jsonify-logo-light Designer: Matt Farley Open in Jsonify

Real-Time Threat Intelligence

Access real-time threat intelligence and IOC insights — automated data collection from deep and dark web sources.

A saved example of what you can collect and monitor with Jsonify. Create your own version in Jsonify.

Build this in JsonifyYour original goal is prefilled.

Goal

I want to get real-time, comprehensive threat intelligence data, including indicators of compromise (IOCs), exploit details, and dark web discussions mentioning third-party vendors, from deep and dark web forums, threat intelligence platforms, and security vulnerability databases.

Source coverage

Sample data

Illustrative sample data from the original configuration, not live or verified results.

idSourceIOCTypeThreatConfidenceFirst SeenLast SeenContextSeverity
1virustotal.com7d0f3a1b9c2f4d5e6a7b8c9d0e1f2a3bFile Hash (SHA256)StealthRAT v2.3 payloadHigh2026-02-02T09:14:22Z2026-02-03T18:45:10ZSubmitted sample with C2 domain 'login-secure[.]zone' and obfuscated strings; matching YARA rule setsCritical
2shodan.io185.62.12.45:6379IP:PortOpen Redis instance exposing credentialsMedium2026-02-01T04:05:00Z2026-02-04T07:12:33ZIndexed banner shows unauthenticated Redis with large keyspace; potential data exfiltration riskHigh
3censys.io2001:0db8:85a3:0000:0000:8a2e:0370:7334IPv6 AddressMisconfigured Elasticsearch cluster fingerprintHigh2026-02-03T11:22:10Z2026-02-04T02:01:48ZCensys banner reveals Elasticsearch 6.x publicly accessible with no authCritical
4recordedfuture.comAPT28 discussion: new loader 'BlackFjord'Threat Actor / ToolBlackFjord loader linked to credential theft campaignsHigh2026-01-30T14:00:00Z2026-02-03T20:30:00ZIntel report correlates malware telemetry with actor infrastructure and GitHub leak referencesHigh
5darkowl.comforum post: 'sell: corp creds, 10k records'Dark Web PostStolen corporate credentials advertisedMedium2026-02-02T22:18:05Z2026-02-04T01:12:44ZPost includes domain list and sample validation screenshots referencing third-party vendor domainsHigh
6reversinglabs.comb4f2e3a9c6d7e8f0a1b2c3d4e5f60718File Hash (SHA256)Obfuscated .NET dropperHigh2026-02-01T16:40:00Z2026-02-03T09:55:12ZStatic analysis shows multiple unpacking stages and suspicious API calls to Windows Credential ManagerHigh
7misp-project.orgmalware:invoice-themed macro campaignCampaign DescriptionMacro-based ransomware distribution via supplier invoicesMedium2026-01-31T08:30:00Z2026-02-03T19:05:00ZMISP event collates sightings, notable C2 'pay-portal[.]top' and email subject patternsCritical
8threatcrowd.orgmalicious[.]vendor-sync[.]comDomainPhishing domain impersonating vendor portalHigh2026-02-02T05:46:12Z2026-02-04T06:50:23ZMultiple IP resolves and WHOIS privacy; linked to previously observed phishing kitHigh
9intel471.comuser: 'vendor-leak' thread mentioning 'AcmePay' breachDark Web DiscussionSale of AcmePay vendor datasetMedium2026-02-03T13:05:00Z2026-02-04T10:20:00ZClosed forum chatter with screenshots and partial CSV samples sold to biddersHigh
10securitytrails.comapi.thirdpartyvendor.comSubdomainExposed API endpoint with verbose error responsesHigh2026-02-02T12:00:00Z2026-02-04T04:15:16ZDNS history and current TXT records show outdated keys and stale certificatesMedium
11malwarebytes.comcybercriminal blog: 'how to use XLoader'Blog/ArticleTutorial enabling commodity malware usageMedium2026-02-01T07:10:00Z2026-02-04T03:40:22ZDetailed walkthrough detected; leads to compiled binaries hosted on file-sharing sitesMedium
12virustotal.com3a9d1c5f8b7e4a2d6c0b1f3e5a8d9c7bFile Hash (SHA256)Encrypted ransomware sample (Sodin-Remnant family)High2026-02-02T21:33:19Z2026-02-04T08:22:01ZMatches IOCs from MISP and shows unique ransom note marker 'REMMED2026'Critical
13threatcrowd.org45.76.89.12IPv4 AddressBotnet C2 serverHigh2026-02-01T02:00:00Z2026-02-03T23:59:59ZAssociated with multiple malicious domains and fast-flux patternHigh
14reversinglabs.comdropped_config.json (contains 'api_key':'ak_live_XXXXX')ArtifactHardcoded API keys in malware configurationHigh2026-02-02T10:15:00Z2026-02-04T02:47:30ZConfiguration extracted from unpacked binary; references cloud storage and vendor API endpointsCritical
