[
  {
    "id": 4142843314,
    "indicator": "foundationasdasd.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "NetSupport",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901825,
    "indicator": "051cdb6ac8e168d178e35489b6da4c74",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "MD5 of 6562585009f15155eea9a489e474cebc4dd2a01a26d846fdd1b93fdc24b0c269",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 2014778466,
    "indicator": "0e37fbfa79d349d672456923ec5fbbe3",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "MD5 of 8793353461826fbd48f25ea8b835be204b758ce7510db2af631b28850355bd18",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142437123,
    "indicator": "14ca8f4ee0dd828ecfd0c566dce00f06",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "MD5 of 83a6feb6304effcd258129e5d46f484e4c34c1cce1ea0c32a94a89283ccd24f9",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 3475746070,
    "indicator": "26e28c01461f7e65c402bdf09923d435",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "MD5 of d96856cd944a9f1587907cacef974c0248b7f4210f1689c1e6bcac5fed289368",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901835,
    "indicator": "3aabcd7c81425b3b9327a2bf643251c6",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "MD5 of 0cff893b1e7716d09fb74b7a0313b78a09f3f48c586d31fc5f830bd72ce8331f",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 3777181996,
    "indicator": "3be27483fdcdbf9ebae93234785235e3",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "MD5 of 4bfa4c00414660ba44bddde5216a7f28aeccaa9e2d42df4bbff66db57c60522b",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4091190844,
    "indicator": "5be6fb8f28544d4f83c25a2b76ff7890",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "MD5 of b11380f81b0a704e8c7e84e8a37885f5879d12fbece311813a41992b3e9787f2",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901845,
    "indicator": "67c53a770390e8c038060a1921c20da9",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "Can't access file",
    "description": "MD5 of 2dfdc169dfc27462adc98dde39306de8d0526dcf4577a1a486c2eef447300689",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901847,
    "indicator": "7629af8099b76f85d37b3802041503ee",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "MD5 of 2cc8ebea55c06981625397b04575ed0eaad9bb9f9dc896355c011a62febe49b5",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4091190851,
    "indicator": "e7b92529ea10176fe35ba73fa4edef74",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "Can't access file",
    "description": "MD5 of b6d4ad0231941e0637485ac5833e0fdc75db35289b54e70f3858b70d36d04c80",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4035567113,
    "indicator": "ee75b57b9300aab96530503bfae8a2f2",
    "type": "FileHash-MD5",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "MD5 of 06a0a243811e9c4738a9d413597659ca8d07b00f640b74adc9cb351c179b3268",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 3777182010,
    "indicator": "1d9b5cfcc30436112a7e31d5e4624f52e845c573",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "SHA1 of d96856cd944a9f1587907cacef974c0248b7f4210f1689c1e6bcac5fed289368",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 3777182013,
    "indicator": "360b61fe19cdc1afb2b34d8c25d8b88a4c843a82",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "SHA1 of 4bfa4c00414660ba44bddde5216a7f28aeccaa9e2d42df4bbff66db57c60522b",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901872,
    "indicator": "38c171457d160f8a6f26baa668f5c302f6c29cd1",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "SHA1 of 6562585009f15155eea9a489e474cebc4dd2a01a26d846fdd1b93fdc24b0c269",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901875,
    "indicator": "49e63af91169c8ce7ef7de3d6a6fb9f8f739fa3a",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "Can't access file",
    "description": "SHA1 of 2dfdc169dfc27462adc98dde39306de8d0526dcf4577a1a486c2eef447300689",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 2014780116,
    "indicator": "4e880fc7625ccf8d9ca799d5b94ce2b1e7597335",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "SHA1 of 8793353461826fbd48f25ea8b835be204b758ce7510db2af631b28850355bd18",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4091190859,
    "indicator": "6ad5d9338984c52b37f2176c8ae4ae2366a7fd25",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "SHA1 of b11380f81b0a704e8c7e84e8a37885f5879d12fbece311813a41992b3e9787f2",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4035567114,
    "indicator": "98dd757e1c1fa8b5605bda892aa0b82ebefa1f07",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "SHA1 of 06a0a243811e9c4738a9d413597659ca8d07b00f640b74adc9cb351c179b3268",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142437147,
    "indicator": "cd7d6a571d58ff9bd6a411f98a205c43b9a34da2",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "SHA1 of 83a6feb6304effcd258129e5d46f484e4c34c1cce1ea0c32a94a89283ccd24f9",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901897,
