{
    "count": 2875,
    "indicators": [
        {
            "ioc_value": "https:\/\/github.com\/TheRavenFile\/Daily-Hunt\/blob\/main\/Gentlemen%20Ransomware",
            "ioc_type": "url",
            "category": "Malware Attribution",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:07:43",
            "last_seen": "2026-08-06 19:46:51"
        },
        {
            "ioc_value": "https:\/\/github.com\/TheRavenFile\/IOC\/blob\/main\/INC-Lynx%20Ransomware",
            "ioc_type": "url",
            "category": "Malware Attribution",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:07:43",
            "last_seen": "2026-08-06 19:46:51"
        },
        {
            "ioc_value": "https:\/\/github.com\/TheRavenFile\/Daily-Hunt\/blob\/main\/Warlock%20Ransomware",
            "ioc_type": "url",
            "category": "Malware Attribution",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:07:43",
            "last_seen": "2026-08-06 19:46:51"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/samftggr\/VEN0m-Ransomware\/main\/src\/VE_m_Ransomware_2.9.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:40",
            "last_seen": "2026-08-06 19:46:43"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/how-falcon-complete-stopped-a-big-game-hunting-ransomware-attack\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2022\/11\/28\/emotet-strikes-again-lnk-file-leads-to-domain-wide-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.securityinbits.com\/malware-analysis\/parent-pid-spoofing-stage-2-ataware-ransomware-part-3",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.recordedfuture.com\/blog\/esxiargs-ransomware-targets-vmware-esxi-openslp-servers",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/double-trouble-ransomware-data-leak-extortion-part-1\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 8,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/blog\/ransomware-extortion-ot-docs",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.cisa.gov\/sites\/default\/files\/Ransomware_Trifold_e-version.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/posts.inthecyber.com\/exposed-fortinet-fortigate-firewall-interface-leads-to-lockbit-ransomware-cve-2024-55591-8f4b7a244041",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/r980-ransomware-disposable-email-service\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/d\/an-investigation-of-the-blackcat-ransomware.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/noberus-blackcat-alphv-rust-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.huntress.com\/blog\/blackcat-ransomware-affiliate-ttps",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/chasing-avaddon-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2022\/05\/avoslocker-ransomware-variant-using-new.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/targeted-dharma-ransomware-intrusions-exhibit-consistent-techniques\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/cdn.logic-control.com\/docs\/scadafence\/Anatomy-Of-A-Targeted-Ransomware-Attack-WP.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/techcommunity.microsoft.com\/t5\/core-infrastructure-and-security\/demystifying-ransomware-attacks-against-microsoft-defender\/ba-p\/1928947",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/24\/g\/new-play-ransomware-linux-variant-targets-esxi-shows-ties-with-p.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.security.com\/threat-intelligence\/play-ransomware-volume-shadow-copy",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/blog\/unc3944-sms-phishing-sim-swapping-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/diavol-new-ransomware-used-by-wizard-spider",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/en-us\/blog\/how-falcon-complete-stopped-a-big-game-hunting-ransomware-attack\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ryuk-ransomware-uses-wake-on-lan-to-encrypt-offline-devices\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/fbi-fin7-hackers-target-us-companies-with-badusb-devices-to-install-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/how-to-decrypt-the-partyticket-ransomware-targeting-ukraine",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cyber.gov.au\/about-us\/advisories\/2022-004-acsc-ransomware-profile-alphv-aka-blackcat",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2022\/07\/14\/blackcat-ransomware-attacks-not-merely-a-byproduct-of-bad-luck\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/06\/13\/the-many-lives-of-blackcat-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/killdisk-disk-wiping-malware-adds-ransomware-component\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2020\/11\/23\/pysa-mespinoza-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/h\/new-golang-ransomware-agenda-customizes-attacks.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-ransomhub",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/25\/j\/agenda-ransomware-deploys-linux-variant-on-windows-systems.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/black-basta-ransomware-attacks-deploy-custom-edr-evasion-tools-tied-to-fin7-threat-actor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cisa.gov\/sites\/default\/files\/2024-09\/aa24-242a-stopransomware-ransomhub-ransomware_1.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2018\/09\/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/lockbit-2-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/redcanary.com\/blog\/how-one-hospital-thwarted-a-ryuk-ransomware-outbreak\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-cuba-ransomware.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cynet.com\/blog\/cynet-detection-report-ragnar-locker-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/05\/21\/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/blogs\/research\/akira-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/enter-the-darkgate-new-cryptocurrency-mining-and-ransomware-campaign",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.dragos.com\/blog\/industry-news\/ekans-ransomware-and-ics-operations\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cisa.gov\/sites\/default\/files\/2023-03\/aa23-075a-stop-ransomware-lockbit.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/threat-assessment-ekans-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/02\/ransomware-against-machine-learning-to-disrupt-industrial-production.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/lockbit-3-0-update-unpicking-the-ransomwares-latest-anti-analysis-and-evasion-techniques",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/ransomware-abuses-bitlocker\/112643\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/clop-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/shinyhunters-ransomware-extortion\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs.-clop-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/clop-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/evilquest-a-new-macos-malware-rolls-ransomware-spyware-and-data-theft-into-one\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/2017\/06\/worldwide-ransomware-variant.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/mac\/2020\/07\/mac-thiefquest-malware-may-not-be-ransomware-after-all\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.avertium.com\/resources\/threat-reports\/in-depth-look-at-black-basta-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20220506143054\/https:\/\/blog.cyble.com\/2022\/05\/06\/black-basta-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/threat-assessment-black-basta-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.deepinstinct.com\/blog\/black-basta-ransomware-threat-emergence",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.carbonblack.com\/2019\/05\/14\/cb-tau-threat-intelligence-notification-jcry-ransomware-pretends-to-be-adobe-flash-player-update-installer\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/11\/15\/exchange-exploit-leads-to-domain-wide-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/04\/unc2447-sombrat-and-fivehands-ransomware-sophisticated-financial-threat.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/minerva-labs.com\/blog\/new-black-basta-ransomware-hijacks-windows-fax-service\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/2019\/04\/sodinokibi-ransomware-exploits-weblogic.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/threatvector.cylance.com\/en_us\/home\/threat-spotlight-sodinokibi-ransomware.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.group-ib.com\/whitepapers\/ransomware-uncovered.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/synack-targeted-ransomware-uses-the-doppelganging-technique\/85431\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/revil-ransomware-as-a-service-an-analysis-of-a-ransomware-affiliate-operation\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/sodin-ransomware\/91473\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/awakesecurity.com\/blog\/threat-hunting-for-avaddon-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.picussecurity.com\/blog\/a-brief-history-and-further-technical-analysis-of-sodinokibi-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cybleinc.com\/2020\/10\/31\/egregor-ransomware-a-deep-dive-into-its-activities-and-techniques\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-crescendo\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20210414101816\/https:\/\/tetradefense.com\/incident-response-services\/cause-and-effect-sodinokibi-ransomware-analysis\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-has-a-new-windows-safe-mode-encryption-mode\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/medusalocker-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2019\/12\/09\/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.varonis.com\/blog\/vmware-esxi-in-the-line-of-ransomware-fire",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/darkside-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/netwalker-fileless-ransomware-injected-via-reflective-loading\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/research\/wcry-ransomware-analysis",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20230522041200\/https:\/\/logrhythm.com\/blog\/a-technical-analysis-of-wannacry-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/research.nccgroup.com\/2020\/06\/23\/wastedlocker-a-new-ransomware-variant-developed-by-the-evil-corp-group\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/wastedlocker-ransomware-us",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/wastedlocker-ransomware-abusing-ads-and-ntfs-file-attributes\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.carbonblack.com\/2019\/03\/22\/tau-threat-intelligence-notification-lockergoga-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20220119114433\/https:\/\/groupib.pathfactory.com\/ransomware-reports\/prolock_wp",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cloudsek.com\/blog\/analysis-of-files-used-in-esxiargs-ransomware-attack-against-vmware-esxi-servers",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/medusa-ransomware-escalation-new-leak-site\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2020\/ransomware-alert-pay2key\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/blackbyte-ransomware-pt-1-in-depth-analysis\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/research.nccgroup.com\/2021\/06\/15\/handy-guide-to-a-new-fivehands-ransomware-variant\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2021\/07\/avoslocker-enters-the-ransomware-scene-asks-for-partners",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-avoslocker",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/geminiadvisory.io\/fin7-ransomware-bastion-secure\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/05\/shining-a-light-on-darkside-ransomware-operations.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 8,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/05\/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ransomware-maze\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/dragos.com\/blog\/industry-news\/implications-of-it-ransomware-for-ics-environments\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.sygnia.co\/blog\/abyss-locker-ransomware-attack-analysis\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/a\/analysis-and-Impact-of-lockbit-ransomwares-first-linux-and-vmware-esxi-variant.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.carbonblack.com\/2019\/05\/17\/cb-tau-threat-intelligence-notification-robbinhood-ransomware-stops-181-windows-services-before-encryption\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/bad-rabbit-ransomware\/82851\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.sygnia.co\/blog\/esxi-ransomware-ssh-tunneling-defense-strategies\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.halcyon.ai\/blog\/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/royal-ransomware-analysis",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.paloaltonetworks.com\/blog\/prisma-cloud\/ransomware-data-protection-cloud\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.kroll.com\/en\/insights\/publications\/cyber\/royal-ransomware-deep-dive",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/23\/b\/royal-ransomware-expands-attacks-by-targeting-linux-esxi-servers.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/b\/new-in-ransomware.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/11\/17\/dev-0569-finds-new-ways-to-deliver-royal-ransomware-various-payloads\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cyberscoop.com\/babuk-ransomware-serco-attack\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-babuk-ransomware.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/technical-papers\/SamSam-ransomware-chooses-Its-targets-carefully-wpna.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.symantec.com\/blogs\/threat-intelligence\/samsam-targeted-ransomware-attacks",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.carbonblack.com\/blog\/tau-threat-discovery-conti-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cybleinc.com\/2021\/01\/21\/conti-ransomware-resurfaces-targeting-government-large-organizations\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs.-conti-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/10\/27\/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 8,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cyble.com\/blog\/the-rust-revolution-new-embargo-ransomware-steps-in\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/20\/e\/netwalker-fileless-ransomware-injected-via-reflective-loading.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/en\/eset-research\/embargo-ransomware-rocknrust\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/12\/13\/diavol-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/05\/09\/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.avertium.com\/resources\/threat-reports\/in-depth-look-at-sabbath-ransomware-gang",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/09\/26\/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/08\/27\/storm-0501s-evolving-techniques-lead-to-cloud-based-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/sabbath-ransomware-affiliate\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/research\/revil-sodinokibi-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/the-evolution-of-revil-ransomware-and-pinchy-spider\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/gold-ionic-deploys-inc-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/hubfs\/dam\/collateral\/reports\/threat-alert-inc-ransomware.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.cisa.gov\/sites\/default\/files\/2024-04\/aa24-109a-stopransomware-akira-ransomware_2.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/akira-ransomware-continues-to-evolve\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/research\/bronze-starlight-ransomware-operations-use-hui-loader",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 8,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/threat-assessment-howling-scorpius-akira-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/blog.sygnia.co\/revealing-emperor-dragonfly-a-chinese-ransomware-group",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_se\/research\/22\/e\/new-linux-based-ransomware-cheerscrypt-targets-exsi-devices.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/research\/strifewater-rat-iranian-apt-moses-staff-adds-new-trojan-to-ransomware-operations",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/11\/29\/continuing-the-bazar-ransomware-story\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.intel471.com\/blog\/threat-hunting-case-study-medusa-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.security.com\/threat-intelligence\/medusa-ransomware-attacks",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/securityscorecard.com\/wp-content\/uploads\/2024\/01\/deep-dive-into-medusa-ransomware.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/10\/kegtap-and-singlemalt-with-a-ransomware-chaser.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 8,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/05\/15\/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.rapid7.com\/blog\/post\/2024\/05\/10\/ongoing-social-engineering-campaign-linked-to-black-basta-ransomware-operators",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-play",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/big-game-hunting-the-evolution-of-indrik-spider-from-dridex-wire-fraud-to-bitpaymer-targeted-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 8,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/hades-ransomware-successor-to-indrik-spiders-wastedlocker\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/posts\/ransomware-2020-attack-trends-new-techniques-affecting-organizations-worldwide\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.picussecurity.com\/resource\/ttps-used-by-blackbyte-ransomware-targeting-critical-infrastructure",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/07\/06\/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.security.com\/threat-intelligence\/blackbyte-exbyte-ransomware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/10\/14\/new-prestige-ransomware-impacts-organizations-in-ukraine-and-poland\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 8,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/TWljcm8tQ29tbSBJbmMuQEJhcnJhY3VkYQ==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/c5927e23bcad8f4dc5d60790d8bbdd38.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/TmFteWFuZyBJbmR1c3RyaWFsIENvLiwgTHRkLiBcIE5BTVlBTkcgTkVYTU9AQmFycmFjdWRh",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/c9dbf9a21b98baf0be16f46749d0c458.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Rml4SVQgVGVrQE9yb3Zh",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/605dae36a9cdff4afb9092a802ff9e9c.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/bGFudGlzbmV0LmNvbUBpbmNyYW5zb20=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/780781de66d01e32eb70f06a1e3b63c0.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/S2V5c2lnaHRAZXZlcmVzdA==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/dd6bf65d333323e77fd7e244619a9940.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UmVpZCBFbGVjdHJpYyBTZXJ2aWNlLCBJbmNARGFyayBQcm9qZWN0",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/f29fd292a4db57292aeb5b33b48bf373.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/VFNDIExvZ2lzdGljc0BEYXJrIFByb2plY3Q=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/5ad79fe24ca2159288a26dddb95f4d9c.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/TG9uZy1MZXdpcyBBdXRvbW90aXZlIEdyb3VwQERhcmsgUHJvamVjdA==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/9c7e8e359e1be155f9f5323826daa0db.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/R2FsdmluIEJyb3RoZXJzQHFpbGlu",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/24121696fb3e8c15f557f91824530bbb.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UlVQUCBTcHJpdHpndXNzQHFpbGlu",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/c545790ba264444e7bf77b6e54c8e58a.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Y2VzbWFjLmVkdS5ickBrcnliaXQ=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/9557b956d424cc200c138d92d834d72c.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/YnJpZ2dzcGxjLmNvbUBsb2NrYml0NQ==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/862faaefc445faa479ed113ed576f189.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Rmlyc3QgVGVrQHBsYXk=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/dc5f25a9c1a873f4e2ec446805b3988a.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UHJlZmVycmVkIEZpbmFuY2lhbCBHcm91cEBwbGF5",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/5a9cc649a5cdbe914568c5face33d1bf.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/U2lnbmF0dXJlIFNlcnZpY2VzQHBsYXk=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/6581c554278fefef648325dff61a1446.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/aGVhbHRoY2FyZWhpZ2h3YXlzLmNvbUBjaGFvcw==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/d693f6787042c14ae62ebdef179b1e94.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/R0NBVFMgSW52ZXN0bWVudHNAcGxheQ==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/d29ybGR0dWJlQGd1bnJh",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/609f7bdf4b0d05fbbb8660f7d3e884f0.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Q29udHJvbCBDb25jZXB0cyBUZWNobm9sb2d5QHRoZWdlbnRsZW1lbg==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UGxhdGludW0gR3JvdXBAcGxheQ==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/VG9wTWFyayBGdW5kaW5nQHRoZWdlbnRsZW1lbg==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/b8a07ecb3492d6c56fe64adf48a204ed.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/d3d3LnRhbGJvdGRlcy5vcmdAbHlueA==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/e15b926360b5d1d0125d8072d11ec61a.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/d3d3LmplcnJ5bGVpZ2guY29tQGx5bng=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/fb3168333cf4b47963348cc0b0081299.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/S2luZyBJbnRlcm5hdGlvbmFsIExMQ0BHYW1tYXg=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/0bfe169bcff5670ba71be5df3516b590.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/QW1TcGVjQHFpbGlu",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/bd83a78e49b39b4fd7ee639526992aaa.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/SmFrbGUgJiBBbGV4YW5kZXJAcWlsaW4=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/525e396e2d62a67038c2fb4e8b6d73c9.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/QWt1dXIgTGF3IEZpcm1AcWlsaW4=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/d4587038aaeb180af2341ad39ae67d6a.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/TUlUQyBBR0BicmF2b3g=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/473dddb1f209305b811e4ffb59c624d5.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UlMgQXV0b21hdGlvbiBDby4sIEx0ZC5AQmFycmFjdWRh",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/30e281e5d5890ca0f60b5e1d7edac51a.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Y2x1Ym9uZWNhc2luby5jb21AdGhyZWVhbQ==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/cbcd91614d43de35f1668738e307e83f.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/QUxJWkUgKGFsaXplLXN1ZC5mcilAcWlsaW4=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/8ed2cb8fd6edc5a655781d346195c8a7.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/SiZUIEJhbmsgYW5kIFRydXN0QHFpbGlu",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/QmFzaWMgR3JhaW4gUHJvZHVjdHNAYWtpcmE=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UGhhcm1hIFRlc3QgQXBwYXJhdGViYXUgQUdAYWtpcmE=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/0059d9591f3a81f0aead3693e446395d.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Rmlyc3QgQmFwdGlzdCBDaHVyY2ggb2YgQmVsbGV2aWV3QE9yb3Zh",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/1d341618beca8f183a614f4c2d16edef.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/SGlsbGlhcmQncyBBaXIgQ29uZGl0aW9uaW5nICYgSGVhdGluZyBJbmNAT3JvdmE=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/6b4c894c1fb74067ceafc4bdb5c10954.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/R2Vtc3RvbmUgVUtAT3JvdmE=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/SG9wZSdzIFdpbmRvd3NAY3J5MA==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/bc9034d308b3ba0d64f0b4d5d9bda9cf.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/U3QgVGhlcmVzYSBDYXRob2xpYyBDaHVyY2hAT3JvdmE=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/3d9aa9cac9b64f282c6c47efec335800.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/U3RvbmV5YnJvb2sgV2VzdCBNYXN0ZXIgQXNzb2NpYXRpb24sIEluY0BPcm92YQ==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/cebb3bdb4072eb61ac687feafd981fb9.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/U3RvbmVjcmVzdCBQT0FAT3JvdmE=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/fc72385fbe73a8899bad6bddeeb51cd4.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/TWFnbm9saWEgRGVudGFsQE9yb3Zh",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/548c77427e94cd0a99b9e0cdd2dc5afc.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Q291bnRyeSBPYWtzIFZldGVyaW5hcnkgQ2xpbmljQE9yb3Zh",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/0430696c6e6ab6ed618c7b6654950e8e.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/RGF2aWQgS2luZyBBcmNoaXRlY3RAT3JvdmE=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/473c69be57153602c0dddbbe9d69415a.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/V29vZHNpZGUgUmFuY2hAT3JvdmE=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/5be74d6d8a200bc68a1c7f8000d5e425.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/dnByai5vcmdAaW5jcmFuc29t",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/3145250deaab5caa24b625cb6f3d31f8.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/RmVycmVsbCBcIFNreWxpbmUgSW1wbGFudHMgJiBQZXJpb2RvbnRpY3MgXCBEci4gU2NvdHQgRmVyZ3Vzb25AQmFycmFjdWRh",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/6102061631e2489ca2c213c1c254aba3.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/bnV2KioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/aXBtKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/ZWNjKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/c3QqKioqKioqQGNsb3A=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/cWMqKioqKioqQGNsb3A=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Zmx1KioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/bWlkKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/aXRrKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/RzNBKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/YXJjKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/b21uKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/bGlmKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/c3AqKioqKioqQGNsb3A=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/aXZhKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/bnVvKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/dGhlKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/d2F0KioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/OWFsKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/aW50KioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/aG9uKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/YXRvKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Y2xvKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/anBtKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/YnJpKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/c3V1KioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/c21hKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/dHJpKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/Y29yKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/bWFtKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/cGFyKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/c3RhKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/bGFyKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/dG9hKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/aXIqKioqKipAY2xvcA==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/YWxkKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/cGhpKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/ZmlzKioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/ZyoqKioqKipAY2xvcA==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/c2gqKioqKioqQGNsb3A=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/bmV0KioqKioqKkBjbG9w",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/def5de99227a6bc78dd536355cf1358c.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/TWVyYSBNZXRhbEBxaWxpbg==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/80f81d83ab14d275dfdde8ad9d22eb70.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UGF2aWxsb25AR2xvYmFsIFNlY3JldCBHcm91cA==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/94d5020f37f671258a86227eeaa20d0f.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/TWlrZSBHcmFoYW0gSGVhdGluZyBBbmQgQWlyIENvbmRpdGlvbmluZ0BkcmFnb25mb3JjZQ==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/0271ec339606ccff85d0686bddb06a16.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UC4gQS4gSW5jLiAoUGVyZm9ybWFuY2UgQWxsb3lzKUBkcmFnb25mb3JjZQ==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/f32e598ca872b000b97b7f9539a8108f.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/U1RBRExFUiBTZW5zb3JpayBDTkMtVGVjaG5pa0BxaWxpbg==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/dd43a1024cda19455754ab367248825e.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/dG9tb3Jyb3dzb2ZmaWNlLmNvbUBjaGFvcw==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/d182e34463b94b2edf7e837dbf1f8751.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/U3RhZGUgRnJhbmNhaXNAcWlsaW4=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/689e7320f449b4a980cdde1fae917702.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/U3VyYWthcnRhIFVuaXZlcnNpdHlAUGFuemVy",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/7dcd9752ba5671d03950fee6cf276751.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/RmVzdGluYSBHcm91cEBQYW56ZXI=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/59373571c0d1d5cd7d9f63c5a1810e00.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/RWR1U3BhQGRyYWdvbmZvcmNl",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/0922d12dd3acb9cfe18baecea7f90be1.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UHJpbWFyeSBFeWUgQ2FyZUBkcmFnb25mb3JjZQ==",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/1ffb3eebb190b5fa169c8e53ed3b6368.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UG9udG9CUiBTaXN0ZW1hc0BzcGFjZWJlYXJz",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/id\/UFQgQWxsIENvc21vcyBCaW90ZWtAZ3VucmE=",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "https:\/\/images.ransomware.live\/victims\/48dd5241c96fc4cd6ca5023a634090aa.png",
            "ioc_type": "url",
            "category": "Ransomware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:48:14"
        },
        {
            "ioc_value": "Ransomware.Troldesh",
            "ioc_type": "other",
            "category": "C2 Certificates",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 14:47:22",
            "last_seen": "2026-08-06 14:47:22"
        },
        {