15recordedfuture.comexploit: CVE-2025-4678 PoC circulatingVulnerability / ExploitUnauthenticated RCE in popular third-party payment gatewayHigh2026-02-02T06:00:00Z2026-02-04T09:30:00ZPoC code appears in GitHub gist and dark web threads; exploit targets /api/v2/pay endpointCritical
16darkowl.comseller listing: 'VPN access to vendor corp'Dark Web Marketplace ListingVPN session cookies and remote access for saleMedium2026-02-03T15:40:00Z2026-02-04T11:05:59ZListing includes screenshots of internal dashboards and vendor brandingHigh
17intel471.comemail sample: 'invoice@thirdvendor.com' with malicious ZIPMalicious Email SampleInvoice-themed phishing with loader attachmentHigh2026-02-01T09:00:00Z2026-02-04T05:55:12ZHeaders show SPF pass but DKIM fail; attachment executes macro dropperCritical
18securitytrails.commx.thirdpartyvendor.comMX Record / Mail ServerMail server with outdated TLS and open relay misconfigMedium2026-02-02T18:30:00Z2026-02-04T01:22:33ZCertificate expired last week and server responds to unauthenticated relays in testsHigh
19threatcrowd.orgwordpress-plugin: 'vendor-wp-pay' outdatedSoftware ComponentKnown vulnerable WordPress plugin enabling SQLiHigh2026-01-31T11:20:00Z2026-02-03T16:44:01ZExploit chains observed leveraging plugin to upload web shellsCritical
20virustotal.com5f6e7d8c9b0a1b2c3d4e5f6a7b8c9d0eFile Hash (SHA256)Firmware backdoor sample for IoT devicesMedium2026-02-02T13:50:00Z2026-02-04T06:10:05ZMatches suspicious strings communicating to vendor-update[.]io domainHigh
21reversinglabs.comPE: imports CreateRemoteThread, VirtualAllocExBinary Analysis IndicatorProcess injection capability in downloaderHigh2026-02-01T20:05:00Z2026-02-04T00:00:00ZDynamic behavior shows DLL sideloading and persistence via scheduled tasksHigh
22malwarebytes.comblog: 'supply-chain compromise trends 2026'Threat ReportIncreased outsourcing risk and vendor credential leaksMedium2026-02-01T10:00:00Z2026-02-04T02:30:00ZArticle references multiple recent incidents and mitigations for vendor access controlsMedium
23darkowl.commarketplace: 'access: vendor-erp' priced 2 BTCDark Web ListingRDP/SSH access to ERP environments for saleMedium2026-02-03T21:10:00Z2026-02-04T08:00:00ZListing claims persistent admin-level sessions and includes last-login screenshotsCritical
24recordedfuture.commalicious-injection: JS snippet 'trackVendor()' used in Mage Commerce sitesMalicious ScriptMageCommerce skimmer targeting checkout formsHigh2026-02-02T09:00:00Z2026-02-04T07:45:00ZRecorded Future detected propagation across multiple third-party extensionsCritical
25misp-project.orgIOC set: domains, hashes, and mutex names for 'BlueTango' campaignMISP Event BundleCoordinated espionage campaign targeting vendors in logistics sectorHigh2026-01-30T06:00:00Z2026-02-03T21:00:00ZEvent aggregates sightings from community analysts and correlates to C2 infraHigh
26threatcrowd.orgcdn.badfileshare[.]net/path/payroll.zipMalicious URLMalicious archive hosting credential harvestersHigh2026-02-02T14:12:00Z2026-02-04T03:18:45ZURL serves password-stealing binary disguised as payroll updateCritical
27intel471.compaste: 'vendor-db leak' posted with sample rowsPaste/DumpPartial vendor customer database leakMedium2026-02-03T02:22:00Z2026-02-04T09:02:14ZPaste contains hashed passwords and PII snippets; sellers reference negotiation threadsHigh
28securitytrails.comtls: expired cert for api.vendor-payments.comCertificate / TLS IndicatorExpired TLS leading to potential MITM and phishing riskHigh2026-02-01T00:00:00Z2026-02-04T06:06:06ZCertificate expired within last 3 days; chain shows weak signature algorithmMedium
29darkowl.comforum thread: 'zero-day PoC for vendor gateway'Dark Web DiscussionPrivate exploit discussion and pricing for zero-day accessLow2026-02-03T19:45:00Z2026-02-04T02:50:00ZThread requests testers; no verified PoC shared publicly yetHigh

Insights and analytics

Change notifications

Integrations and delivery

Make this your own

Start with this goal in Jsonify, then choose the sources and data you need.

Build this in Jsonify