{
    "count": 283,
    "indicators": [
        {
            "ioc_value": "https:\/\/ellio.tech\/en\/blog\/ellio-gets-a-major-upgrade-in-its-recon--mass-exploitation-intelligence\/",
            "ioc_type": "url",
            "category": "IP Blocklists",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:11:12",
            "last_seen": "2026-08-06 19:47:13"
        },
        {
            "ioc_value": "https:\/\/ellio.tech\/en\/blog\/wp2shell-in-the-wild-under-48-hours-from-patch-to-mass-exploitation\/",
            "ioc_type": "url",
            "category": "IP Blocklists",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:11:12",
            "last_seen": "2026-08-06 19:47:13"
        },
        {
            "ioc_value": "https:\/\/ellio.tech\/en\/blog\/ellio-gets-a-major-upgrade-in-its-recon--mass-exploitation-intelligence\/\\",
            "ioc_type": "url",
            "category": "IP Blocklists",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:11:12",
            "last_seen": "2026-08-06 19:47:13"
        },
        {
            "ioc_value": "https:\/\/ellio.tech\/en\/blog\/wp2shell-in-the-wild-under-48-hours-from-patch-to-mass-exploitation\/\\",
            "ioc_type": "url",
            "category": "IP Blocklists",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:11:12",
            "last_seen": "2026-08-06 19:47:13"
        },
        {
            "ioc_value": "http:\/\/64.118.132.61\/exploit.sh",
            "ioc_type": "url",
            "category": "Malware",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 19:46:45",
            "last_seen": "2026-08-06 19:46:45"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/starlincxv177\/Brute-Force-Exploitation-and-Defense-Lab\/main\/src\/python_brute_force\/scripts\/Defense_Exploitation_Brute_Force_and_Lab_1.5.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:41",
            "last_seen": "2026-08-06 19:46:44"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/samsaeed22\/kevlar-benchmark\/main\/modules\/critical\/asi05_rce\/exploits\/benchmark-kevlar-v1.2.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:40",
            "last_seen": "2026-08-06 19:46:43"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/Deracz\/RyExploit\/main\/elastin\/Ry_Exploit_v2.5.zip",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:07:40",
            "last_seen": "2026-08-06 19:46:43"
        },
        {
            "ioc_value": "http:\/\/91.199.133.133:8080\/router_exploit_v2",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:07:37",
            "last_seen": "2026-08-06 19:46:38"
        },
        {
            "ioc_value": "http:\/\/91.199.133.133:8080\/router_exploit",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:07:37",
            "last_seen": "2026-08-06 19:46:38"
        },
        {
            "ioc_value": "cryptoexploite.com",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:08:55",
            "last_seen": "2026-08-06 14:48:49"
        },
        {
            "ioc_value": "revoke-exploit.com",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:53",
            "last_seen": "2026-08-06 14:48:47"
        },
        {
            "ioc_value": "exploitrevoke.com",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:52",
            "last_seen": "2026-08-06 14:48:45"
        },
        {
            "ioc_value": "smartexploit.com",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:52",
            "last_seen": "2026-08-06 14:48:45"
        },
        {
            "ioc_value": "exploitsrevoke.cash",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:48",
            "last_seen": "2026-08-06 14:48:40"
        },
        {
            "ioc_value": "exploits-revoke.com",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:08:48",
            "last_seen": "2026-08-06 14:48:40"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/apt41-initiates-global-intrusion-campaign-using-multiple-exploits",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/wojciechregula.blog\/post\/learn-xpc-exploitation-part-3-code-injections\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/github.com\/rapid7\/metasploit-framework\/tree\/master\/modules\/exploits\/linux\/ssh",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/cybersecuritynews.com\/superblack-actors-exploiting-two-fortinet-vulnerabilities\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/sysdig.com\/blog\/proxyjacking-attackers-log4j-exploited\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/arstechnica.com\/information-technology\/2021\/02\/armed-with-exploits-hackers-on-the-prowl-for-a-critical-vmware-vulnerability\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/cyware.com\/news\/how-hackers-exploit-social-media-to-break-into-your-company-88e8da8e",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.huntress.com\/blog\/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.techtarget.com\/searchsecurity\/tip\/Preparing-for-uniform-resource-identifier-URI-exploits",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/07\/04\/independence-day-revil-uses-supply-chain-exploit-to-attack-hundreds-of-businesses\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.exploit-db.com\/docs\/17802.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/baesystemsai.blogspot.com\/2015\/06\/new-mac-os-malware-exploits-mackeeper.