{"success":true,"data":{"threats":[{"id":"dd2123ce-743f-47b0-b9b9-e1eef080b1f5","slug":"threatfox-1957899","externalId":"threatfox-1957899","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Vidar url: hxxps://kl[.]3toto[.]com","description":"URL that is used for botnet Command&control (C&C) indicator associated with Vidar. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:url","threat:botnet-cc","malware:win-vidar","confidence:100","2f3c6fb2d82ed66e2e45208cd1c7edd1","c2","loader","stealer","vidar"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957899/","type":"report","title":"ThreatFox IOC 1957899"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:02:22.000Z","addedAt":"2026-10-08T20:48:02.508Z","updatedAt":"2026-10-08T20:48:02.508Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"9f6a0052-aa63-40d8-9eb9-8c815bb0d079","slug":"threatfox-1957898","externalId":"threatfox-1957898","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Aisuru ip:port: 165[.]22[.]244[.]100:8443","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Aisuru. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:elf-aisuru","confidence:100","aisuru","c2"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957898/","type":"report","title":"ThreatFox IOC 1957898"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:54:34.000Z","addedAt":"2026-10-08T20:48:02.515Z","updatedAt":"2026-10-08T20:48:02.515Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"0a3f78f6-2bcc-44ec-931b-60df90d30d04","slug":"threatfox-1957871","externalId":"threatfox-1957871","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Remcos ip:port: 128[.]90[.]113[.]76:3000","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Remcos. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:win-remcos","confidence:100","c2","remcos","star-baby-27"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957871/","type":"report","title":"ThreatFox IOC 1957871"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:42:18.000Z","addedAt":"2026-10-08T19:35:12.205Z","updatedAt":"2026-10-08T20:48:02.719Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"65f6949c-35b2-4234-836e-61c317ec9ab5","slug":"threatfox-1957841","externalId":"threatfox-1957841","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Aisuru ip:port: 178[.]16[.]53[.]68:8080","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Aisuru. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:elf-aisuru","confidence:100","aisuru","c2"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957841/","type":"report","title":"ThreatFox IOC 1957841"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:01:51.000Z","addedAt":"2026-10-08T19:35:12.408Z","updatedAt":"2026-10-08T20:48:02.929Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"79ea75de-0ff5-4282-9de7-0340d847fc53","slug":"threatfox-1957835","externalId":"threatfox-1957835","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Remcos ip:port: 172[.]94[.]58[.]29:2303","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Remcos. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:win-remcos","confidence:100","c2","remcos","winprotection2"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957835/","type":"report","title":"ThreatFox IOC 1957835"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:20:52.000Z","addedAt":"2026-10-08T18:41:57.500Z","updatedAt":"2026-10-08T20:48:02.974Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"ffd43a37-74b9-47f6-bec5-254999b3f9f6","slug":"threatfox-1957627","externalId":"threatfox-1957627","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Aisuru ip:port: 178[.]16[.]53[.]76:8443","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Aisuru. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:elf-aisuru","confidence:100","aisuru","c2"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957627/","type":"report","title":"ThreatFox IOC 1957627"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:53:48.000Z","addedAt":"2026-10-08T17:41:58.833Z","updatedAt":"2026-10-08T20:48:04.578Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"1def630f-ea10-4c16-80f6-c41e38f8deb9","slug":"urlhaus-3946277","externalId":"urlhaus-3946277","source":"abuse.ch URLhaus","sourceType":"community","type":"malware","title":"Malware distribution URL on 91[.]240[.]118[.]10","description":"URLhaus recorded hxxp://91[.]240[.]118[.]10/ycl as malware download. The URL is currently offline. Reported by Bitsight.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["urlhaus","ioc","ioc:url","threat:malware-download","status:offline","c2","dropped-by-gcleaner","s"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://urlhaus.abuse.ch/url/3946277/","type":"report","title":"URLhaus entry 3946277"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:38:05.000Z","addedAt":"2026-10-08T14:42:06.925Z","updatedAt":"2026-10-08T20:48:13.777Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"b8472d41-5816-416c-b2a7-ce62435f54fc","slug":"threatfox-1957363","externalId":"threatfox-1957363","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Remcos ip:port: 128[.]90[.]102[.]224:2015","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Remcos. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:win-remcos","confidence:100","c2","ck-099","remcos"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957363/","type":"report","title":"ThreatFox IOC 1957363"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:37:34.000Z","addedAt":"2026-10-08T14:41:57.701Z","updatedAt":"2026-10-08T20:48:05.787Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"82342265-f46b-4141-b58d-29253a2110c6","slug":"urlhaus-3946276","externalId":"urlhaus-3946276","source":"abuse.ch URLhaus","sourceType":"community","type":"malware","title":"Malware distribution URL on 91[.]240[.]118[.]10","description":"URLhaus recorded hxxp://91[.]240[.]118[.]10/service as malware download. The URL is currently offline. Reported by Bitsight.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["urlhaus","ioc","ioc:url","threat:malware-download","status:offline","a","c2","dropped-by-gcleaner"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://urlhaus.abuse.ch/url/3946276/","type":"report","title":"URLhaus entry 3946276"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:33:04.000Z","addedAt":"2026-10-08T14:42:06.932Z","updatedAt":"2026-10-08T20:48:13.784Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"d02c6e96-d65d-40db-8e90-d74967d47b08","slug":"urlhaus-3946273","externalId":"urlhaus-3946273","source":"abuse.ch URLhaus","sourceType":"community","type":"malware","title":"Malware distribution URL on 91[.]240[.]118[.]10","description":"URLhaus recorded hxxp://91[.]240[.]118[.]10/update as malware download. The URL is currently offline. Reported by Bitsight.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["urlhaus","ioc","ioc:url","threat:malware-download","status:offline","1","c2","dropped-by-gcleaner"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://urlhaus.abuse.ch/url/3946273/","type":"report","title":"URLhaus entry 3946273"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:32:05.000Z","addedAt":"2026-10-08T14:42:06.952Z","updatedAt":"2026-10-08T20:48:13.805Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"368ff39c-e10b-4344-b32f-ed1fc97a7e44","slug":"threatfox-1957109","externalId":"threatfox-1957109","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Aisuru ip:port: 209[.]38[.]216[.]204:8001","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Aisuru. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:elf-aisuru","confidence:100","aisuru","c2"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957109/","type":"report","title":"ThreatFox IOC 1957109"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:06:19.000Z","addedAt":"2026-10-08T12:41:58.441Z","updatedAt":"2026-10-08T20:48:06.687Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"690f2f83-54c6-439a-8200-a73dc378d6f4","slug":"threatfox-1957275","externalId":"threatfox-1957275","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"BADBOX domain: api[.]kookjar[.]com","description":"Domain that is used for botnet Command&control (C&C) indicator associated with BADBOX. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:domain","threat:botnet-cc","malware:apk-badbox","confidence:100","android","automotive","badbox","c2","headunit"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957275/","type":"report","title":"ThreatFox IOC 1957275"},{"url":"https://web.archive.org/web/20260929023142/https://securelist.com/android-head-unit-malware/121106/","type":"report","title":"Reporter reference"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:06:16.000Z","addedAt":"2026-10-08T13:41:57.844Z","updatedAt":"2026-10-08T20:48:06.738Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"00ef05e5-0a0a-4ccd-a7dd-a43a133b0945","slug":"threatfox-1957335","externalId":"threatfox-1957335","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Vidar url: hxxps://172[.]105[.]64[.]167","description":"URL that is used for botnet Command&control (C&C) indicator associated with Vidar. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%. Last seen 2026-10-08 20:44:26 UTC.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:url","threat:botnet-cc","malware:win-vidar","confidence:100","9907f3712d269b106ae1de2f415a7914","c2","loader","stealer","vidar"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957335/","type":"report","title":"ThreatFox IOC 1957335"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:06:14.000Z","addedAt":"2026-10-08T14:41:58.598Z","updatedAt":"2026-10-08T20:48:06.753Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"3cd09cee-10d3-4e42-b458-579203deb5f9","slug":"threatfox-1957334","externalId":"threatfox-1957334","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Vidar url: hxxps://172[.]235[.]182[.]6","description":"URL that is used for botnet Command&control (C&C) indicator associated with Vidar. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%. Last seen 2026-10-08 20:44:35 UTC.