            "ioc_value": "https:\/\/www.resecurity.com\/blog\/article\/cybercriminals-are-targeting-edtech-data-breaches-and-ransomware-attacks-on-the-rise",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/blog\/melting-unc2198-icedid-to-ransomware-operations",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/sosransomware.com\/en\/ransomware-groups\/scattered-lapsus-hunters-the-cybercrime-alliance-that-will-shake-global-businesses-in-2025\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/what-old-new-again-nymaim-moves-past-its-ransomware-roots-0",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.security.com\/threat-intelligence\/goddamn-ransomware-beast-rebrand",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ordinypt-ransomware-intentionally-destroys-files-currently-targeting-germany\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2026\/07\/new-encforge-ransomware-targets-ai.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/krypt3ia.wordpress.com\/2026\/07\/13\/threat-intelligence-report-jadepuffer-agentic-ransomware-and-automated-extortion\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/nsfocusglobal.com\/ai-security-incident-jadepuffer-ransomware-leverages-ai-agent-to-automate-attacks\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/securereading.com\/jadepuffer-ai-ransomware-autonomous-llm-attack\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/socfortress.medium.com\/jadepuffer-the-dawn-of-agentic-ransomware-operations-003a59848007",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/free-tools\/ransomware-intelligence\/groups\/orova",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/booba-project",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/free-tools\/ransomware-intelligence\/groups\/gammax",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/24\/i\/how-ransomhub-ransomware-uses-edrkillshifter-to-disable-edr-and-.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.esentire.com\/blog\/threat-actors-deploy-sinobi-ransomware-via-compromised-sonicwall-ssl-vpn-credentials",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/sedgwick-cyber-incident-ransomware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/blog\/dark-web-profile-the-gentlemen-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/25\/i\/unmasking-the-gentlemen-ransomware.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/technical-papers\/SamSam-The-Almost-Six-Million-Dollar-Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/the-gentlemen-ransomware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/dark-peep-17-dark-web-hacker-forums-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.cyjax.com\/resources\/blog\/take-me-down-to-funksec-town-funksec-ransomware-dls-emergence\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/shining-a-light-on-darkside-ransomware-operations",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/flare.io\/learn\/resources\/blog\/teampcp-cloud-native-ransomware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/ransomware-ukraine-russia-bearlyfy",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/unit-42-ransomware-leak-site-data-analysis\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/businessinsights.bitdefender.com\/coinbase-cartel-ransomware-group-extortion-tactics",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.redpacketsecurity.com\/krybit-ransomware-victim-hacked-0apt\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/25\/b\/updated-shadowpad-malware-leads-to-ransomware-deployment.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.redpacketsecurity.com\/krybit-ransomware-victim-fraper-com\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.cyfirma.com\/research\/tracking-ransomware-january-2025\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.forescout.com\/blog\/new-ransomware-operator-exploits-fortinet-vulnerability-duo\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2020\/04\/28\/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.redhotcyber.com\/en\/post\/linkc-ransomware-the-new-cybercriminal-group-targeting-artificial-intelligence-data\/#google_vignette",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.cyfirma.com\/research\/tracking-ransomware-february-2025\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.cyjax.com\/resources\/blog\/new-extortion-ransomware-group-linkc-emerges-what-you-need-to-know\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/04\/08\/exploitation-of-clfs-zero-day-leads-to-ransomware-activity\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.ibm.com\/think\/x-force\/slopoly-start-ai-enhanced-ransomware-attacks",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.tripwire.com\/state-of-security\/featured\/ransomware-characteristics-attack-chains-recent-campaigns\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.computerweekly.com\/news\/252525240\/ALPHV-BlackCat-ransomware-family-becoming-more-dangerous",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2022\/05\/09\/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/07\/29\/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.security.com\/threat-intelligence\/black-basta-ransomware-zero-day",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/10\/fin11-email-campaigns-precursor-for-ransomware-data-theft.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2025\/01\/21\/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "http:\/\/www.csoonline.com\/article\/3193397\/security\/no-netflix-is-not-a-victim-of-ransomware.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "http:\/\/www.microsoft.com\/security\/blog\/2022\/06\/13\/the-many-lives-of-blackcat-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/10\/25\/dev-0832-vice-society-opportunistic-ransomware-campaigns-impacting-us-education-sector\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/fourcore.io\/blogs\/rhysida-ransomware-history-ttp-adversary-emulation",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/detect.fyi\/rhysida-ransomware-and-the-detection-opportunities-3599e9a02bb2",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2023\/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2020\/03\/05\/human-operated-ransomware-attacks-a-preventable-disaster\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/cobalt-mirage-conducts-ransomware-operations-in-us",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/09\/07\/profiling-dev-0270-phosphorus-ransomware-operations\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/lockbit-3-another-upgrade-to-worlds-most-active-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-lockbit",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/moneybirdransomware-removal\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "http:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/10\/27\/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2022\/08\/h0lygh0st-ransomware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2022\/07\/14\/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.picussecurity.com\/resource\/h0lygh0st-north-korean-threat-group-strikes-back-with-new-ransomware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2023\/12\/20\/cryptoguard-an-asymmetric-approach-to-the-ransomware-battle\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/research\/akira-ransomware.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2021\/07\/29\/bazacall-phony-call-centers-lead-to-exfiltration-and-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.sekoia.io\/sekoia-io-mid-2023-ransomware-threat-landscape",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/nwgenransomware-removal\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.reversinglabs.com\/blog\/the-week-in-security-possible-colonial-pipeline-2.0-ransomware-hurts-small-american-eateries",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.databreaches.net\/east-tennessee-childrens-hospital-updates-information-on-ransomware-incident\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/medium.com\/walmartglobaltech\/man1-moskal-hancitor-and-a-side-of-ransomware-d77b4d991618",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/dark-peep-16-play-ransomware-lockbits-alliance-breachforums-leak-and-cyberniggers-revival\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/first-step-initial-access-leads-ransomware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2021\/06\/ransomware-attackers-partnering-with.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.itpro.com\/security\/ransomware\/359919\/ransomware-criminals-look-to-other-hackers-to-provide-them-with-network",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.cyberscoop.com\/coronavirus-hacking-disinformation-ransomware-spearphishing\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/ransomware-preparedness-a-call-to-action\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/carbon-spider-sprite-spider-target-esxi-servers-with-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/double-trouble-ransomware-data-leak-extortion-part-2\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/chamelgang-attacking-critical-infrastructure-with-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/analyst1.com\/blog\/ransom-mafia-analysis-of-the-worlds-first-ransomware-cartel",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.advintel.io\/post\/enter-karakurt-data-extortion-arm-of-prolific-ransomware-group",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/prophet-spider-exploits-oracle-weblogic-to-facilitate-ransomware-activity\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/double-trouble-ransomware-data-leak-extortion-part-1",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/statescoop.com\/baltimore-ransomware-crowdstrike-extortion\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/cyberpress.org\/darkraas-ransomware-oil-gas-company\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/cyberpress.org\/darkraas-ransomware-intelligence-data\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-november-13th-2020-extortion-gone-wild\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/09\/12\/malware-distributor-storm-0324-facilitates-ransomware-access\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/mastercard-data-leak-new-fully-undetectable-ransomware-elusive-stealer-source-code-leak-and-more\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/ransomware-groups-use-tor-based-backdoor-for-persistent-access",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/cyber-awakeness-month-takedown-of-trigona-hive-ransomware-resurges-ransomedforum-and-new-raas-qbit\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/quointelligence.eu\/2024\/06\/analyzing-shift-in-ransomware-dynamics\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/securityaffairs.co\/wordpress\/138933\/malware\/ransomexx-ransomware-rust-language.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/strifewater-rat-iranian-apt-moses-staff-adds-new-trojan-to-ransomware-operations",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.rewterz.com\/rewterz-news\/rewterz-threat-alert-new-ransomware-actor-oldgremlin-hits-multiple-organizations",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.checkpoint.com\/2022\/03\/07\/lapsus-ransomware-gang-uses-stolen-source-code-to-disguise-malware-files-as-trustworthy-check-point-customers-remain-protected\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/buhti-ransomware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.redpacketsecurity.com\/new-buhti-ransomware-gang-uses-leaked-windows-linux-encryptors\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.redpacketsecurity.com\/buhti-ransomware-gang-switches-tactics-utilizes-leaked-lockbit-and-babuk-code\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/blog\/research\/76153\/teamxrat-brazilian-cybercrime-meets-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/anatomy-of-alpha-spider-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/threat-intelligence\/ransomhub-knight-ransomware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/forescoutstage.wpengine.com\/blog\/analysis-a-new-ransomware-group-emerges-from-the-change-healthcare-cyber-attack\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/ransomware-evolution-how-cheated-affiliates-are-recycling-victim-data-for-profit\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/analyst1.com\/file-assets\/RANSOM-MAFIA-ANALYSIS-OF-THE-WORLD%E2%80%99S-FIRST-RANSOMWARE-CARTEL.pdf",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/wizard-spider-adds-new-feature-to-ryuk-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/melting-unc2198-icedid-to-ransomware-operations",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.cybersecurity-insiders.com\/proven-data-restores-powerhosts-vmware-backups-after-sexi-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/colonial-pipeline-attributes-ransomware-claims-to-unrelated-third-party-breach",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/titaniam.io\/ransomware-prevention-daixin-team-ransomware-group\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/heimdalsecurity.com\/blog\/powerhosts-esxi-servers-encrypted-with-new-sexi-ransomware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/on-the-horizon-ransomed-vc-ransomware-group-spotted-in-the-wild\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.darkreading.com\/threat-intelligence\/sexi-ransomware-desires-vmware-hypervisors",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/sep-2023-cybercrime-update-new-ransomware-threats-and-the-rising-menace-of-telegram\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/webz.io\/dwp\/new-ransomware-group-ransomhouse-is-it-real-or-fake\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "http:\/\/internal-www.fireeye.com\/blog\/threat-research\/2021\/05\/shining-a-light-on-darkside-ransomware-operations.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.videogameschronicle.com\/news\/a-ransomware-group-claims-to-have-beached-all-sony-systems\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.resecurity.com\/blog\/article\/ransomedvc-in-the-spotlight-what-we-know-about-the-ransomware-group-targeting-major-japanese-businesses",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "http:\/\/internal-www.fireeye.com\/blog\/threat-research\/2021\/04\/unc2447-sombrat-and-fivehands-ransomware-sophisticated-financial-threat.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.rewterz.com\/rewterz-news\/rewterz-threat-alert-financially-motivated-aggressive-group-carrying-out-ransomware-campaigns-active-iocs",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.esentire.com\/security-advisories\/ransomware-hackers-attack-a-top-safety-testing-org-using-tactics-and-techniques-borrowed-from-chinese-espionage-groups",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/spixnet.at\/cybersecurity-blog\/2022\/11\/15\/russian-hacktivists-hit-ukrainian-orgs-with-ransomware-but-no-ransom-demands\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.rewterz.com\/rewterz-news\/rewterz-threat-alert-leaked-conti-ransomware-used-to-target-russia-active-iocs",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2017\/05\/23\/xdata-ransomware-making-rounds-amid-global-wannacryptor-scare",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2017\/06\/27\/new-ransomware-attack-hits-ukraine",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.uptycs.com\/blog\/ghostlocker-ransomware-ghostsec",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/samas-ransomware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/ransomware-deployed-by-adversary",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/research\/samsam-ransomware-campaigns",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/noname",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/karma",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/royal",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lockbit5",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/kawa4096",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/rransom",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lockdata",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/warlock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/kazu",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/kelvinsecurity",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/sabbath",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/donutleaks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/werewolves",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lolnek",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/killsec",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/doppelpaymer",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lorenz",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/weyhro",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/losttrust",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nova",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/kittykatkrew",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/knight",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/worldleaks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/obscura",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/safepay",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/dragonforce",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/kraken",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lunalock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/x001xs",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/onepercent",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/sarcoma",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/dragonransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/xinglocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/onyx",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lv",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/satanlockv2",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/dread",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/xinof",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/orca",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/xp95",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/krybit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/orion",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/dunghill",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/kryptos",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/osiris",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/yanluowang",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/secp0",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ech0raix",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/kyber",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/yurei",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/securotrop",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/pandora",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/embargo",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/zeon",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/pay2key",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/settra",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/entropy",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/la_piovra",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/zerolockersec",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/shadow",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ep918",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lynx",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/zerotolerance",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/esxiargs",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/payload",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/shaoleaks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lamashtu",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/payloadbin",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/m3rx",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/payoutsking",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/madcat",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/everest",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/madliberator",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/shinyhunters",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/pear",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/exitium",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lapsus$",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/malas",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/leaktheanalyst",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/sicarii",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/exorcist",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lilith",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/malekteam",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/siegedsec",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/fletchen",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mallox",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/linkc",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/silent",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/flocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/play",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lockbit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mamona",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/playboy",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/fog",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/projectrelic",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/prolock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/frag",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/marketo",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/freecivilian",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lockbit2",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/prometheus",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/promptlock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/maze",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/fsteam",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/sinobi",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/pysa",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mbc",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/skira",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/slug",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/fulcrumsec",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/qilin",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/qiulong",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/qlocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/snatch",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/solidbit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/funksec",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/quantum",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/spacebears",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/genesis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/rabbithole",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/sparta",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/medusa",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/spook",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/global",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/radar",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/grief",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/radiant",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/groove",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/medusalocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/stormous",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/gunra",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/meow",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ragnarlocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/sugar",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/hades",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/metaencryptor",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ragnarok",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/suncrypt",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/midas",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/synack",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mindware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/teamxxx",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ralord",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/tengu",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/handala",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/minteye",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/termite",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/haron",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mnt6",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ramp",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mogilevich",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/rancoz",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/moneymessage",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/thegentlemen",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ranion",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lockbit3",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ransombay",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/hellcat",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/monti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/threeam",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/helldown",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/morpheus",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ransomcartel",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/titan",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/hellogookie",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mortar",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ransomcortex",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/hellokitty",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/toufan",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mosesstaff",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/tridentlocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/hive",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ransomed",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mountlocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/holyghost",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ransomexx",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ms13089",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/hotarus",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/mydecryptor",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ransomhouse",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/trigona",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/n3tworm",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/trinity",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/hunters",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nasirsecurity",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ransomhub",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/trisec",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nblock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ranstreet",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/icefire",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/u-bomb",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nefilim",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ranzy",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nemty",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/underground",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/netrunner",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/raworld",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/netwalker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/lockbit3_fs",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/raznatovic",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/unknown",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/unsafe",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nevada",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/rebornvc",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/vanirgroup",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nightsky",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/redalert",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/incransom",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/vect",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/redransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/vendetta",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/insane",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/insomnia",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/vfokx",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nightspire",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/revil",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/interlock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nitrogen",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/reynolds",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/noescape",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/rhysida",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/kairos",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/robinhood",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/vicesociety",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/walocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/karakurt",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/nokoyawa",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/rook",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/wannacry",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:26",
            "last_seen": "2026-08-06 14:45:05"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/donex",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/runsomewares",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/section9",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blackbyte",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blacklock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/sensayq",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blackmatter",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/sevyware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blacknevas",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blackout",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/shadowbyt3$",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/shiba",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/shinysp1d3r",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blackshadow",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/silentransomgroup",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blackshrantac",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/thegreenbloodgroup",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blacksuit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/thesyndicate",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blacktor",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/timc",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blackwater",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/tommyleaks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/bluebox",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/triplex",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/bluelocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ulose",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/bluesky",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/bonacigroup",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/valencialeaks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/bqtlock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/bravox",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/brotherhood",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/vanhelsing",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cactus",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/wallstreet",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "hitleransomware.cf",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "http:\/\/hitleransomware.cf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/agl0bgvycg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cephalus",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/abyss",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/chaos",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/adminlocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/againstthewest",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cheers",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/0apt",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/chilelocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/0daysyndicate",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/chort",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cicada3301",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/0mega",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ciphbit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/akira",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cipherforce",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ako",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cloak",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/8base",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/alphalocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/alp-001",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/abrahams_ax",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/ailock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/alphv",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/clop",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/aptlock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/coinbasecartel",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/anubis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/auditteam",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/apos",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/barracuda",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blackx",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blackfield",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/conti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cooming",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/boobaproject",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/crazyhunter",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/crosslock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/apt73",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/arcusmedia",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cry0",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/argonauts",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/crylock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cryp70n1c0d3",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/arkana",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/braincipher",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cryptbb",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cmdorganization",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/arvinclub",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cryptnet",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/crypto24",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/crpxo",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/atomsilo",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cuba",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/contfr",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/aurora",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/cyclops",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/d1r",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/avaddon",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/d4rk4rmy",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/darkproject",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/avos",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/dan0n",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/darkmatter",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/avoslocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/dagonlocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/aware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/deadlock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/daixin",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/aztroteam",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/doommageddon",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/darkangels",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/babuk",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/eldorado",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/darkbit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/exfilsquad",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/gdlockersec",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/babuk2",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "ransomware.live",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/gammax",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/darkleakmarket",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/babyduck",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/globalsecretgroup",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/darkpower",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/goddamnransomwhere",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/darkrace",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/imncrew",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/beast",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/darkside",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/icarus",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/benzona",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/darkvault",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/j",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/bert",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/datacarry",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/leakbazaar",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/datakeeper",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/loki",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/notpetya",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/bianlian",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/dataleak",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/desolator",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/orova",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/blackbasta",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/panzer",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/payday",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/devman",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/diavol",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/prinzeugen",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/direwolf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/redact",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.live\/group\/dispossessor",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:25",
