{
    "count": 250,
    "indicators": [
        {
            "ioc_value": "https:\/\/www.netskope.com\/jp\/blog\/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "ioc_type": "url",
            "category": "Malware Attribution",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:07:43",
            "last_seen": "2026-08-06 19:46:51"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/MA\/Conting%C3%AAncia\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/SP\/Conting%C3%AAncia\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/PA\/Conting%C3%AAncia\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/PA\/Conting%C3%AAncia\/Homologa%C3%A7%C3%A3o\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/PA\/Conting%C3%AAncia\/Produ%C3%A7%C3%A3o\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/PB\/Conting%C3%AAncia\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/DF\/Conting%C3%AAncia\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/PE\/Conting%C3%AAncia\/Produ%C3%A7%C3%A3o\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/PE\/Conting%C3%AAncia\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/MA\/Conting%C3%AAncia\/Produ%C3%A7%C3%A3o\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/ES\/Conting%C3%AAncia\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/DF\/Conting%C3%AAncia\/Produ%C3%A7%C3%A3o\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "http:\/\/177.70.102.228:8070\/TmpFTP\/Disponibilidade%20de%20Servi%C3%A7o\/PB\/Conting%C3%AAncia\/Produ%C3%A7%C3%A3o\/info.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:50"
        },
        {
            "ioc_value": "https:\/\/submerged-continental-shelf.garden\/f600ff02-9b3d-437d-9f2d-da6a8bce13f0\/google.ct",
            "ioc_type": "url",
            "category": "Malware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 19:46:48",
            "last_seen": "2026-08-06 19:46:48"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/AjayAjishaa\/Contiguous\/main\/downstream\/Software-3.1-beta.2.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:44"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/patenintercontinental4580\/apex-platform\/main\/terraform\/modules\/azure-spoke-vnet\/apex-platform-v3.4.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:44"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/lidand5937\/leads-intercontinental\/main\/assets\/intercontinental-leads-2.7.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:40",
            "last_seen": "2026-08-06 19:46:43"
        },
        {
            "ioc_value": "http:\/\/submerged-continental-shelf.garden\/f600ff02-9b3d-437d-9f2d-da6a8bce13f0\/google.ct",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:07:38",
            "last_seen": "2026-08-06 19:46:39"
        },
        {
            "ioc_value": "us.raccontieassaggi.xyz",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:56",
            "last_seen": "2026-08-06 14:48:50"
        },
        {
            "ioc_value": "continentaldividefilm.com",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:51",
            "last_seen": "2026-08-06 14:48:44"
        },
        {
            "ioc_value": "arcanacontinum.com",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:50",
            "last_seen": "2026-08-06 14:48:43"
        },
        {
            "ioc_value": "contirnext.com",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:50",
            "last_seen": "2026-08-06 14:48:43"
        },
        {
            "ioc_value": "mint.arcanacontinuum.space",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:50",
            "last_seen": "2026-08-06 14:48:43"
        },
        {
            "ioc_value": "arbitrum.bitcontinuity.com",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:49",
            "last_seen": "2026-08-06 14:48:41"
        },
        {
            "ioc_value": "https:\/\/www.forescout.com\/resources\/analysis-of-conti-leaks\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.carbonblack.com\/2016\/04\/28\/threat-advisory-squiblydoo-continues-trend-of-attackers-using-native-os-tools-to-live-off-the-land\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/unit42-sofacy-continues-global-attacks-wheels-new-cannon-trojan\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/community.cisco.com\/t5\/security-blogs\/attackers-continue-to-target-legacy-devices\/ba-p\/4169954",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/systembc-coroxy-continuous-activities",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2018\/11\/unit42-sofacy-continues-global-attacks-wheels-new-cannon-trojan\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/blogs\/research\/the-continued-evolution-of-the-darkgate-malware-as-a-service\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/lazarus-continues-heists-mounts-attacks-on-financial-organizations-in-latin-america\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/fin7-5-the-infamous-cybercrime-rig-fin7-continues-its-activities\/90703\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cylance.com\/shell-crew-variants-continue-to-fly-under-big-avs-radar",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2018\/01\/unit42-comnie-continues-target-organizations-east-asia\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/blog\/apt29-continues-targeting-microsoft",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/2018\/01\/samsam-evolution-continues-netting-over.