    "indicator": "ea841199baa7307280fc9e4688ac75e5624f2181",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "SHA1 of 0cff893b1e7716d09fb74b7a0313b78a09f3f48c586d31fc5f830bd72ce8331f",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901901,
    "indicator": "f40a5efcb9dee679de22658c6f95c7e9c0f2f0c0",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "SHA1 of 2cc8ebea55c06981625397b04575ed0eaad9bb9f9dc896355c011a62febe49b5",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4091190867,
    "indicator": "fc5b325d433cde797f6ad0d8b1305d6fb16d4e34",
    "type": "FileHash-SHA1",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "Can't access file",
    "description": "SHA1 of b6d4ad0231941e0637485ac5833e0fdc75db35289b54e70f3858b70d36d04c80",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050773,
    "indicator": "05b03a25e10535c5c8e2327ee800ff5894f5dbfaf72e3fdcd9901def6f072c6d",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4035567115,
    "indicator": "06a0a243811e9c4738a9d413597659ca8d07b00f640b74adc9cb351c179b3268",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901914,
    "indicator": "0cff893b1e7716d09fb74b7a0313b78a09f3f48c586d31fc5f830bd72ce8331f",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901929,
    "indicator": "2cc8ebea55c06981625397b04575ed0eaad9bb9f9dc896355c011a62febe49b5",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071901930,
    "indicator": "2dfdc169dfc27462adc98dde39306de8d0526dcf4577a1a486c2eef447300689",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "Can't access file",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 3736872793,
    "indicator": "4bfa4c00414660ba44bddde5216a7f28aeccaa9e2d42df4bbff66db57c60522b",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050774,
    "indicator": "62f7a444ab0c645f20c7dc6340c3eaaad7ef033b2188c3e5123406762990c517",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071902051,
    "indicator": "6562585009f15155eea9a489e474cebc4dd2a01a26d846fdd1b93fdc24b0c269",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050775,
    "indicator": "6846bc236bd2095fbf93f8b31dd4ca0798614fcab20fbd2ecac6cc7f431c6dec",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142437200,
    "indicator": "83a6feb6304effcd258129e5d46f484e4c34c1cce1ea0c32a94a89283ccd24f9",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 1571952637,
    "indicator": "8793353461826fbd48f25ea8b835be204b758ce7510db2af631b28850355bd18",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4091191161,
    "indicator": "b11380f81b0a704e8c7e84e8a37885f5879d12fbece311813a41992b3e9787f2",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4091191163,
    "indicator": "b6d4ad0231941e0637485ac5833e0fdc75db35289b54e70f3858b70d36d04c80",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "Can't access file",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 2239475170,
    "indicator": "d96856cd944a9f1587907cacef974c0248b7f4210f1689c1e6bcac5fed289368",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4071902120,
    "indicator": "e0ed36c897eaa5352fab181c20020b60df4c58986193d6aaf5bf3e3ecdc4c05d",
    "type": "FileHash-SHA256",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4121387395,
    "indicator": "http://141.98.11.175/fakeurl.htm",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050776,
    "indicator": "http://83.222.190.174:443/fakeurl.html",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142437275,
    "indicator": "http://85.208.84.35:443/fakeurl.htm",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050777,
    "indicator": "http://fnotusykakimao.com:443",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050778,
    "indicator": "http://pusykakimao.com:443",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050779,
    "indicator": "http://scottvmorton.com/tytuy.json'",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050780,
    "indicator": "https://bestieslos.com/over.js",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4167928643,
    "indicator": "https://booksbypatriciaschultz.com/liner.php",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4159179836,
    "indicator": "https://ksdkgsdkgkgmgm.pro/ofofo.js",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050781,
    "indicator": "https://ksfldfklskdmbxcvb.com/-",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050782,
    "indicator": "https://ksfldfklskdmbxcvb.com/admin/",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050783,
    "indicator": "https://ksfldfklskdmbxcvb.com/gigi?ts=1765169670",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4150652182,
    "indicator": "https://ototaikfffkf.com/fffa.js",
    "type": "URL",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050784,
    "indicator": "27c4a776680b7cfa16280b8c3cf3e6f5edd3517d",
    "type": "YARA",
    "created": "2026-01-30T07:41:37",
    "content": "rule infrastructure_iclickfix_cluster_ic_tracker_js_wordpress {\n   meta:\n       description = \"Find WordPress HTML compromised by the IClickFix cluster, that injects the ic-tracker-js HTML tag\"\n       source = \"Sekoia.io\"\n       creation_date = \"2025-12-04\"\n       modification_date = \"2025-12-04\"\n       classification = \"TLP:CLEAR\"\n\n   strings:\n       $wp01 = \"\\\" id=\\\"ic-tracker-js\\\"\" ascii\n\n   condition:\n       all of them\n}",