            "last_seen": "2026-08-06 14:45:04"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/25\/g\/bert-ransomware-group-targets-asia-and-europe-on-multiple-platforms.html",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:11",
            "last_seen": "2026-08-06 14:43:52"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/25\/g\/bert-ransomware-group-targets-asia-and-europe-on-multiple-platforms\/bert-ransomware-group-targets-asia-and-europe-on-multiple-platforms-iocs.txt",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:11",
            "last_seen": "2026-08-06 14:43:52"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2023\/12\/04\/sql-brute-force-leads-to-bluesky-ransomware\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:10",
            "last_seen": "2026-08-06 14:43:51"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/11\/18\/new-ransomware-actor-uses-password-protected-archives-to-bypass-encryption-protection\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:09",
            "last_seen": "2026-08-06 14:43:49"
        },
        {
            "ioc_value": "https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/lockscreen-ransomware-phishing-leads-to-google-play-card-scam\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:49"
        },
        {
            "ioc_value": "https:\/\/github.com\/advanced-threat-research\/IOCs\/blob\/master\/2018\/2018-03-19-ransomware-takes-open-source-path-encrypts-gnu-privacy-guard%0D\/ransomware-takes-open-source-path-encrypts-gnu-privacy-guard%0D.csv",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "https:\/\/www.symantec.com\/blogs\/threat-intelligence\/targeted-ransomware-threat",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:07",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/dharma-ransomware-uses-av-tool-to-distract-from-malicious-activities\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:07",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "https:\/\/www.cyren.com\/blog\/articles\/new-scarab-ransomware-using-necurs-as-a-service",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:07",
            "last_seen": "2026-08-06 14:43:47"
        },
        {
            "ioc_value": "http:\/\/www.bug.hr\/forum\/topic\/sigurnosni-softver\/ransomware-napada\/223333.aspx",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:07",
            "last_seen": "2026-08-06 14:43:47"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2020\/10\/08\/sophisticated-new-android-malware-marks-the-latest-evolution-of-mobile-ransomware\/",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20231222134431\/https:\/\/cofense.com\/blog\/infostealer-keylogger-ransomware-one-anubis-targets-250-android-applications\/",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/the-rotexy-mobile-trojan-banker-and-ransomware\/88893\/",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "https:\/\/cert.br\/docs\/ransomware\/#divulgacao",
            "ioc_type": "url",
            "category": "CERT Advisories",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:14:13",
            "last_seen": "2026-08-06 13:14:13"
        },
        {
            "ioc_value": "https:\/\/cert.br\/docs\/ransomware\/",
            "ioc_type": "url",
            "category": "CERT Advisories",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:14:13",
            "last_seen": "2026-08-06 13:14:13"
        },
        {
            "ioc_value": "https:\/\/cert.br\/docs\/ransomware\/en\/",
            "ioc_type": "url",
            "category": "CERT Advisories",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:14:13",
            "last_seen": "2026-08-06 13:14:13"
        },
        {
            "ioc_value": "https:\/\/sensorstechforum.com\/crynox-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/31766-crynox-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.fortra.com\/blog\/bert-ransomware-what-you-need-know",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cyclonis.com\/remove-crynox-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/theravenfile.com\/2025\/06\/16\/bert-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/medium.com\/@anyrun\/devman-ransomware-analysis-of-new-dragonforce-variant-ede707fd30b1",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/devman-a-new-dragonforce-ransomware-variant",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/devman",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.hivepro.com\/threat-advisory\/devman-ransomware-is-a-new-derivative-of-the-dragonforce-family\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.helpnetsecurity.com\/2024\/08\/28\/pioneer-kitten-iranian-hackers-partnering-with-ransomware-affiliates\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.anvilogic.com\/threat-reports\/iranian-cyber-groups-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.truesec.com\/hub\/blog\/helldown-ransomware-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/cs-137",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/dire-wolf-strikes-new-ransomware-group-targeting-global-sectors\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/blog.sekoia.io\/helldown-ransomware-an-overview-of-this-emerging-threat",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.darkreading.com\/threat-intelligence\/dire-wolf-ransomware-manufacturing-technology",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/hivepro.com\/threat-advisory\/new-helldown-ransomware-a-growing-threat-across-cross-platform-systems",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/dire-wolf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/helldown-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/sabbath-ransomware-affiliate",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/watchguard.com\/wgrd-security-hub\/ransomware-tracker\/belsen-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/embargo-ransomware-new-raas-on-the-scene\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/h\/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/technical-analysis-embargo-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/24\/f\/embargo-ransomware-raas-analysis.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/dark-vault",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.tinextacyber.com\/wp-content\/uploads\/2025\/06\/Dissecting-a-Python-Ransomware-distributed-through-GitHub-repositories-1.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.threatintelligence.com\/blog\/darkvault-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/25\/g\/gunra-ransomware-linux-variant.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.darkreading.com\/threat-intelligence\/nimble-gunra-ransomware-linux-variant",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/industrialcyber.co\/ransomware\/cyfirma-warns-of-gunra-ransomware-surge-targeting-critical-infrastructure-using-double-extortion",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyberint.com\/blog\/research\/ransomware-trends-2024-report\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/watchguard.com\/wgrd-security-hub\/ransomware-tracker\/gunra",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyble.com\/blog\/top-ransomware-groups-may-2025-safepay-devman-rise\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/theravenfile.com\/2025\/09\/23\/gunra-ransomware-what-you-dont-know\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/the-new-face-of-ransomware-key-players-and-emerging-tactics-of-2024\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/apos-security",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.group-ib.com\/blog\/hunters-international-ransomware-group\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.fortra.com\/blog\/ailock-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/datacarry",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/gbhackers.com\/ailock-ransomware-emerges-with-hybrid-encryption-tactics\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wblog\/detailed-analysis-of-ailock-ransomware-1d3263beff15",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/2021\/08\/vice-society-ransomware-printnightmare.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/d0glun",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/31986-d0glun-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/ransomware-roundup-abyss-locker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/chuongdong.com\/reverse%20engineering\/2022\/09\/03\/PLAYRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/dark-web-profile-abyss-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/i\/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.ransomlook.io\/group\/ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.kroll.com\/en\/publications\/cyber\/fog-ransomware-targets-higher-education",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/babuk2-bjorka-the-evolution-of-ransomware-for-data-commoditization\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/technical-analysis-cryptnet-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/fog-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/blog.barracuda.com\/2025\/04\/29\/a-closer-look-at-fog-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.intellinews.com\/hacker-targets-indonesian-banks-with-ransomware-threats-366102\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.2-spyware.com\/remove-cerbersyslock-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/25\/d\/fog-ransomware-concealed-within-binary-loaders-linking-themselve.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.securitymagazine.com\/articles\/101694-fog-ransomware-group-uses-unconventional-toolset-new-research-finds",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.areteir.com\/static\/FOG_Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/assets.kpmg.com\/content\/dam\/kpmgsites\/in\/pdf\/2024\/11\/kpmg-ctip-fog-ransomware-19-nov-2024.pdf.coredownload.inline.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/i\/blackbit-ransomware-a-lockbit-imitation.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/blackbit-ransomware-imitates-lockbit-demands-bitcoin\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/github.com\/albertzsigovits\/malware-notes\/tree\/master\/Ransomware-Windows-Yanluowang",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.hhs.gov\/sites\/default\/files\/rhysida-ransomware-sector-alert-tlpclear.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/yanluowang-targeted-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_dk\/research\/23\/h\/an-overview-of-the-new-rhysida-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/free-decryptor-released-for-yanluowang-ransomware-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyjax.com\/resources\/blog\/frag-explodes-onto-the-scene-new-dls-emerges-for-frag-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/securityaffairs.com\/170717\/malware\/veeam-backup-replication-flaw-frag-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cybersecuritydive.com\/news\/veeam-cve-exploit-frag-ransomware\/732670\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/c3rb3r-ransomware-ongoing-exploitation-of-cve-2023-22518-targets-unpatched-confluence-servers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/threats.wiz.io\/all-tools\/c3rb3r-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/paraguay-warns-of-black-hunt-ransomware-attacks-after-tigo-business-breach\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.kroll.com\/en\/insights\/publications\/cyber\/cactus-ransomware-prickly-new-variant-evades-detection",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/dark-web-profile-cactus-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/securityscorecard.com\/wp-content\/uploads\/2024\/01\/Whitepaper-Cactus-Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2023\/11\/cactus-ransomware-exploits-qlik-sense.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/dharma-ransomware-switches-to-the-aes-256-encryption-algorithm\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/anthology\/cactus-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/akira-ransomware-attacks-vpn-appliances",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/blog.barracuda.com\/2024\/03\/20\/who-is-behind-cactus-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/19\/h\/dharma-ransomware-continues-to-target-servers-via-open-rdp-ports.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/akira-ransomware-now-targets-linux-vmware-esxi-servers",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.kroll.com\/en\/publications\/cyber\/cactus-ransomware-prickly-new-variant-evades-detection",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/2024\/04\/04\/akira-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/tripwire.com\/state-of-security\/cactus-ransomware-what-you-need-know",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/25\/b\/black-basta-cactus-ransomware-backconnect.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/kraken-cryptor-ransomware-as-a-service\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/kraken-ransomware-distributed-via-malware-infected-installers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/blog.eclecticiq.com\/global-group-emerging-ransomware-as-a-service",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cybersecurity-magazine.com\/news\/ransomware-ai-chatbot-pressure\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/infosecurity-magazine.com\/news\/ransomware-group-uses-ai-chatbot\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/31862-aptlock-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/broadcom.com\/support\/security-center\/protection-bulletin\/global-a-new-blacklock-ransomware-variant",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/ciphbit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/aptlockransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/picussecurity.com\/resource\/blog\/tracking-global-group-ransomware-from-mamona-to-market-scale",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/27862-ciphbit-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.isvworld.com\/search\/news\/1543268-aptlock-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyware.com\/news\/global-group-ransomware-claims-breach-of-media-giant-albavision",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.hookphish.com\/blog\/ransomware-group-ciphbit-hits-iptelecom-gmbh\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/images\/stories\/screenshots202309\/magaskosh-ransomware-ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyberpress.org\/ciphbit-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/27691-magaskosh-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/elpaco-ransomware-a-mimic-variant\/114635\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/elpaco-team-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fargo-ransomware-targeting-ms-sql-servers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cloudsek.com\/blog\/unmasking-media-hungry-ransomware-groups-bashe-apt73",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/chaos-ransomware-group-surfaces-with-aggressive-tactics",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/halcyon.ai\/blog\/arcus-media-ransomware-displays-novel-process-targeting-selective-encryption-and-recovery-disruption",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyble.com\/blog\/top-ransomware-groups-june-2025-qilin-top-spot-",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/halcyon.ai\/blog\/emerging-threat-actor-arcus-media-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.infosecurity-magazine.com\/news\/chaos-ransomware-wave-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/securitybuzz.com\/cybersecurity-news\/arcus-media-the-rising-ransomware-threat-redefining-modern-cybersecurity-defenses\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/chaos-ransomware-hits-optima-tax-relief-leaks-69gb-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/arcus-media",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/freeworld-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/brain-cipher",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.securonix.com\/blog\/securonix-threat-labs-security-advisory-threat-actors-target-mssql-servers-in-dbjammer-to-deliver-freeworld-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/mssql-databases-under-fire-from-freeworld-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/darkrace-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/27581-freeworld-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/wazuh.com\/blog\/detecting-brain-cipher-ransomware-with-wazuh\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.reuters.com\/technology\/cybersecurity\/indonesia-says-it-has-begun-recovering-data-after-major-ransomware-attack-2024-07-12\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/petikvx.github.io\/2024\/06\/20\/darkrace-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.zerofox.com\/intelligence\/flash-report-colossus-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.salvagedata.com\/blog\/darkrace-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/new-threat-actor-using-yashma-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.securityweek.com\/colossus-ransomware-hits-automotive-company-us\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.superantispyware.com\/blog\/what-is-colossus-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/dunghill-leak",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/23\/d\/kuiper-ransomware-targets-multiple-platforms.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/globe-ransomware-gives-you-the-opportunity-to-customize-your-encryption\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/10512-globe-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/ransomware-globe",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/gurucul.com\/blog\/backmydata-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/chort",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.securityweek.com\/ransomware-attack-knocks-100-romanian-hospitals-offline\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/ransomware-sheboygan-breach-notice",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hunters-international-ransomware-likely-a-rebrand-of-hive\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/hunters-international-ransomware-a-possible-hive-successor\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/18\/b\/hermes-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/33382-bqtlock-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.symantec.com\/blogs\/threat-intelligence\/hermes-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/bqtlock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/lorenz-ransomware-attack-victims-can-now-retrieve-their-files-for-free-with-this-decryption-tool",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hermes-ransomware-used-as-a-wiper-in-taiwan-bank-heist\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cybershafarat.com\/2025\/07\/30\/bqtlock-ransomware-op-status\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cybertalk.org\/the-worst-outcomes-lorenz-ransomware-a-new-double-extortion-strategy",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/free-decrypter-available-for-lorenz-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/repellent-scorpius-cicada3301-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.rapid7.com\/blog\/post\/2024\/02\/05\/exploring-the-not-so-secret-code-of-blackhunt-ransomware-2\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/meet-lorenz-a-new-ransomware-gang-targeting-the-enterprise\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2024\/10\/cross-platform-cicada3301-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.scworld.com\/news\/medusalocker-ransomware-variant-paired-with-paid_memes-toolkit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs.-lorenz-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.tesorion.nl\/en\/posts\/lorenz-ransomware-analysis-and-a-free-decryptor\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/knight-ransomware-rebrands-from-cyclops-targets-windows-linux-esxi\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.tesorion.nl\/en\/posts\/lorenz-ransomware-rebound-corruption-and-irrecoverable-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/23\/h\/knight-ransomware-raas.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.morphisec.com\/blog\/cicada3301-ransomware-threat-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.porthas.com\/blog\/b0-ransomware-decryption\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/21736-cryptedpay-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/knight-ransomware-raas-targets-multiple-platforms\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.waterisac.org\/portal\/ransomware-awareness-%E2%80%93-new-ransomware-group-%E2%80%9Ccicada3301%E2%80%9D-surfaces-connections-alphv-network",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/cryptedpayransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2021\/08\/24\/a-deep-dive-analysis-of-karma-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/not-a-good-day-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2021\/11\/threat-thursday-karma-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/argonauts-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/dan0n",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sos-vo.org\/news\/cybersecurity-snapshots-dan0n-and-arcus-media-ransomware-groups",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/security.com\/threat-intelligence\/3am-ransomware-lockbit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2021\/11\/insane-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/tripwire.com\/state-of-security\/3am-ransomware-what-you-need-know",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/22493-insane-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2025\/05\/20\/a-familiar-playbook-with-a-twist-3am-ransomware-actors-dropped-virtual-machine-with-vishing-and-quick-assist\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/quorumcyber.com\/malware-reports\/3am-ransomware-report\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.huntress.com\/blog\/crux-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/sos-vo.org\/index.php\/news\/cybersecurity-snapshots-3am-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.itpro.com\/business\/cybersecurity-researchers-have-spotted-a-potent-new-ransomware-strain-being-used-in-the-wild",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/darkreading.com\/threat-intelligence\/3am-ransomware-adopts-email-bombing-vishing",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/securityboulevard.com\/2025\/07\/new-crux-ransomware-emerges-in-three-attacks-this-month\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cyfirma.com\/research\/vanhelsing-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/blackbyte-crux",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/crosslock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyberscoop.com\/mandiant-sabbath-arcane-ransomware-rebrand\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.netskope.com\/blog\/netskope-threat-coverage-crosslock-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/27387-black-berserk-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyble.com\/blog\/crosslock-ransomware-emerges-new-golang-based-malware-on-the-horizon",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/blackberserkransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/rewterz.com\/rewterz-threat-alert-crosslock-ransomware-active-iocs",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/ransomware-roundup-keganohitobito-and-donex",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/i\/new-donex-ransomware-variant.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.fbi.gov\/contact-us\/field-offices\/cleveland\/news\/international-investigation-leads-to-shutdown-of-ransomware-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/free-decryptor-released-for-donex-muse-and-darkrace-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.reuters.com\/technology\/cybersecurity\/dispossessor-ransomware-group-shut-down-by-us-european-authorities-2024-08-13\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.kelacyber.com\/blog\/cyclops-ransomware-gang-unveils-knight-raas\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cloudsek.com\/ar\/blog\/understanding-knight-ransomware-advisory-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-kasseika-ransomware-emerges-with-links-to-blackmatter-lockbit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.quorumcyber.com\/malware-reports\/knight-ransomware-report\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/24\/a\/kasseika-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/decrypting-catb-ransomware-analyzing-their-latest-attack-methods\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/core-ransomware-a-new-makop-variant",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/ransomware-roundup-catb-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.vmray.com\/catb-ransomware-a-new-threat-exploiting-dll-side-loading\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.securityweek.com\/circuit-board-maker-unimicron-targeted-in-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cymulate.com\/threats\/catb-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/us-govt-links-north-korean-holyghost-ransomware-to-lazarus-group\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyberpress.org\/sarcoma-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/07\/14\/holyghost-north-korean-threat-actor-uses-custom-ransomware-in-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/australiancybersecuritymagazine.com.au\/new-ransomware-group-sarcoma-targets-australian-companies\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/2023lock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-cerber-ransomware-targets-confluence-and-gitlab-servers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyberint.com\/blog\/research\/the-nature-of-the-beast-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyble.com\/blog\/in-the-shadow-of-venus-trinity-ransomwares-covert-ties\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/cerber2021-ransomware-back-in-action\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/ransomware-roundup-bisamware-and-chile-locker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/threat-analysis-beast-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/2023lock-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/elastio.com\/detectable-ransomware\/cerber-2021\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyble.com\/blog\/arcrypt-ransomware-evolves-with-multiple-tor-communication-channels",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.hhs.gov\/sites\/default\/files\/trinity-ransomware-threat-actor-profile.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/24283-darky-lock-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.hookphish.com\/blog\/ransomware-group-blacknevas-hits-tani-and-abe\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.securityweek.com\/gwisin-ransomware-attacks-target-korean-healthcare-firms\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-gwisin-ransomware-targets-south-korean-healthcare-manufacturing\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/2022\/11\/arcrypter-ransomware-expands-its-operations-from-latin-america-to-the-world",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/bidonransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/22722-admin-locker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/27412-bidon-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/cloak",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/adminlockerransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cloudsek.com\/threatintelligence\/axxes-ransomware-group-appears-to-be-the-rebranded-version-of-midas-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyclonis.com\/remove-bidon-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.thaiCERT.or.th\/en\/2025\/03\/25\/cloak-ransomware-attacks-virginia-attorney-generals-office\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.hivepro.com\/wp-content\/uploads\/2022\/05\/New-Ransomware-Group-Axxes-is-on-the-rise_TA2022106.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.halcyon.ai\/blog\/cloak-ransomware-variant-exhibits-advanced-persistence-evasion-and-vhd-extraction-capabilities",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cert.gov.az\/en\/articles\/ctb-locker-and-critroni-ransomware-information-guide-and-faq",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-april-29th-2022-new-operations-emerge\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/dragonforce-ransomware-gang-from-hacktivists-to-high-street-extortionists\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/heimdalsecurity.com\/blog\/ctb-locker-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/deathgrip-emergence-of-a-new-ransomware-as-a-service",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cyberint.com\/blog\/other\/cloak-ransomware-whos-behind-the-cloak\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.barracuda.com\/blog\/dragonforce-ransomware-cartel-vs--everybody",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/ransomware-groups-evolve-affiliate-models",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.eset.com\/afr\/about\/newsroom\/press-releases-afr\/company\/ctb-locker-ransomware-striking-in-europe-and-latin-america10\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/deathgripransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/30382-deathgrip-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.truesec.com\/hub\/blog\/a-case-of-the-faust-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/faust-ransomware-a-phobos-family-variant",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-8base",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/labs.withsecure.com\/publications\/crazyhunter-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.checkpoint.com\/cyber-hub\/threat-prevention\/ransomware\/8base-ransomware-group\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/31727-help-restoremydata-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/darkreading.com\/threat-intelligence\/ransomware-gang-crazyhunter-critical-taiwanese-orgs",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyberint.com\/blog\/research\/all-about-that-8base-ransomware-group-the-details\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cyclonis.com\/remove-help_restoremydata-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/threats.wiz.io\/all-incidents\/crazyhunter-ransomware-group-targets-critical-sectors-in-taiwan",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/ransomware-roundup-8base",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/crazyhunter-a-new-prince-ransomware-variant",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.hhs.gov\/sites\/default\/files\/8base-ransomware-analyst-note.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/32577-crazyhunter-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.eye.security\/blog\/8base-ransomware-investigation-uncovers-surprising-insights",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.axios.com\/2025\/02\/11\/fbi-europol-8base-ransomware-takedown",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/key-figures-behind-phobos-and-8base-ransomware-arrested-in-international-cybercrime-crackdown",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.netskope.com\/blog\/netskope-threat-coverage-blacksnake-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/blacksnake-ransomware-another-chaos-variant",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/arkana-security",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/securityweek.com\/new-ransomware-group-claims-attack-on-us-telecom-firm-wideopenwest\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/cyberpress.org\/arkana-ransomware-group-alleges-breach\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/25442-dataf-locker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.reversinglabs.com\/blog\/smash-and-grab-astralocker-2-pushes-ransomware-direct-from-office-docs",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.emsisoft.com\/en\/ransomware-decryption\/astralocker\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.infosecinstitute.com\/resources\/malware-analysis\/astralocker-releases-the-ransomware-decryptors\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/heimdalsecurity.com\/blog\/astralocker-ransomware-goes-offline-and-makes-decryptors-available\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/crypto24",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sangfor.com\/blog\/cybersecurity\/vietnam-cmc-group-ransomware-attack-anatomy-asian-cyber-shock",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.cyfirma.com\/research\/tracking-ransomware-april-2025",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/jsworm-ransomware-rebrands-to-nemty-with-new-encryption-routines\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/20\/g\/nefilim-ransomware-shifts-to-double-extortion.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/23\/f\/blacksuit-ransomware-and-its-similarities-to-royal.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/blacksuit-ransomware-a-former-conti-affiliate-rebrands-and-evolves\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/bert",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/blacksuit-ransomware-a-new-name-for-royal-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.csoonline.com\/article\/4019468\/trend-micro-flags-bert-a-rapidly-growing-ransomware-threat.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/securityboulevard.com\/2025\/07\/new-bert-ransomware-evolves-with-multiple-variants\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.halcyon.ai\/blog\/bert-ransomwares-first-moves-kill-the-vms-kill-the-backups",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/04\/hpe-ilo-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.knowbe4.com\/bart-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/ghoulsec.medium.com\/mal-series-13-darkside-ransomware-c13d893c36a6",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/08\/venuslocker-ransomware-aes-256.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.accenture.com\/us-en\/blogs\/cyber-defense\/moving-left-ransomware-boom",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/Haxrein\/Malware-Analysis-Reports\/blob\/main\/darkside_ransomware_technical_analysis_report.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/magic-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/redcanary.com\/blog\/blackbyte-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.welivesecurity.com\/2014\/12\/22\/win32virlock-first-self-reproducing-ransomware-also-shape-shifter\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sigrun-ransomware-author-decrypting-russian-victims-for-free\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2020\/08\/darkside-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/borncity.com\/win\/2021\/03\/27\/tu-darmstadt-opfer-der-ragnarok-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/16814-crylock-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/maktub-locker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/05\/sigrun-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-shuts-down-again-after-tor-sites-were-hijacked\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2021\/07\/blackmatter-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/techcrunch.com\/2021\/08\/30\/ragnarok-ransomware-gang-shuts-down-and-releases-its-decryption-key",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/san-francisco-49ers-confirm-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.welivesecurity.com\/2016\/11\/24\/new-decryption-tool-crysis-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/june\/8\/crybrazil.