour and Welfare",
      "targeted_country": "JP",
      "targeted_sector": "government-national",
      "threat_types": {
        "phishing": 20
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 10,
        "url": 10
      }
    },
    {
      "activity": {
        "2026-08-24": 9,
        "2026-09-03": 10
      },
      "anchors": {
        "registered_domains": [
          "1234e.org",
          "123ful.net",
          "12naga.org",
          "epicgames.com",
          "sm188dnsxx.top",
          "sm188dvlv.icu",
          "steamcommunity.com",
          "telegram.me"
        ],
        "tags": [
          "#Vidar"
        ],
        "url_path_patterns": [
          "/community/api",
          "/profiles/N",
          "/sNyme"
        ]
      },
      "confidence": "medium",
      "context": "Vidar infostealer instances on sm188dvlv.icu, 12naga.org, and 1234e.org resolve C2 indirectly via Steam community profiles, Telegram channels, and the Epic Games developer API to evade domain blocklists. The sm188-prefixed domains appear as a recurring naming pattern across the cluster. Three reporters flagged 19 IOCs between 2026-08-24 and 2026-09-03.",
      "enriched_count": 19,
      "families": {
        "Vidar": 19
      },
      "first_seen": "2026-08-24",
      "history": {
        "by_pattern": [],
        "domains_365d": 8,
        "first_seen_365d": "2025-09-07",
        "iocs_365d": 67,
        "iocs_before_window": 50,
        "last_seen_365d": "2026-09-03",
        "window_days": 365
      },
      "id": "tfc-4cae7a37a2a1",
      "infra": [
        {
          "country": "NL",
          "ip_count": 1,
          "org": "AS41436 Kamatera Inc"
        }
      ],
      "ioc_count": 19,
      "ioc_count_1d": 10,
      "ioc_count_30d": 19,
      "ioc_count_7d": 10,
      "iocs": [
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "domain",
          "user": "orlof_v",
          "value": "tra.12naga.org"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "domain",
          "user": "orlof_v",
          "value": "tak.sm188dvlv.icu"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "domain",
          "user": "orlof_v",
          "value": "tak.123ful.net"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "domain",
          "user": "orlof_v",
          "value": "sha.sm188dvlv.icu"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "domain",
          "user": "orlof_v",
          "value": "rrr.12naga.org"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "url",
          "user": "orlof_v",
          "value": "http://tra.12naga.org"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "url",
          "user": "orlof_v",
          "value": "http://tak.sm188dvlv.icu"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "url",
          "user": "orlof_v",
          "value": "http://tak.123ful.net"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "url",
          "user": "orlof_v",
          "value": "http://sha.sm188dvlv.icu"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-09-03 11:32:19",
          "tags": [
            "#Vidar",
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/orlof_v/status/2095474970084143382",
          "type": "url",
          "user": "orlof_v",
          "value": "http://rrr.12naga.org"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-08-24 05:51:56",
          "tags": [
            "#Vidar"
          ],
          "tweet": "https://x.com/skocherhan/status/2091765432038387769",
          "type": "domain",
          "user": "skocherhan",
          "value": "wsp.1234e.org"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-08-24 05:51:56",
          "tags": [
            "#Vidar"
          ],
          "tweet": "https://x.com/skocherhan/status/2091765432038387769",
          "type": "url",
          "user": "skocherhan",
          "value": "http://wsp.1234e.org"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-08-24 05:51:56",
          "tags": [
            "#Vidar"
          ],
          "tweet": "https://x.com/skocherhan/status/2091765432038387769",
          "type": "url",
          "user": "skocherhan",
          "value": "http://telegram.me/s11yme"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-08-24 05:51:56",
          "tags": [
            "#Vidar"
          ],
          "tweet": "https://x.com/skocherhan/status/2091765432038387769",
          "type": "url",
          "user": "skocherhan",
          "value": "http://steamcommunity.com/profiles/76561198652917381"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-08-24 05:51:56",
          "tags": [
            "#Vidar"
          ],
          "tweet": "https://x.com/skocherhan/status/2091765432038387769",
          "type": "url",
          "user": "skocherhan",
          "value": "http://45.91.168.240"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "malware"
          },
          "date": "2026-08-24 05:51:56",
          "net": {
            "country": "NL",
            "org": "AS41436 Kamatera Inc"
          },
          "tags": [
            "#Vidar"
          ],
          "tweet": "https://x.com/skocherhan/status/2091765432038387769",
          "type": "ip",
          "user": "skocherhan",
          "value": "45.91.168.240"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "c2"
          },
          "date": "2026-08-24 05:27:05",
          "tags": [
            "#Vidar"
          ],
          "tweet": "https://x.com/K_N1kolenko/status/2091759176494047575",
          "type": "domain",
          "user": "K_N1kolenko",
          "value": "wsp.sm188dnsxx.top"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "c2"
          },
          "date": "2026-08-24 05:27:05",
          "tags": [
            "#Vidar"
          ],
          "tweet": "https://x.com/K_N1kolenko/status/2091759176494047575",
          "type": "url",
          "user": "K_N1kolenko",
          "value": "http://wsp.sm188dnsxx.top"
        },
        {
          "ai": {
            "family": "Vidar",
            "threat_type": "c2"
          },
          "date": "2026-08-24 05:27:05",
          "tags": [
            "#Vidar"
          ],
          "tweet": "https://x.com/K_N1kolenko/status/2091759176494047575",
          "type": "url",
          "user": "K_N1kolenko",
          "value": "http://dev.epicgames.com/community/api/user_profiles/profile.json?hash_id=roAjr"
        }
      ],
      "last_seen": "2026-09-03",
      "member_cluster_ids": [
        "tfc-4cae7a37a2a1"
      ],
      "name": "Vidar stealer using Steam, Telegram, and Epic Games C2",
      "reporters": [
        "K_N1kolenko",
        "orlof_v",
        "skocherhan"
      ],
      "tags": [
        "#Vidar",
        "#infostealer",
        "#malware"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "c2": 3,
        "malware": 16
      },
      "ttps": [
        "T1588.001",
        "T1102",
        "T1583.001"
      ],
      "types": {
        "domain": 7,
        "ip": 1,
        "url": 11
      }
    },
    {
      "activity": {
        "2026-08-05": 2,
        "2026-08-06": 2,
        "2026-08-07": 2,
        "2026-08-13": 1,
        "2026-08-14": 2,
        "2026-08-17": 2,
        "2026-08-18": 2,
        "2026-08-21": 4,
        "2026-08-25": 2
      },
      "anchors": {
        "registered_domains": [
          "dslkk.cn",
          "fmpqwyp.cn",
          "gkpfz.com",
          "gzmingbo.com",
          "hhttps-www-roblox.co",
          "joannsalestore.com",
          "niuaniu.top",
          "raaglpfplzp.top",
          "tichbox.com"
        ],
        "tags": [],
        "url_path_patterns": [
          "/login"
        ]
      },
      "confidence": "low",
      "context": "A shared /login phishing kit spans Chinese-registered .cn and .top domains alongside generic TLDs including joannsalestore.com and hhttps-www-roblox.co, the latter a Roblox lookalike. Consistent /login path patterns across random-label domains suggest a shared kit deployed against multiple targets including Apple and Docomo. Four reporters flagged 19 IOCs between 2026-08-05 and 2026-08-25.",
      "enriched_count": 19,
      "families": {},
      "first_seen": "2026-08-05",
      "history": {
        "by_pattern": [],
        "domains_365d": 9,
        "first_seen_365d": "2026-08-05",
        "iocs_365d": 18,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-25",
        "window_days": 365
      },
      "id": "tfc-66e666c2695d",
      "ioc_count": 19,
      "ioc_count_1d": 0,
      "ioc_count_30d": 17,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 17:00:58",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2092296188275896742",
          "type": "url",
          "user": "phishunt_io",
          "value": "http://hhttps-www-roblox.co/login?returnUrl=1164408920"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 17:00:58",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2092296188275896742",
          "type": "domain",
          "user": "phishunt_io",
          "value": "hhttps-www-roblox.co"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-21 09:26:22",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2090732229744115892",
          "type": "url",
          "user": "masaomi346",
          "value": "https://gzmingbo.com/login"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-21 09:26:22",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2090732229744115892",
          "type": "domain",
          "user": "masaomi346",
          "value": "gzmingbo.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-21 03:00:07",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2090635029261230470",
          "type": "domain",
          "user": "Metemcyber",
          "value": "login.gkpfz.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-21 03:00:07",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2090635029261230470",
          "type": "url",
          "user": "Metemcyber",
          "value": "https://login.gkpfz.com/login"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-18 06:32:48",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2089601387902730388",
          "type": "domain",
          "user": "masaomi346",
          "value": "tichbox.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-18 06:32:48",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2089601387902730388",
          "type": "url",
          "user": "masaomi346",
          "value": "https://tichbox.com/login"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 04:35:20",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2089209439115218962",
          "type": "url",
          "user": "masaomi346",
          "value": "https://www.fmpqwyp.cn/login"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 04:35:20",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2089209439115218962",
          "type": "domain",
          "user": "masaomi346",
          "value": "fmpqwyp.cn"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-14 07:24:35",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2088164869644386726",
          "type": "domain",
          "user": "masaomi346",
          "value": "joannsalestore.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-14 07:24:35",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2088164869644386726",
          "type": "url",
          "user": "masaomi346",
          "value": "https://joannsalestore.com/login"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-13 15:01:34",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/ThreatOpsX/status/2087917483491471363",
          "type": "url",
          "user": "ThreatOpsX",
          "value": "https://82.22.23.63/login"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 05:11:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2085594781691048396",
          "type": "domain",
          "user": "masaomi346",
          "value": "niuaniu.top"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 05:11:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2085594781691048396",
          "type": "url",
          "user": "masaomi346",
          "value": "https://niuaniu.top/login"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 01:55:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2085182979777954073",
          "type": "url",
          "user": "masaomi346",
          "value": "https://www.dslkk.cn/login"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 01:55:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2085182979777954073",
          "type": "domain",
          "user": "masaomi346",
          "value": "dslkk.cn"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-05 00:41:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2084801945295098263",
          "type": "domain",
          "user": "masaomi346",
          "value": "login.raaglpfplzp.top"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-05 00:41:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2084801945295098263",
          "type": "url",
          "user": "masaomi346",
          "value": "https://login.raaglpfplzp.top/login"
        }
      ],
      "last_seen": "2026-08-25",
      "member_cluster_ids": [
        "tfc-66e666c2695d"
      ],
      "name": "Login-page phishing on Chinese .top and .cn domains",
      "reporters": [
        "Metemcyber",
        "ThreatOpsX",
        "masaomi346",
        "phishunt_io"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "phishing": 19
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 9,
        "url": 10
      }
    },
    {
      "activity": {
        "2026-08-20": 2,
        "2026-08-21": 2,
        "2026-08-22": 2,
        "2026-08-23": 2,
        "2026-08-25": 2,
        "2026-08-27": 2,
        "2026-08-29": 2,
        "2026-08-31": 2,
        "2026-09-01": 2
      },
      "anchors": {
        "registered_domains": [
          "itnessequipmentfor.info"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Phishing emails impersonating QuoteWizard and LendingTree insurance comparison services route all links through itnessequipmentfor.info as the shared redirect endpoint. Sender infrastructure includes southfloridafitnessbootcamp.com and terracollinge.com, identified as recurring sender domains by the same reporter. One reporter flagged IOCs between 2026-08-20 and 2026-09-01.",
      "enriched_count": 18,
      "families": {},
      "first_seen": "2026-08-20",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-20",
        "iocs_365d": 18,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-01",
        "window_days": 365
      },
      "id": "tfc-12a562c4b238",
      "ioc_count": 18,
      "ioc_count_1d": 0,
      "ioc_count_30d": 18,
      "ioc_count_7d": 6,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 03:07:52",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094623244238434411",
          "type": "domain",
          "user": "TKemmerling",
          "value": "itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 03:07:52",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094623244238434411",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-31 16:03:22",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094456016327045599",