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/new-pervasive-worm-exploiting-linux-exim-server-vulnerability",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/cve-2022-0185-kubernetes-container-escape-using-linux-kernel-exploit\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/cobalt-spam-runs-use-macros-cve-2017-8759-exploit\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.exploit-db.com\/google-hacking-database",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/github.com\/Exploit-install\/PSAttack-1",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2022\/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/flashpoint.io\/blog\/mini-shai-hulud-worm-new-era-ci-cd-exploitation\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/shinyhunters-targets-education-sector-oracle-exploit",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.uptycs.com\/blog\/new-poc-exploit-backdoor-malware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2021\/11\/15\/exchange-exploit-leads-to-domain-wide-ransomware\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/2019\/04\/sodinokibi-ransomware-exploits-weblogic.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ivanti-post-exploitation-lateral-movement",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/muddywater-resurfaces-uses-multi-stage-backdoor-powerstats-v3-and-new-post-exploitation-tools\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/unc6201-exploiting-dell-recoverpoint-zero-day",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.rapid7.com\/blog\/post\/2021\/03\/23\/defending-against-the-zero-day-analyzing-attacker-behavior-post-exploitation-of-microsoft-exchange\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-exploited-salesforce-zero-day-in-facebook-phishing-attack\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.netskope.com\/blog\/new-phishing-attacks-exploiting-oauth-authorization-flows-part-1",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.sucuri.net\/2015\/08\/bind9-denial-of-service-exploit-in-the-wild.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2022\/06\/15\/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.mdsec.co.uk\/2021\/01\/macos-post-exploitation-shenanigans-with-vscode-extensions\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/china-nexus-exploiting-critical-ivanti-vulnerability",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.rapid7.com\/db\/modules\/exploit\/linux\/local\/service_persistence",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2018\/11\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/wp-content\/uploads\/2022\/05\/crowdstrike-iceapple-a-novel-internet-information-services-post-exploitation-framework.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/googleprojectzero.blogspot.com\/2018\/04\/windows-exploitation-tricks-exploiting.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/chinese-actors-exploit-fortios-flaw\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/docs.microsoft.com\/windows\/threat-protection\/windows-defender-exploit-guard\/enable-attack-surface-reduction",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/en\/eset-research\/winter-vivern-exploits-zero-day-vulnerability-roundcube-webmail-servers\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/exploitation-dish-best-served-cold-winter-vivern-uses-known-zimbra-vulnerability",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/07\/22\/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities\/#storm-2603",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/arstechnica.com\/information-technology\/2017\/03\/hack-that-escapes-vm-by-exploiting-edge-browser-fetches-105000-at-pwn2own\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/blogs.technet.microsoft.com\/srd\/2017\/08\/09\/moving-beyond-emet-ii-windows-defender-exploit-guard\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2024\/04\/12\/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2024\/01\/15\/ivanti-connect-secure-vpn-exploitation-goes-global\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/blog\/investigating-ivanti-exploitation-persistence",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/blog\/investigating-ivanti-zero-day-exploitation",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2024\/01\/10\/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.oligo.security\/blog\/shadowray-attack-ai-workloads-actively-exploited-in-the-wild",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2021\/08\/17\/north-korean-apt-inkysquid-infects-victims-using-browser-exploits\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2017\/11\/06\/oceanlotus-blossoms-mass-digital-surveillance-and-exploitation-of-asean-nations-the-media-human-rights-and-civil-society\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2021\/03\/02\/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.clearskysec.com\/wp-content\/uploads\/2019\/06\/Clearsky-Iranian-APT-group-%E2%80%98MuddyWater%E2%80%99-Adds-Exploits-to-Their-Arsenal.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/blackoasis-apt-and-new-targeted-attacks-leveraging-zero-day-exploit\/82732\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 9,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.sygnia.co\/threat-reports-and-advisories\/china-nexus-threat-group-velvet-ant-exploits-cisco-0-day\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2016\/06\/20\/reverse-engineering-dubniums-flash-targeting-exploit\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/blog.lumen.com\/taking-the-crossroads-the-versa-director-zero-day-exploitation\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "Exploit.AndroidOS.Lotoor",
            "ioc_type": "other",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:10:28",
            "last_seen": "2026-08-06 14:48:26"
        },
        {