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.carbonblack.com\/blog\/tau-threat-discovery-conti-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cybleinc.com\/2021\/01\/21\/conti-ransomware-resurfaces-targeting-government-large-organizations\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs.-conti-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2021\/06\/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/blog.google\/threat-analysis-group\/exposing-initial-access-broker-ties-conti\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20200420201624\/https:\/\/securityintelligence.com\/posts\/ta505-continues-to-infect-networks-with-sdbbot-rat\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20190625182633if_\/https:\/\/ti.360.net\/blog\/articles\/apt-c-36-continuous-attacks-targeting-colombian-government-institutions-and-corporations-en\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2018\/03\/unit42-patchwork-continues-deliver-badnews-indian-subcontinent\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/akira-ransomware-continues-to-evolve\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/arcticwolf.com\/resources\/blog\/conti-and-akira-chained-together\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/scarcruft-continues-to-evolve-introduces-bluetooth-harvester\/90729\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/11\/29\/continuing-the-bazar-ransomware-story\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/c\/earth-vetala---muddywater-continues-to-target-organizations-in-t.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2021\/indigozebra-apt-continues-to-attack-central-asia-with-evolving-tools\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "accounts.google.com.serviceloginservicemailpassivetruerm-falsecontinuemail.google.com.mail.ss1scc1tmpldefaultltmplcache2emr1osid1.financetrendnews.com",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:11",
            "last_seen": "2026-08-06 14:47:32"
        },
        {
            "ioc_value": "addrfinancialcontinue33providing.weebly.com",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:11",
            "last_seen": "2026-08-06 14:47:32"
        },
        {
            "ioc_value": "https:\/\/blog.cylance.com\/shell-crew-variants-continue-to-fly-under-big-avs-radar",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2020\/04\/28\/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/info.phishlabs.com\/blog\/silent-librarian-university-attacks-continue-unabated-in-days-following-indictment",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20130701021735\/https:\/\/www.symantec.com\/connect\/blogs\/four-years-darkseoul-cyberattacks-against-south-korea-continue-anniversary-korean-war",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.sekoia.io\/calisto-continues-its-credential-harvesting-campaign",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.recordedfuture.com\/research\/bluecharlie-previously-tracked-as-tag-53-continues-to-deploy-new-infrastructure-in-2023",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.databreaches.net\/thai-entities-continue-to-fall-prey-to-cyberattacks-and-leaks\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.ncsc.gov.uk\/files\/Advisory-Russian-FSB-cyber-actor-star-blizzard-continues-worldwide-spear-sphishing-campaigns.pdf",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/indonesian-sudanese-cyber-threats-continue-grow-size-scope\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/copacabana-barcelona-cross-continental-threat-brazilian-banking-malware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2017\/07\/unit42-tick-group-continues-attacks\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/threatvector.cylance.com\/en_us\/home\/shell-crew-variants-continue-to-fly-under-big-avs-radar.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.google\/threat-analysis-group\/continued-cyber-activity-in-eastern-europe-observed-by-tag",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/new-and-improved-madi-spyware-campaign-continues-072512\/76849\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/community.rsa.com\/community\/products\/netwitness\/blog\/2018\/02\/13\/lotus-blossom-continues-asean-targeting",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/cyber-soft-power-chinas-continental-takeover\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/lookback-forges-ahead-continued-targeting-united-states-utilities-sector-reveals",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/posts\/ta505-continues-to-infect-networks-with-sdbbot-rat\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.google\/threat-analysis-group\/exposing-initial-access-broker-ties-conti",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/strapi.eurepoc.eu\/uploads\/Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.rewterz.com\/rewterz-news\/rewterz-threat-alert-leaked-conti-ransomware-used-to-target-russia-active-iocs",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/ti.360.net\/blog\/articles\/apt-c-36-continuous-attacks-targeting-colombian-government-institutions-and-corporations-en\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.deepinstinct.com\/blog\/threat-actor-uac-0099-continues-to-target-ukraine",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "contiuevxdgdhn3zl2kubpajtfgqq4ssj2ipv6ujw7fwhggev3rk6hqd.onion",