    "title": "",
    "description": "Find WordPress HTML compromised by the IClickFix cluster, that injects the ic-tracker-js HTML tag",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050785,
    "indicator": "d26141f8db39bbbb05c48e2f3b659a775093f736",
    "type": "YARA",
    "created": "2026-01-30T07:41:37",
    "content": "rule infrastructure_iclickfix_cluster_ic_tracker_js_javascript2 {\n    meta:\n        description = \"Find the second JavaScript of the IClickFix cluster, that contacts the .php?page= URL to download the ClickFix lure\"\n        source = \"Sekoia.io\"\n        creation_date = \"2025-12-04\"\n        modification_date = \"2025-12-04\"\n        classification = \"TLP:CLEAR\"\n\n    strings:\n        $datajs01 = \"xhr.send();\" ascii\n        $datajs02 = \".php?page=\\\");\" ascii\n        $datajs03 = \"function getFaviconPath() {\" ascii\n        $datajs04 = \"close-tlc-data\" ascii\n        $datajs05 = \".php?click=1&data=\\\"\" ascii\n        $datajs06 = \"// listen from child\" ascii\n        $datajs07 = \"--loadNumValue\" ascii\n        $datajs08 = \"encodeURIComponent(JSON.stringify(data))\" ascii\n        $datajs09 = \"/* WHITE background: rgba(255,255,255,0.65); */\" ascii\n\n    condition:\n        6 of ($datajs0*)\n}",
    "title": "",
    "description": "Find the second JavaScript of the IClickFix cluster, that contacts the .php?page= URL to download the ClickFix lure",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050786,
    "indicator": "cc1fbd7c3f6242fd3b2ff042af856c57e22835ae",
    "type": "YARA",
    "created": "2026-01-30T07:41:37",
    "content": "rule infrastructure_iclickfix_cluster_ic_tracker_js_wordpress {   \n      meta:   \n          description = \"Find WordPress HTML compromised by the IClickFix cluster, that injects the ic-tracker-js HTML tag\"   \n          source = \"Sekoia.io\"   \n          creation_date = \"2025-12-04\"   \n          modification_date = \"2025-12-04\"   \n          classification = \"TLP:CLEAR\"   \n      \n      strings:   \n          $wp01 = \"\\\" id=\\\"ic-tracker-js\\\"\" ascii   \n      \n      condition:   \n          all of them   \n   }",
    "title": "",
    "description": "Find WordPress HTML compromised by the IClickFix cluster, that injects the ic-tracker-js HTML tag",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050787,
    "indicator": "ce9195af37e24e20fe74bca13a348f92e28aa0a6",
    "type": "YARA",
    "created": "2026-01-30T07:41:37",
    "content": "rule infrastructure_iclickfix_cluster_ic_tracker_html_lure {   \n       meta:   \n           description = \"Find the HTML lure used by the IClickFix cluster, impersonating Cloudflare Turnstile CAPTCHA\"   \n           source = \"Sekoia.io\"   \n           creation_date = \"2025-12-04\"   \n           modification_date = \"2025-12-04\"   \n           classification = \"TLP:CLEAR\"   \n      \n       strings:   \n           //HTML page containing JavaScript and a second HTML corresponding to the ClickFix lure   \n           $lure01 = \"let clickCopy\" ascii   \n           $lure02 = \"let clickCounts\" ascii   \n           $lure03 = \"let delay\" ascii   \n           $lure04 = \"let COPYbase64Text\" ascii   \n           $lure05 = \"let rayID\" ascii   \n           $lure06 = \"'Cloudflare protection  verify with code:\" ascii   \n           $lure07 = \"center.innerHTML\" ascii   \n           $lure08 = \"Verify you are human\" ascii   \n           $lure09 = \"location.host + \" ascii   \n           $lure10 = \"needs to review the security of your connection before proceeding.\" ascii   \n           $lure11 = \"Unusual Web Traffic Detected\" ascii   \n           $lure12 = \"Our security system has identified irregular web activity\" ascii   \n           $lure13 = \"originating from your IP address. Automated verification\" ascii   \n           $lure14 = \"unable to confirm that you are a legitimate user.\" ascii   \n           $lure15 = \"This manual verification step helps us ensure that your connection\" ascii   \n      \n       condition:   \n           9 of ($lure*)   \n   }",
    "title": "",
    "description": "Find the HTML lure used by the IClickFix cluster, impersonating Cloudflare Turnstile CAPTCHA",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050788,
    "indicator": "d448b53a0c953d809857c6fe3f561a60a377eb7b",
    "type": "YARA",
    "created": "2026-01-30T07:41:37",
    "content": "rule infrastructure_iclickfix_cluster_ic_tracker_js_javascript1 {   \n       meta:   \n           description = \"Find the first obfuscated JavaScript of the IClickFix cluster, that contacts the .php?data= URL to download the second JavaScript\"   \n           source = \"Sekoia.io\"   \n           creation_date = \"2025-12-04\"   \n           modification_date = \"2025-12-04\"   \n           classification = \"TLP:CLEAR\"   \n      \n       strings:   \n           $obfjs01 = \"'location'\" ascii   \n           $obfjs02 = \"'style'\" ascii   \n           $obfjs03 = \"?data=\" ascii   \n           $obfjs04 = \"={'host'\" ascii   \n           $obfjs05 = \"animation:1s\\\\x20ease-in-out\\\\x201s\\\\x20forwards\\\\x20fadeIn}',\" ascii   \n           $obfjs06 = \"}(document,\" ascii   \n           $obfjs07 = \"'aHR0cH\" ascii   \n           $obfjs08 = \"'now'\" ascii   \n      \n       condition:   \n           6 of ($obfjs0*)   \n   }",
