{"success":true,"data":{"threats":[{"id":"dd2123ce-743f-47b0-b9b9-e1eef080b1f5","slug":"threatfox-1957899","externalId":"threatfox-1957899","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Vidar url: hxxps://kl[.]3toto[.]com","description":"URL that is used for botnet Command&control (C&C) indicator associated with Vidar. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:url","threat:botnet-cc","malware:win-vidar","confidence:100","2f3c6fb2d82ed66e2e45208cd1c7edd1","c2","loader","stealer","vidar"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957899/","type":"report","title":"ThreatFox IOC 1957899"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:02:22.000Z","addedAt":"2026-10-08T20:48:02.508Z","updatedAt":"2026-10-08T20:48:02.508Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"86321160-b92d-4528-805c-d2d9b9652404","slug":"threatfox-1957626","externalId":"threatfox-1957626","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Unknown Stealer sha256_hash: d12968c99af8b54320593d5574e160856112c442ec7a39fb55672f3849bddb87","description":"SHA256 hash of a malware sample (payload) indicator associated with Unknown Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:unknown-stealer","confidence:90","dropped-by-offloader","exe","rustystealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957626/","type":"report","title":"ThreatFox IOC 1957626"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:40:43.000Z","addedAt":"2026-10-08T16:41:57.532Z","updatedAt":"2026-10-08T20:48:04.612Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"27adef54-0e9b-4eed-96ea-1176ed75b14a","slug":"threatfox-1957625","externalId":"threatfox-1957625","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Unknown Stealer sha256_hash: 72e540c3f9aaf67b471b3024ea4df294bcff28bea7fc8fc17395ad04ca39b285","description":"SHA256 hash of a malware sample (payload) indicator associated with Unknown Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:unknown-stealer","confidence:90","579cd0","dropped-by-amadey","exe","remusstealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957625/","type":"report","title":"ThreatFox IOC 1957625"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:40:42.000Z","addedAt":"2026-10-08T16:41:57.542Z","updatedAt":"2026-10-08T20:48:04.619Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"fb2ae68f-e9d3-465c-af48-80731dd6aa0f","slug":"threatfox-1957624","externalId":"threatfox-1957624","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Unknown Stealer sha256_hash: 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90","description":"SHA256 hash of a malware sample (payload) indicator associated with Unknown Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:unknown-stealer","confidence:90","exe","lunex","lunexstealer","psychedelicstealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957624/","type":"report","title":"ThreatFox IOC 1957624"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:40:41.000Z","addedAt":"2026-10-08T16:41:57.548Z","updatedAt":"2026-10-08T20:48:04.626Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"86aebae7-8949-44ae-a1e6-18b10ff64b7a","slug":"threatfox-1957623","externalId":"threatfox-1957623","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Unknown Stealer sha256_hash: 9dbeb21f4052803456605326333dd5512f604fdb88a6eb85d0a1e675d094df58","description":"SHA256 hash of a malware sample (payload) indicator associated with Unknown Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:unknown-stealer","confidence:90","corvusminer","etherhiding","exe","overlord","python","rustystealer","stealer","xmrig"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957623/","type":"report","title":"ThreatFox IOC 1957623"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:40:40.000Z","addedAt":"2026-10-08T16:41:57.555Z","updatedAt":"2026-10-08T20:48:04.634Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"86e3b715-189a-4fa4-b51e-105d66c55d46","slug":"threatfox-1957622","externalId":"threatfox-1957622","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Unknown Stealer sha256_hash: 37f2c4607a1fad32eda76af2514588cd704b5d5ee83ceb93c14bf10b33c1c8f3","description":"SHA256 hash of a malware sample (payload) indicator associated with Unknown Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:unknown-stealer","confidence:90","msi","rustystealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957622/","type":"report","title":"ThreatFox IOC 1957622"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:40:39.000Z","addedAt":"2026-10-08T16:41:57.562Z","updatedAt":"2026-10-08T20:48:04.640Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"80890da4-0e64-403b-90e5-95f0893575cb","slug":"threatfox-1957621","externalId":"threatfox-1957621","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Unknown Stealer sha256_hash: 580900e5f4412f9f870fd05bb4a04a670958ba7773125a050be3619a64fb4a9f","description":"SHA256 hash of a malware sample (payload) indicator associated with Unknown Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 75%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:unknown-stealer","confidence:75","rustystealer","stealer","zip"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957621/","type":"report","title":"ThreatFox IOC 