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.br.de\/nachrichten\/deutschland-welt\/mutmasslicher-ransomware-millionaer-identifiziert",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/revil-ransomware-gang-acquires-kpot-malware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/17016-razor-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2021\/05\/a-closer-look-at-the-darkside-ransomware-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cpomagazine.com\/cyber-security\/ragnarok-ransomware-gang-closes-up-shop-leaves-master-decryptor-key-behind",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fbi-blackbyte-ransomware-breached-us-critical-infrastructure\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/MarsJoke-Ransomware-Mimics-CTB-Locker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/revil-ransomware-gang-launches-auction-site-to-sell-stolen-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/labs.bitdefender.com\/2021\/01\/darkside-ransomware-decryption-tool\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sababasecurity.com\/cheese-shortage-in-dutch-supermarkets-after-a-ransomware-attack",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.singleton.com\/blog\/describing-crylock-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/09\/jokefrommars-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/06\/crybrazil-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/kaseya-supply-chain-ransomware-attack-technical-analysis-revil-payload",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wlab\/w1-jun-en-story-of-the-week-ransomware-on-the-darkweb-af491d33868b",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/research\/trellix-global-defenders-analysis-and-protections-for-blackbyte-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cert.pl\/en\/news\/single\/technical-analysis-of-cryptomixcryptfile2-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/june\/8\/De00yEDVQAE_p9z[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/05\/11\/a-defenders-view-inside-a-darkside-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/analysis-blackbyte-ransomwares-go-based-variants",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/06\/pedcont-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/new-phobos-ransomware-exploits-weak-security-to-hit-targets-around-the-world\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/posts\/darkside-oil-pipeline-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ragnarok-ransomware-releases-master-decryptor-after-shutdown\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/the-blackbyte-ransomware-group-is\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-empty-cryptomix-ransomware-variant-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/crysis-ransomware-master-decryption-keys-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/june\/8\/De2sj4GW0AAuQer[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.darktrace.com\/en\/blog\/staying-ahead-of-r-evils-ransomware-as-a-service-business-model\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityscorecard.com\/blog\/new-evidence-supports-assessment-that-darkside-likely-responsible-for-colonial-pipeline-ransomware-attack-others-targeted",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ragnarok-ransomware-targets-citrix-adc-disables-windows-defender\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/0000-cryptomix-ransomware-variant-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/meteoritan-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/crysis-ransomware-distributed-through-remote-desktop-services",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/06\/scarab-diskdoctor-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.ehackingnews.com\/2019\/05\/getcrypt-ransomware-modus-operandi-and.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2022\/10\/04\/blackbyte-ransomware-returns\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/xzzx-cryptomix-ransomware-variant-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/618457\/microcop-ransomware-help-support-lock-mircop\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/crysis-ransomware\/78775\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.domaintools.com\/resources\/blog\/the-most-prolific-ransomware-families-a-defenders-guide",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/2022\/05\/the-blackbyte-ransomware-group-is.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/test-cryptomix-ransomware-variant-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.avast.com\/ransomware-decryption-tools#!",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/june\/8\/DfCO0T2WsAQvclJ[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elliptic.co\/blog\/revil-revealed-tracking-ransomware-negotiation-and-payment",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cyber-attacks\/nemty-ransomware-possibly-spreads-through-exposed-remote-desktop-connections",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-spotlight\/2021\/03\/pysa-the-ransomware-attacking-schools",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/popular-hacking-forum-bans-ransomware-ads\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/de.darktrace.com\/blog\/detecting-the-unknown-revealing-uncategorised-ransomware-using-darktrace",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/work-cryptomix-ransomware-variant-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/instruction-less-ransomware-mircop-channels-guy-fawkes\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/labs.opendns.com\/2016\/07\/13\/wildfire-ransomware-gaining-momentum\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/ransomware-gang-wants-to-short-the-stock-price-of-their-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/threat-labs\/trellix-global-defenders-analysis-and-protections-for-blackbyte-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.group-ib.com\/hancitor-cuba-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/system-cryptomix-ransomware-variant-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/wildfire-locker-ransomware-aes-256-cbc.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/bartblaze.blogspot.com\/2018\/06\/redeye-ransomware-theres-more-than.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.fincen.gov\/sites\/default\/files\/advisory\/2021-11-08\/FinCEN%20Ransomware%20Advisory_FINAL_508_.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2021\/11\/29\/pysa-ransomware-under-the-lens-a-deep-dive-analysis\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/guess-fashion-data-loss-ransomware\/167754\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2020\/06\/21\/snatch-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/my\/security\/news\/ransomware-spotlight\/ransomware-spotlight-blackbyte",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2019\/12\/cuba-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/mole66-cryptomix-ransomware-variant-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/mircop-ransomware-4848.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/06\/redeye-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.flashpoint-intel.com\/blog\/interview-with-revil-affiliated-ransomware-contractor\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/labs.sentinelone.com\/meet-nemty-successor-nefilim-nephilim-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/lab52.io\/blog\/cuba-ransomware-analysis\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-backup-cryptomix-ransomware-variant-actively-infecting-users\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/mireware-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/dissectingmalwa.re\/another-one-for-the-collection-mespinoza-pysa-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/shared-public-reports.s3-eu-west-1.amazonaws.com\/Cuba+Ransomware+Group+-+on+a+roll.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/petya-is-back-and-with-a-friend-named-mischa-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.justice.gov\/opa\/pr\/ukrainian-arrested-and-charged-ransomware-attack-kaseya",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2019\/10\/mespinoza-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/snatch-ransomware-reboots-to-windows-safe-mode-to-bypass-av-tools\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/cuba-ransomware-tropical-scorpius\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.coveware.com\/blog\/cryptomix-ransomware-exploits-cancer-crowdfunding",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/05\/petya-mischa-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/k-vitali\/Malware-Misc-RE\/master\/2019-08-24-nemty-ransomware-notes.vk.raw",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/cryptomix-ransomware-exploits-sick-children-to-coerce-payments\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/mm-locker-ransomware-aes-2256-1.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.reuters.com\/technology\/exclusive-governments-turn-tables-ransomware-gang-revil-by-pushing-it-offline-2021-10-21\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/evolution-of-jsworm-ransomware\/102428\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-exchange-servers-hacked-to-deploy-cuba-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/xrtn-ransomware-rsa-1024-gnu-privacy.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/revil-ransomware-reemerges-after-shutdown-universal-decryptor-released",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/nemty-ransomware-trik-botnet",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elastic.co\/security-labs\/cuba-ransomware-campaign-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-ransomware-called-cryptoroger-that-appends-crptrgr-to-encrypted-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fake-paypal-site-spreads-nemty-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/gasket-and-magicsocks-tools-install-mespinoza-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.acronis.com\/en-us\/articles\/darkside-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elastic.co\/security-labs\/cuba-ransomware-malware-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/cryptoroger-aes-256-0.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-revil",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/nemty-ransomware-decryptor-released-recover-files-for-free\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-gangs-script-shows-exactly-the-files-theyre-after\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advanced-intel.com\/post\/from-dawn-to-silent-night-darkside-ransomware-initial-attack-vector-evolution",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/ransomware-roundup-gwisin-kriptor-cuba-and-more",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2016\/07\/unit42-cryptobit-another-ransomware-family-gets-an-update\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/zcrypt-ransomware-rsa-2048-email.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/a\/aurora\/ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/nemty-ransomware-gets-distribution-from-rig-exploit-kit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/threat-analysis-report-inside-the-destructive-pysa-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/chemical-distributor-pays-44-million-to-darkside-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/a\/aurora\/wallpaper.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-nemty-ransomware-may-spread-via-compromised-rdp-connections\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/mobef-yakes-ransomware-4-bitcoins-2000.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.spamfighter.com\/News-21588-Aurora-Ransomware-Circulating-the-Cyber-Space.htm",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/nemty-ransomware-early-stage-threat.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.lacework.com\/blog\/pysa-ransomware-gang-adds-linux-support\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/darkside-ransomware-gang-returns-as-new-blackmatter-operation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.it-connect.fr\/le-ransomware-cuba-sen-prend-aux-serveurs-exchange\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/617601\/cryptoshocker-ransomware-help-and-support-topic-locked-attentionurl\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/617874\/zimbra-ransomware-written-in-python-help-and-support-topic-crypto-howtotxt\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.lastline.com\/labsblog\/nemty-ransomware-scaling-up-apac-mailboxes-swarmed-dual-downloaders\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/darkside-ransomware-is-creating-a-secure-data-leak-service-in-iran\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/unc2596-cuba-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/cryptoshocker-ransomware-aes-200.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/zimbra-ransomware-aes-optzimbrastore.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/aurora-zorro-ransomware-actively-being-distributed\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/areteir.com\/wp-content\/uploads\/2020\/07\/Arete_Insight_Sodino-Ransomware_June-2020.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/nemty-ransomware-learning-by-doing\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.prodaft.com\/resource\/detail\/pysa-ransomware-group-depth-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/darkside-ransomware-servers-reportedly-seized-revil-restricts-targets\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/mcafee-atr-threat-report-a-quick-primer-on-cuba-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/565020\/new-cryptotorlocker2015-ransomware-discovered-and-easily-decrypted\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/05\/aurora-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/from-the-front-lines-peering-into-a-pysa-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/us-chemical-distributor-shares-info-on-darkside-ransomware-data-theft\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/f\/cuba-ransomware-group-s-new-variant-found-using-optimized-infect.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/cryptotorlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/zorro-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/june\/8\/pgpsnippet-variant.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/karma-ransomware-an-emerging-threat-with-a-hint-of-nemty-pedigree\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/france-warns-of-new-ransomware-gang-targeting-local-governments\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/news.softpedia.com\/news\/new-open-source-linux-ransomware-shows-infosec-community-divide-508669.shtml",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/zyklon-locker-ransomware-windows-250.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/05\/pgpsnippet-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/awakesecurity.com\/blog\/threat-hunting-for-revil-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/nokoyawa-ransomware-new-karma-nemty-variant-wears-thin-disguise\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/@velasco.l.n\/exorcist-ransomware-from-triaging-to-deep-dive-5b7da4263d81",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.avertium.com\/resources\/threat-reports\/in-depth-look-at-avoslocker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2023\/08\/cuba-ransomware-deploys-new-tools-targets-critical-infrastructure-sector-in-the-usa-and-it-integrator-in-latin-america",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/09\/n1n1n1-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/01\/vxlock-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.symantec.broadcom.com\/hubfs\/SED\/SED_Threat_Hunter_Reports_Alerts\/SED_FY22Q2_SES_Ransomware-Threat-Landscape_WP.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/falcon-protects-from-darkside-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/atoms\/avoslocker-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/blog\/unc2596-cuba-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/how-ransomware-adversaries-reacted-to-the-darkside-pipeline-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.kroll.com\/en\/insights\/publications\/cyber\/avoslocker-ransomware-update",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.talosintelligence.com\/2017\/05\/jaff-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/04\/spartacus-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/c\/coronavirus-ransomware\/ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs-darkside-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.ransomlook.io\/group\/bitransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.picussecurity.com\/resource\/avos-locker-ransomware-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/profero.io\/posts\/cubaransomware\/Cuba-Ransomware-Group-on-a-roll.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/lockbit-ransomware-proliferates-globally\/168746",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/nanolocker-ransomware-aes-256-rsa-01.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/jaff-ransomware-distributed-via-necurs-malspam-and-asking-for-a-3-700-ransom\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/june\/15\/DfQI_lnXUAAukGK[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/c\/coronavirus-ransomware\/mbr-locker.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.vmware.com\/security\/2020\/12\/phorpiex-powered-bitransomware-targets-apac-universities.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/brandefense.io\/blog\/ransomware\/in-depth-analysis-of-avoslocker-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/05\/jaff-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.acronis.com\/en-us\/blog\/posts\/meet-buran-new-delphi-ransomware-delivered-rig-exploit-kit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/c\/coronavirus-ransomware\/changed-mbrlocker-screen.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.databreachtoday.com\/blogs\/darkside-ransomware-gang-launches-affiliate-program-p-2968",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/1-id--ransomware-blogspot-com.translate.goog\/2021\/12\/blackcat-ransomware.html?_x_tr_enc=1&_x_tr_sl=ru&_x_tr_tl=en&_x_tr_hl=ru",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/virus-removal\/cryptxxx-ransomware-help-information",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-june-15th-2018-dbger-scarab-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.intel471.com\/2020\/03\/31\/revil-ransomware-as-a-service-an-analysis-of-a-ransomware-affiliate-operation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securitynews.sonicwall.com\/xmlpost\/hildacrypt-ransomware-actively-spreading-in-the-wild\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-coronavirus-ransomware-acts-as-cover-for-kpot-infostealer\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.deepinstinct.com\/2021\/06\/04\/the-ransomware-conundrum-a-look-into-darkside\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.techrepublic.com\/article\/avos-ransomware-updates-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/cryptxxx-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.symantec.com\/connect\/blogs\/jaff-new-ransomware-spread-necurs-botnet",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/06\/donut-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2020\/11\/german-users-targeted-with-gootkit-banker-or-revil-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.2-spyware.com\/remove-mr-dec-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/blackcat-ransomware-highly-configurable-rust-driven-raas-on-the-prowl-for-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.tripwire.com\/state-of-security\/avoslocker-ransomware-what-you-need-to-know",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/decryptor-released-for-the-nemucod-trojans-crypted-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/05\/jaff-ransomware-analysis\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.morphisec.com\/real-time-prevention-of-the-kaseya-vsa-supply-chain-revil-ransomware-attack",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/05\/mrdec-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/s\/SNAKE\/may-2020-campaign\/snake-ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elliptic.co\/blog\/darkside-ransomware-has-netted-over-90-million-in-bitcoin",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.varonis.com\/blog\/alphv-blackcat-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cisecurity.org\/malware-analysis-report-nemucod-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/jaff-ransomware-infected-over-100000-computers-in-just-a-few-days\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/nemes1s-raas-is-padcrypt-ransomwares-affiliate-system\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.redteam.pl\/2020\/05\/sodinokibi-revil-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybersecurity-insiders.com\/meet-the-snake-ransomware-which-encrypts-all-connected-devices\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elliptic.co\/blog\/elliptic-follows-bitcoin-ransoms-paid-by-darkside-ransomware-victims",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/blackcat-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/kaspersky-releases-decryptor-for-cryptxxx-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/nemucod-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/uiwix-ransomware-using-eternalblue-smb-exploit-to-infect-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/01\/nemesis-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.sensecy.com\/2020\/08\/20\/global-ransomware-attacks-in-2020-the-top-4-vulnerabilities\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2019\/06\/freeme-freezing-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.tripwire.com\/state-of-security\/security-data-protection\/massive-spike-in-snake-ransomware-activity-attributed-to-new-campaign\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/advisories\/2022-004-acsc-ransomware-profile-alphv-aka-blackcat",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-spotlight\/2016\/05\/cryptxxx-ransomware-now-steals-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/01\/netflix-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/05\/uiwix-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/large-scale-snake-ransomware-campaign-targets-healthcare-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/newly-discovered-function-in-darkside-ransomware-variant-targets-disk-partitions",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.symantec.com\/connect\/blogs\/cryptxxx-ransomware-evolves-v30",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "all-ransomware.info",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.truesec.com\/2021\/07\/04\/kaseya-supply-chain-attack-targeting-msps-to-deliver-revil-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.emsisoft.com\/en\/40931\/ransomware-profile-alphv\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/cryptxxx2-ransomware-authors-strike-back-against-free-decryption-tool",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/analyzing-fileless-code-injecting-sorebrect-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "all-ransomware.info.txt",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/doppelpaymer-ransomware-and-dridex-2\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.intel471.com\/blog\/darkside-ransomware-colonial-pipeline-attack",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2022\/03\/06\/avoslocker-ransomware-behavior-examined-on-windows-linux",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/nhtnwcuf-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2017\/august\/25\/DHvA8CDWAAIR5er.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2021\/05\/threat-thursday-dr-revil-ransomware-strikes-again-employs-double-extortion-tactics",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.intel471.com\/blog\/darkside-ransomware-shut-down-revil-avaddon-cybercrime",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/aithority.com\/security\/doppelpaymer-ransomware-attack-sinks-a-global-motor-companys-20-million",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.maltego.com\/blog\/chasing-darkside-affiliates-identifying-threat-actors-connected-to-darkside-ransomware-using-maltego-intel-471-1\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/advisories\/2021-010-acsc-ransomware-profile-conti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2022\/01\/who-wrote-the-alphv-blackcat-ransomware-strain\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.vmware.com\/security\/2022\/02\/avoslocker-modern-linux-ransomware-threats.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/cryptxxx-ransomware-learns-samba-other-new-tricks-with-version3100",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/08\/cyron-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/09\/paradise-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ongoing-ech0raix-ransomware-campaign-targets-qnap-nas-devices\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/s3.amazonaws.com\/talos-intelligence-site\/production\/document_files\/files\/000\/095\/787\/original\/ransomware-chats.pdf?1651576098",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2022\/01\/17\/avoslocker-ransomware-linux-version-targets-vmware-esxi-servers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/ctb-faker-ransomware-does-a-poor-job-imitating-ctb-locker\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "id-ransomware.blogspot.com",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2017\/august\/25\/DHvDae7XoAE9usO[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cisoclub.ru\/doc\/otchet-kompanii-group-ib-ransomware-uncovered-2020-2021\/?bp-attachment=group-ib_ransomware_uncovered_2020-2021.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.anomali.com\/blog\/the-ech0raix-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/ransomware-virtual-machines",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/daixin-ransomware-hits-healthcare-targets-leaks-stolen-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityaffairs.co\/wordpress\/119306\/malware\/lv-ransomware-repurposed-revil-binary.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/09\/crypy-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.metabaseq.com\/recursos\/inside-darkside-the-ransomware-that-attacked-colonial-pipeline#",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/affiliate-leaks-conti-ransomware-playbook\/168442",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/ctb-faker-ransomware-008.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/noobcrypt-ransomware-dev-shows-noobness-by-using-same-password-for-everyone\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2017\/august\/25\/DHvM552WsAAuDbi[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.chainalysis.com\/reports\/ransomware-connections-maze-egregor-suncrypt-doppelpaymer",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.nozominetworks.com\/blog\/colonial-pipeline-ransomware-attack-revealing-how-darkside-works\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/conti-ransomware-gang",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/noobcrypt-ransomare-250-nzd.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/ransomware-attack-access-merchants-infostealer-escrow-service\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/malware-before-ransomware-trojan-information-stealer-cobalt-strike",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hive-ransomware-ports-its-linux-vmware-esxi-encryptor-to-rust\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/e\/avoslocker-ransomware-variant-abuses-driver-file-to-disable-anti-Virus-scans-log4shell.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/10\/nuke-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/ech0raix-ransomware-soho\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2021\/07\/23\/deep-dive-analysis-avoslocker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/research\/dark-power-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/ctb-locker-for-websites-04.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/08\/xolzsec-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/03\/b2dr-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/doublepulsar.com\/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/lifars.com\/wp-content\/uploads\/2022\/01\/GriefRansomware_Whitepaper-2.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/qnap-warns-of-ech0raix-ransomware-attacks-roon-server-zero-day\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/threat-labs\/blackcat-ransomware-as-a-service.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-intelligence\/2021\/07\/avoslocker-enters-the-ransomware-scene-asks-for-partners",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/dark-power-nim-based-ransomware-demands-10k-from-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/aaaddress1\/my-Little-Ransomware\/tree\/master\/decryptoTool",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-nullbyte-ransomware-pretends-to-be-the-necrobot-pokemon-go-application\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2017\/august\/25\/DH5KChhXsAADOIu[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.secjuice.com\/blue-team-detection-darkside-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/blackcat-ransomware-implicated-in-attack-on-german-oil-companies\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2021\/07\/avoslocker-enters-the-ransomware-scene-asks-for-partners\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/aaaddress1\/my-Little-Ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/08\/nullbyte-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/redcanary.com\/blog\/grief-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.intezer.com\/blog-russian-cybercrime-group-fullofdeep-behind-qnapcrypt-ransomware-campaigns\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.threatstop.com\/blog\/first-conti-then-hive-costa-rica-gets-hit-with-ransomware-again",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/08\/flatchestware-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/05\/yyto-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/f.hubspotusercontent10.net\/hubfs\/5943619\/Whitepaper-Downloads\/Ransomware_in_ICS_Environments_Whitepaper_10_12_20.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.intezer.com\/blog-seizing-15-active-ransomware-campaigns-targeting-linux-file-storage-servers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/meet-darkside-and-their-ransomware-sentinelone-customers-protected\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2021\/12\/blackcat-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/shining-light-dark-angels-ransomware-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2022\/01\/25\/windows-services-lay-the-groundwork-for-a-midas-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.intezer.com\/blog\/malware-analysis\/when-viruses-mutate-did-suncrypt-ransomware-evolve-from-qnapcrypt",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.splunk.com\/en_us\/blog\/security\/darkside-ransomware-splunk-threat-update-and-detections.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityscorecard.com\/blog\/ttps-associated-with-new-version-of-blackcat-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityboulevard.com\/2022\/03\/midas-ransomware-tracing-the-evolution-of-thanos-ransomware-variants\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/09\/cyber-splitter-vbs-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.splunk.com\/en_us\/blog\/security\/the-darkside-of-the-ransomware-pipeline.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/chuongdong.com\/reverse%20engineering\/2020\/12\/15\/ContiRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityscorecard.com\/research\/deep-dive-into-alphv-blackcat-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/anthology\/dark-angels-team-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/midas-ransomware-tracing-evolution-thanos-ransomware-variants",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/23\/DsoIB_0U0AAXgEz[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.technologyreview.com\/2021\/05\/24\/1025195\/colonial-pipeline-ransomware-bitdefender\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/0xthreatintel.medium.com\/reversing-conti-ransomware-bfce15019e74",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/synack-ransomware-sees-huge-spike-in-activity\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/decryptor-released-for-the-everbe-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.armor.com\/resources\/threat-intelligence\/the-evolution-of-doppel-spider-from-bitpaymer-to-grief-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/e\/what-we-know-about-darkside-ransomware-and-the-us-pipeline-attac.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/arcticwolf.com\/resources\/blog\/conti-ransomware-leak-analyzed",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/german-wind-farm-operator-confirms-cybersecurity-incident-after-ransomware-group\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/purplesec.us\/breach-report\/avoslocker-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mphasis.com\/content\/dam\/mphasis-com\/global\/en\/home\/services\/cybersecurity\/dark-angels-ransomware-apr28-22-5.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/odcodc-ransomware-rsa-2048.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/synack-ransomware-uses-process-doppelg-nging-technique\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/hatching.io\/blog\/ransomware-part2",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/doppelpaymer-ransomware-launches-site-to-post-victims-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.varonis.com\/blog\/darkside-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/bartblaze.blogspot.com.co\/2016\/02\/vipasana-ransomware-new-ransom-on-block.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/09\/synack-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/03\/everbe-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/i.blackhat.com\/eu-20\/Wednesday\/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations-wp.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs.-blackcat-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/dedcryptor-ransomware-aes-256rsa-2.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/synack-ransomware-group-releases-decryption-keys-as-they-rebrand-to-el-cometa",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/i.blackhat.com\/eu-20\/Wednesday\/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/foxconn-electronics-giant-hit-by-ransomware-34-million-ransom\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2020\/september\/25\/egregor.