            "ioc_value": "https:\/\/blog.newskysecurity.com\/masuta-satori-creators-second-botnet-weaponizes-a-new-router-exploit-2ddc51cc52a7",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.forescout.com\/blog\/threat-analysis-sap-vulnerability-exploited-in-the-wild-by-chinese-threat-actor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/teamt5.org\/tw\/posts\/alert-exploitation-of-cve-2026-34197-in-apache-active-mq?utm_source=rss&tm_medium=rss",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2020\/11\/malsmoke-operators-abandon-exploit-kits-in-favor-of-social-engineering-scheme\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2025\/07\/nighteagle-apt-exploits-microsoft.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/cybersecuritynews.com\/nighteagle-apt-exploiting-0-days\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2026\/07\/17\/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/blog.eclecticiq.com\/china-nexus-nation-state-actors-exploit-sap-netweaver-cve-2025-31324-to-target-critical-infrastructures",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/aws.amazon.com\/blogs\/security\/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/meterpreter.org\/anssi-exposes-houken-china-linked-apt-exploiting-ivanti-csa-zero-days-deploying-linux-rootkits\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/threat-actors-exploit-react2shell-cve-2025-55182",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.secpod.com\/blog\/zero-day-crisis-cve-2025-20393-unpatched-on-cisco-email-gateways-exploited-by-china-linked-hackers\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/sonicwall-secure-mobile-access-exploitation-overstep-backdoor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/en\/podcasts\/eset-apt-activity-report-q4-2024q1-2025-malware-sharing-wipers-exploits\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.symantec.com\/connect\/blogs\/trojanhydraq-incident-analysis-aurora-0-day-exploit",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.symantec.com\/connect\/blogs\/cve-2012-1875-exploited-wild-part-1-trojannaid",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/10\/06\/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Exploit.APT.RICECURRY",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/uat-6382-exploits-cityworks-vulnerability\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "http:\/\/labs.alienvault.com\/labs\/index.php\/2013\/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/nsfocusglobal.com\/warning-newly-discovered-apt-attacker-atlascross-exploits-red-cross-blood-drive-phishing-for-cyberattack\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/coruna-powerful-ios-exploit-kit?linkId=59478481",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/fortigate-firewall-configs-cve-2022-40684-exploitation\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.forescout.com\/blog\/new-ransomware-operator-exploits-fortinet-vulnerability-duo\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2014\/10\/08\/sednit-espionage-group-now-using-custom-exploit-kit\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/darksword-ios-exploit-chain\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/04\/08\/exploitation-of-clfs-zero-day-leads-to-ransomware-activity\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/ti.360.net\/blog\/articles\/apt-c-27-(goldmouse):-suspected-target-attack-against-the-middle-east-with-winrar-exploit-en\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2024\/01\/18\/ivanti-connect-secure-vpn-exploitation-new-observations\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2021\/12\/11\/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/securingtomorrow.mcafee.com\/other-blogs\/mcafee-labs\/targeted-attacks-on-french-company-exploit-multiple-word-vulnerabilities\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/sysdig.com\/blog\/crystalray-rising-threat-actor-exploiting-oss-tools\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/paper.seebug.org\/papers\/APT\/APT_CyberCriminal_Campagin\/2015\/Aug.10.The_Italian_Connection_An_analysis_of_exploit_supply_chains_and_digital_quartermasters\/HTExploitTelemetry.pdf",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.thezdi.com\/blog\/2023\/1\/23\/activation-context-cache-poisoning-exploiting-csrss-for-privilege-escalation",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/10\/18\/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2022\/07\/27\/untangling-knotweed-european-private-sector-offensive-actor-using-0-day-exploits\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/07\/29\/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2017\/03\/27\/detecting-and-mitigating-elevation-of-privilege-exploit-for-cve-2017-0005\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Exploit:Python\/CVE-2024-1709.A!dha&ThreatID=2147903327",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/citizenlab.ca\/2023\/04\/spyware-vendor-quadream-exploits-victims-customers\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.esentire.com\/security-advisories\/ongoing-email-bombing-campaigns-leading-to-remote-access-and-post-exploitation",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2021\/07\/15\/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/x-force\/gootbot-gootloaders-new-approach-to-post-exploitation\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/psirt-blogs\/importance-of-patching-an-analysis-of-the-exploitation-of-n-day-vulnerabilities",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.google\/threat-analysis-group\/government-backed-actors-exploiting-winrar-vulnerability\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/securityboulevard.com\/2022\/10\/analysis-of-cisa-releases-advisory-on-top-cves-exploited-chinese-state-sponsored-groups\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/log4j2-in-the-wild-iranian-aligned-threat-actor-tunnelvision-actively-exploiting-vmware-horizon\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.lacework.com\/blog\/androxghost-the-python-malware-exploiting-your-aws-keys\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/gbhackers.com\/vedalia-apt-group-exploits\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.reddit.com\/r\/msp\/comments\/lwmo5c\/mass_exploitation_of_onprem_exchange_servers",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/03\/detection-response-to-exploitation-of-microsoft-exchange-zero-day-vulnerabilities.