1957621"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:40:38.000Z","addedAt":"2026-10-08T16:41:57.569Z","updatedAt":"2026-10-08T20:48:04.647Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"d952d2ae-f41b-4aa5-93ca-42d146d4c768","slug":"threatfox-1957620","externalId":"threatfox-1957620","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Unknown Stealer sha256_hash: 51a371c23d6bb298259d5cd10f8bd86b16e992a9d80c107a69eaa60e2bc793a3","description":"SHA256 hash of a malware sample (payload) indicator associated with Unknown Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 75%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:unknown-stealer","confidence:75","rustystealer","stealer","zip"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957620/","type":"report","title":"ThreatFox IOC 1957620"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:40:37.000Z","addedAt":"2026-10-08T16:41:57.576Z","updatedAt":"2026-10-08T20:48:04.654Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"1d4d3830-d58e-4905-8075-6af7336064cb","slug":"threatfox-1957619","externalId":"threatfox-1957619","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Unknown Stealer sha256_hash: 029b9627303993756e3a7006c0ef7420a18fac1f43b11cf1e5b293a3197e94ae","description":"SHA256 hash of a malware sample (payload) indicator associated with Unknown Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 80%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:unknown-stealer","confidence:80","exe","rustystealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957619/","type":"report","title":"ThreatFox IOC 1957619"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:40:36.000Z","addedAt":"2026-10-08T16:41:57.582Z","updatedAt":"2026-10-08T20:48:04.662Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"f7563517-d8e2-4f01-9c3a-6323c289f550","slug":"threatfox-1957616","externalId":"threatfox-1957616","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Unknown Stealer sha256_hash: f08967cdbdb0e00f35378885142dc5a33f305791496ab4977384050fcf8e3571","description":"SHA256 hash of a malware sample (payload) indicator associated with Unknown Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:unknown-stealer","confidence:90","pythonstealer","stealer","zip"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957616/","type":"report","title":"ThreatFox IOC 1957616"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:40:33.000Z","addedAt":"2026-10-08T16:41:57.597Z","updatedAt":"2026-10-08T20:48:04.676Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"73b6f754-1d33-48a5-a5f8-6986cd75ec3a","slug":"threatfox-1957529","externalId":"threatfox-1957529","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"SantaStealer sha256_hash: 16477487dcabd96bfe805d0e98378516cba21e75158908cb9d61c8d7a2037a9f","description":"SHA256 hash of a malware sample (payload) indicator associated with SantaStealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:win-santa-stealer","confidence:90","exe","santastealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957529/","type":"report","title":"ThreatFox IOC 1957529"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:40:00.000Z","addedAt":"2026-10-08T15:41:57.809Z","updatedAt":"2026-10-08T20:48:05.333Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"20b144a7-ec01-418c-acf1-3e5c3501a251","slug":"threatfox-1957525","externalId":"threatfox-1957525","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Lumma Stealer sha256_hash: 775d25d0bc3125ae6df9a2e84cd448e2108ae7edf6d66916e39f97e9b5cb86e2","description":"SHA256 hash of a malware sample (payload) indicator associated with Lumma Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:win-lumma","confidence:90","exe","lummastealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957525/","type":"report","title":"ThreatFox IOC 1957525"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:39:55.000Z","addedAt":"2026-10-08T15:41:57.835Z","updatedAt":"2026-10-08T20:48:05.360Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"31f8d833-c68b-44af-8362-09f726c5a59e","slug":"threatfox-1957524","externalId":"threatfox-1957524","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Lumma Stealer sha256_hash: 479b3c923be6125530e99f24e611547aa5d8861d1e88b75a03ce5527a2052213","description":"SHA256 hash of a malware sample (payload) indicator associated with Lumma Stealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:win-lumma","confidence:90","exe","lummastealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957524/","type":"report","title":"ThreatFox IOC 1957524"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:39:54.000Z","addedAt":"2026-10-08T15:41:57.842Z","updatedAt":"2026-10-08T20:48:05.367Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"4ce46fca-3c93-476f-a0ff-03c30a73f078","slug":"threatfox-1957498","externalId":"threatfox-1957498","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"SantaStealer sha256_hash: ea28b85e97fdfe77335e8625586212f0df64ceee15c8290d17b75e6096694d81","description":"SHA256 hash of a malware sample (payload) indicator associated with SantaStealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:win-santa-stealer","confidence:90","exe","santastealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957498/","type":"report","title":"ThreatFox IOC 1957498"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:40:44.000Z","addedAt":"2026-10-08T14:41:57.462Z","updatedAt":"2026-10-08T20:48:05.549Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"21541f2d-7a2f-4688-9390-7ffa4e92aef2","slug":"threatfox-1957496","externalId":"threatfox-1957496","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"SantaStealer sha256_hash: 9df11356c5ac61d2aa7b5425e6322fc016b0ed5790dacb201396500b3eee03f7","description":"SHA256 hash of a malware sample (payload) indicator associated with SantaStealer. Indicator that identifies a malware sample (payload) Reporter confidence 90%.