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/assets.sentinelone.com\/ransomware-enterprise\/conti-ransomware-unpacked",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/11220-cryakl-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/laptop-maker-compal-hit-by-ransomware-17-million-demanded\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/zawadidone.nl\/2020\/10\/05\/darkside-ransomware-analysis.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/attackiq.com\/2022\/06\/15\/attack-graph-emulating-the-conti-ransomware-teams-behaviors\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2022\/06\/13\/the-many-lives-of-blackcat-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2023\/02\/darkbit-ransomware-targets-israel",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/10\/cryptodemo-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/synack-ransomware-gang-releases-decryption-keys-for-old-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/u\/986406\/Ransomware\/DBGer\/DBGer-ransom-note.png",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-attackers-use-your-cloud-backups-against-you\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.appgate.com\/news-press\/appgate-labs-analyzes-new-family-of-ransomware-egregor",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/zawadidone.nl\/darkside-ransomware-analysis\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-detoxcrypto-ransomware-pretends-to-be-pokemongo-or-uploads-a-picture-of-your-screen\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/free-decryption-tool-released-for-cryakl-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/dbger-ransomware-uses-eternalblue-and-mimikatz-to-spread-across-networks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/changes-in-revil-ransomware-version-2-2",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/crytek-hit-by-egregor-ransomware-ubisoft-data-leaked\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/08\/detoxcrypto-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/synccrypt-ransomware-hides-inside-jpg-files-appends-kk-extension\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/06\/dbger-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cybersecuritynews.com\/egregor-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/elastio.com\/detectable-ransomware\/darkbit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/08\/synccrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/11\/rastakhiz-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2021\/06\/09\/darkside-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2021\/11\/18\/conti-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.varonis.com\/blog\/darkside-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.reversinglabs.com\/blog\/conversinglabs-ep-2-conti-pivots-as-ransomware-as-a-service-struggles",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyclonis.com\/mount-locker-ransomware-more-dangerous",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/news.thewindowsclub.com\/operation-global-iii-ransomware-decryption-tool-released-70341\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.heise.de\/news\/Uniklinik-Duesseldorf-Ransomware-DoppelPaymer-soll-hinter-dem-Angriff-stecken-4908608.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/egregor-ransomware-linked-to-maze-arrests-made-in-ukraine\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/mount-locker-ransomware-joins-the-multi-million-dollar-ransom-game",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/revoyem-dirtydecrypt-ransomware-doc.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/10\/badrabbit-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/10\/tyrant-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/ke-la.com\/easy-way-in-5-ransomware-victims-had-their-pulse-secure-vpn-credentials-leaked\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/20\/k\/egregor-ransomware-emerges-as-maze-shuts-down-operations.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/2022\/05\/conti-and-hive-ransomware-operations.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.securitymagazine.com\/articles\/94954-sophos-identifies-connection-between-mount-locker-and-astro-locker-team-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/ke-la.com\/how-ransomware-gangs-find-new-monetization-schemes-and-evolve-in-marketing\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/egregor-ransomware-gang-arrested-in-ukraine\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2021\/05\/darkside-ransomware-gang-quits-after-servers-bitcoin-stash-seized\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2022\/09\/the-curious-case-of-monti-ransomware-a-real-world-doppelganger",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/chuongdong.com\/reverse%20engineering\/2021\/12\/17\/DiavolRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/ke-la.com\/ransomware-gangs-are-starting-to-look-like-oceans-11\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/mount-locker-ransomware-changes-tactics\/165559\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/heimdalsecurity.com\/blog\/is-diavol-ransomware-connected-to-wizard-spider\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/10\/cryptowire-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/padcrypt-the-first-ransomware-with-live-support-chat-and-an-uninstaller\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/halloware-ransomware-on-sale-on-the-dark-web-for-only-40\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/a\/an-overview-of-the-doppelpaymer-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/s\/suncrypt\/maze-cartel\/ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.guidepointsecurity.com\/from-zloader-to-darkside-a-ransomware-story\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/karakurt-data-extortion-group-linked-to-conti-ransomware-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/walmartglobaltech\/diavol-the-enigma-of-ransomware-1fd78ffda648",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/11\/halloware-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/11\/wannasmile-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2019\/07\/is-revil-the-new-gandcrab-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/ransomware-gang-says-it-breached-one-of-nasas-it-contractors\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.acronis.com\/en-us\/blog\/posts\/suncrypt-adopts-attacking-techniques-netwalker-and-maze-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.justice.gov\/opa\/pr\/department-justice-seizes-23-million-cryptocurrency-paid-ransomware-extortionists-darkside",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/posts\/analysis-of-diavol-ransomware-link-trickbot-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyber.nj.gov\/threat-profiles\/ransomware-variants\/japanlocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.org\/threat-analysis\/2016\/02\/dma-locker-a-new-ransomware-but-no-reason-to-panic\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/padcrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2021\/08\/ransomware-gangs-and-the-name-game-distraction\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/the-malware-that-usually-installs-ransomware-and-you-need-to-remove-right-away\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/suncrypt-ransomware-sheds-light-on-the-maze-ransomware-cartel\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/darkside-ransomware-victims-sold-short\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.binarydefense.com\/threat_watch\/new-ransomware-diavol-being-dropped-by-trickbot\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/fortiguard-lion\/schRansomwareDecryptor\/blob\/master\/schRansomwarev1_decryptor.php",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-keypass-ransomware-campaign-underway\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.nytimes.com\/2021\/05\/29\/world\/europe\/ransomware-russia-darkside.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/diavol-ransomware-sample-shows-stronger-connection-to-trickbot-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/02\/decrypting-after-a-findzip-ransomware-infection\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/storagecrypt-ransomware-infecting-nas-devices-using-sambacry\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.kaspersky.com\/blog\/keypass-ransomware\/23447\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wlab\/deep-analysis-of-revil-ransomware-written-in-korean-d1899c0e9317",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.tetradefense.com\/incident-response-services\/cause-and-effect-suncrypt-ransomware-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2022\/03\/15\/deep-dive-analysis-pandora-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fbi-links-diavol-ransomware-to-the-trickbot-cybercrime-group\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-macos-patcher-ransomware-locks-data-for-good-no-way-to-recover-your-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/11\/storagecrypter.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/23\/DsW33OQXgAAwJzv[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wlab\/w4-may-en-story-of-the-week-ransomware-on-the-darkweb-5f5b8d4c3b6f",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/account-with-admin-privileges-abused-to-install-bitpaymer-ransomware-via-psexec",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.minerva-labs.com\/suncrypt-ransomware-gains-new-abilities-in-2022",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cyware.com\/news\/ransomware-becomes-deadlier-conti-makes-the-most-money-39e17bae\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cloudsek.com\/technical-analysis-of-emerging-sophisticated-pandora-ransomware-group\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/the-curious-case-of-the-domino-ransomware-a-windows-crack-and-a-cow\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/23\/DsobVENXcAAR3GC[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/anubis-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/08\/domino-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/06\/30\/mtr-in-real-time-hand-to-hand-combat-with-revil-ransomware-chasing-a-2-5-million-pay-day\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/nakedsecurity.sophos.com\/2018\/09\/11\/the-rise-of-targeted-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/@sapphirex00\/diving-into-the-sun-suncrypt-a-new-neighbour-in-the-ransomware-mafia-d89010c9df83",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/kienmanowar.wordpress.com\/2022\/03\/21\/quicknote-analysis-of-pandora-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-0mega-ransomware-targets-businesses-in-double-extortion-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.scythe.io\/library\/adversary-emulation-diavol-ransomware-threatthursday",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.thewindowsclub.com\/petya-ransomware-decrypt-tool-password-generator",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hc7-gotya-ransomware-installed-via-remote-desktop-services-spread-with-psexec\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/06\/30\/what-to-expect-when-youve-been-hit-with-revil-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-evil-corp-ransomware-mimics-payloadbin-gang-to-evade-us-sanctions\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wlab\/case-analysis-of-suncrypt-ransomware-negotiation-and-bitcoin-transaction-43a2194ac0bc",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cyware.com\/news\/new-0mega-ransomware-joins-the-double-extortion-threat-landscape-158fb321",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/643330\/donotchange-ransomware-id-7es642406cry-do-not-change-the-file-namecryp\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/12\/hc7-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/12\/stop-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.blueliv.com\/cyber-security-and-cyber-threat-intelligence-blog-blueliv\/research\/everis-bitpaymer-ransomware-attack-analysis-dridex\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wlab\/w4-july-en-story-of-the-week-ransomware-on-the-darkweb-c61965d0386a",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/whichbuffer\/Conti-Ransomware-IOC",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/03\/donotchange-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.org\/threat-analysis\/2016\/04\/petya-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/b\/barack-obama-ransomware\/barack-obama-everlasting-blue-blackmail-virus.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2022\/03\/17\/the-ransomware-threat-intelligence-center\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/conti-emotet-ransomware-conti-leaks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/11\/hc6-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/public.intel471.com\/blog\/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/csi-evidence-indicators-for-targeted-ransomware-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/suncrypt-ransomware-is-still-alive-and-kicking-in-2022\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/xtplocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/qkg-ransomware-encrypts-only-word-documents-hides-and-spreads-via-macros\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/barack-obamas-blackmail-virus-ransomware-only-encrypts-exe-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/public.intel471.com\/blog\/revil-ransomware-interview-russian-osint-100-million\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-april-1st-2022-i-can-fight-with-a-keyboard\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/627831\/dxxd-ransomware-dxxd-help-support-readmetxt\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/11\/qkg-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/08\/barack-obamas-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/shipping-companies-ransomware-credentials",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/new-rook-ransomware-feeds-off-the-code-of-babuk",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-dxxd-ransomware-displays-legal-notice-before-users-login\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.ru\/2016\/09\/philadelphia-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2018\/01\/26\/friedex-bitpaymer-ransomware-work-dridex-authors\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/abrahams-ax",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/09\/dxxd-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2020\/06\/ransomexx-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2022\/03\/conti-ransomware-group-diaries-part-ii-the-office\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/chuongdong.com\/reverse%20engineering\/2022\/01\/06\/RookRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/hitlerransomware[.]000webhostapp[.]com\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/continental-confirms-data-breach-after-donut-leaks-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2019\/01\/unnamed-desync-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/lifars.com\/wp-content\/uploads\/2021\/10\/ContiRansomware_Whitepaper.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/Dump-GUY\/Malware-analysis-and-Reverse-engineering\/blob\/main\/NightSky_Ransomware%E2%80%93just_a_Rook_RW_fork_in_VMProtect_suit\/NightSky_Ransomware%E2%80%93just_a_Rook_RW_fork_in_VMProtect_suit.md",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/hitleransomware[.]cf\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/continental-confirms-data-breach-donut-leaks-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/eviltwins-exotic-ransomware-targets-executable-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/hiddentear-2.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/pizzacrypts-ransomware-1.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/august\/31\/ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/searchsecurity.techtarget.com\/feature\/Ransomware-negotiations-An-inside-look-at-the-process",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/marcoramilli.com\/2021\/11\/07\/conti-ransomware-cheat-sheet\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/seguranca-informatica.pt\/rook-ransomware-analysis\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.securityweek.com\/donut-leaks-ransomware-group-claims-attack-on-continental\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-october-14-2016-exotic-lockydump-comrade-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/cryptonar-ransomware-discovered-and-quickly-decrypted\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/ransomware-world-in-2021\/102169\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/brazils-court-system-under-massive-ransomexx-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/new-rook-ransomware-feeds-off-the-code-of-babuk\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/stamparm\/maltrail\/master\/trails\/static\/malware\/hitler_ransomware.txt",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/netwalker-ransomware-suspect-charged\/163405",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyber.nj.gov\/threat-profiles\/ransomware-variants\/exotic-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/pokemongo-ransomware-installs-backdoor-accounts-and-spreads-to-other-drives\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/revil-ransomware-attack-on-msp-companies\/103075\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tales-from-the-trenches-a-lockbit-ransomware-story\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/@whickey000\/how-i-cracked-conti-ransomware-groups-leaked-source-code-zip-file-e15d54663a8",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs.-netwalker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/exotic-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/08\/pokemongo-ransomware-aes-256.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/08\/cryptonar-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/usa.kaspersky.com\/resource-center\/threats\/lockbit-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/cycraft\/the-road-to-ransomware-resilience-c1ca37036efd",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/endurance",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.ncsc.org\/trends\/monthly-trends-articles\/2020\/netwalker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securingtomorrow.mcafee.com\/other-blogs\/mcafee-labs\/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-crescendo\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/computer-hardware-giant-gigabyte-hit-by-ransomexx-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/nakedsecurity.sophos.com\/2021\/08\/06\/conti-ransomware-affiliate-goes-rogue-leaks-company-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/development-version-of-the-hitler-ransomware-discovered\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/apt-ransomware-2.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/el-polocker-ransomware-aes-450-aud.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/08\/creampie-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securingtomorrow.mcafee.com\/other-blogs\/mcafee-labs\/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/lifars.com\/wp-content\/uploads\/2022\/02\/LockBitRansomware_Whitepaper.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs.-ransomexx-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/02\/16\/conti-ransomware-attack-day-by-day\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/helloxd-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.securityweek.com\/unfinished-hitler-ransomware-variant-deletes-user-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/02\/16\/conti-ransomware-evasive-by-nature\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/stairwell.com\/wp-content\/uploads\/2022\/07\/Stairwell-Threat-Report-Maui-Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.infosecurity-magazine.com\/news\/hitler-ransomware-deletes-users\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2021\/03\/zerologon-to-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/ws-go-ransonware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/august\/31\/DlpDe-kXsAA2lmH[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/posts\/sodinokibi-ransomware-incident-response-intelligence-together\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/gustavopalazolo.medium.com\/ransomexx-an%C3%A1lise-do-ransomware-utilizado-no-ataque-ao-stj-918001ec8195",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/02\/16\/what-to-expect-when-youve-been-hit-with-conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.theregister.com\/2016\/08\/10\/hitler_ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cert-agid.gov.it\/news\/netwalker-il-ransomware-che-ha-beffato-lintera-community\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyber.nj.gov\/threat-profiles\/ransomware-variants\/apt-ransomware-v2",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.carbonblack.com\/2016\/03\/25\/threat-alert-powerware-new-ransomware-written-in-powershell-targets-organizations-via-microsoft-word\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/posts\/sodinokibi-revil-ransomware-disrupt-trade-secrets\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/maze-ransomware-now-delivered-by-spelevo-exploit-kit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/lockbit-victim-estimates-cost-of-ransomware-attack-to-be-42-million\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ecuadors-state-run-cnt-telco-hit-by-ransomexx-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/09\/03\/conti-affiliates-use-proxyshell-exchange-exploit-in-ransomware-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/siliconangle.com\/2016\/08\/10\/hitler-ransomware-may-be-goosestepping-onto-a-computer-near-you\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2022\/02\/23\/dridex-bots-deliver-entropy-ransomware-in-recent-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/11\/encryptojjs-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2016\/07\/unit42-powerware-ransomware-spoofing-locky-malware-family\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/08\/cassetto-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityscorecard.com\/research\/a-detailed-analysis-of-the-last-version-of-revil-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.ctir.gov.br\/arquivos\/alertas\/2020\/alerta_2020_03_ataques_de_ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.knowbe4.com\/hitler-ransomware-just-deletes-files-instead-of-encrypting-them",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2022\/02\/23\/dridex-bots-deliver-entropy-ransomware-in-recent-attacks\/?cmp=30728",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/powerware-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/september\/14\/Scarab-ransomware.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/august\/31\/Dlq8W3FXoAAYR1v[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/techcrunch.com\/2020\/11\/02\/maze-ransomware-group-shutting-down",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.dragos.com\/blog\/industry-news\/dragos-ics-ot-ransomware-analysis-q4-2021\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/arcticwolf.com\/resources\/blog\/lorenz-ransomware-chiseling-in\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2019\/09\/koko-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/ncrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/23\/DsnFZrGX4AE2H1c[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/kaseya-ransomware-supply-chain",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/ransomware-roundup-new-variants",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2022\/leaks-of-conti-ransomware-group-paint-picture-of-a-surprisingly-normal-tech-start-up-sort-of\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2021\/01\/arrest-seizures-tied-to-netwalker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/the-enigma-ransomware-targets-russian-speaking-users\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/30\/Ds8PMFpW0AIcYuJ[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/august\/31\/DlraMbTWwAA_367[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/sodinokibi-ransomware-cobalt-strike-pos",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/venis-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/05\/enigma-ransomware-aes-128-0.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/introducing-her-royal-highness-the-princess-locker-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/december\/7\/DtzAAIAW0AEHC86[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/symantec.broadcom.com\/hubfs\/The_Ransomware_Threat_September_2021.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/05\/27\/netwalker-ransomware-tools-give-insight-into-threat-actor\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2016\/11\/princess-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/august\/31\/Dl2M9kdX0AAcGbJ[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/teamt5.org\/en\/posts\/introducing-the-most-profitable-ransomware-revil\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/amgedwageh.medium.com\/lockbit-ransomware-analysis-notes-93a542fc8511",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/s3.amazonaws.com\/talos-intelligence-site\/production\/document_files\/files\/000\/095\/787\/original\/ransomware-chats.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-fairware-ransomware-targeting-linux-computers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/09\/princess-locker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/scarab-ransomware-pushed-via-massive-spam-campaign\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/luna-black-basta-ransomware\/106950",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/seguranca-informatica.pt\/netwalker-ransomware-full-analysis\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.fortinet.com\/post\/fakben-team-ransomware-uses-open-source-hidden-tear-code",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.enigmasoftware.com\/prismyourcomputerhasbeenlockedransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/labsblog.f-secure.com\/2017\/11\/23\/necurs-business-is-booming-in-a-new-partnership-with-scarab-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/s\/sigma\/craigslist-malspam\/ransom-note-html-part_01.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/tehtris.com\/fr\/peut-on-neutraliser-un-ransomware-lance-en-tant-que-system-sur-des-milliers-de-machines-en-meme-temps\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.minerva-labs.com\/egregor-ransomware-an-in-depth-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityaffairs.co\/wordpress\/128190\/cyber-crime\/conti-ransomware-takes-over-trickbot.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/tccontre.blogspot.com\/2020\/05\/netwalker-ransomware-api-call.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/fakben-team-ransomware-aes-256-1505.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.forcepoint.com\/security-labs\/massive-email-campaign-spreads-scarab-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/s\/sigma\/craigslist-malspam\/ransom-note-html-part_02.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/03\/29\/sodinokibi-aka-revil-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-ransomexx",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityandtechnology.org\/wp-content\/uploads\/2021\/04\/IST-Ransomware-Task-Force_Final_Report.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2020\/08\/31\/netwalker-ransomware-in-1-hour\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "Ransomware.txt",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/s\/sigma\/craigslist-malspam\/payment-portal.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2022\/07\/05\/lockbit-3-0-ransomware-group-launches-new-version\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advanced-intel.com\/post\/netwalker-ransomware-group-enters-advanced-targeting-game",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/fantom-ransomware-encrypts-your-files-while-pretending-to-be-windows-update\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/myonlinesecurity.co.uk\/necurs-botnet-malspam-delivering-a-new-ransomware-via-fake-scanner-copier-messages\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sigma-ransomware-being-distributed-using-fake-craigslist-malspam\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/an-interview-with-blackmatter-a-new-ransomware-group-thats-learning-from-the-mistakes-of-darkside-and-revil\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.reuters.com\/article\/us-usa-products-colonial-pipeline-ransom\/more-ransomware-websites-disappear-in-aftermath-of-colonial-pipeline-hack-idUSKCN2CX0KT",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/enel-group-hit-by-ransomware-again-netwalker-demands-14-million",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/enigma-2-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/r-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/darkside-gang-estimated-to-have-made-over-90-million-from-ransomware-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.quickheal.com\/maze-ransomware-continues-threat-consumers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/ransomware-hive-conti-avoslocker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/16737-ako-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/enel-group-hit-by-ransomware-again-netwalker-demands-14-million\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/darkside-ransomware-gang-says-it-lost-control-of-its-servers-money-a-day-after-biden-threat\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/covidlock-android-ransomware-walkthrough-and-unlocking-routine",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/05\/12\/conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/hive-attacks-analysis-of-the-human-operated-ransomware-targeting-healthcare\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/everest-ransomware-extortion",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/mailto-netwalker-ransomware-targets-enterprise-networks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/deadly-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/chuongdong.com\/reverse%20engineering\/2022\/03\/19\/LockbitRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cyberflorida.org\/threat-advisory\/tycoon-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/08\/01\/bazarcall-to-conti-ransomware-via-trickbot-and-cobalt-strike\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-hive",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/images\/stories\/screenshots202004\/ako-ransomware-update-2020-04-09-text-file.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/research\/everest-ransomware-gang-offers-access-to-compromised-networks.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/michigan-state-university-network-breached-in-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/09\/fenixlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/07\/r980-ransomware-aes-256-rsa4096-05.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/ransomwhere-project-wants-to-create-a-database-of-past-ransomware-payments\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/albertzsigovits\/malware-notes\/blob\/master\/Ransomware\/Maze.md",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cluster25.io\/2022\/07\/06\/lockbit-3-0-making-the-ransomware-great-again\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/09\/13\/bazarloader-to-conti-ransomware-in-32-hours\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/07\/05\/hive-ransomware-gets-upgrades-in-rust\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/everest-ransomware-now-selling-company-data-on-hacker-forums\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/netwalker-ransomware-affiliate-sentenced-to-80-months-in-prison\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/reaqta.com\/2016\/06\/raa-ransomware-delivering-pony\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fallout-exploit-kit-now-installing-the-kraken-cryptor-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/revil-ransomware-executes-supply-chain-attack-via-malicious-kaseya-update\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2019\/05\/chacha-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/yoroi.company\/wp-content\/uploads\/2022\/07\/Yoroi-On-The-Footsteps-of-Hive-Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/netwalker-ransomware-infecting-users-via-coronavirus-phishing\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/03\/filefrozr-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/the-new-raa-ransomware-is-created-entirely-using-javascript\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/kraken-cryptor-ransomware-masquerading-as-superantispyware-security-program\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/conti-ransomware-cooperation-maze-lockbit-ragnar-locker",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/documents.trendmicro.com\/assets\/pdf\/datasheet-ransomware-in-Q1-2022.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.varonis.com\/blog\/hive-ransomware-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/images\/stories\/screenshots202010\/ako-ransomware-update-2020-10-15-text-file.gif",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/raa-ransomware-aes-256-039-250.