          "type": "domain",
          "user": "TKemmerling",
          "value": "itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-31 16:03:22",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094456016327045599",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:57:56",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533579670426096",
          "type": "domain",
          "user": "TKemmerling",
          "value": "itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:57:56",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533579670426096",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 00:23:19",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092769894815371621",
          "type": "domain",
          "user": "TKemmerling",
          "value": "itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 00:23:19",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092769894815371621",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 03:22:30",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092090213149671880",
          "type": "domain",
          "user": "TKemmerling",
          "value": "itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 03:22:30",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092090213149671880",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-23 07:33:44",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2091428661425844324",
          "type": "domain",
          "user": "TKemmerling",
          "value": "itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-23 07:33:44",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2091428661425844324",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-22 07:06:18",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2091059372206215597",
          "type": "domain",
          "user": "TKemmerling",
          "value": "itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-22 07:06:18",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2091059372206215597",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-21 14:46:28",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2090812785970303089",
          "type": "domain",
          "user": "TKemmerling",
          "value": "itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-21 14:46:28",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2090812785970303089",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-20 04:22:15",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2090293310216892804",
          "type": "domain",
          "user": "TKemmerling",
          "value": "itnessequipmentfor.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-20 04:22:15",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2090293310216892804",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://itnessequipmentfor.info"
        }
      ],
      "last_seen": "2026-09-01",
      "member_cluster_ids": [
        "tfc-12a562c4b238"
      ],
      "name": "QuoteWizard insurance phishing via itnessequipmentfor.info",
      "reporters": [
        "TKemmerling"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "QuoteWizard",
      "targeted_country": null,
      "targeted_sector": "insurance",
      "threat_types": {
        "phishing": 18
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 9,
        "url": 9
      }
    },
    {
      "activity": {
        "2026-08-26": 2,
        "2026-08-29": 6,
        "2026-08-30": 4,
        "2026-09-01": 2,
        "2026-09-04": 4
      },
      "anchors": {
        "registered_domains": [
          "harbor-belong.com",
          "hbjbkf.com",
          "nsbpay.com",
          "yancha123.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Personal loan, debt-consolidation, and cloud-storage quota phishing emails use invisible Unicode padding in subject lines to evade filters, routing victims to recently registered domains including yancha123.com, hbjbkf.com, harbor-belong.com, and nsbpay.com. TKemmerling flagged combined IOCs between 2026-08-26 and 2026-09-04.",
      "enriched_count": 14,
      "families": {},
      "first_seen": "2026-08-26",
      "history": {
        "by_pattern": [],
        "domains_365d": 4,
        "first_seen_365d": "2026-08-26",
        "iocs_365d": 18,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-04",
        "window_days": 365
      },
      "id": "tfc-621fee6c649f",
      "ioc_count": 18,
      "ioc_count_1d": 4,
      "ioc_count_30d": 18,
      "ioc_count_7d": 16,
      "iocs": [
        {
          "date": "2026-09-04 03:01:53",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095708902260191236",
          "type": "domain",
          "user": "TKemmerling",
          "value": "ra.hbjbkf.com"
        },
        {
          "date": "2026-09-04 03:01:53",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095708902260191236",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://ra.hbjbkf.com"
        },
        {
          "date": "2026-09-04 02:50:06",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095705939470954880",
          "type": "domain",
          "user": "TKemmerling",
          "value": "se.nsbpay.com"
        },
        {
          "date": "2026-09-04 02:50:06",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095705939470954880",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://se.nsbpay.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 14:34:08",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094795948027437382",
          "type": "domain",
          "user": "TKemmerling",
          "value": "nsbpay.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 14:34:08",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094795948027437382",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://nsbpay.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:15:28",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096676260868224",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://harbor-belong.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:15:28",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096676260868224",
          "type": "domain",
          "user": "TKemmerling",
          "value": "harbor-belong.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:15:14",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096615829299560",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://hbjbkf.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:15:14",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096615829299560",
          "type": "domain",
          "user": "TKemmerling",
          "value": "hbjbkf.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:58:53",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533820649894034",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://harbor-belong.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:58:53",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533820649894034",
          "type": "domain",
          "user": "TKemmerling",
          "value": "harbor-belong.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:57:49",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533550775857212",
          "type": "domain",
          "user": "TKemmerling",
          "value": "yancha123.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:57:49",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533550775857212",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://yancha123.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:57:01",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533352112587262",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://hbjbkf.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:57:01",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533352112587262",
          "type": "domain",
          "user": "TKemmerling",
          "value": "hbjbkf.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-26 04:00:01",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092462040325697910",
          "type": "domain",
          "user": "TKemmerling",
          "value": "re.yancha123.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-26 04:00:01",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092462040325697910",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://re.yancha123.com"
        }
      ],
      "last_seen": "2026-09-04",
      "member_cluster_ids": [
        "tfc-621fee6c649f",
        "tfc-db63b4bf97b9",
        "tfc-c6cad4e1a3b8",
        "tfc-66530fa3936f"
      ],
      "name": "Personal loan phishing with Unicode subject obfuscation",
      "reporters": [
        "TKemmerling"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": "financial-services",
      "threat_types": {
        "phishing": 14
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 9,
        "url": 9
      }
    },
    {
      "activity": {
        "2026-08-05": 2,
        "2026-08-06": 2,
        "2026-08-07": 2,
        "2026-08-08": 2,
        "2026-08-09": 2,
        "2026-08-10": 2,
        "2026-08-11": 2,
        "2026-08-12": 2,
        "2026-08-13": 2
      },
      "anchors": {
        "registered_domains": [
          "sqllq.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "sqllq.com operates as a cloaking funnel routing visitors to an online betting platform. Enrichment describes a churning gambling domain network alongside an active gambling ASN and SSL certificate pair. One reporter flagged 20 IOC observations of the same domain between 2026-08-04 and 2026-08-13.",
      "enriched_count": 18,
      "families": {},
      "first_seen": "2026-08-05",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-07-28",
        "iocs_365d": 32,
        "iocs_before_window": 14,
        "last_seen_365d": "2026-08-13",
        "window_days": 365
      },
      "id": "tfc-732ca93798d6",
      "ioc_count": 18,
      "ioc_count_1d": 0,
      "ioc_count_30d": 18,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-13 11:59:39",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2087871701275066605",
          "type": "domain",
          "user": "webamon_search",
          "value": "sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-13 11:59:39",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2087871701275066605",
          "type": "url",
          "user": "webamon_search",
          "value": "http://sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 12:36:51",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2087518677021188301",
          "type": "domain",
          "user": "webamon_search",
          "value": "sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 12:36:51",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2087518677021188301",
          "type": "url",
          "user": "webamon_search",
          "value": "http://sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-11 13:04:55",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2087163353663701316",
          "type": "domain",
          "user": "webamon_search",
          "value": "sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-11 13:04:55",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2087163353663701316",
          "type": "url",
          "user": "webamon_search",
          "value": "http://sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-10 13:07:30",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2086801613788786973",
          "type": "domain",
          "user": "webamon_search",
          "value": "sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-10 13:07:30",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2086801613788786973",
          "type": "url",
          "user": "webamon_search",
          "value": "http://sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 13:42:12",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2086447957973291166",
          "type": "domain",
          "user": "webamon_search",
          "value": "sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-09 13:42:12",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2086447957973291166",
          "type": "url",
          "user": "webamon_search",
          "value": "http://sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 12:13:00",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2086063278170534042",
          "type": "domain",
          "user": "webamon_search",
          "value": "sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-08 12:13:00",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2086063278170534042",
          "type": "url",
          "user": "webamon_search",
          "value": "http://sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 12:46:00",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2085709242686705944",
          "type": "domain",
          "user": "webamon_search",
          "value": "sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 12:46:00",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2085709242686705944",
          "type": "url",
          "user": "webamon_search",
          "value": "http://sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 12:10:00",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2085337645261979903",
          "type": "domain",
          "user": "webamon_search",
          "value": "sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 12:10:00",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2085337645261979903",
          "type": "url",
          "user": "webamon_search",
          "value": "http://sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-05 13:36:00",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2084996888487469305",
          "type": "domain",
          "user": "webamon_search",
          "value": "sqllq.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-05 13:36:00",
          "tags": [],
          "tweet": "https://x.com/webamon_search/status/2084996888487469305",
          "type": "url",
          "user": "webamon_search",
          "value": "http://sqllq.com"
        }
      ],
      "last_seen": "2026-08-13",
      "member_cluster_ids": [
        "tfc-732ca93798d6"
      ],
      "name": "Cloaking gambling funnel via sqllq.com",
      "reporters": [
        "webamon_search"
      ],
      "tags": [],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "phishing": 18
      },
      "ttps": [
        "T1583.001"
      ],
      "types": {
        "domain": 9,
        "url": 9
      }
    },
    {
      "activity": {
        "2026-08-05": 2,
        "2026-08-06": 5,
        "2026-08-10": 1,
        "2026-08-12": 1,
        "2026-08-13": 4,
        "2026-08-15": 1,
        "2026-08-21": 2,
        "2026-08-24": 1
      },
      "anchors": {
        "registered_domains": [
          "dichcxosghnd-dsvekdc.top",
          "ptnrmat.xyz"
        ],
        "tags": [
          "#Android"
        ],
        "url_path_patterns": [
          "/police/mydata.php"