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/falcon-complete-stops-microsoft-exchange-server-zero-day-exploits",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/prophet-spider-exploits-citrix-sharefile\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:11:09",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/24\/i\/earth-baxia-spear-phishing-and-geoserver-exploit.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.huntress.com\/blog\/rapid-response-mass-exploitation-of-on-prem-exchange-servers",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/i\/earth-baxia-uses-spear-phishing-and-geoserver-exploit-to-target-apac\/IOCs%20-%20Earth%20Baxia%20Uses%20Spear-Phishing%20and%20GeoServer%20Exploit%20to%20Target%20APAC.txt",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.nextron-systems.com\/2021\/03\/06\/scan-for-hafnium-exploitation-evidence-with-thor-lite",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/nsfocusglobal.com\/the-new-apt-group-darkcasino-and-the-global-surge-in-winrar-0-day-exploits\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/08\/30\/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/isc.sans.edu\/diary\/TA570+Qakbot+Qbot+tries+CVE202230190+Follina+exploit+msmsdt\/28728",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ta2552-uses-oauth-access-token-phishing-exploit-read-only-risks",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/07\/22\/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/viceroy-tiger-delivers-new-zero-day-exploit\/index.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/driftingcloud-apt-group-exploits-zero-day-in-sophos-firewall\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/prophet-spider-exploits-oracle-weblogic-to-facilitate-ransomware-activity\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.recordedfuture.com\/research\/redmike-salt-typhoon-exploits-vulnerable-devices",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20130924130243\/https:\/\/www.fireeye.com\/blog\/technical\/cyber-exploits\/2013\/09\/operation-deputydog-zero-day-cve-2013-3893-attack-against-japanese-targets.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/barracuda-esg-exploited-globally\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/fortimanager-zero-day-exploitation-cve-2024-47575\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/ios-exploit-chain-deploys-lightspy-malware\/96407\/",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/windows-task-scheduler-zero-day-exploited-by-malware\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2022\/02\/03\/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2016\/10\/unit42-dealerschoice-sofacys-flash-player-exploit-platform\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.clearskysec.com\/0d-vulnerability-exploited-in-the_wild\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.csoonline.com\/article\/3190055\/new-nsa-leak-may-expose-its-bank-spying-windows-exploits.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/blog\/initial-access-brokers-exploit-f5-screenconnect",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/socradar.io\/acuity-federal-breach-okta-leak-dcrat-exploit\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/hookads-malvertising-installing-malware-via-the-fallout-exploit-kit\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.fox-it.com\/2021\/11\/08\/ta505-exploits-solarwinds-serv-u-vulnerability-cve-2021-35211-for-initial-access\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/security\/blog\/2021\/07\/13\/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/crowdstrike-discovers-use-64-bit-zero-day-privilege-escalation-exploit-cve-2014-4113-hurricane-panda\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/citizenlab.ca\/2019\/09\/poison-carp-tibetan-groups-targeted-with-1-click-mobile-exploits\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2019\/09\/02\/digital-crackdown-large-scale-surveillance-and-exploitation-of-uyghurs\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/how-cyber-adversaries-are-adapting-to-exploit-the-global-pandemic",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium\/94866\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.tenable.com\/blog\/cve-2020-1472-advanced-persistent-threat-actors-use-zerologon-vulnerability-in-exploit-chain",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/energy-watering-hole-attack-used-lightsout-exploit-kit\/104772\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2021\/09\/15\/analyzing-attacks-that-exploit-the-mshtml-cve-2021-40444-vulnerability",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.systemtek.co.uk\/2018\/07\/luoxk-malware-exploiting-cve-2018-2893\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20141016132823\/https:\/\/www.symantec.com\/connect\/blogs\/sandworm-windows-zero-day-vulnerability-being-actively-exploited-targeted-attacks",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.crowdstrike.com\/blog\/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/new-uyghur-and-tibetan-themed-attacks-using-pdf-exploits\/35465",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "http:\/\/www.securiteam.com\/exploits\/Netscape_4_7_and_earlier_vulnerable_to__Huge_Key__DoS.html",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:25"