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/06\/scarab-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/killbit.medium.com\/applying-the-diamond-model-to-cognizant-msp-and-maze-ransomware-and-a-policy-assessment-498f01bd723f",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/albertzsigovits\/malware-notes\/blob\/master\/Ransomware\/Lockbit.md",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/comrade-circle-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/01\/bleedgreen-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-november-9th-2018-mostly-dharma-variants\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2019\/12\/ransomware-gangs-now-outing-victim-businesses-that-dont-pay-up\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/search?q=lockbit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2022\/04\/04\/stolen-images-campaign-ends-in-conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.healthcareitnews.com\/news\/fbi-issues-alert-about-hive-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/tripwire.com\/state-of-security\/ako-ransomware-using-spam-attachments-to-target-networks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fallout-exploit-kit-pushing-the-savefiles-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/labs.sentinelone.com\/case-study-catching-a-human-operated-maze-ransomware-attack-in-action\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/attackiq.com\/2025\/01\/09\/emulating-ako-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.incibe-cert.es\/blog\/ransomware-netwalker-analisis-y-medidas-preventivas",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/globe2-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/09\/flyper-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/file-spider-ransomware-targeting-the-balkans-with-malspam\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/conti-leaks-the-panama-papers-of-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/sonicwall.com\/blog\/ako-ransomware-demands-3000-operators-hide-behind-tor",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.justice.gov\/opa\/pr\/department-justice-launches-global-action-against-netwalker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-radamant-ransomware-kit-adds-rdm-extension-to-encrypted-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/12\/file-spider-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/@amgedwageh\/lockbit-ransomware-analysis-notes-93a542fc8511",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/disgruntled-ransomware-affiliate-leaks-the-conti-gangs-technical-manuals\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/nakedsecurity.sophos.com\/2020\/06\/04\/nuclear-missile-contractor-hacked-in-maze-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wlab\/w4-jan-en-story-of-the-week-ransomware-on-the-darkweb-7595544363b1",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/affiliate-leaks-conti-ransomware-playbook\/168442\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/lifars.com\/2022\/02\/how-to-decrypt-the-files-encrypted-by-the-hive-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/radamant-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/05\/12\/maze-ransomware-1-year-counting\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/04\/24\/lockbit-ransomware-borrows-tricks-to-keep-up-with-revil-and-maze\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/conti-ransomware-decryptor-trickbot-source-code-leaked\/178727\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityaffairs.co\/wordpress\/128232\/security\/recover-files-hive-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/grief-ransomware-linked-to-evil-corp-hackers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/an-in-depth-look-at-mailto-ransomware-part-one-of-three\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/kostya-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/f\/file-locker\/ransom-note%20-%20Copy.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/conti-ransomware-v-3-including-decryptor-leaked\/179006\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2022\/02\/master-key-for-hive-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/an-in-depth-look-at-mailto-ransomware-part-three-of-three\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-october-14-2016-exotic-lockydump-comrade-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/12\/roga-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/file-locker-ransomware-targets-korean-victims-and-asks-for-50k-won\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/09\/22\/mtr-casebook-blocking-a-15-million-maze-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2022\/04\/12\/attackers-linger-on-government-agency-computers-before-deploying-lockbit-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/academics-publish-method-for-recovering-data-encrypted-by-the-hive-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cloudsek.com\/ar\/threatintelligence\/ransomware-group-profile-arvin-club",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/an-in-depth-look-at-mailto-ransomware-part-two-of-three\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/bandarchor-ransomware-aes-256.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/12\/08\/egregor-ransomware-mazes-heir-apparent\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ragnar-locker-ransomware-targets-msp-enterprise-support-tools\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/hive-ransomware-shuts-down-california-health-care-organization\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/arvin-club",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/i\/grief-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/fs0ciety-locker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/628199\/fs0ciety-locker-ransomware-help-support-fs0cietyhtml\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/research.nccgroup.com\/2022\/08\/19\/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-fsociety-ransomware-pays-homage-to-mr-robot\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/new-ransomware-trends-in-2022\/106457\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybersecurity-insiders.com\/ransomware-attack-makes-cwt-pay-4-5-million-in-bitcoins-to-hackers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/intel471.com\/blog\/groove-gang-ransomware-babuk-revil-blackmatter",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zeit.de\/digital\/2021-06\/cybercrime-extortion-internet-spyware-ransomware-police-prosecution-hackers",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/09\/erebus-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2017\/03\/unit42-targeted-ransomware-attacks-middle-eastern-government-organizations-political-purposes\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/c\/CommonRansom\/ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/maze-ransomware\/99137\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/posts\/lockbit-ransomware-attacks-surge-affiliate-recruitment\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/05\/21\/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/yoroi.company\/research\/on-the-footsteps-of-hive-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/enterprise\/mcafee-enterprise-atr\/how-groove-gang-is-shaking-up-the-ransomware-as-a-service-market-to-empower-affiliates",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/zengo.com\/bitcoin-ransomware-detective-ucsf\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/08\/fsociety-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-ranran-ransomware-uses-encryption-tiers-political-messages\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/commonransom-ransomware-demands-rdp-access-to-decrypt-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/targeted-ransomware-encrypting-data\/99255\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityscorecard.com\/research\/the-increase-in-ransomware-attacks-on-local-governments",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-gang-threatens-to-leak-data-if-victim-contacts-fbi-police",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/conti-ransomware-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/labs.sentinelone.com\/hive-attacks-analysis-of-the-human-operated-ransomware-targeting-healthcare\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/ransoc-desktop-locking-ransomware-ransacks-local-files-social-media-profiles",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/prometheus-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/seguranca-informatica.pt\/malware-analysis-details-on-lockbit-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hive-ransomware-uses-new-ipfuscation-trick-to-hide-payload\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransoc-ransomware-extorts-users-who-accessed-questionable-content\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/threat-labs\/analysis-and-protections-for-ragnarlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/dark-web-profile-fsociety-flocker-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/ransom32.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/threat-brief-kaseya-vsa-ransomware-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/techcrunch.com\/2020\/03\/26\/chubb-insurance-breach-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advanced-intel.com\/post\/secret-backdoor-behind-conti-ransomware-operation-introducing-atera-agent",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/new-haron-ransomware-gang-emerges-borrowing-from-avaddon-and-thanos",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/ransomware-gangs-haron-blackmatter\/168212",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/09\/rarvault-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-pretends-to-be-proton-security-team-securing-data-from-hackers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/techcommunity.microsoft.com\/t5\/security-compliance-and-identity\/part-1-lockbit-2-0-ransomware-bugs-and-database-recovery\/ba-p\/3254354",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advintel.io\/post\/backup-removal-solutions-from-conti-ransomware-with-love",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2022\/07\/05\/hive-ransomware-gets-upgrades-in-rust\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/05\/ghostcrypt-ransomware-aes-256-2-bitcoins.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/september\/14\/mvp.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/techcommunity.microsoft.com\/t5\/security-compliance-and-identity\/part-2-lockbit-2-0-ransomware-bugs-and-database-recovery\/ba-p\/3254421",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.netskope.com\/blog\/hive-ransomware-actively-targeting-hospitals",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/vulnerability.ch\/2021\/04\/ransomware-and-date-leak-site-publication-time-analysis\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/allied-universal-breached-by-maze-ransomware-stolen-data-leaked\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/australian-cybersecurity-agency-warns-of-spike-in-lockbit-ransomware-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2022\/01\/20\/deep-dive-into-ragnar-locker-ransomware-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advintel.io\/post\/hydra-with-three-heads-blackbyte-the-future-of-ransomware-subsidiary-groups",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.scmagazine.com\/brief\/breach\/novel-obfuscation-leveraged-by-hive-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/the-globe-ransomware-wants-to-purge-your-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/08\/razy-ransomware-aes.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20210305181115\/https:\/\/cisoclub.ru\/doc\/otchet-kompanii-group-ib-ransomware-uncovered-2020-2021\/?bp-attachment=group-ib_ransomware_uncovered_2020-2021.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/chipmaker-maxlinear-reports-data-breach-after-maze-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/conti-ransomware-gang-chats-leaked-by-pro-ukraine-member\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advintel.io\/post\/ransomware-advisory-log4shell-exploitation-for-initial-access-lateral-movement",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/hive-ransomware-deploys-novel-ipfuscation-technique\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/images\/stories\/screenshots202109\/atomsilo-ransomware-ransom-note-in-gif-image.gif",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/07\/purge-kind-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/9\/moira.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.accenture.com\/us-en\/blogs\/cyber-defense\/evolving-danger-ransomware-extortion",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/crytek-confirms-egregor-ransomware-attack-customer-data-theft\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/missed-opportunity-bug-in-lockbit-ransomware-allowed-free-decryptions\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bankinfosecurity.com\/cybercrime-moves-conti-ransomware-absorbs-trickbot-malware-a-18573",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyfirma.com\/outofband\/malware-research-on-atomsilo-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hotarus-ransomware-gang-hacks-ecuadorian-government-agencies-banks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/night-sky-is-the-latest-ransomware-targeting-corporate-networks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/08\/rektlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.acronis.com\/en-sg\/articles\/sodinokibi-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/angry-conti-ransomware-affiliate-leaks-gangs-attack-playbook\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/atomsilo-ransomware-enters-league-double-extortion",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/it-services-giant-cognizant-suffers-maze-ransomware-cyber-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2020\/02\/ragnarlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-updates-conti-ransomware-alert-with-nearly-100-domain-names\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.ru\/2016\/05\/gnl-locker-ransomware-gnl-locker-ip.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advanced-intel.com\/post\/from-qbot-with-revil-ransomware-initial-attack-exposure-of-jbs",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/maze-ransomware-behind-pensacola-cyberattack-1m-ransom-demand\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/emerging-ransomware-groups\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2020\/11\/ransomware-group-turns-to-facebook-ads\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/conti-ransomware-gang-takes-over-trickbot-malware-operation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/10\/04\/atom-silo-ransomware-actors-use-confluence-exploit-dll-side-load-for-stealthy-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/gomasom-ransonware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/remindme-ransomware-2.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/g\/gandcrab\/v3\/desktop-background.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/maze-ransomware-is-shutting-down-its-cybercrime-operation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/conti-ransomware-source-code-leaked-by-ukrainian-researcher\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/chuongdong.com\/reverse%20engineering\/2021\/10\/13\/AtomSiloRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/angler-shift-ek-landscape-new-crytpo-ransomware-activity\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/maze-ransomware-now-encrypts-via-virtual-machines-to-evade-detection\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advanced-intel.com\/post\/from-russia-with-lockbit-ransomware-inside-look-preventive-solutions",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/conti-ransomwares-internal-chats-leaked-after-siding-with-russia\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/decoded.avast.io\/threatintel\/decryptor-for-atomsilo-and-lockfile-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-alfa-or-alpha-ransomware-from-the-same-devs-as-cerber\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.org\/threat-analysis\/2016\/04\/rokku-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/gandcrab-ransomware-distributed-by-exploit-kits-appends-gdcb-extension\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/maze-ransomware-releases-files-stolen-from-city-of-pensacola\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/blackmatter-ransomware-moves-victims-to-lockbit-after-shutdown\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-use-contis-leaked-ransomware-to-attack-russian-companies\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.softpedia.com\/news\/cerber-devs-create-new-ransomware-called-alfa-506165.shtml",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/12\/hackedlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/rokku-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/gandcrab-ransomware-being-distributed-via-malspam-disguised-as-receipts\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.appgate.com\/blog\/electric-company-ransomware-attack-calls-for-14-million-in-ransom",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-dev-releases-egregor-maze-master-decryption-keys\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/energy-group-erg-reports-minor-disruptions-after-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hhs-conti-ransomware-encrypted-80-percent-of-irelands-hse-it-systems\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/info.phishlabs.com\/blog\/alma-ransomware-analysis-of-a-new-ransomware-threat-and-a-decrypter",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/gandcrab-ransomware-version-2-released-with-new-crab-extension-and-other-changes\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/23\/vapor.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bankinfosecurity.com\/interviews\/ransomware-files-episode-6-kaseya-revil-i-5045",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/lockbit-ransomware-gang-claims-attack-on-bridgestone-americas\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/capcom-hit-by-ragnar-locker-ransomware-1tb-allegedly-stolen\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/chuongdong.com\/\/reverse%20engineering\/2021\/10\/13\/AtomSiloRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-alma-locker-ransomware-being-distributed-via-the-rig-exploit-kit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/happydayzz-blackjocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/02\/allyourdocuments-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.blackberry.com\/content\/dam\/blackberry-com\/asset\/enterprise\/pdf\/wp-spark-state-of-ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.brighttalk.com\/webcast\/7451\/408167\/navigating-maze-analysis-of-a-rising-ransomware-threat",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/lockbit-ransomware-gang-gets-aggressive-with-triple-extortion-tactic\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fbi-ransomware-gang-breached-52-us-critical-infrastructure-orgs\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-exchange-servers-hacked-to-deploy-hive-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-fallout-exploit-kit-drops-gandcrab-ransomware-or-redirects-to-pups\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/23\/DsPVGaHXcAAtnXz[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/a-look-inside-the-highly-profitable-sodinokibi-ransomware-business\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/lockbit-ransomware-now-encrypts-windows-domains-using-group-policies\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ryuk-successor-conti-ransomware-releases-data-leak-site\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/decrypted-alpha-ransomware-accepts-itunes-gift-cards-as-payment\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.linkedin.com\/pulse\/mamba-new-full-disk-encryption-ransomware-family-member-marinho",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/gandcrab-v5-ransomware-utilizing-the-alpc-task-scheduler-exploit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/another-ransomware-will-now-publish-victims-data-if-not-paid\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/lockbit-ransomware-recruiting-insiders-to-breach-corporate-networks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/taiwanese-apple-and-tesla-contractor-hit-by-conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/01\/gandcrab-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/23\/DsiUA0LXgAAoqkd[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/blackmatter-ransomware-gang-rises-from-the-ashes-of-darkside-revil\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/maze-ransomware-deobfuscation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-attack-hits-italys-lazio-region-affects-covid-19-site\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/09\/hddcryptor-ransomware-mbr.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/sadstory-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/23\/DsuMFrZW0AIIUXs[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/darkside-ransomware-made-90-million-in-just-nine-months\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/uk-rail-network-merseyrail-likely-hit-by-lockbit-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/heimdalsecurity.com\/blog\/avaddon-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/heimdall-open-source-php-ransomware-targets-web-servers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/malwarebreakdown.com\/2017\/03\/16\/sage-2-2-ransomware-from-good-man-gate",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/gandcrab-ransomware-shuts-down-after-claiming-to-have-made-over-2-billion\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fbi-revil-cybergang-behind-the-jbs-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ragnarlocker-ransomware-threatens-to-release-confidential-information",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.clearskysec.com\/wp-content\/uploads\/2021\/02\/Conti-Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/atos.net\/en\/lp\/securitydive\/avaddon-ransomware-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/ambaransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/11\/heimdall-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/19\/f\/uncovering-the-evolution-of-gandcrab-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/kaseya-obtains-universal-decryptor-for-revil-ransomware-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/02\/melting-unc2198-icedid-to-ransomware-operations.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.coveware.com\/blog\/2022\/1\/26\/ransomware-as-a-service-innovation-curve",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.theregister.com\/2022\/03\/09\/fbi_says_ragnar_locker_ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.acronis.com\/en-us\/articles\/avaddon-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/november\/30\/Ds4IYbfWsAECNuJ[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/csi-evidence-indicators-for-targeted-ransomware-attacks-part-ii\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/how-crowdstrike-prevents-volume-shadow-tampering-by-lockbit-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyber.gov.au\/sites\/default\/files\/2021-05\/2021-003%20Ongoing%20campaign%20using%20Avaddon%20Ransomware%20-%2020210508.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/09\/helpdcfile-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.talosintel.com\/2016\/03\/samsam-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/gandcrab-ransomware\/89631\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-jersey-synagogue-suffers-sodinokibi-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crypsisgroup.com\/insights\/ransomwares-new-trend-exfiltration-and-extortion",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.fortinet.com\/2016\/06\/03\/cooking-up-autumn-herbst-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.intelsecurity.com\/advanced-threat-research\/content\/Analysis_SamSa_Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/shurl0ckr-ransomware-as-a-service-peddled-on-dark-web-can-reportedly-bypass-cloud-applications",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/popular-russian-hacking-forum-xss-bans-all-ransomware-topics\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/rising-threat-from-lockbit-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "ransomware.attack",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/herbst-autumn-ransomware-aes-256-01.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/sensorstechforum.com\/fr\/fairytail-files-virus-cryakl-ransomware-remove-restore-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-november-30th-2018-indictments-sanctions-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-threatens-to-reveal-companys-dirty-secrets\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/threat-analysis-report-from-shatak-emails-to-the-conti-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/samsam-ransomware-crew-made-nearly-6-million-from-ransom-payments\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.technologynews.tech\/cryakl-ransomware-virus",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/threat-labs\/conti-leaks-examining-the-panama-papers-of-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyberscoop.com\/ransomware-gang-conti-bounced-back\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wlab\/quick-analysis-of-haron-ransomware-feat-avaddon-and-thanos-1ebb70f64dc4",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.ru\/2016\/05\/hi-buddy-ransomware-aes-256-0.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.zdnet.com\/article\/cryakl-ransomware-decryption-keys-now-available-for-free\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-devs-added-a-backdoor-to-cheat-affiliates\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/avaddon-ransomware-operation-shuts-down-and-releases-decryption-keys\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/development-version-of-the-hitler-ransomware-discovered\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/03\/samsam.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-gang-claims-over-100-million-profit-in-a-year\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/ransomware-gang-publishes-tens-of-gbs-of-internal-data-from-lg-and-xerox\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.darktrace.com\/en\/blog\/the-double-extortion-business-conti-ransomware-gang-finds-new-avenues-of-negotiation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2022\/07\/12\/new-ransomware-groups-on-the-rise\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.eclecticiq.com\/resources\/thanatos--ransomware-first-ransomware-ask-payment-bitcoin-cash?type=intel-report",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-gangs-web-sites-mysteriously-shut-down\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.intrinsec.com\/alphv-ransomware-gang-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/as-maze-ransomware-group-retires-clients-turn-to-sekhmet-ransomware-spin-off-egregor\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.dragos.com\/blog\/industry-news\/suspected-conti-ransomware-activity-in-the-auto-manufacturing-sector\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/08\/hitler-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/sanction-ransomware-3.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/02\/thanatos-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-infects-100k-pcs-in-china-demands-wechat-payment\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.lemagit.fr\/actualites\/252516821\/Ransomware-LockBit-30-commence-a-etre-utilise-dans-des-cyberattaques",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-python-ransomware-called-holycrypt-discovered\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sanctions-ransomware-makes-fun-of-usa-sanctions-against-russia\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/chinese-police-arrest-dev-behind-unnamed1989-wechat-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-hits-1-000-plus-companies-in-msp-supply-chain-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/fake-windows-update-spam-leads-to-cyborg-ransomware-and-its-builder\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mbsd.jp\/2021\/10\/27\/assets\/images\/MBSD_WhitePaper_A-deep-dive-analysis-of-LockBit2.0_Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elliptic.co\/blog\/conti-ransomware-nets-at-least-25.5-million-in-four-months",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advanced-intel.com\/post\/the-rise-demise-of-multi-million-ransomware-business-empire",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.emsisoft.com\/2016\/06\/29\/apocalypse-ransomware-which-targets-companies-through-insecure-rdp\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/holycrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/sanctions-2017-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/december\/7\/Dtlxf0eW4AAJCdZ[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-hits-managedcom-hosting-provider-500k-ransom\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2022\/05\/09\/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/another-ransomware-now-uses-ddos-attacks-to-force-victims-to-pay\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-returns-new-malware-sample-confirms-gang-is-back\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/avaddon-ransomware-shuts-down-and-releases-decryption-keys\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.securityweek.com\/rsautil-ransomware-distributed-rdp-attacks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-december-7th-2018-wechat-ransomware-scammers-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomwares-servers-mysteriously-come-back-online\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/exchange.xforce.ibmcloud.com\/collection\/FTCODE-Ransomware-45dacdc2d5cf30722ced20b9d37988c2",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/elastio.com\/detectable-ransomware\/amnesia-2\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/hydracrypt-ransomware-aes-256-cbc-rsa.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2016\/06\/satana-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/rsautil-ransomware-helppme-india-com-installed-via-hacked-remote-desktop-services\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revils-tor-sites-come-alive-to-redirect-to-new-ransomware-operation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sonicwall.com\/blog\/amnesia-ransomware-continues-high-payment-trend-july-21-2017",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.kaspersky.com\/satana-ransomware\/12558\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.lu\/2017\/04\/rsautil-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sodinokibi-ransomware-hits-new-york-airport-systems\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/lockbit-3-0-update-unpicking-the-ransomwares-latest-anti-analysis-and-evasion-techniques\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.emsisoft.com\/en\/ransomware-decryption\/amnesia2\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.swascan.com\/it\/avaddon-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/satana-ransomware-0.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.lu\/2017\/04\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/december\/7\/DtkQKCDWoAM13kD[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sodinokibi-ransomware-hits-travelex-demands-3-million\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mbsd.jp\/research\/20210413\/conti-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/securelist.com\/blog\/research\/69481\/a-flawed-ransomware-encryptor\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/qwerty-ransomware-utilizes-gnupg-to-encrypt-a-victims-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sodinokibi-ransomware-may-tip-nasdaq-on-attacks-to-hurt-stock-prices\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/ransomware-report-avaddon-and-new-techniques-emerge-industrial-sector-targeted",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/11\/iransom-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sodinokibi-ransomware-publishes-stolen-data-for-the-first-time\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/la-es\/2021\/05\/31\/ransomware-avaddon-principales-caracteristicas\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/08\/serpico-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/december\/14\/Dt-APfCW0AADWV8[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sodinokibi-ransomware-says-travelex-will-pay-one-way-or-another\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/the-shark-ransomware-project-allows-to-create-your-own-customized-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sodinokibi-ransomware-threatens-to-publish-data-of-automotive-group\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/h\/lockbit-resurfaces-with-version-2-0-ransomware-detections-in-chi.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/0xc1r3ng.wordpress.com\/2016\/06\/24\/bakso-crypt-simple-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/shark-ransomware-rebrands-as-atom-for-a-fresh-start\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sodinokibi-ransomware-to-stop-taking-bitcoin-to-hide-money-trail\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/zenis-ransomware-encrypts-your-data-and-deletes-your-backups\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/december\/7\/Dt1_DpMXcAMC8J_[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/three-more-ransomware-families-create-sites-to-leak-stolen-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/g\/lockbit-ransomware-group-augments-its-latest-variant--lockbit-3-.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.redhotcyber.com\/post\/il-ransomware-conti-si-schiera-a-favore-della-russia",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/reaqta.com\/2016\/03\/bandarchor-ransomware-still-active\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-educational-shinolocker-ransomware-project-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/03\/zenis-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-by-the-numbers\/lockbit-conti-and-blackcat-lead-pack-amid-rise-in-active-raas-and-extortion-groups-ransomware-in-q1-2022",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/leaked-babuk-locker-ransomware-builder-used-in-new-attacks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cyberintelmag.com\/malware-viruses\/payloadbin-ransomware-attributed-to-evil-corp",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-bandarchor-ransomware-variant-spreads-via-malvertising-on-adult-sites\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/08\/shinolocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/author-of-polski-vortex-and-flotera-ransomware-families-arrested-in-poland\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/babuk-ransomwares-full-source-code-leaked-on-hacker-forum",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/flotera-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityscorecard.pathfactory.com\/research\/quantum-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/jigsaw-ransomware-decrypted-will-delete-your-files-until-you-pay-the-ransom\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/chinese-language-ransomware-makes-appearance\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/ransomware-hits-helicopter-maker-kopter\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/mount-locker-ransomware-joins-the-multi-million-dollar-ransom-game\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/phishme.com\/rockloader-downloading-new-ransomware-bart\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.helpnetsecurity.com\/2016\/04\/20\/jigsaw-crypto-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/chinese-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.threatstop.com\/blog\/conti-ransomware-source-code-leaked",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/mount-locker-ransomware-now-targets-your-turbotax-tax-returns\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/New-Bart-Ransomware-from-Threat-Actors-Spreading-Dridex-and-Locky",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/tilde-ransomware-aes-08.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/black-ruby-ransomware-skips-victims-in-iran-and-adds-a-miner-for-good-measure\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/dissectingmalwa.re\/between-a-rock-and-a-hard-place-exploring-mount-locker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/decryptor-released-for-prometheus-ransomware-victims",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/jigsaw-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/pompous-ransomware-dev-gets-defeated-by-backdoor\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-december-14th-2018-slow-week\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2020\/12\/mountlocker-ransomware-as-a-service-offers-double-extortion-capabilities-to-affiliates",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/05\/bitcryptor-ransomware-aes-256-1-btc.