        ]
      },
      "confidence": "medium",
      "context": "An Android trojan campaign distributes malicious APKs and retrieves C2 config from a Pastebin raw endpoint. The /police/mydata.php path on ptnrmat.xyz exfiltrates documents, WhatsApp media, contacts, and device info, suggesting law-enforcement app impersonation as the lure. Three reporters flagged 18 IOCs between 2026-08-04 and 2026-08-24.",
      "enriched_count": 17,
      "families": {
        "Joker": 10
      },
      "first_seen": "2026-08-05",
      "history": {
        "by_pattern": [],
        "domains_365d": 2,
        "first_seen_365d": "2026-06-15",
        "iocs_365d": 10,
        "iocs_before_window": 6,
        "last_seen_365d": "2026-08-21",
        "window_days": 365
      },
      "id": "tfc-f7f1750c34a4",
      "ioc_count": 17,
      "ioc_count_1d": 0,
      "ioc_count_30d": 16,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-24 09:17:28",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2091817154454901131",
          "type": "md5",
          "user": "ReBensk",
          "value": "51adfa78768ee78d78f9cf26b8346a47"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-21 17:25:39",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2090852847550418994",
          "type": "url",
          "user": "ReBensk",
          "value": "https://dichcxosghnd-dsvekdc.top"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-21 17:25:39",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2090852847550418994",
          "type": "domain",
          "user": "ReBensk",
          "value": "dichcxosghnd-dsvekdc.top"
        },
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-15 04:06:51",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2088477496828424509",
          "type": "md5",
          "user": "ReBensk",
          "value": "e5997f06aeb17e126cdef11a7f8b26a3"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-13 12:01:38",
          "tags": [
            "#Android",
            "#malware"
          ],
          "tweet": "https://x.com/OpcodeIntel/status/2087872200892408124",
          "type": "domain",
          "user": "OpcodeIntel",
          "value": "ptnrmat.xyz"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-13 12:01:38",
          "tags": [
            "#Android",
            "#malware"
          ],
          "tweet": "https://x.com/OpcodeIntel/status/2087872200892408124",
          "type": "url",
          "user": "OpcodeIntel",
          "value": "https://ptnrmat.xyz/police/mydata.php"
        },
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:33:46",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2087819891676176792",
          "type": "md5",
          "user": "ReBensk",
          "value": "6e5022d49b561db98abd4c676dbec56b"
        },
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:32:30",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2087819571193577535",
          "type": "md5",
          "user": "ReBensk",
          "value": "70e2d670095d47e6ffebecc30df7d4fd"
        },
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-12 07:14:06",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2087437455440171055",
          "type": "md5",
          "user": "ReBensk",
          "value": "1302c33507dccf698a2a890a9a247ad4"
        },
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-10 05:57:25",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2086693379795194029",
          "type": "md5",
          "user": "ReBensk",
          "value": "f9370d681e8f9a6788d463dd45e2e0d3"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-06 08:23:00",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2085280571031540140",
          "type": "md5",
          "user": "ReBensk",
          "value": "394ebca8fe5b92a028cd8c30a609d912"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-06 06:59:00",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2085259472948396046",
          "type": "md5",
          "user": "ReBensk",
          "value": "e93fadfff4634a5b5fd77dba5705e761"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-06 06:30:00",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2085252246217101580",
          "type": "md5",
          "user": "ReBensk",
          "value": "3f5393dc8ce0ab48fb0c4639b345bd60"
        },
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-06 05:55:00",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2085243321925140490",
          "type": "md5",
          "user": "ReBensk",
          "value": "0822e2e190d05897cb3594fb868370d4"
        },
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-06 05:53:00",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2085242862078509239",
          "type": "md5",
          "user": "ReBensk",
          "value": "37f3156a3de77d3470a09029dc3fcfa5"
        },
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-05 07:20:00",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2084902400901742646",
          "type": "md5",
          "user": "ReBensk",
          "value": "275ca41efe4cca35a5672d81630bb25c"
        },
        {
          "ai": {
            "family": "Joker",
            "threat_type": "malware"
          },
          "date": "2026-08-05 06:41:00",
          "tags": [
            "#Android",
            "#Trojan",
            "#malware"
          ],
          "tweet": "https://x.com/ReBensk/status/2084892553745440795",
          "type": "md5",
          "user": "ReBensk",
          "value": "38446c05a225119e5a6c002d207c5aaf"
        }
      ],
      "last_seen": "2026-08-24",
      "member_cluster_ids": [
        "tfc-f7f1750c34a4"
      ],
      "name": "Android trojan with /police/ lure using Pastebin C2 config",
      "reporters": [
        "OpcodeIntel",
        "ReBensk"
      ],
      "tags": [
        "#Android",
        "#Trojan",
        "#malware"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "malware": 17
      },
      "ttps": [
        "T1102",
        "T1583.001"
      ],
      "types": {
        "domain": 2,
        "md5": 13,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-11": 4,
        "2026-08-19": 10
      },
      "anchors": {
        "registered_domains": [
          "allremdeskriki.com",
          "dubl1allremriki.com",
          "dubl2allremriki.com",
          "studiotikva.com",
          "woolvilli.com"
        ],
        "tags": [],
        "url_path_patterns": [
          "/api/vN"
        ]
      },
      "confidence": "medium",
      "context": "NeedleStealer, a Go-based infostealer, operates C2 botnet infrastructure at allremdeskriki.com, dubl1allremriki.com, and dubl2allremriki.com with /api/v2 endpoints behind Cloudflare CDN backed by a Vultr server. AgentTesla indicators are also present on studiotikva.com and woolvilli.com within the same cluster. Two reporters attributed 10 NeedleStealer and 4 AgentTesla samples to this infrastructure.",
      "enriched_count": 14,
      "families": {
        "NeedleStealer": 10,
        "agenttesla": 4
      },
      "first_seen": "2026-08-11",
      "history": {
        "by_pattern": [],
        "domains_365d": 5,
        "first_seen_365d": "2026-08-11",
        "iocs_365d": 12,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-19",
        "window_days": 365
      },
      "id": "tfc-22ef21288f47",
      "ioc_count": 14,
      "ioc_count_1d": 0,
      "ioc_count_30d": 14,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "domain",
          "user": "abuse_ch",
          "value": "woolvilli.com"
        },
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "url",
          "user": "abuse_ch",
          "value": "http://woolvilli.com/api/v2"
        },
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "url",
          "user": "abuse_ch",
          "value": "http://dubl2allremriki.com/api/v2"
        },
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "url",
          "user": "abuse_ch",
          "value": "http://dubl1allremriki.com/api/v2"
        },
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "url",
          "user": "abuse_ch",
          "value": "http://allremdeskriki.com/api/v2"
        },
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "url",
          "user": "abuse_ch",
          "value": "http://136.244.100.54:8899/api/v1/agent/ws"
        },
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "url",
          "user": "abuse_ch",
          "value": "http://136.244.100.54:8899/api/v1/agent/register"
        },
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "domain",
          "user": "abuse_ch",
          "value": "dubl2allremriki.com"
        },
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "domain",
          "user": "abuse_ch",
          "value": "dubl1allremriki.com"
        },
        {
          "ai": {
            "family": "NeedleStealer",
            "threat_type": "malware"
          },
          "date": "2026-08-19 11:28:30",
          "tags": [],
          "tweet": "https://x.com/abuse_ch/status/2090038189347987611",
          "type": "domain",
          "user": "abuse_ch",
          "value": "allremdeskriki.com"
        },
        {
          "ai": {
            "family": "agenttesla",
            "threat_type": "malware"
          },
          "date": "2026-08-11 12:00:12",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087147065285738674",
          "type": "domain",
          "user": "ishivtripathi",
          "value": "studiotikva.com"
        },
        {
          "ai": {
            "family": "agenttesla",
            "threat_type": "malware"
          },
          "date": "2026-08-11 12:00:12",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087147065285738674",
          "type": "url",
          "user": "ishivtripathi",
          "value": "https://studiotikva.com"
        },
        {
          "ai": {
            "family": "agenttesla",
            "threat_type": "malware"
          },
          "date": "2026-08-11 12:00:12",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087147065285738674",
          "type": "url",
          "user": "ishivtripathi",
          "value": "https://api.studiotikva.com/api/v1/update/check"
        },
        {
          "ai": {
            "family": "agenttesla",
            "threat_type": "malware"
          },
          "date": "2026-08-11 12:00:12",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087147065285738674",
          "type": "domain",
          "user": "ishivtripathi",
          "value": "api.studiotikva.com"
        }
      ],
      "last_seen": "2026-08-19",
      "member_cluster_ids": [
        "tfc-22ef21288f47"
      ],
      "name": "NeedleStealer infostealer C2 botnet on allrem* domains",
      "reporters": [
        "abuse_ch",
        "ishivtripathi"
      ],
      "tags": [
        "#malware"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "malware": 14
      },
      "ttps": [
        "T1071.001",
        "T1583.001"
      ],
      "types": {
        "domain": 6,
        "url": 8
      }
    },
    {
      "activity": {
        "2026-08-08": 3,
        "2026-08-10": 2,
        "2026-08-11": 2,
        "2026-08-15": 2,
        "2026-08-29": 4
      },
      "anchors": {
        "registered_domains": [
          "xyzblue.dpdns.org"
        ],
        "tags": [
          "#ClickFix",
          "#CobaltStrike",
          "#log4j"
        ],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "ClickFix lure abuses the search-ms protocol at xyzblue.dpdns.org to relay NTLM credentials before deploying a CobaltStrike beacon via .lnk dropper with AMSI bypass and fileless execution. Open directories at 154.94.224.35:54321 and 8.137.23.180 expose staged tooling alongside Log4j exploitation. Three researchers reported 13 IOCs between 2026-08-08 and 2026-08-29.",
      "enriched_count": 13,
      "families": {
        "CobaltStrike": 8
      },
      "first_seen": "2026-08-08",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-08",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-10",
        "window_days": 365
      },
      "id": "tfc-463d53f90671",
      "infra": [
        {
          "country": "US",
          "ip_count": 1,
          "org": "AS132203 Tencent Building, Kejizhongyi Avenue"
        },
        {
          "country": "CN",
          "ip_count": 1,
          "org": "AS37963 Hangzhou Alibaba Advertising Co.,Ltd."
        },
        {
          "country": "HK",
          "ip_count": 1,
          "org": "AS401701 cognetcloud INC"
        },
        {
          "country": "FR",
          "ip_count": 1,
          "org": "AS51167 Contabo GmbH"
        }
      ],
      "ioc_count": 13,
      "ioc_count_1d": 0,
      "ioc_count_30d": 13,
      "ioc_count_7d": 4,
      "iocs": [
        {
          "ai": {
            "family": "CobaltStrike",
            "threat_type": "c2"
          },
          "date": "2026-08-29 07:10:17",
          "tags": [
            "#CobaltStrike"
          ],
          "tweet": "https://x.com/abodovic1/status/2093597089171124550",
          "type": "url",
          "user": "abodovic1",
          "value": "http://49.51.230.17:8888"
        },
        {
          "ai": {
            "family": "CobaltStrike",
            "threat_type": "c2"
          },
          "date": "2026-08-29 07:10:17",
          "net": {
            "country": "US",
            "org": "AS132203 Tencent Building, Kejizhongyi Avenue"
          },
          "tags": [
            "#CobaltStrike"
          ],
          "tweet": "https://x.com/abodovic1/status/2093597089171124550",
          "type": "ip",
          "user": "abodovic1",
          "value": "49.51.230.17"
        },
        {
          "ai": {
            "family": "CobaltStrike",
            "threat_type": "c2"
          },
          "date": "2026-08-29 07:00:27",
          "tags": [
            "#CobaltStrike"
          ],
          "tweet": "https://x.com/abodovic1/status/2093594610937258360",
          "type": "url",
          "user": "abodovic1",
          "value": "http://154.94.224.35:54321"
        },
        {
          "ai": {
            "family": "CobaltStrike",
            "threat_type": "c2"
          },
          "date": "2026-08-29 07:00:27",
          "net": {
            "country": "HK",
            "org": "AS401701 cognetcloud INC"
          },
          "tags": [
            "#CobaltStrike"
          ],
          "tweet": "https://x.com/abodovic1/status/2093594610937258360",
          "type": "ip",
          "user": "abodovic1",
          "value": "154.94.224.35"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-15 15:57:56",
          "tags": [
            "#CobaltStrike",
            "#malware",
            "#opendir"
          ],
          "tweet": "https://x.com/etugenio/status/2088656446174970367",
          "type": "url",
          "user": "etugenio",
          "value": "http://8.137.23.180"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-15 15:57:56",
          "net": {
            "country": "CN",
            "org": "AS37963 Hangzhou Alibaba Advertising Co.,Ltd."