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:url","threat:botnet-cc","malware:win-vidar","confidence:100","0086075e3f7c97c9ab04a1a2cd48e78b","c2","loader","stealer","vidar"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957334/","type":"report","title":"ThreatFox IOC 1957334"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:06:14.000Z","addedAt":"2026-10-08T14:41:58.591Z","updatedAt":"2026-10-08T20:48:06.745Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"141f5a48-9de6-41a4-b723-b2451c75b1d9","slug":"threatfox-1957082","externalId":"threatfox-1957082","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Aisuru ip:port: 45[.]156[.]87[.]230:8001","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Aisuru. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:elf-aisuru","confidence:100","aisuru","c2"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957082/","type":"report","title":"ThreatFox IOC 1957082"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T11:47:15.000Z","addedAt":"2026-10-08T12:41:58.628Z","updatedAt":"2026-10-08T20:48:08.622Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"797a1d43-bf54-4135-97df-004278916bdb","slug":"threatfox-1957072","externalId":"threatfox-1957072","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Remcos ip:port: 95[.]211[.]44[.]207:2404","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Remcos. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%. Last seen 2026-10-08 20:12:59 UTC.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:win-remcos","confidence:100","c2","remcos","remotehost"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957072/","type":"report","title":"ThreatFox IOC 1957072"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T10:45:56.000Z","addedAt":"2026-10-08T10:41:57.442Z","updatedAt":"2026-10-08T20:48:08.686Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"60241228-bb4b-4cd5-86bb-01e094cb1a16","slug":"threatfox-1957073","externalId":"threatfox-1957073","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Remcos ip:port: 45[.]128[.]234[.]124:7070","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with Remcos. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%. Last seen 2026-10-08 20:39:53 UTC.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:win-remcos","confidence:100","c2","cveil","remcos"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957073/","type":"report","title":"ThreatFox IOC 1957073"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T10:45:56.000Z","addedAt":"2026-10-08T10:41:57.433Z","updatedAt":"2026-10-08T20:48:08.693Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"b4d5be08-6ecb-48e2-b58c-4b1d13260074","slug":"threatfox-1957031","externalId":"threatfox-1957031","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Remus domain: zeodth[.]click","description":"Domain that is used for botnet Command&control (C&C) indicator associated with Remus. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:domain","threat:botnet-cc","malware:win-remus","confidence:100","c2","remusstealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957031/","type":"report","title":"ThreatFox IOC 1957031"},{"url":"https://bazaar.abuse.ch/sample/c975e382d6cb1003895b5c9ba7465aa1886621b0674ddba837d2a1f45eccfd39/","type":"report","title":"Reporter reference"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T08:52:25.000Z","addedAt":"2026-10-08T09:41:57.469Z","updatedAt":"2026-10-08T20:48:08.934Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"22a372c8-9fc9-4200-8349-d80a0dc365a7","slug":"threatfox-1956999","externalId":"threatfox-1956999","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"CraxsRAT ip:port: 151[.]243[.]126[.]22:9443","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with CraxsRAT. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 75%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:apk-craxs-rat","confidence:75","c2","craxsrat","shodan"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1956999/","type":"report","title":"ThreatFox IOC 1956999"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T06:26:07.000Z","addedAt":"2026-10-08T05:41:57.681Z","updatedAt":"2026-10-08T20:48:09.210Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"15b9c96a-7eda-4a71-8c73-c26de5130566","slug":"threatfox-1956998","externalId":"threatfox-1956998","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"CraxsRAT ip:port: 151[.]243[.]126[.]22:443","description":"ip:port combination that is used for botnet Command&control (C&C) indicator associated with CraxsRAT. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 75%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:ip-port","threat:botnet-cc","malware:apk-craxs-rat","confidence:75","c2","craxsrat","shodan"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1956998/","type":"report","title":"ThreatFox IOC 1956998"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T06:26:06.000Z","addedAt":"2026-10-08T05:41:57.674Z","updatedAt":"2026-10-08T20:48:09.216Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":3430,"totalPages":172,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:53:13.345Z","durationMs":46,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["c2"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}