{
  "generated": "2026-07-09T21:00:23Z",
  "count": 5,
  "reports": [
    {
      "id": "e5f607182a3b",
      "sha256": "e5f607182a3b0718293a4b5c6d7e8f90112233445566778899aabbccddeeff05",
      "actor": "TA-Voltage",
      "collection": "stealers",
      "filename": "invoice_march.exe",
      "filetype": "pe",
      "size": 187904,
      "family": "AgentTesla",
      "classification": "stealer",
      "verdict": "malicious",
      "severity": "high",
      "first_seen": "2026-07-09T16:40:00Z",
      "tags": [
        "phishing",
        "stealer",
        "repacked"
      ],
      "techniques": [
        "T1059.003",
        "T1055",
        "T1071",
        "T1547"
      ],
      "capabilities": [
        "c2/http",
        "host-interaction/registry/create"
      ],
      "signatures": [
        "ET MALWARE AgentTesla CnC Checkin"
      ],
      "tlp": "TLP:CLEAR",
      "report": "stealers/2026/e5f607182a3b-march.md",
      "network_iocs": [
        "hxxp://c2[.]agent-tesla[.]top/gate[.]php",
        "185[.]220[.]101[.]45",
        "45[.]83[.]13[.]4"
      ],
      "ioc_counts": {
        "network": 3,
        "hosts": 0,
        "files": 1,
        "registry": 1,
        "mutexes": 1
      },
      "config": {
        "c2": [
          "hxxp://c2[.]agent-tesla[.]top/gate[.]php"
        ],
        "keys": [
          "rc4:8F2A1B3C4D9E7F60"
        ],
        "campaign": [
          "TESLA-0725"
        ],
        "mutex": [
          "tesla-mtx-9F2A"
        ],
        "version": [
          "4.9.2"
        ]
      },
      "ioc_context": {
        "185[.]220[.]101[.]45": {
          "classification": "malicious",
          "noise": true,
          "riot": false,
          "name": "Tor exit / AgentTesla CnC",
          "tags": [
            "Tor Exit Node",
            "AgentTesla CnC"
          ],
          "asn": "AS208294",
          "last_seen": "2026-07-08"
        },
        "45[.]83[.]13[.]4": {
          "classification": "benign",
          "noise": true,
          "riot": true,
          "name": "Censys",
          "tags": [
            "Censys Scanner"
          ],
          "asn": "AS398324",
          "last_seen": "2026-07-09"
        }
      }
    },
    {
      "id": "a1b2c3d4e5f6",
      "sha256": "a1b2c3d4e5f60718293a4b5c6d7e8f90112233445566778899aabbccddeeff00",
      "actor": "TA-Voltage",
      "collection": "stealers",
      "filename": "invoice_2026.exe",
      "filetype": "pe",
      "size": 184320,
      "family": "AgentTesla",
      "classification": "stealer",
      "verdict": "malicious",
      "severity": "high",
      "first_seen": "2026-07-08T09:12:00Z",
      "tags": [
        "phishing",
        "stealer"
      ],
      "techniques": [
        "T1059.003",
        "T1055",
        "T1112",
        "T1547",
        "T1071"
      ],
      "capabilities": [
        "c2/http",
        "host-interaction/registry/create",
        "data-manipulation/encoding/base64"
      ],
      "signatures": [
        "ET MALWARE AgentTesla CnC Checkin"
      ],
      "tlp": "TLP:CLEAR",
      "report": "stealers/2026/a1b2c3d4e5f6-invoice.md",
      "network_iocs": [
        "hxxp://c2[.]agent-tesla[.]top/gate[.]php",
        "185[.]220[.]101[.]45",
        "45[.]83[.]13[.]4"
      ],
      "ioc_counts": {
        "network": 3,
        "hosts": 0,
        "files": 1,
        "registry": 1,
        "mutexes": 1
      },
      "config": {
        "c2": [
          "hxxp://c2[.]agent-tesla[.]top/gate[.]php"