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2021\/02\/clop-targets-execs-ransomware-tactics-get-another-new-twist",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/digitalrecovery.com\/wp-content\/uploads\/2022\/12\/Ransomware-Baby-Duck.webp",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2021\/05\/prometheus-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-jigsaw-ransomware-decrypted\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/pompous-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.coveware.com\/blog\/ransomware-attack-vectors-shift-as-new-software-vulnerability-exploits-abound",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/clop-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-spotlight\/2020\/07\/threat-spotlight-wastedlocker-customized-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-conti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/chuongdong.com\/reverse%20engineering\/2021\/05\/23\/MountLockerRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/ransomware-007867.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.symantec.com\/connect\/blogs\/jigsaw-ransomware-saw-movie-deletes-files-hour",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/smash-ransomware-is-cute-rather-than-dangerous\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cronup.com\/post\/de-ataque-con-malware-a-incidente-de-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trmlabs.com\/post\/analysis-corroborates-suspected-ties-between-conti-and-ryuk-ransomware-groups-and-wizard-spider",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wlab\/prometheus-x-spook-prometheus-ransomware-rebranded-spook-ransomware-6f93bd8ab5dd",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/jigsaw-ransomware-makes-victims-play-a-game",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/08\/smrss32-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/chuongdong.com\/\/reverse%20engineering\/2021\/01\/03\/BabukRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-security-hub\/ransomware-tracker\/blackout",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.truesec.com\/hub\/blog\/proxyshell-qbot-and-conti-ransomware-combined-in-a-series-of-cyber-attacks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs.-quantum-locker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/posts\/ransomware-encryption-goes-wrong\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/carbon-spider-sprite-spider-target-esxi-servers-with-ransomware\/?utm_campaign=blog&utm_medium=soc&utm_source=twtr&utm_content=sprout",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/asec.ahnlab.com\/wp-content\/uploads\/2021\/01\/Analysis_ReportCLOP_Ransomware.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2022\/04\/25\/quantum-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/decryptor-released-for-prometheus-ransomware-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/silentshade-ransomware-blackshades.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/614456\/bloccato-ransomware-bloccato-help-support-leggi-questo-filetxt\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs.-prometheus-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/05\/booyah-ransomware-1-2-btc.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/forum.malekal.com\/jobcrypter-geniesanstravaille-extension-locked-crypto-ransomware-t54381.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/sns-locker-ransomware-aes-256-066.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-whiterose-ransomware-is-decryptable-and-tells-a-strange-story\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/how-crowdstrike-stops-revil-ransomware-from-kaseya-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/spook-ransomware-prometheus-derivative-names-those-that-pay-shames-those-that-dont\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/stampado-ransomware-campaign-decrypted-before-it-started\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/03\/whiterose-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/how-falcon-complete-thwarted-a-revil-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/github.com\/albertzsigovits\/malware-notes\/blob\/master\/Ransomware\/Clop.md",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/deathransom-ransomware-now-encrypting-victims-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/conti-ransomware-attacks-persist-updated-version-despite-leaks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/jobcrypter-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/p\/pubg-ransomware\/pubg-ransomware.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/how-to-defend-against-conti-darkside-revil-and-other-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2021\/06\/ukrainian-police-nab-six-tied-to-clop-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/16697-deathransom-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/yoroi.company\/research\/conti-ransomware-source-code-a-well-designed-cots-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.broadcom.com\/support\/security-center\/protection-bulletin\/dagon-locker-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/johnycryptor-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/pubg-ransomware-decrypts-your-files-if-you-play-playerunknowns-battlegrounds\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.digitalshadows.com\/blog-and-research\/darkside-the-new-ransomware-group-behind-highly-targeted-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/mphasis.com\/content\/dam\/mphasis-com\/global\/en\/home\/services\/cybersecurity\/icedid-infection-to-dagon-locker-ransomware-apr29-22-7.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/redacted.com\/blog\/bianlian-ransomware-gang-gives-it-a-go\/v8_screenshot.png",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/the-economics-behind-ransomware-prices\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/04\/pubg-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/cybereason-vs-revil-ransomware-the-kaseya-chronicles",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2022\/06\/23093553\/Common-TTPs-of-the-modern-ransomware_low-res.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.wired.com\/story\/ransomware-gone-corporate-darkside-where-will-it-end\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/redacted.com\/blog\/bianlian-ransomware-gang-gives-it-a-go\/v28_screenshot.png",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/ransomware-explosion-continues-cryptflle2-brlock-mm-locker-discovered",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/09\/kawaiilocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/stampado-ransomware-1.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/august\/31\/DlsLwUjXsAA0xyY[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cyborgsecurity.com\/cyborg_labs\/hunting-ransomware-inhibiting-system-backup-or-recovery\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/lockcrypt-ransomware-cracked-due-to-bad-crypto\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/modern-ransomware-groups-ttps\/106824\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.tripwire.com\/state-of-security\/featured\/blackmatter-pose-new-ransomware-threat",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2022\/08\/18\/bianlian-new-ransomware-variant-on-the-rise\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2016\/05\/unit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.welivesecurity.com\/2016\/03\/07\/new-mac-ransomware-appears-keranger-spread-via-transmission-app\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securingtomorrow.mcafee.com\/other-blogs\/mcafee-labs\/clop-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/venturebeat.com\/2021\/08\/23\/sophoslabs-research-shows-blackmatter-ransomware-is-closely-acquainted-with-darkside",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2022\/10\/bianlian-ransomware-encrypts-files-in-the-blink-of-an-eye",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/05\/bucbi-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/03\/keranger-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/surprise-ransomware-aes-256.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/06\/lockcrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/ukrainian-police-arrest-clop-ransomware-members-seize-server-infrastructure\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/awakesecurity.com\/blog\/incident-response-hades-ransomware-gang-or-hafnium\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.digitalshadows.com\/blog-and-research\/ransomware-as-a-service-rogue-affiliates-and-whats-next\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2020\/ransomware-alert-pay2key",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/05\/buyunlockcode-ransomware-rsa-1024.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/u\/1100723\/Ransomware\/LockerGoga-ransom-note.png",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/625820\/central-security-treatment-organization-ransomware-help-topic-cry-extension\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/559463\/keyholder-ransomware-support-and-help-topic-how-decryptgifhow-decrypthtml",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-lockergoga-ransomware-allegedly-used-in-altran-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.domaintools.com\/resources\/blog\/revealing-revil-ransomware-with-domaintools-and-maltego",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.binance.com\/en\/blog\/421499824684902240\/Binance-Helps-Take-Down-Cybercriminal-Ring-Laundering-%24500M-in-Ransomware-Attacks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.blackberry.com\/en\/2021\/09\/threat-thursday-blackmatter-ransomware-as-a-service",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.accenture.com\/us-en\/blogs\/cyber-defense\/unknown-threat-group-using-hades-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/09\/cry-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/keyholder-ransomware-xor-cfb-cipher.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/szflocker-polish-ransomware-email.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elastic.co\/blog\/elastic-security-prevents-100-percent-of-revil-ransomware-samples?utm_content=&utm_medium=social&utm_source=twitter",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/clop-ransomware-gang-is-back-hits-21-victims-in-a-single-month\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.accenture.com\/us-en\/blogs\/security\/ransomware-hades",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elastic.co\/blog\/ransomware-interrupted-sodinokibi-and-the-supply-chain",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/cryptomix-clop-ransomware-says-its-targeting-networks-not-computers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/evil-corp-switches-to-hades-ransomware-to-evade-sanctions\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/redacted.com\/blog\/bianlian-ransomware-gang-gives-it-a-go\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.org\/threat-analysis\/2016\/03\/cerber-ransomware-new-but-mature\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/10\/killerlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/decrypters-for-some-versions-of-magniber-ransomware-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/ransomware-as-a-service-princess-evolution-looking-for-affiliates\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/indiabulls-group-hit-by-clop-ransomware-gets-24h-leak-deadline\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/hades-ransomware-operators-use-distinctive-tactics-and-infrastructure",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/intels-habana-labs-hacked-by-pay2key-ransomware-data-stolen\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/rhisac.org\/threat-intelligence\/bianlian-ransomware-expanding-c2-infrastructure-and-operational-tempo\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.fortinet.com\/post\/kimcilware-ransomware-how-to-decrypt-encrypted-files-and-who-is-behind-it",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/goodbye-cerber-hello-magniber-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-gang-says-they-stole-2-million-credit-cards-from-e-land\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/08\/09\/blackmatter-ransomware-emerges-from-the-shadow-of-darkside\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/the-kimcilware-ransomware-targets-web-sites-running-the-magento-platform\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/jokeroo-ransomware-as-a-service-offers-multiple-membership-packages\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.flashpoint-intel.com\/blog\/cl0p-and-revil-escalate-their-ransomware-tactics\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-gang-urges-victims-customers-to-demand-a-ransom-payment\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2022\/04\/researchers-connect-blackcat-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/kimcilware-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.welivesecurity.com\/2016\/05\/18\/eset-releases-decryptor-recent-variants-teslacrypt-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/10\/my-decryptor-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/analysis-of-new-globeimposter-ransomware-variant.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.flashpoint-intel.com\/blog\/darkside-ransomware-links-to-revil-difficult-to-dismiss\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ta505-hackers-behind-maastricht-university-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/darkside-ransomware-gang-moves-some-of-its-bitcoin-after-revil-got-hit-by-law-enforcement\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/chimera-ransomware-decryption-keys-released-by-petya-devs\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/spyware-techie.com\/blackworm-ransomware-removal-guide",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.org\/threat-analysis\/2015\/12\/inside-chimera-ransomware-the-first-doxingware-in-wild\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/april\/6\/vurten.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.flashpoint-intel.com\/blog\/revils-cryptobackdoor-con-ransomware-groups-tactics-roil-affiliates-sparking-a-fallout\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.carbonblack.com\/blog\/cb-tau-threat-intelligence-notification-cryptomix-clop-ransomware-disables-startup-repair-removes-edits-shadow-volume-copies\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/08\/korean-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.2-spyware.com\/remove-bigbobross-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/paying-the-coverton-ransomware-may-not-get-your-data-back\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/04\/vurten-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/12121-planetary-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.goggleheadedhacker.com\/blog\/post\/sodinokibi-ransomware-analysis",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/darkside-ransomware-rushes-to-cash-out-7-million-in-bitcoin\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.sekoia.io\/vice-society-a-discreet-but-steady-double-extortion-ransomware-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/coverton-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.coveware.com\/blog\/2019\/3\/13\/cr1ptt0r-ransomware-targets-nas-devices-with-old-firmware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/linux-version-of-blackmatter-ransomware-targets-vmware-esxi-servers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-engineer-charged-in-reveton-ransomware-case\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.hornetsecurity.com\/en\/security-informationen-en\/leakware-ransomware-hybrid-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/linux-version-of-hellokitty-ransomware-targets-vmware-esxi-servers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/547708\/torrentlocker-ransomware-cracked-and-decrypter-has-been-made\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/en.wikipedia.org\/wiki\/Ransomware#Reveton",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.hsgac.senate.gov\/media\/minority-media\/new-portman-report-demonstrates-threat-ransomware-presents-to-the-united-states",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.elliptic.co\/blog\/darkside-bitcoins-on-the-move-following-government-cyberattack-against-revil-ransomware-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.govinfosecurity.com\/vice-society-ransomware-gang-disrupted-spar-stores-a-18225",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/b\/black-basta\/wallpaper.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/617802\/kozyjozy-ransomware-help-support-wjpg-31392e30362e32303136-num-lsbj1\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/nakedsecurity.sophos.com\/2012\/08\/29\/reveton-ransomware-exposed-explained-and-eliminated\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/b\/black-basta\/ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/kozy.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/en.wikipedia.org\/wiki\/Ransomware#Fusob",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.notion.so\/S2W-LAB-Analysis-of-Clop-Ransomware-suspiciously-related-to-the-Recent-Incident-English-088056baf01242409a6e9f844f0c5f2e",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cisa.gov\/uscert\/sites\/default\/files\/publications\/AA22-181A_stopransomware_medusalocker.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2020\/11\/hellokitty-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/e\/examining-the-black-basta-ransomwares-infection-routine\/blackbasta07PII.PNG",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/cryfile-ransomware-100.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.ru\/2016\/05\/torrentlocker-ransomware-aes-cbc-2048.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.huntress.com\/blog\/security-researchers-hunt-to-discover-origins-of-the-kaseya-vsa-mass-ransomware-incident",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.notion.so\/S2W-LAB-Analysis-of-Clop-Ransomware-suspiciously-related-to-the-Recent-Incident-c26daec604da4db6b3c93e26e6c7aa26",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/enterprise\/mcafee-enterprise-atr\/how-groove-gang-is-shaking-up-the-ransomware-as-a-service-market-to-empower-affiliates\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/labs.sentinelone.com\/hellokitty-ransomware-lacks-stealth-but-still-strikes-home\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/e\/examining-the-black-basta-ransomwares-infection-routine\/blackbasta08PII.PNG",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/the-crylocker-ransomware-communicates-using-udp-and-stores-data-on-imgur-com\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/618055\/towerweb-ransomware-help-support-topic-payment-instructionsjpg\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.ironnet.com\/blog\/ransomware-graphic-blog",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/kratoscrypt-ransomware-aes-256-0.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/towerweb-ransonware-100.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.justice.gov\/opa\/pr\/sodinokibirevil-ransomware-defendant-extradited-united-states-and-arraigned-texas",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/a-deep-dive-into-nefilim-a-double-extortion-ransomware-group",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/american-dental-association-hit-by-new-black-basta-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/crypmic-ransomware-wants-to-follow-cryptxxx\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/kryptolocker-ransomware-aes-256.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/toxcrypt-ransomware-aes-crypto-0.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.splunk.com\/en_us\/blog\/security\/clop-ransomware-detection-threat-research-release-april-2021.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_nz\/research\/21\/f\/nefilim-modern-ransomware-attack-story.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-black-basta-ransomware-springs-into-action-with-a-dozen-breaches\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/crypmic-ransomware-aes-256.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.splunk.com\/en_us\/blog\/security\/detecting-clop-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.qualys.com\/vulnerabilities-research\/2021\/05\/12\/nefilim-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hellokitty-ransomware-is-targeting-vulnerable-sonicwall-devices\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/e\/examining-the-black-basta-ransomwares-infection-routine.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/bluesky-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/lanran-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/documents.trendmicro.com\/assets\/white_papers\/wp-modern-ransomwares-double-extortion-tactics.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cadosecurity.com\/post\/punk-kitty-ransom-analysing-hellokitty-ransomware-attacks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/posts\/black-basta-ransomware-group-besting-network\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/12\/braincrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/chuongdong.com\/reverse%20engineering\/2021\/09\/05\/BlackMatterRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2020\/03\/nefilim-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/yoroi.company\/research\/dissecting-bluesky-ransomware-payload\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.org\/threat-analysis\/2016\/01\/lechiffre-a-manually-run-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/03\/bansomqarewanna-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/new-ransomware-variant-uses-golang-packer\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/lechiffre-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.nytimes.com\/2019\/08\/22\/us\/ransomware-attacks-hacking.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.telekom.com\/en\/blog\/group\/article\/inside-of-cl0p-s-ransomware-operation-615824",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/01\/26\/nefilim-ransomware-attack-uses-ghost-credentials\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/gbhackers.com\/black-basta-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-ransomware\/bluesky",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.fortinet.com\/2016\/06\/17\/buggy-russian-ransomware-inadvertently-allows-free-decryption",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/04\/skyfile-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/revil-ransomware-group-resurfaces-after-brief-hiatus",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.paloaltonetworks.com\/content\/dam\/pan\/en_US\/assets\/pdf\/reports\/Unit_42\/unit42-ransomware-threat-report-2021.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-clop",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/ke-la.com\/the-ideal-ransomware-victim-what-attackers-are-looking-for\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/home-appliance-giant-whirlpool-hit-in-nefilim-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/f\/black-basta-ransomware-operators-expand-their-attack-arsenal-wit.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/regist-crypt38-ransomware-aes-1000-15.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.2-spyware.com\/remove-lick-ransomware-virus.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/minecraft-and-cs-go-ransomware-strive-for-media-attention\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pandasecurity.com\/emailhtml\/2007-CAM-RANSOMWARE-AD360-WG\/2006-Report-Sodinokibi-EN.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.vice.com\/en\/article\/wx5eyx\/meet-the-ransomware-gang-behind-one-of-the-biggest-supply-chain-hacks-ever",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/medium.com\/s2wblog\/blackcat-new-rust-based-ransomware-borrowing-blackmatters-configuration-31c8d330a809",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-nefilim-ransomware-threatens-to-release-victims-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/luna-black-basta-ransomware\/106950\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.unit42.paloaltonetworks.com\/bluesky-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/labs.bitdefender.com\/2015\/11\/linux-ransomware-debut-fails-on-predictable-encryption-key\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/kelihos-botnet-delivering-shade-troldesh-ransomware-with-no-more-ransom-extension\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.theverge.com\/2021\/7\/22\/22589643\/ransomware-kaseya-vsa-decryptor-revil",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/antonioCoco\/infosec-talks\/main\/InsomniHack_2022_Ransomware_Encryption_Internals.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cert.govt.nz\/it-specialists\/advisories\/active-ransomware-campaign-leveraging-remote-access-technologies\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.speartip.com\/resources\/fbi-hellokitty-ransomware-adds-ddos-to-extortion-arsenal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securityscorecard.com\/research\/a-deep-dive-into-black-basta-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cloudsek.com\/blog\/technical-analysis-of-bluesky-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/troldesh-ransomware-email.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/threat-assessment-black-basta-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/cryptfile2-ransomware-rsa-email.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/german-tech-giant-software-ag-down-after-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.picussecurity.com\/resource\/blog\/how-to-beat-nefilim-ransomware-attacks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-blackbasta",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/lk-encryption-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/truecrypter-ransomware-accepts-payment-in-bitcoins-or-amazon-gift-card\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/2018\/june\/8\/De8WvF_X0AARtYr[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/angle.ankura.com\/post\/102hcny\/revix-linux-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.pwc.co.uk\/issues\/cyber-security-services\/insights\/what-is-behind-ransomware-attacks-increase.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/noberus-blackcat-ransomware-ttps",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/b\/nefilim-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/e\/fivehands-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/truecrypter-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/xiaoba-ransomware-retooled-as-coinminer-but-manages-to-ruin-your-files-anyway\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.vmware.com\/security\/2022\/09\/esxi-targeting-ransomware-the-threats-that-are-after-your-virtual-machines-part-1.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.recordedfuture.com\/blackmatter-ransomware-successor-darkside-revil\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/blackmatter-ransomware-says-its-shutting-down-due-to-pressure-from-local-authorities\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/f\/nefilim-modern-ransomware-attack-story.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/fivehands-ransomware-replaces-hellokitty\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cynet.com\/blog\/orion-threat-alert-qakbot-ttps-arsenal-and-the-black-basta-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/news.softpedia.com\/news\/new-cryptobit-ransomware-could-be-decryptable-503239.shtml",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-lltp-ransomware-appears-to-be-a-rewritten-venus-locker\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.reddit.com\/r\/msp\/comments\/ocggbv\/crticial_ransomware_incident_in_progress\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.ciphertechsolutions.com\/rapidly-evolving-blackmatter-ransomware-tactics\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/nefilim-ransomware-threatens-to-expose-stolen-data",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fivehands-ransomware-uses-new-malware-to-steal-data-before-encrypting\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/cryptobit-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/lltp-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cybleinc.com\/2021\/07\/03\/uncensored-interview-with-revil-sodinokibi-ransomware-operators\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/cryptography-blackmatter-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.watchguard.com\/wgrd-ransomware\/cheerscrypt",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/forums\/t\/577246\/locker-ransomware-support-and-help-topic\/page-32#entry3721545",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.thewindowsclub.com\/emsisoft-decrypter-hydracrypt-umbrecrypt-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2018\/06\/kingouroboros-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/enterprise\/blackmatter-ransomware-analysis-the-dark-side-returns\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/blackbasta-ransomware-group-an-analysis\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/e\/new-linux-based-ransomware-cheerscrypt-targets-exsi-devices.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/locker-ransomware-2015.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/umbrecrypt-ransomware-aes.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/research\/lv-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/bartblaze.blogspot.com\/2018\/08\/mafia-ransomware-targeting-users-in.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2022\/04\/13\/dismantling-zloader-how-malicious-ads-led-to-disabled-security-tools-and-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2019\/10\/pwndlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/f\/blackbasta-ransomware-attacks-target-windows-and-linux.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/cryptodefense-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/627582\/unblockupc-ransomware-help-support-topic-files-encryptedtxt\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/10\/xiaoba-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/07\/27\/prolock-ransomware-gives-you-the-first-8-kilobytes-of-decryption-for-free\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/malware-guide.com\/blog\/remove-amjixius-ransomware-restore-encrypted-files",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/blackbasta-ransomware-linked-to-conti-gang\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sygnia.co\/threat-reports-and-advisories\/revealing-emperor-dragonfly-a-chinese-ransomware-group\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/626750\/locklock-ransomware-locklock-help-support\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/09\/unblockupc-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/bartblaze.blogspot.com\/2020\/01\/satan-ransomware-rebrands-as-5ss5c.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.nozominetworks.com\/blog\/blackmatter-ransomware-technical-analysis-and-tools-from-nozomi-networks-labs\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/heimdalsecurity.com\/blog\/cheerscrypt-ransomware-strain-attributed-to-chinese-hacking-group\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/nakedsecurity.sophos.com\/2016\/07\/13\/ransomware-that-demands-money-and-gives-you-back-nothing\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/09\/locklock-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.splunk.com\/en_us\/blog\/security\/gone-in-52-seconds-and-42-minutes-a-comparative-analysis-of-ransomware-encryption-speed.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.tesorion.nl\/en\/posts\/analysis-of-the-blackmatter-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/fboldewin\/When-ransomware-hits-an-ATM-giant---The-Diebold-Nixdorf-case-dissected\/main\/When%20ransomware%20hits%20an%20ATM%20giant%20-%20The%20Diebold%20Nixdorf%20case%20dissected%20-%20Group-IB%20CyberCrimeCon2020.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/search?q=CryptoFinancial",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/sensorstechforum.com\/wp-content\/uploads\/2018\/04\/stf-NMCRYPT-ransomware-virus-ransom-note-tor-onion-network-page-768x827.png",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.quickheal.com\/first-node-js-based-ransomware-nodera\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.theregister.com\/2022\/03\/22\/talos-ransomware-blackcat\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/soolidsnake.github.io\/2020\/05\/11\/Prolock_ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/05\/cryptofortress-ransomware-aes-256-1.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/05\/bitmessage-ransomware-aes-256-25-btc.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/sensorstechforum.com\/nmcrypt-files-ransomware-virus-remove-restore-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/malienist.medium.com\/revix-linux-ransomware-d736956150d0",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.splunk.com\/en_us\/blog\/security\/revil-ransomware-threat-research-update-and-detections.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.varonis.com\/blog\/blackmatter-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-pwndlocker-ransomware-targeting-us-cities-enterprises\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.splunk.com\/en_us\/pdfs\/resources\/whitepaper\/an-empirically-comparative-analysis-of-ransomware-binaries.pdf",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/chuongdong.com\/reverse%20engineering\/2021\/05\/06\/DarksideRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/pwndlocker-ransomware-gets-pwned-decryption-now-available\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/04\/cryptohost-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/new-locky-ransomware-spotted-in-the-brazilian-underground-market-uses-windows-script-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/02\/unlock26-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/bartblaze.blogspot.lu\/2018\/04\/maktub-ransomware-possibly-rebranded-as.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/arstechnica.com\/information-technology\/2019\/05\/baltimore-city-government-hit-by-robbinhood-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.cert-pa.it\/notizie\/pwndlocker-si-rinnova-in-prolock-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/nakedsecurity.sophos.com\/2016\/10\/06\/odin-ransomware-takes-over-from-zepto-and-locky\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/04\/ironlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/20\/l\/the-impact-of-modern-ransomware-on-manufacturing-networks.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.quickheal.com\/a-new-ransomware-goodwill-hacks-the-victims-for-charity-read-more-to-know-more-about-this-ransomware-and-how-it-affects-its-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/bartblaze.blogspot.com\/2016\/02\/vipasana-ransomware-new-ransom-on-block.