            "ioc_type": "onion",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "http:\/\/contiuevxdgdhn3zl2kubpajtfgqq4ssj2ipv6ujw7fwhggev3rk6hqd.onion",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "continews.click",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "http:\/\/continews.click",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "continews.bz",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "http:\/\/continews.bz",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "continewsnv5otx5kaoje7krkto2qbu3gtqef22mnr7eaxw3y6ncz3ad.onion",
            "ioc_type": "onion",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "http:\/\/continewsnv5otx5kaoje7krkto2qbu3gtqef22mnr7eaxw3y6ncz3ad.onion\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "CONTI.News",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/conti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "furnisconti.com",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:26",
            "last_seen": "2026-08-06 14:44:59"
        },
        {
            "ioc_value": "discontinued.site",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:23",
            "last_seen": "2026-08-06 14:44:57"
        },
        {
            "ioc_value": "continentalretribrrutions.info",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 14:44:56"
        },
        {
            "ioc_value": "continualai.life",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 14:44:56"
        },
        {
            "ioc_value": "continuationspeach.jneck.com",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 14:44:56"
        },
        {
            "ioc_value": "continuationssmell.geracaoinvest.com",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 14:44:56"
        },
        {
            "ioc_value": "continuesmotherbbhouse.info",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 14:44:56"
        },
        {
            "ioc_value": "continuingto.com",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 14:44:56"
        },
        {
            "ioc_value": "continuity.zone",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 14:44:56"
        },
        {
            "ioc_value": "continuouspent.printerial.com",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 14:44:56"
        },
        {
            "ioc_value": "continvu.com",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 14:44:56"
        },
        {
            "ioc_value": "beacontin.vip",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:08:20",
            "last_seen": "2026-08-06 14:44:53"
        },
        {
            "ioc_value": "1760891282-pol-n544534f54634z.visconticentrotim.it",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:08:15",
            "last_seen": "2026-08-06 14:44:47"
        },
        {
            "ioc_value": "continuously-protected-kiss-bread.trycloudflare.com",
            "ioc_type": "other",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:11",
            "last_seen": "2026-08-06 14:43:53"
        },
        {
            "ioc_value": "dhprasetyocontinenteightbizdhprasetyocontinenteightbiz.ydns.eu",
            "ioc_type": "other",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:49"
        },
        {
            "ioc_value": "continentaltourist.icu",
            "ioc_type": "other",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:07",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "autodiscover.continueoraweb.com",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:37",
            "last_seen": "2026-08-06 14:42:14"
        },
        {
            "ioc_value": "avoiding-discontinuous.click",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:37",
            "last_seen": "2026-08-06 14:42:14"
        },
        {
            "ioc_value": "alzheimercapacitacioncontinua.org",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:34",
            "last_seen": "2026-08-06 14:42:11"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/arid-viper-apts-nest-of-spyc23-malware-continues-to-target-android-devices\/",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "https:\/\/cyble.com\/blog\/mobile-malware-app-anubis-strikes-again-continues-to-lure-users-disguised-as-a-fake-antivirus\/",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "bbvacontinental.co.at.hm",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:43",
            "last_seen": "2026-08-06 14:41:11"
        },
        {
            "ioc_value": "be.contimo.app",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:43",
            "last_seen": "2026-08-06 14:41:11"
        },
        {
            "ioc_value": "ashameskirmishcontinuing.com",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:41",
            "last_seen": "2026-08-06 14:41:09"
        },
        {
            "ioc_value": "aconti.net",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:36",
            "last_seen": "2026-08-06 14:41:03"
        },
        {
            "ioc_value": "accountinglocksmithcontinental.com",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:36",
            "last_seen": "2026-08-06 14:41:03"
        },
        {
            "ioc_value": "5continents.com",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:35",
            "last_seen": "2026-08-06 14:41:01"
        },
        {