    "title": "",
    "description": "Find the first obfuscated JavaScript of the IClickFix cluster, that contacts the .php?data= URL to download the second JavaScript",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050789,
    "indicator": "d92f5cd6d068b14e3687fef1aba28b4078bd2fcf",
    "type": "YARA",
    "created": "2026-01-30T07:41:37",
    "content": "rule infrastructure_iclickfix_cluster_ic_tracker_js_javascript2 {   \n       meta:   \n           description = \"Find the second JavaScript of the IClickFix cluster, that contacts the .php?page= URL to download the ClickFix lure\"   \n           source = \"Sekoia.io\"   \n           creation_date = \"2025-12-04\"   \n           modification_date = \"2025-12-04\"   \n           classification = \"TLP:CLEAR\"   \n      \n       strings:   \n           $datajs01 = \"xhr.send();\" ascii   \n           $datajs02 = \".php?page=\\\");\" ascii   \n           $datajs03 = \"function getFaviconPath() {\" ascii   \n           $datajs04 = \"close-tlc-data\" ascii   \n           $datajs05 = \".php?click=1&data=\\\"\" ascii   \n           $datajs06 = \"// listen from child\" ascii   \n           $datajs07 = \"--loadNumValue\" ascii   \n           $datajs08 = \"encodeURIComponent(JSON.stringify(data))\" ascii   \n           $datajs09 = \"/* WHITE background: rgba(255,255,255,0.65); */\" ascii   \n      \n       condition:   \n           6 of ($datajs0*)   \n   }",
    "title": "",
    "description": "Find the second JavaScript of the IClickFix cluster, that contacts the .php?page= URL to download the ClickFix lure",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050790,
    "indicator": "1teamintl.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4150652286,
    "indicator": "aasdtvcvchcvhhhhh.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050791,
    "indicator": "abogados-gs.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142843067,
    "indicator": "adventurergsdfjg.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050792,
    "indicator": "ahpc.gov.gh",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050793,
    "indicator": "aksdaitkatktk.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4168077449,
    "indicator": "almhdnursing.qa",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4168077450,
    "indicator": "alsokdalsdkals.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4150652294,
    "indicator": "appasdmdamsdmasd.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050794,
    "indicator": "asdaotasktjastmnt.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050795,
    "indicator": "atmospheredast.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4136818990,
    "indicator": "basketballast.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4037936569,
    "indicator": "bestiamos.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4042036091,
    "indicator": "bestieslos.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4136818993,
    "indicator": "blueprintsfdskjhfd.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4167929854,
    "indicator": "booksbypatriciaschultz.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4052515637,
    "indicator": "caprofklfkzttripwith.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050796,
    "indicator": "dasdalksdkmasdas.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4168077851,
    "indicator": "dasktiitititit.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4065174973,
    "indicator": "dasopdoaodoaoaoao.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4148281754,
    "indicator": "dhdjisksnsbhssu.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050797,
    "indicator": "dreamdraftingsydney.com.au",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050798,
    "indicator": "ecoawnings.com.au",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050799,
    "indicator": "erisaactuarialservices.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050800,
    "indicator": "fnotusykakimao.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4168078052,
    "indicator": "foflfalflafl.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4052515636,
    "indicator": "forfsakencoilddxga.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4079363987,
    "indicator": "fsdotiototakkaakkal.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4167930457,
    "indicator": "fsdtiototoitweot.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142843319,
    "indicator": "generationkasdm.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050801,
    "indicator": "gerab.bt",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4073832221,
    "indicator": "ikfsdfksldkflsktoq.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050802,