          },
          "tags": [
            "#CobaltStrike",
            "#malware",
            "#opendir"
          ],
          "tweet": "https://x.com/etugenio/status/2088656446174970367",
          "type": "ip",
          "user": "etugenio",
          "value": "8.137.23.180"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-11 06:05:08",
          "tags": [
            "#CobaltStrike",
            "#log4j",
            "#malware"
          ],
          "tweet": "https://x.com/etugenio/status/2087057711183585573",
          "type": "url",
          "user": "etugenio",
          "value": "http://169.58.82.229"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-11 06:05:08",
          "net": {
            "country": "FR",
            "org": "AS51167 Contabo GmbH"
          },
          "tags": [
            "#CobaltStrike",
            "#log4j",
            "#malware"
          ],
          "tweet": "https://x.com/etugenio/status/2087057711183585573",
          "type": "ip",
          "user": "etugenio",
          "value": "169.58.82.229"
        },
        {
          "ai": {
            "family": "CobaltStrike",
            "threat_type": "c2"
          },
          "date": "2026-08-10 05:01:22",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/etugenio/status/2086679273444606245",
          "type": "domain",
          "user": "etugenio",
          "value": "xyzblue.dpdns.org"
        },
        {
          "ai": {
            "family": "CobaltStrike",
            "threat_type": "c2"
          },
          "date": "2026-08-10 05:01:22",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/etugenio/status/2086679273444606245",
          "type": "url",
          "user": "etugenio",
          "value": "http://xyzblue.dpdns.org"
        },
        {
          "ai": {
            "family": "CobaltStrike",
            "threat_type": "c2"
          },
          "date": "2026-08-08 18:06:17",
          "tags": [
            "#ClickFix",
            "#CobaltStrike"
          ],
          "tweet": "https://x.com/Yusufcancakiir/status/2086152030024855665",
          "type": "domain",
          "user": "Yusufcancakiir",
          "value": "xyzblue.dpdns.org"
        },
        {
          "ai": {
            "family": "CobaltStrike",
            "threat_type": "c2"
          },
          "date": "2026-08-08 18:06:17",
          "tags": [
            "#ClickFix",
            "#CobaltStrike"
          ],
          "tweet": "https://x.com/Yusufcancakiir/status/2086152030024855665",
          "type": "url",
          "user": "Yusufcancakiir",
          "value": "http://xyzblue.dpdns.org"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-08 18:06:17",
          "tags": [
            "#ClickFix",
            "#CobaltStrike"
          ],
          "tweet": "https://x.com/Yusufcancakiir/status/2086152030024855665",
          "type": "url",
          "user": "Yusufcancakiir",
          "value": "http://43.156.228.149"
        }
      ],
      "last_seen": "2026-08-29",
      "member_cluster_ids": [
        "tfc-463d53f90671"
      ],
      "name": "CobaltStrike via ClickFix with open-directory C2 servers",
      "reporters": [
        "Yusufcancakiir",
        "abodovic1",
        "etugenio"
      ],
      "tags": [
        "#ClickFix",
        "#CobaltStrike",
        "#log4j",
        "#malware",
        "#opendir"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "c2": 12,
        "malware": 1
      },
      "ttps": [
        "T1588.002",
        "T1204.004",
        "T1608.001",
        "T1071.001"
      ],
      "types": {
        "domain": 2,
        "ip": 4,
        "url": 7
      }
    },
    {
      "activity": {
        "2026-08-21": 2,
        "2026-08-27": 4,
        "2026-08-29": 4,
        "2026-09-02": 2
      },
      "anchors": {
        "registered_domains": [
          "anadolucuhuriyeti.info",
          "ezcapsforums.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Phishing emails impersonating Insurify insurance comparison route victims to anadolucuhuriyeti.info via terminandoconlatrata.com, and separately to a DGA-style domain via ezcapsforums.com. Both waves use unrelated business domains as senders to obscure the brand impersonation. TKemmerling flagged 12 combined IOCs between 2026-08-21 and 2026-08-29.",
      "enriched_count": 12,
      "families": {},
      "first_seen": "2026-08-21",
      "history": {
        "by_pattern": [],
        "domains_365d": 2,
        "first_seen_365d": "2026-08-21",
        "iocs_365d": 12,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-02",
        "window_days": 365
      },
      "id": "tfc-1bf924d82aff",
      "ioc_count": 12,
      "ioc_count_1d": 0,
      "ioc_count_30d": 12,
      "ioc_count_7d": 6,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 14:05:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095151161070498131",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://anadolucuhuriyeti.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 14:05:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095151161070498131",
          "type": "domain",
          "user": "TKemmerling",
          "value": "anadolucuhuriyeti.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 03:02:45",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093534793472655841",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://ezcapsforums.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 03:02:45",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093534793472655841",
          "type": "domain",
          "user": "TKemmerling",
          "value": "ezcapsforums.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:58:46",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533790807470133",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://anadolucuhuriyeti.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 02:58:46",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093533790807470133",
          "type": "domain",
          "user": "TKemmerling",
          "value": "anadolucuhuriyeti.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 00:21:19",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092769392467841300",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://ezcapsforums.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 00:21:19",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092769392467841300",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://anadolucuhuriyeti.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 00:21:19",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092769392467841300",
          "type": "domain",
          "user": "TKemmerling",
          "value": "ezcapsforums.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 00:21:19",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092769392467841300",
          "type": "domain",
          "user": "TKemmerling",
          "value": "anadolucuhuriyeti.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-21 14:46:09",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2090812709092962792",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://anadolucuhuriyeti.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-21 14:46:09",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2090812709092962792",
          "type": "domain",
          "user": "TKemmerling",
          "value": "anadolucuhuriyeti.info"
        }
      ],
      "last_seen": "2026-09-02",
      "member_cluster_ids": [
        "tfc-1bf924d82aff",
        "tfc-f70bea04dce2"
      ],
      "name": "Insurify auto-insurance phishing via multiple sender domains",
      "reporters": [
        "TKemmerling"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Insurify",
      "targeted_country": null,
      "targeted_sector": "insurance",
      "threat_types": {
        "phishing": 12
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 6,
        "url": 6
      }
    },
    {
      "activity": {
        "2026-08-13": 12
      },
      "anchors": {
        "registered_domains": [
          "futupath.cyou",
          "smarture.cyou"
        ],
        "tags": [
          "#Lumma"
        ],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Lumma Stealer C2 infrastructure is identified at futupath.cyou and smarture.cyou, accompanied by eight SHA256 hashes of malware samples. Enrichment attributes 12 Lumma samples to this cluster; the .cyou TLD and short random labels are consistent with Lumma's known domain pattern. No delivery or phishing infrastructure is observed beyond the C2 domains. One reporter flagged 12 IOCs on 2026-08-13.",
      "enriched_count": 12,
      "families": {
        "Lumma": 12
      },
      "first_seen": "2026-08-13",
      "history": {
        "by_pattern": [],
        "domains_365d": 2,
        "first_seen_365d": "2026-08-13",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-13",
        "window_days": 365
      },
      "id": "tfc-414ac58a2af9",
      "ioc_count": 12,
      "ioc_count_1d": 0,
      "ioc_count_30d": 12,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "c2"
          },
          "date": "2026-08-13 08:21:07",
          "tags": [
            "#Lumma",
            "#infostealer"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816707628994675",
          "type": "domain",
          "user": "ishivtripathi",
          "value": "smarture.cyou"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "c2"
          },
          "date": "2026-08-13 08:21:07",
          "tags": [
            "#Lumma",
            "#infostealer"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816707628994675",
          "type": "url",
          "user": "ishivtripathi",
          "value": "http://smarture.cyou"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "c2"
          },
          "date": "2026-08-13 08:21:07",
          "tags": [
            "#Lumma",
            "#infostealer"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816707628994675",
          "type": "url",
          "user": "ishivtripathi",
          "value": "http://futupath.cyou"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "c2"
          },
          "date": "2026-08-13 08:21:07",
          "tags": [
            "#Lumma",
            "#infostealer"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816707628994675",
          "type": "domain",
          "user": "ishivtripathi",
          "value": "futupath.cyou"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:19:21",
          "tags": [
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816262298796136",
          "type": "sha256",
          "user": "ishivtripathi",
          "value": "f1cb8444675f9a1e517ec3f81bc1344ff98223d25842eb3c72d75b455c9d1fe5"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:19:21",
          "tags": [
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816262298796136",
          "type": "sha256",
          "user": "ishivtripathi",
          "value": "e1e3c99ed272e9b6c23c77976f49d220b4634bf8960f54acd5a33e82901eb789"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:19:21",
          "tags": [
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816262298796136",
          "type": "sha256",
          "user": "ishivtripathi",
          "value": "b001177ca1d027b107321288b444848a9025ddc34f63508f95e39ea344b0936f"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:19:21",
          "tags": [
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816262298796136",
          "type": "sha256",
          "user": "ishivtripathi",
          "value": "9ebdd9ebd7486caf3c80de10224fdb2dc0ca0c9c27b186e0ae35ca0c0057444f"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:19:21",
          "tags": [
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816262298796136",
          "type": "sha256",
          "user": "ishivtripathi",
          "value": "95814ce45fa953600f89878d81d9169ef708ad8070f404576b1e0f882c76f538"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:19:21",
          "tags": [
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816262298796136",
          "type": "sha256",
          "user": "ishivtripathi",
          "value": "82b3333a2742998141fef03601f65d3fd2d4461edf7d2dce81ea20094a63f2c1"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:19:21",
          "tags": [
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816262298796136",
          "type": "sha256",
          "user": "ishivtripathi",
          "value": "69c7561fa1c73490eb47bc79f33d0c3bac3e2894f67a869cd93c1ec6ca400591"
        },
        {
          "ai": {
            "family": "Lumma",
            "threat_type": "malware"
          },
          "date": "2026-08-13 08:19:21",
          "tags": [
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/ishivtripathi/status/2087816262298796136",
          "type": "sha256",
          "user": "ishivtripathi",
          "value": "4b5c5b08a3562b923847d2fdc909d665feed737c772d0a61c96361fca1aaf853"
        }
      ],
      "last_seen": "2026-08-13",
      "member_cluster_ids": [
        "tfc-414ac58a2af9"
      ],
      "name": "Lumma Stealer C2 on futupath.cyou and smarture.cyou",
      "reporters": [
        "ishivtripathi"
      ],
      "tags": [
        "#Lumma",
        "#infostealer",
        "#malware"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "c2": 4,
        "malware": 8
      },
      "ttps": [
        "T1588.001",
        "T1583.001"
      ],
      "types": {
        "domain": 2,
        "sha256": 8,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-06": 12
      },
      "anchors": {
        "registered_domains": [],
        "tags": [
          "#Evilginx"
        ],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Twelve IP addresses host Evilginx and Modlishka AiTM reverse-proxy kits that steal MFA session tokens by intercepting credential submissions in real time. Enrichment attributes these to a mass deployment spanning 1,504 servers across 303 ASNs. No registered domains are present; grouping is based on shared tool attribution from one reporter on 2026-08-06.",
      "enriched_count": 12,
      "families": {},