        },
        {
            "ioc_value": "http:\/\/www.securiteam.com\/exploits\/3J5QQPPQ0O.html",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:25"
        },
        {
            "ioc_value": "http:\/\/www.securiteam.com\/unixfocus\/HHP-Pine_remote_exploit.html",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:25"
        },
        {
            "ioc_value": "http:\/\/security-protocols.com\/sploits\/unsorted_exploits\/nlps_server.c",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:25"
        },
        {
            "ioc_value": "http:\/\/www.securityfocus.com\/data\/vulnerabilities\/exploits\/nlps_server.c",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:25"
        },
        {
            "ioc_value": "http:\/\/www.securiteam.com\/exploits\/E-MailClub__FROM__remote_buffer_overflow.html",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:25"
        },
        {
            "ioc_value": "http:\/\/www.securiteam.com\/exploits\/5ZP0O1P35O.html",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:25"
        },
        {
            "ioc_value": "http:\/\/www.securityfocus.com\/bid\/213\/exploit",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:24"
        },
        {
            "ioc_value": "http:\/\/spisa.act.uji.es\/spi\/progs\/codigo\/www.hack.co.za\/exploits\/daemon\/ident\/cidentd.c",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:24"
        },
        {
            "ioc_value": "http:\/\/www.eeye.com\/html\/Research\/Advisories\/IIS%20Remote%20FTP%20Exploit\/DoS%20Attack.html",
            "ioc_type": "url",
            "category": "Vulnerabilities",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:10:33",
            "last_seen": "2026-08-06 14:44:24"
        },
        {
            "ioc_value": "https:\/\/isc.sans.edu\/diary\/Exploit+attempts+for+unpatched+Citrix+vulnerability\/31446",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:10",
            "last_seen": "2026-08-06 14:43:52"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/exploiting-cve-2024-21412-stealer-campaign-unleashed",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:10",
            "last_seen": "2026-08-06 14:43:52"
        },
        {
            "ioc_value": "https:\/\/www.wiz.io\/blog\/wiz-research-gogs-cve-2025-8110-rce-exploit",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:11",
            "last_seen": "2026-08-06 14:43:52"
        },
        {
            "ioc_value": "https:\/\/blog.talosintelligence.com\/active-exploitation-of-cisco-ios-xe-software\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:10",
            "last_seen": "2026-08-06 14:43:51"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/threat-actors-exploit-cve-2017-11882-deliver-agent-tesla",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:10",
            "last_seen": "2026-08-06 14:43:51"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2022\/06\/06\/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:09",
            "last_seen": "2026-08-06 14:43:50"
        },
        {
            "ioc_value": "https:\/\/thedfirreport.com\/2020\/11\/12\/cryptominers-exploiting-weblogic-rce-cve-2020-14882\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:49"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2022\/can-you-trust-a-files-digital-signature-new-zloader-campaign-exploits-microsofts-signature-verification-putting-users-at-risk\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:09",
            "last_seen": "2026-08-06 14:43:49"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/cve-2019-2725-exploited-and-certificate-files-used-for-obfuscation-to-deliver-monero-miner\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:07",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "zerodayv3startedexploitpcwithexcelgreat.duckdns.org",
            "ioc_type": "other",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:07",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "https:\/\/github.com\/advanced-threat-research\/IOCs\/blob\/master\/2011\/2011-12-14-inside-adobe-reader-zero-day-exploit-cve-2011-2462\/inside-adobe-reader-zero-day-exploit-cve-2011-2462.csv",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "https:\/\/github.com\/advanced-threat-research\/IOCs\/blob\/master\/2014\/2014-04-03-rtf-attack-takes-advantage-of-multiple-exploits\/rtf-attack-takes-advantage-of-multiple-exploits.csv",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "exploits.pro",
            "ioc_type": "other",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "xyskyewhitedevilexploitgreat.duckdns.org",
            "ioc_type": "other",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "lnkexploit.com",
            "ioc_type": "other",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "zerosugaraddonexploit.duckdns.org",
            "ioc_type": "other",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "https:\/\/www.nao-sec.org\/2018\/09\/hello-fallout-exploit-kit.html",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:07",
            "last_seen": "2026-08-06 14:43:47"
        },
        {
            "ioc_value": "https:\/\/ti.360.net\/blog\/articles\/upgrades-in-winrar-exploit-with-social-engineering-and-encryption\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:07",
