{
    "count": 9,
    "indicators": [
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/APT-targets-russia-belarus-zerot-plugx",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "http:\/\/circl.lu\/assets\/files\/tr-12\/tr-12-circl-plugx-analysis-v1.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.eclecticiq.com\/mustang-panda-apt-group-uses-european-commission-themed-lure-to-deliver-plugx-malware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ta416-goes-ground-and-returns-golang-plugx-malware-loader",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/bronze-president-targets-russian-speakers-with-updated-plugx",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.bitdefender.com\/blog\/labs\/luminousmoth-plugx-file-exfiltration-and-persistence-revisited",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/web-attack\/112\/pulling-the-plug-on-plugx",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/i.blackhat.com\/Asia-22\/Thursday-Materials\/AS-22-LeonSilvia-NextGenPlugXShadowPad.pdf",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.sentinelone.com\/labs\/moshen-dragons-triad-and-error-approach-abusing-security-software-to-sideload-plugx-and-shadowpad\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        }
    ]
}