      "first_seen": "2026-08-06",
      "id": "tfc-c0dc0ffd19e4",
      "infra": [
        {
          "country": "US",
          "ip_count": 4,
          "org": "AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP"
        },
        {
          "country": "US",
          "ip_count": 2,
          "org": "AS14061 DigitalOcean, LLC"
        },
        {
          "country": "DE",
          "ip_count": 1,
          "org": "AS12574 Hosting.de GmbH"
        },
        {
          "country": "VN",
          "ip_count": 1,
          "org": "AS140770 Digilife Vietnam Digital Services Company Limited"
        },
        {
          "country": "RU",
          "ip_count": 1,
          "org": "AS204997 FIRST SERVER LIMITED"
        },
        {
          "country": "US",
          "ip_count": 1,
          "org": "AS213122 Hyonix"
        },
        {
          "country": "US",
          "ip_count": 1,
          "org": "AS25820 IT7 Networks Inc"
        },
        {
          "country": "US",
          "ip_count": 1,
          "org": "AS36352 HostPapa"
        }
      ],
      "ioc_count": 12,
      "ioc_count_1d": 0,
      "ioc_count_30d": 12,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "US",
            "org": "AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "89.185.80.222"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "US",
            "org": "AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "78.153.155.124"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "US",
            "org": "AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "5.181.3.137"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "DE",
            "org": "AS12574 Hosting.de GmbH"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "213.160.77.221"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "US",
            "org": "AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "193.202.11.45"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "RU",
            "org": "AS204997 FIRST SERVER LIMITED"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "185.104.248.45"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "US",
            "org": "AS213122 Hyonix"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "170.39.185.141"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "GB",
            "org": "AS14061 DigitalOcean, LLC"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "167.71.140.130"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "US",
            "org": "AS14061 DigitalOcean, LLC"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "134.209.9.147"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "US",
            "org": "AS36352 HostPapa"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "107.174.244.118"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "US",
            "org": "AS25820 IT7 Networks Inc"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "104.128.90.27"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-06 16:29:00",
          "net": {
            "country": "VN",
            "org": "AS140770 Digilife Vietnam Digital Services Company Limited"
          },
          "tags": [
            "#Evilginx",
            "#phishing"
          ],
          "tweet": "https://x.com/teamcymru_S2/status/2085403006879637538",
          "type": "ip",
          "user": "teamcymru_S2",
          "value": "103.176.145.220"
        }
      ],
      "last_seen": "2026-08-06",
      "member_cluster_ids": [
        "tfc-c0dc0ffd19e4"
      ],
      "name": "Evilginx AiTM credential-harvesting infrastructure",
      "reporters": [
        "teamcymru_S2"
      ],
      "tags": [
        "#Evilginx",
        "#phishing"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "phishing": 12
      },
      "ttps": [
        "T1557"
      ],
      "types": {
        "ip": 12
      }
    },
    {
      "activity": {
        "2026-08-09": 11
      },
      "anchors": {
        "registered_domains": [
          "aidsp.top",
          "controllerscompetiv5.com"
        ],
        "tags": [
          "#AdaptixC2"
        ],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "AdaptixC2 C2 server at 194.59.31.175:4444 is supported by aidsp.top and controllerscompetiv5.com, with ScreenConnect also present in the deployment. Two reporters identified the infrastructure on 2026-08-09; controllerscompetiv5.com follows a freshly registered operational naming pattern consistent with attacker-provisioned domains.",
      "enriched_count": 11,
      "families": {},
      "first_seen": "2026-08-09",
      "history": {
        "by_pattern": [],
        "domains_365d": 2,
        "first_seen_365d": "2026-08-09",
        "iocs_365d": 8,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-09",
        "window_days": 365
      },
      "id": "tfc-41e68bae945a",
      "infra": [
        {
          "country": "FR",
          "ip_count": 1,
          "org": "AS399486 12651980 CANADA INC."
        }
      ],
      "ioc_count": 11,
      "ioc_count_1d": 0,
      "ioc_count_30d": 11,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:38:23",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2086477198542647449",
          "type": "domain",
          "user": "skocherhan",
          "value": "ns2.aidsp.top"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:38:23",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2086477198542647449",
          "type": "domain",
          "user": "skocherhan",
          "value": "ns1.aidsp.top"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:38:23",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2086477198542647449",
          "type": "url",
          "user": "skocherhan",
          "value": "http://ns2.aidsp.top"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:38:23",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2086477198542647449",
          "type": "url",
          "user": "skocherhan",
          "value": "http://ns1.aidsp.top"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:38:23",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2086477198542647449",
          "type": "url",
          "user": "skocherhan",
          "value": "http://controllerscompetiv5.com"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:38:23",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2086477198542647449",
          "type": "url",
          "user": "skocherhan",
          "value": "http://aidsp.top"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:38:23",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2086477198542647449",
          "type": "url",
          "user": "skocherhan",
          "value": "http://194.59.31.175:4444"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:38:23",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2086477198542647449",
          "type": "domain",
          "user": "skocherhan",
          "value": "controllerscompetiv5.com"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:38:23",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2086477198542647449",
          "type": "domain",
          "user": "skocherhan",
          "value": "aidsp.top"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:16:36",
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/etugenio/status/2086471715765284982",
          "type": "url",
          "user": "etugenio",
          "value": "http://194.59.31.175"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-09 15:16:36",
          "net": {
            "country": "FR",
            "org": "AS399486 12651980 CANADA INC."
          },
          "tags": [
            "#AdaptixC2",
            "#malware"
          ],
          "tweet": "https://x.com/etugenio/status/2086471715765284982",
          "type": "ip",
          "user": "etugenio",
          "value": "194.59.31.175"
        }
      ],
      "last_seen": "2026-08-09",
      "member_cluster_ids": [
        "tfc-41e68bae945a"
      ],
      "name": "AdaptixC2 command-and-control at 194.59.31.175",
      "reporters": [
        "etugenio",
        "skocherhan"
      ],
      "tags": [
        "#AdaptixC2",
        "#malware"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "c2": 11
      },
      "ttps": [
        "T1588.002",
        "T1071.001",
        "T1583.001"
      ],
      "types": {
        "domain": 4,
        "ip": 1,
        "url": 6
      }
    },
    {
      "activity": {
        "2026-08-05": 5,
        "2026-08-07": 6
      },
      "anchors": {
        "registered_domains": [
          "angels-travel.com",
          "caixacat.com",
          "geek-asylum.com",
          "urbanizab2b.com",
          "vignobles-lorgeril.com"
        ],
        "tags": [],
        "url_path_patterns": [
          "/jmFfvPRN",
          "/jmFfvPRN/ip"
        ]
      },
      "confidence": "medium",
      "context": "Five domains - caixacat.com, geek-asylum.com, angels-travel.com, urbanizab2b.com, and vignobles-lorgeril.com - share the /jmFfvPRN/ kit path hosting Resona Bank credential-harvest pages. The domains appear unrelated to banking but are registered via Gname and hosted on HostPapa and GNET infrastructure. Three reporters flagged 11 IOCs between 2026-08-05 and 2026-08-07.",
      "enriched_count": 11,
      "families": {},
      "first_seen": "2026-08-05",
      "history": {
        "by_pattern": [],
        "domains_365d": 5,
        "first_seen_365d": "2026-08-05",
        "iocs_365d": 11,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-07",
        "window_days": 365
      },
      "id": "tfc-c817d4987dd0",
      "ioc_count": 11,
      "ioc_count_1d": 0,
      "ioc_count_30d": 11,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 22:48:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/kubotaa3/status/2085860573259210880",
          "type": "url",
          "user": "kubotaa3",
          "value": "https://geek-asylum.com/jmFfvPRN/"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 22:48:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/kubotaa3/status/2085860573259210880",
          "type": "url",
          "user": "kubotaa3",
          "value": "https://caixacat.com/jmFfvPRN/"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 22:48:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/kubotaa3/status/2085860573259210880",
          "type": "domain",
          "user": "kubotaa3",
          "value": "geek-asylum.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 22:48:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/kubotaa3/status/2085860573259210880",
          "type": "domain",
          "user": "kubotaa3",
          "value": "caixacat.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 14:44:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2085738913289945155",
          "type": "url",
          "user": "masaomi346",
          "value": "https://angels-travel.com/jmFfvPRN/"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-07 14:44:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2085738913289945155",
          "type": "domain",
          "user": "masaomi346",
          "value": "angels-travel.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-05 21:19:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2085113595487047788",
          "type": "domain",
          "user": "skocherhan",
          "value": "vignobles-lorgeril.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-05 21:19:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2085113595487047788",
          "type": "domain",
          "user": "skocherhan",
          "value": "urbanizab2b.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-05 21:19:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2085113595487047788",
          "type": "url",
          "user": "skocherhan",
          "value": "https://vignobles-lorgeril.com/jmFfvPRN/"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-05 21:19:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2085113595487047788",
          "type": "url",
          "user": "skocherhan",
          "value": "https://urbanizab2b.com/jmFfvPRN/ip"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-05 21:07:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/kubotaa3/status/2085110467488632880",
          "type": "url",
          "user": "kubotaa3",
          "value": "https://urbanizab2b.com/jmFfvPRN/"
        }
      ],
      "last_seen": "2026-08-07",
      "member_cluster_ids": [
        "tfc-c817d4987dd0"
      ],
      "name": "Resona Bank phishing via /jmFfvPRN/ kit on unrelated domains",
      "reporters": [
        "kubotaa3",
        "masaomi346",
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Resona Bank",
      "targeted_country": "JP",
      "targeted_sector": "financial-services",
      "threat_types": {
        "phishing": 11
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 5,
        "url": 6
      }
    },
    {
      "activity": {
        "2026-08-23": 8
      },
      "anchors": {
        "registered_domains": [
          "nexovanta.bond",
          "stackluma.sbs"
        ],
        "tags": [],
        "url_path_patterns": [
          "/rooms/res"
        ]
      },
      "confidence": "medium",
      "context": "APT-tagged clusters share the stackluma.sbs backend with a /rooms/res/get-command.php UID-based command-retrieval endpoint. nexovanta.bond provides supporting subdomains (checkout, khuh) hosted on Contabo infrastructure alongside the primary C2 at stackluma.sbs. Reporters skocherhan and byrne_emmy12099 flagged 8 IOCs on 2026-08-23.",
      "enriched_count": 8,
      "families": {},
      "first_seen": "2026-08-23",
      "history": {
        "by_pattern": [],
        "domains_365d": 2,
        "first_seen_365d": "2026-08-23",
        "iocs_365d": 8,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-23",
        "window_days": 365
      },
      "id": "tfc-123a230007c4",
      "ioc_count": 8,
      "ioc_count_1d": 0,
      "ioc_count_30d": 8,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "domain",
          "user": "skocherhan",
          "value": "shop.stackluma.sbs"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "domain",