        ],
        "keys": [
          "rc4:8F2A1B3C4D9E7F60"
        ],
        "campaign": [
          "TESLA-0725"
        ],
        "mutex": [
          "tesla-mtx-9F2A"
        ],
        "version": [
          "4.9.2"
        ]
      },
      "ioc_context": {
        "185[.]220[.]101[.]45": {
          "classification": "malicious",
          "noise": true,
          "riot": false,
          "name": "Tor exit / AgentTesla CnC",
          "tags": [
            "Tor Exit Node",
            "AgentTesla CnC"
          ],
          "asn": "AS208294",
          "last_seen": "2026-07-08"
        },
        "45[.]83[.]13[.]4": {
          "classification": "benign",
          "noise": true,
          "riot": true,
          "name": "Censys",
          "tags": [
            "Censys Scanner"
          ],
          "asn": "AS398324",
          "last_seen": "2026-07-09"
        }
      }
    },
    {
      "id": "b2c3d4e5f607",
      "sha256": "b2c3d4e5f60718293a4b5c6d7e8f90112233445566778899aabbccddeeff0011",
      "actor": "TA-Voltage",
      "collection": "stealers",
      "filename": "order_confirmation.exe",
      "filetype": "pe",
      "size": 189440,
      "family": "AgentTesla",
      "classification": "stealer",
      "verdict": "malicious",
      "severity": "high",
      "first_seen": "2026-07-07T14:30:00Z",
      "tags": [
        "phishing",
        "stealer"
      ],
      "techniques": [
        "T1059.003",
        "T1055",
        "T1071",
        "T1552"
      ],
      "capabilities": [
        "c2/http",
        "host-interaction/registry/create"
      ],
      "signatures": [
        "ET MALWARE AgentTesla CnC Checkin"
      ],
      "tlp": "TLP:CLEAR",
      "report": "stealers/2026/b2c3d4e5f607-order.md",
      "network_iocs": [
        "hxxp://c2[.]agent-tesla[.]top/gate[.]php",
        "45[.]83[.]13[.]4"
      ],
      "ioc_counts": {
        "network": 2,
        "hosts": 0,
        "files": 0,
        "registry": 1,
        "mutexes": 1
      },
      "config": {
        "c2": [
          "hxxp://c2[.]agent-tesla[.]top/gate[.]php"
        ],
        "keys": [
          "rc4:8F2A1B3C4D9E7F60"
        ],
        "campaign": [
          "TESLA-0725"
        ],
        "mutex": [
          "tesla-mtx-9F2A"
        ],
        "version": [
          "4.9.2"
        ]
      },
      "ioc_context": {
        "45[.]83[.]13[.]4": {
          "classification": "benign",
          "noise": true,
          "riot": true,
          "name": "Censys",
          "tags": [
            "Censys Scanner"
          ],
          "asn": "AS398324",
          "last_seen": "2026-07-09"
        }
      }
    },
    {
      "id": "c3d4e5f60718",
      "sha256": "c3d4e5f60718293a4b5c6d7e8f90112233445566778899aabbccddeeff001122",
      "actor": "",
      "collection": "loaders",
      "filename": "setup_x86.scr",
      "filetype": "pe",
      "size": 421888,
      "family": "Formbook",
      "classification": "loader",
      "verdict": "malicious",
      "severity": "critical",
      "first_seen": "2026-07-06T20:05:00Z",
      "tags": [
        "loader",
        "injection"
      ],
      "techniques": [
        "T1055",
        "T1027",
        "T1497",
        "T1105",
        "T1071"
      ],
      "capabilities": [
        "host-interaction/process/inject",
        "anti-analysis/anti-vm/vm-detection"
      ],
      "signatures": [
        "ET MALWARE FormBook CnC"
      ],
      "tlp": "TLP:CLEAR",
      "report": "loaders/2026/c3d4e5f60718-setup.md",