    "indicator": "ititoiaitoaitoiakkaka.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4148281756,
    "indicator": "jairecanoas.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4088785885,
    "indicator": "jdaklsjdklajsldkjd.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4049325391,
    "indicator": "kalkgmbzfghq.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050803,
    "indicator": "kdfmmikfkafjikmfikfjhm.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050804,
    "indicator": "kdkdaosdkalkdkdakd.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050805,
    "indicator": "ksaitkktkatfl.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4159138716,
    "indicator": "ksdkgsdkgkgmgm.pro",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4159179834,
    "indicator": "ksfldfklskdmbxcvb.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4127041069,
    "indicator": "lastmychancetoss.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4150652467,
    "indicator": "ldasldalsd.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 2288107485,
    "indicator": "location.host",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4118856972,
    "indicator": "losiposithankyou.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050806,
    "indicator": "makimakiokina.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050807,
    "indicator": "medi-care.gr",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050808,
    "indicator": "mexicaletta.com.br",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050809,
    "indicator": "newgenlosehops.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050810,
    "indicator": "nightlomsknies.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050811,
    "indicator": "notlimbobimboa.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050812,
    "indicator": "notmauserfizko.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4150652490,
    "indicator": "ototaikfffkf.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4056358076,
    "indicator": "ototoqtklktzlk.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050813,
    "indicator": "otpnemoyjfh.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4050246728,
    "indicator": "overtimeforus.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050814,
    "indicator": "pisikakimmmad.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4054638158,
    "indicator": "pptpooalfkakktl.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4044103536,
    "indicator": "pqoqllalll.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050815,
    "indicator": "pusykakimao.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142843917,
    "indicator": "remarkableaskf.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050816,
    "indicator": "scottvmorton.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4059767644,
    "indicator": "sdfikguoriqoir.cloud",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4049325392,
    "indicator": "serviceverifcaptcho.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050817,
    "indicator": "sfc-oman.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4168125831,
    "indicator": "skldfjgsldkmfgsdfg.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142844053,
    "indicator": "smallfootmyfor.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4168139033,
    "indicator": "soinpharmaceuticals.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050818,
    "indicator": "solpower.com.my",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050819,
    "indicator": "stangherlini.com.br",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4150652532,
    "indicator": "talentforth.org",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4049325393,
    "indicator": "tripallmaljok.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4042031828,
    "indicator": "undermymindops.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142844094,
    "indicator": "understandott.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4142844096,
    "indicator": "universitynsd.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050820,
    "indicator": "voluntarydasd.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 2207355729,
    "indicator": "wintars.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4150652666,
    "indicator": "xxclglglglklgkxlc.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4148281759,
    "indicator": "zmzkdodudhdbdu.com",
    "type": "domain",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4168088445,
    "indicator": "www.alwanqa.com",
    "type": "hostname",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050821,
    "indicator": "www.mitaxi.net",
    "type": "hostname",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4190050822,
    "indicator": "www.raftingsella.com",
    "type": "hostname",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  },
  {
    "id": 4168088451,
    "indicator": "www.webentangled.com",
    "type": "hostname",
    "created": "2026-01-30T07:41:37",
    "content": "",
    "title": "",
    "description": "",
    "expiration": null,
    "is_active": 1
  }
]