          "user": "skocherhan",
          "value": "khuh.nexovanta.bond"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "url",
          "user": "skocherhan",
          "value": "http://shop.stackluma.sbs"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "url",
          "user": "skocherhan",
          "value": "http://khuh.nexovanta.bond"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "url",
          "user": "skocherhan",
          "value": "http://checkout.nexovanta.bond"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "domain",
          "user": "skocherhan",
          "value": "checkout.nexovanta.bond"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:18:59",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/byrne_emmy12099/status/2091530645600371044",
          "type": "domain",
          "user": "byrne_emmy12099",
          "value": "tony.stackluma.sbs"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:18:59",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/byrne_emmy12099/status/2091530645600371044",
          "type": "url",
          "user": "byrne_emmy12099",
          "value": "http://tony.stackluma.sbs/rooms/res/get-command.php?uid=[UID"
        }
      ],
      "last_seen": "2026-08-23",
      "member_cluster_ids": [
        "tfc-123a230007c4",
        "tfc-6a280227fd5d"
      ],
      "name": "APT C2 cluster on stackluma.sbs command-retrieval endpoint",
      "reporters": [
        "byrne_emmy12099",
        "skocherhan"
      ],
      "tags": [
        "#APT"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "c2": 8
      },
      "ttps": [
        "T1071.001",
        "T1583.001"
      ],
      "types": {
        "domain": 4,
        "url": 4
      }
    },
    {
      "activity": {
        "2026-08-17": 4,
        "2026-08-24": 2,
        "2026-09-01": 2
      },
      "anchors": {
        "registered_domains": [
          "bnznji.net"
        ],
        "tags": [],
        "url_path_patterns": [
          "/Adobe/Adobe-digital-exe"
        ]
      },
      "confidence": "medium",
      "context": "gk.bnznji.net hosts an Adobe-branded phishing page at /Adobe/Adobe-digital-exe/ that delivers a ScreenConnect remote-access executable. The path structure mimics an Adobe software installer to deceive victims into running the payload. Four reporters including phishunt_io and skocherhan flagged 8 IOCs between 2026-08-17 and 2026-09-01.",
      "enriched_count": 8,
      "families": {},
      "first_seen": "2026-08-17",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-17",
        "iocs_365d": 8,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-01",
        "window_days": 365
      },
      "id": "tfc-58a8465f8f21",
      "ioc_count": 8,
      "ioc_count_1d": 0,
      "ioc_count_30d": 8,
      "ioc_count_7d": 2,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 08:45:03",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/PhishStats/status/2094708099001000180",
          "type": "url",
          "user": "PhishStats",
          "value": "https://gk.bnznji.net/Adobe/Adobe-digital-exe/download.html"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 08:45:03",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/PhishStats/status/2094708099001000180",
          "type": "domain",
          "user": "PhishStats",
          "value": "gk.bnznji.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 07:00:59",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2091782807144042941",
          "type": "url",
          "user": "phishunt_io",
          "value": "http://gk.bnznji.net/Adobe/Adobe-digital-exe/download.html"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 07:00:59",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2091782807144042941",
          "type": "domain",
          "user": "phishunt_io",
          "value": "gk.bnznji.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 15:57:19",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089381066251419788",
          "type": "url",
          "user": "skocherhan",
          "value": "https://gk.bnznji.net/Adobe/Adobe-digital-exe/download.php"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 15:57:19",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089381066251419788",
          "type": "url",
          "user": "skocherhan",
          "value": "https://gk.bnznji.net/Adobe/Adobe-digital-exe/Download"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 15:57:19",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2089381066251419788",
          "type": "domain",
          "user": "skocherhan",
          "value": "gk.bnznji.net"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 15:51:32",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/patialavii/status/2089379610861699295",
          "type": "url",
          "user": "patialavii",
          "value": "https://gk.bnznji.net/Adobe/Adobe-digital-exe/"
        }
      ],
      "last_seen": "2026-09-01",
      "member_cluster_ids": [
        "tfc-58a8465f8f21"
      ],
      "name": "Adobe lure delivering ScreenConnect RMM via bnznji.net",
      "reporters": [
        "PhishStats",
        "patialavii",
        "phishunt_io",
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Adobe",
      "targeted_country": null,
      "targeted_sector": "technology",
      "threat_types": {
        "phishing": 8
      },
      "ttps": [
        "T1566.002",
        "T1036.005",
        "T1588.002",
        "T1583.001"
      ],
      "types": {
        "domain": 3,
        "url": 5
      }
    },
    {
      "activity": {
        "2026-08-24": 7
      },
      "anchors": {
        "registered_domains": [
          "gmas34.ju.mp",
          "mvkpop.es"
        ],
        "tags": [],
        "url_path_patterns": [
          "/dNbNdN-bdN-Neaa-bNb-NeaN"
        ]
      },
      "confidence": "medium",
      "context": "A Google Voice voicemail-notification lure routes victims through a hash-keyed clickthru.php redirect at cbspokane.com and a ju.mp short link (gmas34.ju.mp), landing on a cloned Google sign-in page rendered as a blob URL to evade URL scanners. Two reporters flagged 7 combined IOCs on 2026-08-24.",
      "enriched_count": 7,
      "families": {},
      "first_seen": "2026-08-24",
      "history": {
        "by_pattern": [],
        "domains_365d": 2,
        "first_seen_365d": "2026-08-24",
        "iocs_365d": 7,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-24",
        "window_days": 365
      },
      "id": "tfc-18f9901a58da",
      "ioc_count": 7,
      "ioc_count_1d": 0,
      "ioc_count_30d": 7,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 16:21:33",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2091923878905782652",
          "type": "domain",
          "user": "skocherhan",
          "value": "mvkpop.es"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 16:21:33",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2091923878905782652",
          "type": "url",
          "user": "skocherhan",
          "value": "https://mvkpop.es/d00b9d48-bd85-4eaa-b80b-8220987ea812##Phishing"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 16:21:33",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2091923878905782652",
          "type": "url",
          "user": "skocherhan",
          "value": "http://mvkpop.es"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 16:21:33",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2091923878905782652",
          "type": "url",
          "user": "skocherhan",
          "value": "http://gmas34.ju.mp"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 16:21:33",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2091923878905782652",
          "type": "domain",
          "user": "skocherhan",
          "value": "gmas34.ju.mp"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 16:16:31",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2091922612406628810",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://mvkpop.es/d00b9d48-bd85-4eaa-b80b-8220987ea812"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 16:16:31",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2091922612406628810",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://gmas34.ju.mp"
        }
      ],
      "last_seen": "2026-08-24",
      "member_cluster_ids": [
        "tfc-18f9901a58da",
        "tfc-7c6357924ff6"
      ],
      "name": "Google Voice voicemail phishing via UUID-path redirect chain",
      "reporters": [
        "Malwarehunterr",
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Google",
      "targeted_country": null,
      "targeted_sector": "technology",
      "threat_types": {
        "phishing": 7
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 2,
        "url": 5
      }
    },
    {
      "activity": {
        "2026-08-29": 2,
        "2026-08-30": 2,
        "2026-09-02": 2
      },
      "anchors": {
        "registered_domains": [
          "thebitcoincenter.info"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Phishing emails use a fake antivirus expiry warning to pressure victims into renewing a security product, routing the payment link to thebitcoincenter.info instead of any legitimate vendor. The landing domain suggests a cryptocurrency-themed payment endpoint rather than a genuine security provider. TKemmerling flagged 6 IOCs between 2026-08-29 and 2026-09-02.",
      "enriched_count": 6,
      "families": {},
      "first_seen": "2026-08-29",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-29",
        "iocs_365d": 6,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-02",
        "window_days": 365
      },
      "id": "tfc-ae404e23e760",
      "ioc_count": 6,
      "ioc_count_1d": 0,
      "ioc_count_30d": 6,
      "ioc_count_7d": 6,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 04:07:27",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095000627382501829",
          "type": "domain",
          "user": "TKemmerling",
          "value": "thebitcoincenter.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 04:07:27",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095000627382501829",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://thebitcoincenter.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:16:58",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094097050829045815",
          "type": "domain",
          "user": "TKemmerling",
          "value": "thebitcoincenter.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:16:58",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094097050829045815",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://thebitcoincenter.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 03:02:38",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093534763726586313",
          "type": "domain",
          "user": "TKemmerling",
          "value": "thebitcoincenter.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-29 03:02:38",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2093534763726586313",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://thebitcoincenter.info"
        }
      ],
      "last_seen": "2026-09-02",
      "member_cluster_ids": [
        "tfc-ae404e23e760"
      ],
      "name": "Fake antivirus billing lure via thebitcoincenter.info",
      "reporters": [
        "TKemmerling"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "phishing": 6
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 3,
        "url": 3
      }
    },
    {
      "activity": {
        "2026-08-12": 2,
        "2026-08-17": 2,
        "2026-09-02": 2
      },
      "anchors": {
        "registered_domains": [
          "chktxw.info",
          "u0fnd.info",
          "xeduvt.info"
        ],
        "tags": [],
        "url_path_patterns": [
          "/HNAoO"
        ]
      },
      "confidence": "medium",
      "context": "UC Card and Saison credit card phishing sites share an /H80AoO path across three .info parent domains - chktxw.info, u0fnd.info, and xeduvt.info. Subdomain labels embed partial brand strings such as saissodbn to deceive Japanese cardholders into entering credentials. Two reporters flagged 6 IOCs between 2026-08-12 and 2026-09-02.",
      "enriched_count": 6,
      "families": {},
      "first_seen": "2026-08-12",
      "history": {
        "by_pattern": [],
        "domains_365d": 3,
        "first_seen_365d": "2026-08-12",
        "iocs_365d": 6,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-02",
        "window_days": 365
      },
      "id": "tfc-ed66a6988cc9",
      "ioc_count": 6,
      "ioc_count_1d": 0,
      "ioc_count_30d": 6,
      "ioc_count_7d": 2,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 12:29:16",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2095126912683344129",
          "type": "domain",
          "user": "masaomi346",
          "value": "rhigcrimelet.chktxw.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 12:29:16",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2095126912683344129",
          "type": "url",
          "user": "masaomi346",
          "value": "https://rhigcrimelet.chktxw.info/H80AoO"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 11:53:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2089319735720907234",
          "type": "domain",
          "user": "Metemcyber",
          "value": "saissodbn202607oint.u0fnd.info"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-17 11:53:37",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2089319735720907234",
          "type": "url",
          "user": "Metemcyber",
          "value": "https://saissodbn202607oint.u0fnd.info/H80AoO"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 13:38:01",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2087534069307543822",
          "type": "url",
          "user": "masaomi346",
          "value": "https://asoiasonc.xeduvt.info/H80AoO"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-12 13:38:01",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2087534069307543822",
          "type": "domain",
          "user": "masaomi346",
          "value": "asoiasonc.xeduvt.info"