            "ioc_value": "continuumdownload.com",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 14:40:55",
            "last_seen": "2026-08-06 14:40:55"
        },
        {
            "ioc_value": "kesconti.com",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:27",
            "last_seen": "2026-08-06 14:40:54"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/19\/h\/dharma-ransomware-continues-to-target-servers-via-open-rdp-ports.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/blacksuit-ransomware-a-former-conti-affiliate-rebrands-and-evolves\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "http:\/\/contirec7nchr45rx6ympez5rjldibnqzh7lsa56lvjvaeywhvoj3wad.onion\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/contirecj4hbzmyzuydyzrvm2c65blmvhoj2cvf25zqj2dwrrqcq5oad.onion\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/contirecj4hbzmyzuydyzrvm2c65blmvhoj2cvf25zqj2dwrrqcq5oad.onion",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/contirecovery.best",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/contirecovery.top",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/advisories\/2021-010-acsc-ransomware-profile-conti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/doppelpaymer-continues-cause-grief-through-rebranding",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/affiliate-leaks-conti-ransomware-playbook\/168442",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/conti-ransomware-gang",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.esentire.com\/blog\/analysis-of-leaked-conti-intrusion-procedures-by-esentires-threat-response-unit-tru",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/gold-ulrick-continues-conti-operations-despite-public-disclosures",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.threatstop.com\/blog\/first-conti-then-hive-costa-rica-gets-hit-with-ransomware-again",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/threat-labs\/conti-group-targets-esxi-hypervisors-with-its-linux-variant.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/chuongdong.com\/reverse%20engineering\/2020\/12\/15\/ContiRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/0xthreatintel.medium.com\/reversing-conti-ransomware-bfce15019e74",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/arcticwolf.com\/resources\/blog\/conti-ransomware-leak-analyzed",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/areteir.com\/wp-content\/uploads\/2020\/08\/Arete_Insight_Is-Conti-the-new-Ryuk_August2020.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/assets.sentinelone.com\/ransomware-enterprise\/conti-ransomware-unpacked",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/attackiq.com\/2022\/06\/15\/attack-graph-emulating-the-conti-ransomware-teams-behaviors\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.bushidotoken.net\/2022\/04\/lessons-from-conti-leaks.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2021\/11\/18\/conti-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.reversinglabs.com\/blog\/conversinglabs-ep-2-conti-pivots-as-ransomware-as-a-service-struggles",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/2021\/09\/Conti-leak-translation.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/2022\/05\/conti-and-hive-ransomware-operations.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cluster25.io\/2022\/03\/02\/contis-source-code-deep-dive-into\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cocomelonc.github.io\/investigation\/2022\/03\/27\/malw-inv-conti-1.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/karakurt-data-extortion-group-linked-to-conti-ransomware-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cocomelonc.github.io\/investigation\/2022\/04\/11\/malw-inv-conti-2.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cybersecurity.att.com\/blogs\/security-essentials\/stories-from-the-soc-powershell-proxyshell-conti-ttps-oh-my",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cyware.com\/news\/ransomware-becomes-deadlier-conti-makes-the-most-money-39e17bae\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/eclypsium.com\/2022\/06\/02\/conti-targets-critical-firmware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/TheParmak\/conti-leaks-englished",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/cdong1012\/ContiUnpacker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/whichbuffer\/Conti-Ransomware-IOC",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/conti-emotet-ransomware-conti-leaks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/conti-leaks-cybercrime-fire-team",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/conti-vs-monti-a-reinvention-or-just-a-simple-rebranding",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2021\/10\/conti-ransom-gang-starts-selling-access-to-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2022\/03\/conti-ransomware-group-diaries-part-ii-the-office\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/continental-confirms-data-breach-after-donut-leaks-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/lifars.com\/wp-content\/uploads\/2021\/10\/ContiRansomware_Whitepaper.