            "last_seen": "2026-08-06 14:43:47"
        },
        {
            "ioc_value": "amazonexploitkeloid.info",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:34",
            "last_seen": "2026-08-06 14:42:11"
        },
        {
            "ioc_value": "7xexploit.xyz",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:31",
            "last_seen": "2026-08-06 14:42:07"
        },
        {
            "ioc_value": "33exploit.xyz",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:29",
            "last_seen": "2026-08-06 14:42:04"
        },
        {
            "ioc_value": "https:\/\/citizenlab.ca\/2020\/12\/the-great-ipwn-journalists-hacked-with-suspected-nso-group-imessage-zero-click-exploit\/",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "http:\/\/www.computerworld.com\/article\/2484538\/cybercrime-hacking\/researchers-exploit-cellular-tech-flaws-to-intercept-phone-calls.html",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2016\/05\/android-kernal-exploit.html",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "https:\/\/googleprojectzero.blogspot.com\/2017\/04\/over-air-exploiting-broadcoms-wi-fi_4.html",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "https:\/\/www.volexity.com\/blog\/2020\/04\/21\/evil-eye-threat-actor-resurfaces-with-ios-exploit-and-updated-implant\/",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "https:\/\/conference.hitb.org\/hitbsecconf2011kul\/materials\/D1T1%20-%20Riley%20Hassell%20-%20Exploiting%20Androids%20for%20Fun%20and%20Profit.pdf",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "blockchain-exploit.site",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:07",
            "last_seen": "2026-08-06 14:41:43"
        },
        {
            "ioc_value": "http:\/\/blockchain-exploit.site",
            "ioc_type": "url",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:07",
            "last_seen": "2026-08-06 14:41:43"
        },
        {
            "ioc_value": "https:\/\/cryptoexploite.com",
            "ioc_type": "url",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:05",
            "last_seen": "2026-08-06 14:41:40"
        },
        {
            "ioc_value": "ethexploit.org",
            "ioc_type": "other",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:05",
            "last_seen": "2026-08-06 14:41:40"
        },
        {
            "ioc_value": "https:\/\/ethexploit.org",
            "ioc_type": "url",
            "category": "Cryptocurrency",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:05",
            "last_seen": "2026-08-06 14:41:40"
        },
        {
            "ioc_value": "bitcoin-exploit.com",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:44",
            "last_seen": "2026-08-06 14:41:13"
        },
        {
            "ioc_value": "backgroundexploit.pages.dev",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:42",
            "last_seen": "2026-08-06 14:41:10"
        },
        {
            "ioc_value": "snapexploit.com",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 14:40:55",
            "last_seen": "2026-08-06 14:40:55"
        },
        {
            "ioc_value": "facexploit.com",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 14:40:55",
            "last_seen": "2026-08-06 14:40:55"
        },
        {
            "ioc_value": "onlinexploits.com",
            "ioc_type": "other",
            "category": "Scam",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:08:27",
            "last_seen": "2026-08-06 14:40:54"
        },
        {
            "ioc_value": "https:\/\/www.cyber.gov.au\/about-us\/view-all-content\/alerts-and-advisories\/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms",
            "ioc_type": "url",
            "category": "CERT Advisories",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:14:05",
            "last_seen": "2026-08-06 13:14:05"
        },
        {
            "ioc_value": "https:\/\/www.cybersecuritydive.com\/news\/veeam-cve-exploit-frag-ransomware\/732670\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/blog\/c3rb3r-ransomware-ongoing-exploitation-of-cve-2023-22518-targets-unpatched-confluence-servers\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/thehackernews.com\/2023\/11\/cactus-ransomware-exploits-qlik-sense.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.vmray.com\/catb-ransomware-a-new-threat-exploiting-dll-side-loading\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:02",
            "last_seen": "2026-08-06 13:13:02"
        },
        {
            "ioc_value": "https:\/\/www.zdnet.com\/article\/new-phobos-ransomware-exploits-weak-security-to-hit-targets-around-the-world\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.coveware.com\/blog\/cryptomix-ransomware-exploits-cancer-crowdfunding",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/cryptomix-ransomware-exploits-sick-children-to-coerce-payments\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/nemty-ransomware-gets-distribution-from-rig-exploit-kit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.acronis.com\/en-us\/blog\/posts\/meet-buran-new-delphi-ransomware-delivered-rig-exploit-kit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/uiwix-ransomware-using-eternalblue-smb-exploit-to-infect-victims\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.truesec.com\/2021\/07\/06\/kaseya-vsa-zero-day-exploit",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/07\/04\/independence-day-revil-uses-supply-chain-exploit-to-attack-hundreds-of-businesses",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2020\/graphology-of-an-exploit-playbit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/maze-ransomware-now-delivered-by-spelevo-exploit-kit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/09\/03\/conti-affiliates-use-proxyshell-exchange-exploit-in-ransomware-attacks\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2022\/02\/28\/conti-and-karma-actors-attack-healthcare-provider-at-same-time-through-proxyshell-exploits\/?cmp=30728",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/security\/f\/fallout-exploit-kit\/savefiles\/ransom-note-red.