        }
      ],
      "last_seen": "2026-09-02",
      "member_cluster_ids": [
        "tfc-ed66a6988cc9"
      ],
      "name": "UC Card and Saison phishing on .info domains targeting Japan",
      "reporters": [
        "Metemcyber",
        "masaomi346"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "UC Card",
      "targeted_country": "JP",
      "targeted_sector": "financial-services",
      "threat_types": {
        "phishing": 6
      },
      "ttps": [
        "T1566.002",
        "T1684.001",
        "T1583.001"
      ],
      "types": {
        "domain": 3,
        "url": 3
      }
    },
    {
      "activity": {
        "2026-08-11": 4,
        "2026-08-28": 1
      },
      "anchors": {
        "registered_domains": [],
        "tags": [
          "#MustangPanda"
        ],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "MustangPanda (Chinese-nexus APT) indicators flagged by two researchers include one IP (43.254.132.217) and three MD5 hashes observed between 2026-08-11 and 2026-08-28. Enrichment identifies a ToneShell backdoor masquerading as TurboVPN using FakeTLS with a 512-byte XOR key alongside XtremeProtector and HTran proxy tooling. No registered domain infrastructure is present, limiting characterisation to endpoint indicators.",
      "enriched_count": 5,
      "families": {},
      "first_seen": "2026-08-11",
      "id": "tfc-c0acabb6f143",
      "infra": [
        {
          "country": "TH",
          "ip_count": 1,
          "org": "AS131447 POPIDC powered by CSLoxinfo"
        }
      ],
      "ioc_count": 5,
      "ioc_count_1d": 0,
      "ioc_count_30d": 5,
      "ioc_count_7d": 1,
      "iocs": [
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-28 11:19:01",
          "tags": [
            "#MustangPanda"
          ],
          "tweet": "https://x.com/skocherhan/status/2093297295752126742",
          "type": "md5",
          "user": "skocherhan",
          "value": "43349dd33578dd9dc7388894670e0d07"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-11 14:02:50",
          "tags": [
            "#MustangPanda"
          ],
          "tweet": "https://x.com/SinghSoodeep/status/2087177925850251274",
          "type": "url",
          "user": "SinghSoodeep",
          "value": "http://43.254.132.217"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-11 14:02:50",
          "tags": [
            "#MustangPanda"
          ],
          "tweet": "https://x.com/SinghSoodeep/status/2087177925850251274",
          "type": "md5",
          "user": "SinghSoodeep",
          "value": "f93f9aec0f8f927267ba50a92923d663"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-11 14:02:50",
          "tags": [
            "#MustangPanda"
          ],
          "tweet": "https://x.com/SinghSoodeep/status/2087177925850251274",
          "type": "md5",
          "user": "SinghSoodeep",
          "value": "7ee5f62767b5703b408a70148f519792"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-11 14:02:50",
          "net": {
            "country": "TH",
            "org": "AS131447 POPIDC powered by CSLoxinfo"
          },
          "tags": [
            "#MustangPanda"
          ],
          "tweet": "https://x.com/SinghSoodeep/status/2087177925850251274",
          "type": "ip",
          "user": "SinghSoodeep",
          "value": "43.254.132.217"
        }
      ],
      "last_seen": "2026-08-28",
      "member_cluster_ids": [
        "tfc-c0acabb6f143"
      ],
      "name": "MustangPanda APT - IP and hash indicators",
      "reporters": [
        "SinghSoodeep",
        "skocherhan"
      ],
      "tags": [
        "#MustangPanda"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "malware": 5
      },
      "ttps": [],
      "types": {
        "ip": 1,
        "md5": 3,
        "url": 1
      }
    },
    {
      "activity": {
        "2026-08-24": 2,
        "2026-08-25": 2
      },
      "anchors": {
        "registered_domains": [
          "lewokodwqko.icu"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "MioLab stealer targets macOS users via a fake Adobe InDesign DMG installer, using lewokodwqko.icu as its C2 domain. Grouping comes from malware family enrichment; the C2 domain is the only network indicator present. No credential-harvest infrastructure is observed beyond the C2 endpoint. One reporter flagged 4 IOCs between 2026-08-24 and 2026-08-25.",
      "enriched_count": 4,
      "families": {
        "MioLab": 4
      },
      "first_seen": "2026-08-24",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-07-28",
        "iocs_365d": 7,
        "iocs_before_window": 3,
        "last_seen_365d": "2026-08-25",
        "window_days": 365
      },
      "id": "tfc-0eebc91ceb12",
      "ioc_count": 4,
      "ioc_count_1d": 0,
      "ioc_count_30d": 4,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "family": "MioLab",
            "threat_type": "malware"
          },
          "date": "2026-08-25 13:42:00",
          "tags": [
            "#stealer"
          ],
          "tweet": "https://x.com/suyog41/status/2092246114179432584",
          "type": "domain",
          "user": "suyog41",
          "value": "lewokodwqko.icu"
        },
        {
          "ai": {
            "family": "MioLab",
            "threat_type": "malware"
          },
          "date": "2026-08-25 13:42:00",
          "tags": [
            "#stealer"
          ],
          "tweet": "https://x.com/suyog41/status/2092246114179432584",
          "type": "url",
          "user": "suyog41",
          "value": "http://lewokodwqko.icu"
        },
        {
          "ai": {
            "family": "MioLab",
            "threat_type": "malware"
          },
          "date": "2026-08-24 13:57:16",
          "tags": [
            "#stealer"
          ],
          "tweet": "https://x.com/suyog41/status/2091887566928941517",
          "type": "domain",
          "user": "suyog41",
          "value": "lewokodwqko.icu"
        },
        {
          "ai": {
            "family": "MioLab",
            "threat_type": "malware"
          },
          "date": "2026-08-24 13:57:16",
          "tags": [
            "#stealer"
          ],
          "tweet": "https://x.com/suyog41/status/2091887566928941517",
          "type": "url",
          "user": "suyog41",
          "value": "http://lewokodwqko.icu"
        }
      ],
      "last_seen": "2026-08-25",
      "member_cluster_ids": [
        "tfc-0eebc91ceb12"
      ],
      "name": "MioLab macOS stealer via fake Adobe InDesign DMG installer",
      "reporters": [
        "suyog41"
      ],
      "tags": [
        "#stealer"
      ],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "malware": 4
      },
      "ttps": [
        "T1583.001"
      ],
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-30": 2,
        "2026-09-02": 2
      },
      "anchors": {
        "registered_domains": [
          "prosperityplanningguide.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Phishing email impersonating Pennie, a Pennsylvania health insurance marketplace, uses prosperityplanningguide.com as sender and routes clicks to horizonpeak.shop. The Message-ID mismatch with adoreme.com suggests a spoofed sending environment. TKemmerling flagged 4 IOCs between 2026-08-30 and 2026-09-02.",
      "enriched_count": 4,
      "families": {},
      "first_seen": "2026-08-30",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-30",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-02",
        "window_days": 365
      },
      "id": "tfc-5b85735ac61b",
      "ioc_count": 4,
      "ioc_count_1d": 0,
      "ioc_count_30d": 4,
      "ioc_count_7d": 4,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 03:00:48",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094983856529326218",
          "type": "domain",
          "user": "TKemmerling",
          "value": "prosperityplanningguide.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 03:00:48",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094983856529326218",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://prosperityplanningguide.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:16:16",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096877092495704",
          "type": "domain",
          "user": "TKemmerling",
          "value": "prosperityplanningguide.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:16:16",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096877092495704",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://prosperityplanningguide.com"
        }
      ],
      "last_seen": "2026-09-02",
      "member_cluster_ids": [
        "tfc-5b85735ac61b"
      ],
      "name": "Pennie-branded loan phishing via prosperityplanningguide.com",
      "reporters": [
        "TKemmerling"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Pennie",
      "targeted_country": "US",
      "targeted_sector": "insurance",
      "threat_types": {
        "phishing": 4
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-25": 4
      },
      "anchors": {
        "registered_domains": [
          "hezhiad.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Phishing lures impersonating Scotiabank, Rogers wireless with a fake refund offer, and hotel booking services are served from loosun.net and hezhiad.com, both running on expresshost.cloud infrastructure. The shared lure themes, same reporter (skocherhan), and underlying platform link these two domains to a common operator. Eight IOCs were flagged on 2026-08-25.",
      "enriched_count": 4,
      "families": {},
      "first_seen": "2026-08-25",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-25",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-25",
        "window_days": 365
      },
      "id": "tfc-7f422aee4bf3",
      "ioc_count": 4,
      "ioc_count_1d": 0,
      "ioc_count_30d": 4,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 04:39:07",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2092109492695491017",
          "type": "domain",
          "user": "skocherhan",
          "value": "m.hezhiad.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 04:39:07",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2092109492695491017",
          "type": "url",
          "user": "skocherhan",
          "value": "http://m.hezhiad.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 04:39:07",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2092109492695491017",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hezhiad.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 04:39:07",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2092109492695491017",
          "type": "domain",
          "user": "skocherhan",
          "value": "hezhiad.com"
        }
      ],
      "last_seen": "2026-08-25",
      "member_cluster_ids": [
        "tfc-7f422aee4bf3"
      ],
      "name": "Scotiabank, Rogers, and hotel-themed phishing on loosun.net",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Scotiabank",
      "targeted_country": "CA",
      "targeted_sector": "financial-services",
      "threat_types": {
        "phishing": 4
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-25": 2,
        "2026-09-02": 2
      },
      "anchors": {
        "registered_domains": [
          "cartshopdaily.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "A phishing email impersonating Brinks Home security is sent from cartshopdaily.com and routes victim clicks to tophealthcareproduct.info with a mismatched phone number as a secondary indicator. The freshly registered sender domain is the primary attacker-controlled artifact in this single-reporter cluster. TKemmerling flagged 4 IOCs between 2026-08-25 and 2026-09-02.",
      "enriched_count": 4,
      "families": {},
      "first_seen": "2026-08-25",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-25",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-02",
        "window_days": 365
      },
      "id": "tfc-8b91a2b854d1",
      "ioc_count": 4,
      "ioc_count_1d": 0,
      "ioc_count_30d": 4,
      "ioc_count_7d": 2,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 14:06:36",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095151410031841566",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://cartshopdaily.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-02 14:06:36",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2095151410031841566",
          "type": "domain",
          "user": "TKemmerling",
          "value": "cartshopdaily.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 03:21:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092090059856187507",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://cartshopdaily.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-25 03:21:54",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2092090059856187507",
          "type": "domain",
          "user": "TKemmerling",
          "value": "cartshopdaily.com"
        }
      ],
      "last_seen": "2026-09-02",
      "member_cluster_ids": [
        "tfc-8b91a2b854d1"
      ],
      "name": "Brinks Home security quote phishing via cartshopdaily.com",
      "reporters": [
        "TKemmerling"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Brinks Home",
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "phishing": 4
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-13": 2,
        "2026-08-25": 2
      },
      "anchors": {
        "registered_domains": [
          "frontend148.blob.core.windows.net"
        ],
        "tags": [],
        "url_path_patterns": [
          "/main/remote_stager.py"
        ]
      },
      "confidence": "medium",
      "context": "frontend148.blob.core.windows.net stages a Python script (remote_stager.py) under /main/, indicating an attacker abusing Microsoft Azure Blob Storage as a payload host to evade network controls. TheDFIRReport and TheM3gatr0n flagged 4 IOCs between 2026-08-13 and 2026-08-25.",
      "enriched_count": 4,
      "families": {},
      "first_seen": "2026-08-13",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-13",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-25",