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2017\/07\/cryptojoker-2017-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/locky-ransomware-switches-to-egyptian-mythology-with-the-osiris-extension\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/a\/sodinokibi-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.360totalsecurity.com\/en\/darksides-targeted-ransomware-analysis-report-for-critical-u-s-infrastructure-2\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.checkpoint.com\/2015\/11\/04\/offline-ransomware-encrypts-your-data-without-cc-communication\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/02\/locky.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2019\/06\/report-no-eternal-blue-exploit-found-in-baltimore-city-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.cyble.com\/2021\/08\/05\/blackmatter-under-the-lens-an-emerging-ransomware-group-looking-for-affiliates\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/hackmag.com\/security\/ransomware-russian-style\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/reaqta.com\/2016\/04\/uncovering-ransomware-distribution-operation-part-2\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2018\/04\/tron-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/therecord.media\/us-arrests-and-charges-ukrainian-man-for-kaseya-ransomware-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/02\/06\/living-off-another-land-ransomware-borrows-vulnerable-driver-to-remove-security-software\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.gigamon.com\/2021\/05\/17\/tracking-darkside-and-ransomware-the-network-view\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/cis-ransomware\/104452\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/06\/lortok-ransomware-aes-256-5.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/c\/compiled-ransomware\/ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/linux-variant-ransomware-vmwares-nas\/167511\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/ransomware-as-a-service-enabler-of-widespread-attacks",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blogs.keysight.com\/blogs\/tech\/nwvs.entry.html\/2021\/05\/18\/darkside_ransomware-QfsV.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/04\/lowlevel04-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-c-ransomware-compiles-itself-at-runtime\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/ransomware-revil-sites-disappears\/167745\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/ransomware-double-extortion-and-beyond-revil-clop-and-conti",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/a-closer-look-at-the-robbinhood-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blueteamblog.com\/darkside-ransomware-operations-preventions-and-detections",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.it-klinika.rs\/blog\/paznja-novi-opasni-ransomware-pwndlocker-i-u-srbiji",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2020\/12\/jcrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-exploits-gigabyte-driver-to-kill-av-processes\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/brandefense.io\/darkside-ransomware-analysis-report\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/fbi-prolock-ransomware-gains-access-to-victim-networks-via-qakbot-infections\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2016\/12\/m4n1f3sto-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/robinhood-ransomware-coolmaker-function-not-cool\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/chuongdong.com\/reverse%20engineering\/2021\/05\/06\/DarksideRansomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-hits-hpe-ilo-remote-management-interfaces\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.washingtonpost.com\/national-security\/ransomware-fbi-revil-decryption-key\/2021\/09\/21\/4a9417d0-f15f-11eb-a452-4da5fe48582d_story.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/decoded.avast.io\/threatresearch\/decrypted-mafiaware666-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.com\/2017\/03\/macandchess-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2016\/08\/venus-locker-another-net-ransomware\/?utm_source=twitter&utm_medium=social",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/cybergeeks.tech\/a-step-by-step-analysis-of-a-new-version-of-darkside-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/msn-cryptolocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/rotorcrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.2-spyware.com\/remove-ransomplus-ransomware-virus.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/cryptoblock-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/ransomplus-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/aes-ni-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/ishtar-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/koolova-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/koolova-ransomware-decrypts-for-free-if-you-read-two-articles-about-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/cryptconsole-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/masterbuster-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/fake-globe-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-december-30th-2016-infected-tvs-and-open-source-ransomware-sucks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/jackpot-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/638191\/zxz-ransomware-support-help-topic-zxz\/?hl=%2Bzxz#entry4168310",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-october-28-2016-locky-angry-duck-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/zxz-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/vxlock-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/globeimposter-ransomware-spreading-via-spam-campaigns\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/onyx-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/blog.emsisoft.com\/en\/23639\/globeimposter-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/17\/g\/globeimposter-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/funfact.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/ifn643-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.enigmasoftware.com\/funfactransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/v8locker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/cryptorium-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/alcatraz-locker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/06\/zekwacrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/antihacker2017-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.2-spyware.com\/remove-zekwacrypt-ransomware-virus.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/esmeralda-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/cia-special-agent-767-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/630835\/esmeralda-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/sage-2-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/isc.sans.edu\/forums\/diary\/Sage+20+Ransomware\/21959\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-december-16th-2016-samas-no-more-ransom-screen-lockers-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/encryptile-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.securityweek.com\/sage-20-ransomware-demands-2000-ransom",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/sage-2-0-ransomware-gearing-up-for-possible-greater-distribution\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/loveserver-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/fileice-ransomware-survey.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/cloudsword.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/bestsecuritysearch.com\/cloudsword-ransomware-virus-removal-steps-protection-updates\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/kraken-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/antix-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/cryptowire-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/dn-donotopen.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/payday-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/-proof-of-concept-cryptowire-ransomware-spawns-lomix-and-ultralocker-families\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/slimhem-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/garryweber.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/m4n1f3sto-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/satan-raas.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/ultralocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/637811\/satan-ransomware-help-support-topic-stn-extension-help-decrypt-fileshtml\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/hucky-ransomware-hungarian-locky.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-january-20th-2017-satan-raas-spora-locky-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/blog.avast.com\/hucky-ransomware-a-hungarian-locky-wannabe",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-satan-ransomware-available-through-a-ransomware-as-a-service-\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/aeskeygenassist-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/09\/dxxd-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/havoc-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/cryptosweettooth.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/code-virus-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/sensorstechforum.com\/remove-cryptosweettooth-ransomware-restore-locked-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/kaandsona-ransomtroll.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/flkr-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/p\/Popcorn-time\/refer-a-friend.png",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/winnix-cryptor-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/lambdalocker.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/cfoc.org\/how-to-restore-files-affected-by-the-lambdalocker-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/popcorntime-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/angryduck-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-scheme-spread-popcorn-time-ransomware-get-chance-of-free-decryption-key\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/hakunamatata.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.com\/2016\/07\/ransomware-list.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016_03_01_archive.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/hackedlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/lock93-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/nhtnwcuf-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/marlboro.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/goldeneye-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/petya-ransomware-returns-with-goldeneye-version-continuing-james-bond-theme\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/asn1-encoder-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/cryptojacky-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/marlboro-ransomware-defeated-in-one-day\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/malwarebreakdown.com\/2017\/03\/02\/rig-ek-at-92-53-105-43-drops-asn1-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/sage-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/click-me-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/kaenlupuf-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/spora-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/blog.gdatasoftware.com\/2017\/01\/29442-spora-worm-and-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/634747\/sage-20-ransomware-sage-support-help-topic\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/blog.emsisoft.com\/2017\/01\/10\/from-darknet-with-love-meet-spora-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/japanlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/cryptokill-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/sq-vo-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/enjey-crypter-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-march-10th-2017-spora-cerber-and-technical-writeups\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/allyourdocuments-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/embittered-enjey-ransomware-developer-launches-ddos-attack-on-id-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/dangerous-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/serbransom-2017.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/m\/matrix\/4-7-2018\/1\/ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ultranationalist-developer-behind-serbransom-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/m\/matrix\/4-7-2018\/1\/background.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-february-10th-2017-serpent-spora-id-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/m\/matrix\/4-7-2018\/2\/wallpaper.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/vortex-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/fadesoft-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-december-2nd-2016-screenlockers-kangaroo-the-sfmta-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/gc47-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/matrix-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/hugeme-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-matrix-ransomware-variants-installed-via-hacked-remote-desktop-services\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-august-31st-2018-devs-on-vacation\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/04\/magic-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/rozalocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-fox-ransomware-matrix-variant-tries-its-best-to-close-all-file-handles\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/dyna-crypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-october-12th-2018-notpetya-gandcrab-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/cryptomeister-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/gg-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-september-14th-2018-kraken-dharma-and-matrix\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/project34-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/serpent-danish-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/satan666-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/petrwrap-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/erebus-2017-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/rip-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/petrwrap-ransomware-is-a-petya-offspring-used-in-targeted-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/erebus-ransomware-utilizes-a-uac-bypass-and-request-a-90-ransom-payment\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-march-17th-2017-revenge-petrwrap-and-captain-kirk\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/blog\/research\/77762\/petrwrap-the-new-petya-based-ransomware-used-in-targeted-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/ransomuhahawhere.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/novalid-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/634754\/locked-in-ransomware-help-support-restore-corupted-fileshtml\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/karmen-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/cancer-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/chartwig-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revenge-ransomware-a-cryptomix-variant-being-distributed-by-rig-exploit-kit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/updatehost-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/renlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/revenge-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/thanksgiving-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/nemesis-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/07\/stampado-ransomware-1.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/turkish-fileencryptor.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/cockblocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/evil-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.enigmasoftware.com\/evilransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/usproins.com\/evil-ransomware-is-lurking\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/lomix-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/ozozalocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/ocelot-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/kirkspock-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/642239\/kirk-ransomware-help-support-topic-kirk-extension-ransom-notetxt\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.networkworld.com\/article\/3182415\/security\/star-trek-themed-kirk-ransomware-has-spock-decryptor-demands-ransom-be-paid-in-monero.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/crypute-ransomware-m0on.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.securityweek.com\/star-trek-themed-kirk-ransomware-emerges",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/virus-removal\/threat\/ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.grahamcluley.com\/kirk-ransomware-sports-star-trek-themed-decryptor-little-known-crypto-currency\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/skyname-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/nmoreira-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/10\/airacrop-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/zinocrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/mafiaware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-january-6th-2017-fsociety-mongodb-pseudo-darkleech-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/vindowslocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/crptxxx-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/609690\/ultracrypter-cryptxxx-ultradecrypter-ransomware-help-topic-crypt-cryp1\/page-84",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/vindowslocker-ransomware-mimics-tech-support-scam-not-the-other-way-around\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.fixinfectedpc.com\/uninstall-crptxxx-ransomware-from-pc",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.co.il\/2016\/09\/donald-trump-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/3.bp.blogspot.com\/-RwJ6R-uvYg0\/V-qfeRPz7GI\/AAAAAAAABi8\/7x4MxRP7Jp8edbTJqz4iuEye0q1u5k3pQCLcB\/s1600\/donald-trump-ransomware.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/globe3-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-donald-trump-ransomware-tries-to-build-walls-around-your-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/624518\/globe-ransomware-help-and-support-purge-extension-how-to-restore-fileshta\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/motd-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-globe-ransomware-wants-to-purge-your-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/id-ransomware.blogspot.co.il\/2016\/09\/nagini-voldemort-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/642409\/motd-ransomware-help-support-topics-motdtxt-and-enc-extension\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-nagini-ransomware-sics-voldemort-on-your-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/shelllocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/cryptodevil-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/bleedgreen-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/firecrypt-ransomware-comes-with-a-ddos-component\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/chip-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/fabsyscrypto-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/btcamant.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/rig-e-exploit-kit-now-distributing-new-chip-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/x3m-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/lock2017-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/redants-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/gog-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/consoleapplication1-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/krider-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/edgelocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/d\/dharma\/cmb\/hta-ransom-note.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/search?updated-min=2017-01-01T00:00:00-08:00&amp;updated-max=2018-01-01T00:00:00-08:00&amp;max-results=50",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/dotransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/red-alert-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/dharma-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/kaspersky-releases-decryptor-for-the-dharma-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/unlock26-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/first-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-cmb-dharma-ransomware-variant-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-raas-portal-preparing-to-spread-unlock26-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-bip-dharma-ransomware-variant-released\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/xcrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/pickles-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/7zipper-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/vanguard-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/zyka-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-november-23rd-2018-stop-dharma-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.pcrisk.com\/removal-guides\/10899-zyka-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/pyl33t-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/angela-merkel-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/sureransom-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/u\/986406\/Ransomware\/TrumpLocker\/TrumpLocker-wallpaper.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.forbes.com\/sites\/leemathews\/2017\/01\/27\/fake-ransomware-is-tricking-people-into-paying\/#777faed0381c",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-trump-locker-ransomware-is-a-fraud-just-venuslocker-in-disguise\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/trumplocker.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/cryptoluck-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-february-24th-2017-trump-locker-macos-rw-and-cryptomix\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/netflix-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/cryptoluck-ransomware-being-malvertised-via-rig-e-exploit-kits\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/damage-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/netflix-scam-delivers-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/rogue-netflix-app-spreads-netix-ransomware-that-targets-windows-7-and-10-users\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.darkreading.com\/attacks-breaches\/netflix-scam-spreads-ransomware\/d\/d-id\/1328012",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/xyzware-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/crypton-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.enigmasoftware.com\/youarefuckedransomware-removal\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/crypton-ransomware-is-here-and-its-not-so-bad-\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/mrcr1-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/-merry-christmas-ransomware-now-steals-user-private-data-via-diamondfox-malware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/cryptconsole-2-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.zdnet.com\/article\/not-such-a-merry-christmas-the-ransomware-that-also-steals-user-data\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-june-8th-2018-crybrazil-cryptconsole-and-magniber\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/merry-christmas-ransomware-and-its-dev-comodosecurity-not-bringing-holiday-cheer\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/ransomware\/k\/karma-ransomware\/ransom-note.png",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/barraxcrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/karma-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/seoirse-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/researcher-finds-the-karma-ransomware-being-distributed-via-pay-per-install-network\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-november-18th-2016-crysis-cryptoluck-chip-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/cryptolocker-by-ntk-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/killdisk-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/killdisk-ransomware-now-targets-linux-prevents-boot-up-has-faulty-encryption\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/wickedlocker-ht-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/userfileslocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017_03_01_archive.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.zdnet.com\/article\/247000-killdisk-ransomware-demands-a-fortune-forgets-to-unlock-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/suppteam-ransomware-sysras.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/avastvirusinfo-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.securityweek.com\/destructive-killdisk-malware-turns-ransomware",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2015\/09\/updated-pclock-ransomware-still-comes-up-short\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/03\/suchsecurity-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/cyberx-labs.com\/en\/blog\/new-killdisk-malware-brings-ransomware-into-industrial-domain\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.ransomware.wiki\/tag\/kolobo\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/kolobo-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/vhd-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/derialock-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-derialock-ransomware-active-on-christmas-includes-an-unlock-all-command\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/paysafegen-german-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/kasiski-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/badencript-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-february-17th-2017-live-hermes-reversing-and-scada-poc-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/telecrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.securityweek.com\/telecrypt-ransomwares-encryption-cracked",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/adamlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-locky-ransomware-encrypts-local-files-and-unmapped-network-shares\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2016\/11\/telecrypt-the-ransomware-abusing-telegram-api-defeated\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/locky-impersonator.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/alphabet-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/locky-ransomware-switches-to-thor-extension-after-being-a-bad-malware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/cerbertear-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/cryptoshield-2-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/kokokrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.tripwire.com\/state-of-security\/security-data-protection\/cyber-security\/november-2016-month-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/cryptomix-variant-named-cryptoshield-1-0-ransomware-distributed-by-exploit-kits\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/removevirusadware.com\/tips-for-removeing-kokokrypt-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.ru\/2016\/05\/remindme-ransomware-2.html\\",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/fucksociety-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/hermes-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/l33taf-locker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/paydos-ransomware-serpent.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/forums\/t\/642019\/hermes-ransomware-help-support-decrypt-informationhtml\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-goes-retro-with-paydos-and-serpent-written-as-batch-files\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hermes-ransomware-decrypted-in-live-video-by-emsisofts-fabian-wosar\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/pclock4-sysgop-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-november-4th-2016-cerber-paydos-alcatraz-locker-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/new-serpent-ransomware-targets-danish-speakers",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/lovelock-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/guster-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/zscreenlocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/wcry-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/columns\/week-in-ransomware\/11-4-16\/CwZubUHW8AAE4qi[1].jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/gremit-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/roga-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/dumb-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/cryptolocker3-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/hollycrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017_02_01_archive.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/x-files-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/proposalcrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/btclocker-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.archersecuritygroup.com\/what-is-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/polski-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/kangaroo-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/yourransom-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/manifestus-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-kangaroo-ransomware-not-only-encrypts-your-data-but-tries-to-lock-you-out-of-windows\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/yourransom-is-the-latest-in-a-long-line-of-prank-and-educational-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/the-week-in-ransomware-december-23rd-2016-cryptxxx-koolova-cerber-and-more\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/dummyencrypter-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/02\/ranion-raas.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/enkripsipc-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/encryptss77-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ranion-ransomware-as-a-service-available-on-the-dark-web-for-educational-purposes\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/winrarer-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/polato-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/russian-globe-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/12\/braincrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2016\/11\/zerocrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/id-ransomware.blogspot.co.il\/2017\/01\/opentodecrypt-ransomware.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/shinyhunters-ransomware-\\n\\nextortion\/\\n\\n[2]\u00a0\u201cDefending",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "Ransomware.Nemty",
            "ioc_type": "other",
            "category": "C2 Certificates",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:11:42",
            "last_seen": "2026-08-06 13:11:42"
        },
        {
            "ioc_value": "Ransomware.DarkSide",
            "ioc_type": "other",
            "category": "C2 Certificates",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:11:42",
            "last_seen": "2026-08-06 13:11:42"
        },
        {
            "ioc_value": "https:\/\/www.forbes.com\/sites\/daveywinder\/2020\/06\/10\/honda-hacked-japanese-car-giant-confirms-cyber-attack-on-global-operations-snake-ransomware\/?sh=2725c35753ad",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2020\/06\/honda-and-enel-impacted-by-cyber-attack-suspected-to-be-ransomware\/",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/www.dragos.com\/blog\/industry-news\/ekans-ransomware-misconceptions-and-misunderstandings\/#_edn7",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2020\/10\/14\/inside-a-new-ryuk-ransomware-attack\/",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/ekans-ransomware-targeting-ot-ics-systems",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/doublepulsar.com\/how-lockergoga-took-down-hydro-ransomware-used-in-targeted-attacks-aimed-at-big-business-c666551f5880",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/www.darkreading.com\/attacks-breaches\/how-a-manufacturing-firm-recovered-from-a-devastating-ransomware-attack\/d\/d-id\/1334760",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/the-sodinokibi-ransomware-attack",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/f.hubspotusercontent10.net\/hubfs\/5943619\/Whitepaper-Downloads\/Ransomware_in_ICS_Environments_Whitepaper_10_12_20.pdf?utm_referrer=https%3A%2F%2Fwww.dragos.com%2Fresource%2Fransomware-in-ics-environments%2F",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/www.darktrace.com\/en\/blog\/post-mortem-of-a-targeted-sodinokibi-ransomware-attack\/",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/securityaffairs.co\/wordpress\/104749\/cyber-crime\/ransomware-attack-hit-lion.html",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/Da2dalus\/The-MALWARE-Repo\/master\/Ransomware\/Annabelle.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/Da2dalus\/The-MALWARE-Repo\/master\/Ransomware\/CryptoWall.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/Da2dalus\/The-MALWARE-Repo\/master\/Ransomware\/CryptoLocker.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/Da2dalus\/The-MALWARE-Repo\/raw\/refs\/heads\/master\/Ransomware\/WannaCry.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/trasherwithadollarsign\/Trashers-Malware-Repo\/raw\/main\/Ransomware\/Jigsaw.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/trasherwithadollarsign\/Trashers-Malware-Repo\/raw\/main\/Ransomware\/Hive%20Ransomware.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/trasherwithadollarsign\/Trashers-Malware-Repo\/raw\/main\/Ransomware\/WannaCry.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/trasherwithadollarsign\/Trashers-Malware-Repo\/raw\/main\/Ransomware\/NoMoreRansom.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/trasherwithadollarsign\/Trashers-Malware-Repo\/raw\/main\/Ransomware\/Petya.A.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/trasherwithadollarsign\/Trashers-Malware-Repo\/raw\/main\/Ransomware\/CryptoWall.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/trasherwithadollarsign\/Trashers-Malware-Repo\/raw\/main\/Ransomware\/InfinityCrypt.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/trasherwithadollarsign\/Trashers-Malware-Repo\/raw\/main\/Ransomware\/CoronaVirus.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/keygroup777-ransomware\/downloader\/refs\/heads\/main\/taskmoder.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/keygroup777-Ransomware\/DOWNLOADER\/refs\/heads\/main\/cssgo.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "http:\/\/github.com\/keygroup777-Ransomware\/DOWNLOADER\/raw\/refs\/heads\/main\/black.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/ytisf\/theZoo\/refs\/heads\/master\/malware\/Binaries\/Ransomware.WannaCry\/Ransomware.WannaCry.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        }
    ]
}