      "network_iocs": [
        "hxxps://formbook-panel[.]xyz/fb/",
        "91[.]92[.]240[.]12"
      ],
      "ioc_counts": {
        "network": 2,
        "hosts": 0,
        "files": 1,
        "registry": 0,
        "mutexes": 2
      },
      "config": {
        "c2": [
          "hxxps://formbook-panel[.]xyz/fb/"
        ],
        "keys": [
          "xor:5A"
        ],
        "campaign": [
          "FB-DECEMBER"
        ],
        "mutex": [
          "fb-mtx-7c"
        ],
        "version": [
          "4.1"
        ]
      },
      "ioc_context": {
        "91[.]92[.]240[.]12": {
          "classification": "unknown",
          "noise": false,
          "riot": false,
          "name": "",
          "tags": [],
          "asn": "",
          "last_seen": ""
        }
      }
    },
    {
      "id": "d4e5f6071829",
      "sha256": "d4e5f60718293a4b5c6d7e8f90112233445566778899aabbccddeeff00112233",
      "actor": "",
      "collection": "maldocs",
      "filename": "resume_update.doc",
      "filetype": "ole",
      "size": 96256,
      "family": "",
      "classification": "maldoc",
      "verdict": "suspicious",
      "severity": "medium",
      "first_seen": "2026-07-05T11:00:00Z",
      "tags": [
        "maldoc",
        "macro"
      ],
      "techniques": [
        "T1059.003",
        "T1204",
        "T1027"
      ],
      "capabilities": [
        "executable/office-macro"
      ],
      "signatures": [],
      "tlp": "TLP:CLEAR",
      "report": "maldocs/2026/d4e5f6071829-resume.md",
      "network_iocs": [
        "hxxp://staging[.]doc-download[.]cc/p[.]php"
      ],
      "ioc_counts": {
        "network": 1,
        "hosts": 0,
        "files": 0,
        "registry": 0,
        "mutexes": 0
      }
    }
  ],
  "techniques": {
    "T1059.003": 4,
    "T1055": 4,
    "T1071": 4,
    "T1547": 2,
    "T1112": 1,
    "T1552": 1,
    "T1027": 2,
    "T1497": 1,
    "T1105": 1,
    "T1204": 1
  },
  "techniques_resolved": [
    {
      "id": "T1055",
      "name": "Process Injection",
      "tactic": "Defense Evasion",
      "count": 4
    },
    {
      "id": "T1059.003",
      "name": "Command and Scripting Interpreter",
      "tactic": "Execution",
      "count": 4
    },
    {
      "id": "T1071",
      "name": "Application Layer Protocol",
      "tactic": "Command and Control",
      "count": 4
    },
    {
      "id": "T1027",
      "name": "Obfuscated Files or Information",
      "tactic": "Defense Evasion",
      "count": 2
    },
    {
      "id": "T1547",
      "name": "Boot or Logon Autostart Execution",
      "tactic": "Persistence",
      "count": 2
    },
    {
      "id": "T1105",
      "name": "Ingress Tool Transfer",
      "tactic": "Command and Control",
      "count": 1
    },
    {
      "id": "T1112",
      "name": "Modify Registry",
      "tactic": "Defense Evasion",
      "count": 1
    },
    {
      "id": "T1204",
      "name": "User Execution",
      "tactic": "Execution",
      "count": 1
    },
    {
      "id": "T1497",
      "name": "Virtualization/Sandbox Evasion",
      "tactic": "Defense Evasion",
      "count": 1
    },
    {
      "id": "T1552",
      "name": "Unsecured Credentials",
      "tactic": "Credential Access",
      "count": 1
    }
  ],
  "families": {
    "AgentTesla": 3,
    "Formbook": 1
  },
  "verdicts": {
    "malicious": 4,
    "suspicious": 1
  },
  "collections": {
    "stealers": 3,
    "loaders": 1,
    "maldocs": 1
  }
}