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fallout-exploit-kit-now-installing-the-kraken-cryptor-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/fallout-exploit-kit-pushing-the-savefiles-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advintel.io\/post\/ransomware-advisory-log4shell-exploitation-for-initial-access-lateral-movement",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/10\/04\/atom-silo-ransomware-actors-use-confluence-exploit-dll-side-load-for-stealthy-attack\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepstatic.com\/images\/news\/security\/f\/fallout-exploit-kit\/gandcrab-fallout.jpg",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/gandcrab-ransomware-distributed-by-exploit-kits-appends-gdcb-extension\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/new-alma-locker-ransomware-being-distributed-via-the-rig-exploit-kit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/new-fallout-exploit-kit-drops-gandcrab-ransomware-or-redirects-to-pups\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/gandcrab-v5-ransomware-utilizing-the-alpc-task-scheduler-exploit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.coveware.com\/blog\/ransomware-attack-vectors-shift-as-new-software-vulnerability-exploits-abound",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "Exploit.in",
            "ioc_type": "other",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/02\/accellion-fta-exploited-for-data-theft-and-extortion.html",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/krebsonsecurity.com\/2019\/06\/report-no-eternal-blue-exploit-found-in-baltimore-city-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-exploits-gigabyte-driver-to-kill-av-processes\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revenge-ransomware-a-cryptomix-variant-being-distributed-by-rig-exploit-kit\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/rig-e-exploit-kit-now-distributing-new-chip-ransomware\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/cryptoluck-ransomware-being-malvertised-via-rig-e-exploit-kits\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/blog\/research\/76558\/the-first-cryptor-to-exploit-telegram\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/cryptomix-variant-named-cryptoshield-1-0-ransomware-distributed-by-exploit-kits\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 13:13:00"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nAdversaries",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nSupply",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nThreat",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nTo",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nFigure",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nIn",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\n\\",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nmodel",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nGTIG",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nAs",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nAPI",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nTable",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nThroughout",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nBuilding",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nmade",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nTactic",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nAML.T0040:",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nT1592.001:",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nhttps:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\\n\\nT1588.007:",
            "ioc_type": "url",
            "category": "Threat Reports",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:12:36",
            "last_seen": "2026-08-06 13:12:36"
        },
        {
            "ioc_value": "https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/11\/28\/exploitation-unitronics-plcs-used-water-and-wastewater-systems",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/msrc-blog.microsoft.com\/2017\/08\/09\/moving-beyond-emet-ii-windows-defender-exploit-guard\/",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 13:09:23"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/zev3n\/Ubuntu-Gnome-privilege-escalation\/main\/CVE-2020-1612%5B6_7%5D_exploit.sh",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/Kabot\/Unix-Privilege-Escalation-Exploits-Pack\/master\/2012\/vmsplice-local-root-exploit",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/g1vi\/CVE-2023-2640-CVE-2023-32629\/main\/exploit.sh",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/nguyenmanmkt\/repo1\/main\/exploit-2",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/mach1el\/htb-scripts\/master\/exploit-fuse\/shell.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/SecWiki\/windows-kernel-exploits\/master\/MS14-068\/MS14-068.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/newlog\/exploiting\/refs\/heads\/master\/training\/windows\/practical_malware_analysis\/labs\/Chapter_1L\/Lab01-02.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        }
    ]
}