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/continental-confirms-data-breach-donut-leaks-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/marcoramilli.com\/2021\/11\/07\/conti-ransomware-cheat-sheet\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.securityweek.com\/donut-leaks-ransomware-group-claims-attack-on-continental\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/@arnozobec\/analyzing-conti-leaks-without-speaking-russian-only-methodology-f5aecc594d1b",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/@whickey000\/how-i-cracked-conti-ransomware-groups-leaked-source-code-zip-file-e15d54663a8",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/nakedsecurity.sophos.com\/2021\/08\/06\/conti-ransomware-affiliate-goes-rogue-leaks-company-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/02\/16\/conti-ransomware-attack-day-by-day\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/02\/16\/conti-ransomware-evasive-by-nature\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/02\/16\/what-to-expect-when-youve-been-hit-with-conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/09\/03\/conti-affiliates-use-proxyshell-exchange-exploit-in-ransomware-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2022\/02\/28\/conti-and-karma-actors-attack-healthcare-provider-at-same-time-through-proxyshell-exploits\/?cmp=30728",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2022\/leaks-of-conti-ransomware-group-paint-picture-of-a-surprisingly-normal-tech-start-up-sort-of\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/research.nccgroup.com\/2022\/03\/31\/conti-nuation-methods-and-techniques-observed-in-operations-post-the-leaks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityaffairs.co\/wordpress\/128190\/cyber-crime\/conti-ransomware-takes-over-trickbot.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/share.vx-underground.org\/Conti\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.quickheal.com\/maze-ransomware-continues-threat-consumers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/ransomware-hive-conti-avoslocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/05\/12\/conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/08\/01\/bazarcall-to-conti-ransomware-via-trickbot-and-cobalt-strike\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/09\/13\/bazarloader-to-conti-ransomware-in-32-hours\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/10\/04\/bazarloader-and-the-conti-leaks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/conti-ransomware-cooperation-maze-lockbit-ragnar-locker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2022\/04\/04\/stolen-images-campaign-ends-in-conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/conti-leaks-the-panama-papers-of-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/disgruntled-ransomware-affiliate-leaks-the-conti-gangs-technical-manuals\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/affiliate-leaks-conti-ransomware-playbook\/168442\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/conti-ransomware-decryptor-trickbot-source-code-leaked\/178727\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/conti-ransomware-v-3-including-decryptor-leaked\/179006\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/conti-ransomware-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advanced-intel.com\/post\/secret-backdoor-behind-conti-ransomware-operation-introducing-atera-agent",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advintel.io\/post\/24-hours-from-log4shell-to-local-admin-deep-dive-into-conti-gang-attack-on-fortune-500-dfir",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advintel.io\/post\/backup-removal-solutions-from-conti-ransomware-with-love",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advintel.io\/post\/discontinued-the-end-of-conti-s-brand-marks-new-chapter-for-cybercrime-landscape",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/conti-ransomware-gang-chats-leaked-by-pro-ukraine-member\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bankinfosecurity.com\/cybercrime-moves-conti-ransomware-absorbs-trickbot-malware-a-18573",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/angry-conti-ransomware-affiliate-leaks-gangs-attack-playbook\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-updates-conti-ransomware-alert-with-nearly-100-domain-names\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/conti-ransomware-gang-takes-over-trickbot-malware-operation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/conti-ransomware-source-code-leaked-by-ukrainian-researcher\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/conti-ransomwares-internal-chats-leaked-after-siding-with-russia\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-use-contis-leaked-ransomware-to-attack-russian-companies\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hhs-conti-ransomware-encrypted-80-percent-of-irelands-hse-it-systems\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/karakurt-revealed-as-data-extortion-arm-of-conti-cybercrime-syndicate\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ryuk-successor-conti-ransomware-releases-data-leak-site\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/taiwanese-apple-and-tesla-contractor-hit-by-conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.clearskysec.com\/wp-content\/uploads\/2021\/02\/Conti-Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.connectwise.com\/resources\/conti-profile",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyberark.com\/resources\/threat-research-blog\/conti-group-leaked",