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:sha256-hash","threat:payload","malware:win-santa-stealer","confidence:90","exe","santastealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957496/","type":"report","title":"ThreatFox IOC 1957496"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:40:35.000Z","addedAt":"2026-10-08T14:41:57.476Z","updatedAt":"2026-10-08T20:48:05.563Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"00ef05e5-0a0a-4ccd-a7dd-a43a133b0945","slug":"threatfox-1957335","externalId":"threatfox-1957335","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Vidar url: hxxps://172[.]105[.]64[.]167","description":"URL that is used for botnet Command&control (C&C) indicator associated with Vidar. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%. Last seen 2026-10-08 20:44:26 UTC.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:url","threat:botnet-cc","malware:win-vidar","confidence:100","9907f3712d269b106ae1de2f415a7914","c2","loader","stealer","vidar"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957335/","type":"report","title":"ThreatFox IOC 1957335"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:06:14.000Z","addedAt":"2026-10-08T14:41:58.598Z","updatedAt":"2026-10-08T20:48:06.753Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"3cd09cee-10d3-4e42-b458-579203deb5f9","slug":"threatfox-1957334","externalId":"threatfox-1957334","source":"abuse.ch ThreatFox","sourceType":"community","type":"indicator","title":"Vidar url: hxxps://172[.]235[.]182[.]6","description":"URL that is used for botnet Command&control (C&C) indicator associated with Vidar. Indicator that identifies a botnet command&control server (C&C) Reporter confidence 100%. Last seen 2026-10-08 20:44:35 UTC.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["threatfox","ioc","ioc:url","threat:botnet-cc","malware:win-vidar","confidence:100","0086075e3f7c97c9ab04a1a2cd48e78b","c2","loader","stealer","vidar"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://threatfox.abuse.ch/ioc/1957334/","type":"report","title":"ThreatFox IOC 1957334"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:06:14.000Z","addedAt":"2026-10-08T14:41:58.591Z","updatedAt":"2026-10-08T20:48:06.745Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"571cfdaf-a079-4dcf-96a6-c44e415ad46a","slug":"urlhaus-3945974","externalId":"urlhaus-3945974","source":"abuse.ch URLhaus","sourceType":"community","type":"malware","title":"Malware distribution URL on gitlab[.]com","description":"URLhaus recorded hxxps://gitlab[.]com/graymid/tinnylieh/-/raw/main/79K5P6K67H63[.]exe as malware download. The URL is currently online. Reported by shmulc.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["urlhaus","ioc","ioc:url","threat:malware-download","status:online","cheatsheet","exe","gitlab","rustystealer","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://urlhaus.abuse.ch/url/3945974/","type":"report","title":"URLhaus entry 3945974"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:53:23.000Z","addedAt":"2026-10-08T06:42:07.155Z","updatedAt":"2026-10-08T20:48:15.995Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"6b5207d8-7a5c-48ee-ad01-b79664d6ab33","slug":"urlhaus-3945822","externalId":"urlhaus-3945822","source":"abuse.ch URLhaus","sourceType":"community","type":"malware","title":"Malware distribution URL on gitlab[.]com","description":"URLhaus recorded hxxps://gitlab[.]com/hexxycally/code/-/raw/main/W52UE52XBY31[.]exe as malware download. The URL is currently online. Reported by shmulc.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["urlhaus","ioc","ioc:url","threat:malware-download","status:online","cheatsheet","exe","gitlab","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://urlhaus.abuse.ch/url/3945822/","type":"report","title":"URLhaus entry 3945822"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:51:48.000Z","addedAt":"2026-10-08T06:42:08.179Z","updatedAt":"2026-10-08T20:48:17.167Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"9b1d4976-205c-4821-9b3f-267d9f36f8f9","slug":"urlhaus-3945788","externalId":"urlhaus-3945788","source":"abuse.ch URLhaus","sourceType":"community","type":"malware","title":"Malware distribution URL on gitlab[.]com","description":"URLhaus recorded hxxps://gitlab[.]com/hexxycally/code/-/raw/main/7PGV5X7885T8[.]exe as malware download. The URL is currently online. Reported by shmulc.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["urlhaus","ioc","ioc:url","threat:malware-download","status:online","cheatsheet","exe","gitlab","stealer"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://urlhaus.abuse.ch/url/3945788/","type":"report","title":"URLhaus entry 3945788"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:51:25.000Z","addedAt":"2026-10-08T06:42:08.419Z","updatedAt":"2026-10-08T20:48:17.407Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":1019,"totalPages":51,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:58:15.815Z","durationMs":16,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["stealer"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}