        "window_days": 365
      },
      "id": "tfc-a5d472396f19",
      "ioc_count": 4,
      "ioc_count_1d": 0,
      "ioc_count_30d": 4,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-25 13:06:38",
          "tags": [],
          "tweet": "https://x.com/TheM3gatr0n/status/2092237213174214656",
          "type": "url",
          "user": "TheM3gatr0n",
          "value": "http://frontend148.blob.core.windows.net/main/remote_stager.py"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-25 13:06:38",
          "tags": [],
          "tweet": "https://x.com/TheM3gatr0n/status/2092237213174214656",
          "type": "domain",
          "user": "TheM3gatr0n",
          "value": "frontend148.blob.core.windows.net"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-13 16:45:05",
          "tags": [],
          "tweet": "https://x.com/TheDFIRReport/status/2087943536066925004",
          "type": "url",
          "user": "TheDFIRReport",
          "value": "http://frontend148.blob.core.windows.net"
        },
        {
          "ai": {
            "threat_type": "malware"
          },
          "date": "2026-08-13 16:45:05",
          "tags": [],
          "tweet": "https://x.com/TheDFIRReport/status/2087943536066925004",
          "type": "domain",
          "user": "TheDFIRReport",
          "value": "frontend148.blob.core.windows.net"
        }
      ],
      "last_seen": "2026-08-25",
      "member_cluster_ids": [
        "tfc-a5d472396f19"
      ],
      "name": "Python remote stager hosted on Azure Blob Storage",
      "reporters": [
        "TheDFIRReport",
        "TheM3gatr0n"
      ],
      "tags": [],
      "targeted_brand": null,
      "targeted_country": null,
      "targeted_sector": null,
      "threat_types": {
        "c2": 1,
        "malware": 3
      },
      "ttps": [
        "T1608.001",
        "T1583.006"
      ],
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-24": 4
      },
      "anchors": {
        "registered_domains": [
          "ploferta3217832819.sbs"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "allegro.ploferta3217832819.sbs and allegrolokalnie.ploferta3217832819.sbs impersonate Allegro and its local-classifieds variant on a .sbs domain with a random numeric string. The subdomain naming mirrors Allegro's brand assets to deceive Polish users. One reporter flagged 4 IOCs on 2026-08-24.",
      "enriched_count": 4,
      "families": {},
      "first_seen": "2026-08-24",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-24",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-24",
        "window_days": 365
      },
      "id": "tfc-ab72a428ad26",
      "ioc_count": 4,
      "ioc_count_1d": 0,
      "ioc_count_30d": 4,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 17:01:20",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2091933892047499550",
          "type": "url",
          "user": "phishunt_io",
          "value": "http://allegrolokalnie.ploferta3217832819.sbs"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 17:01:20",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2091933892047499550",
          "type": "domain",
          "user": "phishunt_io",
          "value": "allegrolokalnie.ploferta3217832819.sbs"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 12:01:31",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2091858439353803119",
          "type": "url",
          "user": "phishunt_io",
          "value": "http://allegro.ploferta3217832819.sbs"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-24 12:01:31",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2091858439353803119",
          "type": "domain",
          "user": "phishunt_io",
          "value": "allegro.ploferta3217832819.sbs"
        }
      ],
      "last_seen": "2026-08-24",
      "member_cluster_ids": [
        "tfc-ab72a428ad26"
      ],
      "name": "Allegro marketplace phishing on .sbs typosquat",
      "reporters": [
        "phishunt_io"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Allegro",
      "targeted_country": "PL",
      "targeted_sector": "retail",
      "threat_types": {
        "phishing": 4
      },
      "ttps": [
        "T1566.002",
        "T1583.001",
        "T1684.001"
      ],
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-23": 4
      },
      "anchors": {
        "registered_domains": [
          "mainguardsec.site"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Subdomains nid-naver.mainguardsec.site and nid.naver.mainguardsec.site impersonate Naver's NID login portal (nid.naver.com), likely harvesting South Korean user credentials. The subdomain structure closely mirrors the legitimate Naver identity URL to deceive victims. One researcher flagged 4 IOCs on 2026-08-23.",
      "enriched_count": 4,
      "families": {},
      "first_seen": "2026-08-23",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-23",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-23",
        "window_days": 365
      },
      "id": "tfc-bd6c2a697b19",
      "ioc_count": 4,
      "ioc_count_1d": 0,
      "ioc_count_30d": 4,
      "ioc_count_7d": 0,
      "iocs": [
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "domain",
          "user": "skocherhan",
          "value": "nid.naver.mainguardsec.site"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "domain",
          "user": "skocherhan",
          "value": "nid-naver.mainguardsec.site"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "url",
          "user": "skocherhan",
          "value": "http://nid.naver.mainguardsec.site"
        },
        {
          "ai": {
            "threat_type": "c2"
          },
          "date": "2026-08-23 14:24:01",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2091531911449493728",
          "type": "url",
          "user": "skocherhan",
          "value": "http://nid-naver.mainguardsec.site"
        }
      ],
      "last_seen": "2026-08-23",
      "member_cluster_ids": [
        "tfc-bd6c2a697b19"
      ],
      "name": "Naver login phishing on mainguardsec.site",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#APT"
      ],
      "targeted_brand": "Naver",
      "targeted_country": "KR",
      "targeted_sector": "technology",
      "threat_types": {
        "c2": 4
      },
      "ttps": [
        "T1566.002",
        "T1583.001",
        "T1684.001"
      ],
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-30": 2,
        "2026-09-01": 2
      },
      "anchors": {
        "registered_domains": [
          "cedarpointlabs.blog"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Phishing email impersonating LifeLoans uses loanterritory.com for delivery and routes financial data submissions to the 10-day-old domain cedarpointlabs.blog. The recently registered backend domain is the primary indicator of attacker-controlled infrastructure. TKemmerling flagged 4 IOCs between 2026-08-30 and 2026-09-01.",
      "enriched_count": 4,
      "families": {},
      "first_seen": "2026-08-30",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-30",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-09-01",
        "window_days": 365
      },
      "id": "tfc-e038718e881c",
      "ioc_count": 4,
      "ioc_count_1d": 0,
      "ioc_count_30d": 4,
      "ioc_count_7d": 4,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 14:35:06",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094796191158727164",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://cedarpointlabs.blog"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-09-01 14:35:06",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094796191158727164",
          "type": "domain",
          "user": "TKemmerling",
          "value": "cedarpointlabs.blog"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:15:57",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096796268294642",
          "type": "url",
          "user": "TKemmerling",
          "value": "http://cedarpointlabs.blog"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-30 16:15:57",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/TKemmerling/status/2094096796268294642",
          "type": "domain",
          "user": "TKemmerling",
          "value": "cedarpointlabs.blog"
        }
      ],
      "last_seen": "2026-09-01",
      "member_cluster_ids": [
        "tfc-e038718e881c"
      ],
      "name": "LifeLoans phishing via cedarpointlabs.blog",
      "reporters": [
        "TKemmerling"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "LifeLoans",
      "targeted_country": null,
      "targeted_sector": "financial-services",
      "threat_types": {
        "phishing": 4
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-27": 2,
        "2026-08-31": 2
      },
      "anchors": {
        "registered_domains": [
          "icloud-i-cl.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Apple iCloud lookalike domain icloud-i-cl.com and its mail. subdomain were registered on 2026-08-25 and served phishing pages via Cloudflare (AS13335). The domain embeds the iCloud brand string in a hyphenated pattern to deceive victims into entering credentials. Phishunt_io reported 4 IOCs between 2026-08-27 and 2026-08-31.",
      "enriched_count": 4,
      "families": {},
      "first_seen": "2026-08-27",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-27",
        "iocs_365d": 4,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-31",
        "window_days": 365
      },
      "id": "tfc-e78d161f6652",
      "ioc_count": 4,
      "ioc_count_1d": 0,
      "ioc_count_30d": 4,
      "ioc_count_7d": 2,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-31 17:01:03",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2094470533828035043",
          "type": "domain",
          "user": "phishunt_io",
          "value": "mail.icloud-i-cl.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-31 17:01:03",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2094470533828035043",
          "type": "url",
          "user": "phishunt_io",
          "value": "http://mail.icloud-i-cl.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 12:01:14",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2092945532503179671",
          "type": "domain",
          "user": "phishunt_io",
          "value": "icloud-i-cl.com"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-27 12:01:14",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/phishunt_io/status/2092945532503179671",
          "type": "url",
          "user": "phishunt_io",
          "value": "http://icloud-i-cl.com"
        }
      ],
      "last_seen": "2026-08-31",
      "member_cluster_ids": [
        "tfc-e78d161f6652"
      ],
      "name": "Apple iCloud phishing on icloud-i-cl.com lookalike domain",
      "related": {
        "checked_at": "2026-09-04T06:56:16Z",
        "match_count": 2,
        "matches": [
          {
            "asn": "AS13335",
            "company": "apple",
            "domain": "icloud-i-cl.com",
            "match": "exact"
          },
          {
            "asn": "AS13335",
            "company": "apple",
            "domain": "mail.icloud-i-cl.com",
            "match": "exact"
          }
        ],
        "source": "phishunt.io"
      },
      "reporters": [
        "phishunt_io"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Apple",
      "targeted_country": null,
      "targeted_sector": "technology",
      "threat_types": {
        "phishing": 4
      },
      "ttps": [
        "T1566.002",
        "T1583.001",
        "T1684.001"
      ],
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "activity": {
        "2026-08-31": 3
      },
      "anchors": {
        "registered_domains": [
          "pvvchxh.cn"
        ],
        "tags": [],
        "url_path_patterns": [
          "/tNijauryj"
        ]
      },
      "confidence": "low",
      "context": "A single .cn domain pvvchxh.cn and its rnwm. subdomain serve Amazon-branded phishing pages with an /ap/ path targeting Japanese users, hosted at 43.165.128.22 (AS132203). The /ap/ path mimics Amazon Japan's sign-in endpoint structure. Two reporters flagged 3 IOCs on 2026-08-31.",
      "enriched_count": 3,
      "families": {},
      "first_seen": "2026-08-31",
      "history": {
        "by_pattern": [],
        "domains_365d": 1,
        "first_seen_365d": "2026-08-31",
        "iocs_365d": 3,
        "iocs_before_window": 0,
        "last_seen_365d": "2026-08-31",
        "window_days": 365
      },
      "id": "tfc-4536c14bf828",
      "ioc_count": 3,
      "ioc_count_1d": 0,
      "ioc_count_30d": 3,
      "ioc_count_7d": 3,
      "iocs": [
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-31 06:37:28",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2094313604724212181",
          "type": "url",
          "user": "Metemcyber",
          "value": "https://rnwm.pvvchxh.cn/ap/"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-31 03:42:09",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2094269486916575527",
          "type": "domain",
          "user": "masaomi346",
          "value": "rnwm.pvvchxh.cn"
        },
        {
          "ai": {
            "threat_type": "phishing"
          },
          "date": "2026-08-31 03:42:09",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2094269486916575527",
          "type": "url",
          "user": "masaomi346",
          "value": "https://rnwm.pvvchxh.cn/t10ijauryj"
        }
      ],
      "last_seen": "2026-08-31",
      "member_cluster_ids": [
        "tfc-4536c14bf828"
      ],
      "name": "Amazon Japan phishing on pvvchxh.cn via /ap/ login path",
      "reporters": [
        "Metemcyber",
        "masaomi346"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Amazon",
      "targeted_country": "JP",
      "targeted_sector": "retail",
      "threat_types": {
        "phishing": 3
      },
      "ttps": [
        "T1566.002",
        "T1583.001"
      ],
      "types": {
        "domain": 1,
        "url": 2
      }
    }
  ],
  "generated_at": "2026-09-04T06:56:16Z",
  "stale": false,
  "stale_since": null,
  "version": 1,
  "window": "month"
}