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/threat-analysis-report-from-shatak-emails-to-the-conti-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/labs.sentinelone.com\/avaddon-raas-breaks-public-decryptor-continues-on-rampage\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/threat-labs\/conti-leaks-examining-the-panama-papers-of-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyberscoop.com\/ransomware-gang-conti-bounced-back\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.darktrace.com\/en\/blog\/the-double-extortion-business-conti-ransomware-gang-finds-new-avenues-of-negotiation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.dragos.com\/blog\/industry-news\/suspected-conti-ransomware-activity-in-the-auto-manufacturing-sector\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elliptic.co\/blog\/conti-ransomware-nets-at-least-25.5-million-in-four-months",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.esentire.com\/blog\/conti-affiliate-exposed-new-domain-names-ip-addresses-and-email-addresses-uncovered-by-esentire",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.hse.ie\/eng\/services\/publications\/conti-cyber-attack-on-the-hse-full-report.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sonicwall.com\/blog\/amnesia-ransomware-continues-high-payment-trend-july-21-2017",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mbsd.jp\/2022\/03\/08\/assets\/images\/MBSD_Summary_of_ContiLeaks_Rev3.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mbsd.jp\/research\/20210413\/conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.ncsc.gov.ie\/pdfs\/HSE_Conti_140521_UPDATE.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.prodaft.com\/m\/reports\/Conti_TLPWHITE_v1.6_WVcSEtc.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.redhotcyber.com\/post\/il-ransomware-conti-si-schiera-a-favore-della-russia",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-by-the-numbers\/lockbit-conti-and-blackcat-lead-pack-amid-rise-in-active-raas-and-extortion-groups-ransomware-in-q1-2022",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sekoia.io\/en\/an-insider-insights-into-conti-operations-part-one",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sekoia.io\/en\/an-insider-insights-into-conti-operations-part-two\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.silentpush.com\/blog\/consequences-the-conti-leaks-and-future-problems",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.threatstop.com\/blog\/conti-ransomware-source-code-leaked",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-conti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trmlabs.com\/post\/analysis-corroborates-suspected-ties-between-conti-and-ryuk-ransomware-groups-and-wizard-spider",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.truesec.com\/hub\/blog\/proxyshell-qbot-and-conti-ransomware-combined-in-a-series-of-cyber-attacks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.unh4ck.com\/detection-engineering-and-threat-hunting\/lateral-movement\/detecting-conti-cobaltstrike-lateral-movement-techniques-part-1",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.unh4ck.com\/detection-engineering-and-threat-hunting\/lateral-movement\/detecting-conti-cobaltstrike-lateral-movement-techniques-part-2",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/conti-ransomware-attacks-persist-updated-version-despite-leaks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/how-to-defend-against-conti-darkside-revil-and-other-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/yoroi.company\/research\/conti-ransomware-source-code-a-well-designed-cots-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.ransomlook.io\/group\/conti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/ransomware-explosion-continues-cryptflle2-brlock-mm-locker-discovered",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/blackbasta-ransomware-linked-to-conti-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/ransomware-double-extortion-and-beyond-revil-clop-and-conti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/petya-ransomware-returns-with-goldeneye-version-continuing-james-bond-theme\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "continuar-verify365.kesug.com",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 13:08:22"
        },
        {
            "ioc_value": "cartaocontinte-ptrc.cfd",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 13:08:22"
        },
        {
            "ioc_value": "cartaocontinte-ptsz.cfd",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 13:08:22"
        },
        {
            "ioc_value": "cartaocontintene.cfd",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 13:08:22"
        },
        {
            "ioc_value": "cartaocontintve.cfd",
            "ioc_type": "other",
            "category": "Phishing",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:08:22",
            "last_seen": "2026-08-06 13:08:22"
        },
        {
            "ioc_value": "https:\/\/img1.wsimg.com\/blobby\/go\/bb45e14d-29c5-4287-b67f-843105f3b091\/downloads\/continental_online_assessment_test_answers.pdf",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/continentalgroup.net.in\/squalid.php",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/www.benshamcentre.co.uk\/continue\/45.ps1",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        }
    ]
}