{"api":"v1","generated_at":"2026-09-15T23:40:45.128Z","licence":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/","attribution":"TOLL, with a link to the page cited"},"page":"https://tollindex.com/e/ot-intel-api-onrender-com-ot-malware-574aae","pinned_page":"https://tollindex.com/e/ot-intel-api-onrender-com-ot-malware-574aae/at/2026-09-15T21-20Z","pinned":false,"method":"https://tollindex.com/ledger/method","snapshot_at":"2026-09-15T21:20:12.737Z","snapshot_stamp":"2026-09-15T21-20Z","endpoint":{"slug":"ot-intel-api-onrender-com-ot-malware-574aae","canonical_url":"https://ot-intel-api.onrender.com/ot/malware","resource":"https://ot-intel-api.onrender.com/ot/malware","http_method":"GET","type":"http","x402_version":2,"registries":["cdp"],"primary_registry":"cdp","curated_by_coinbase":false,"description":"ICS malware encyclopedia. Pass ?name=PIPEDREAM. Returns capabilities, targeted OT protocols, attributed actor, affected vendors, detection signatures, and MITRE ATT&CK ICS techniques. Covers PIPEDREAM, TRITON, INDUSTROYER2, CRASHOVERRIDE, FROSTYLOOP, BLACKENERGY.","service_name":null,"declared_category":null,"declared_tags":[],"route_template":null,"registry_updated":"2026-09-11T23:53:33.687Z"},"derived":{"note":"fields no registry supplies; TOLL derives them and marks them derived on the page","title":"ot malware","category":"other","first_observed_by_toll":"2026-09-12T04:32:46.837Z","last_observed_by_toll":"2026-09-15T21:20:12.737Z","observation_began":"2026-09-10"},"presence":{"listed_now":true,"first_absent_at":null,"delisting_confirmed_at":null,"events":[{"registry":"cdp","at":"2026-09-12T04:32:46.838Z","event":"listed"}]},"accepts":[{"registry":"cdp","ordinal":0,"network":"eip155:8453","asset":"0x833589fcd6edb6e08f4c7c32d4f71b54bda02913","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.02 USDC","amount_units":0.02,"decimals_known":true,"pay_to":"0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B","scheme":"exact"}],"counters":{"observed_at":"2026-09-15T21:20:12.737Z","calls_30d":1,"unique_payers_30d":1,"last_called_at":"2026-09-11T23:53:33.285Z"},"validation":{"latest":{"observed_at":"2026-09-15T04:48:44.243Z","state":"pass","failed_checks":[],"endpoint_http_status":402,"run_id":"daily-2026-09-15"},"uptime":[{"days":7,"observed":5,"passed":5,"ratio":1},{"days":30,"observed":5,"passed":5,"ratio":1},{"days":90,"observed":5,"passed":5,"ratio":1}],"history_90d":[{"observed_at":"2026-09-15T04:48:44.243Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-15","state_changed":false},{"observed_at":"2026-09-14T04:44:00.185Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-14","state_changed":false},{"observed_at":"2026-09-13T04:41:42.476Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-13","state_changed":false},{"observed_at":"2026-09-12T06:58:31.739Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-12","state_changed":false},{"observed_at":"2026-09-12T05:25:36.471Z","state":"pass","failed_checks":[],"run_id":"new-2026-09-12T05-25-11-634Z","state_changed":true}]},"seller":{"wallet":"0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B","page":"https://tollindex.com/seller/0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B","endpoints":11,"hosts":1},"reports":0,"registry_record":{"cdp":[{"type":"http","accepts":[{"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"name":"USD Coin","version":"2"},"payTo":"0x1888192FAc6a69e4cd7d078eC4bCf6F24f7C767B","amount":"20000","scheme":"exact","network":"eip155:8453","maxTimeoutSeconds":300}],"quality":{"lastCalledAt":"2026-09-11T23:53:33.285Z","l30DaysTotalCalls":1,"l30DaysUniquePayers":1},"resource":"https://ot-intel-api.onrender.com/ot/malware","extensions":{"bazaar":{"info":{"input":{"type":"http","method":"GET","queryParams":{"name":"PIPEDREAM"}},"output":{"type":"json","example":{"name":"PIPEDREAM","aliases":["INCONTROLLER"],"confidence":"high","first_seen":"2022","capabilities":["discovery","lateral_movement","disruption","destruction"],"data_sources":["Dragos-Threat-Intelligence","OT-Intel-DB","MITRE-ATT&CK-ICS","DeepSeek-CTI-Analysis"],"affected_vendors":["Schneider Electric","OMRON"],"attributed_actor":"CHERNOVITE","mitre_techniques":["T0843","T0821","T0855"],"targeted_protocols":["Modbus","OPC UA","CODESYS","IEC 61850"],"detection_signatures":["YARA rule: PIPEDREAM_loader","Anomalous CODESYS write commands"]}}},"schema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["name"],"properties":{"name":{"type":"string","description":"Malware name e.g. PIPEDREAM, TRITON, INDUSTROYER2, CRASHOVERRIDE, FROSTYLOOP, BLACKENERGY"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}}}},"description":"ICS malware encyclopedia. Pass ?name=PIPEDREAM. Returns capabilities, targeted OT protocols, attributed actor, affected vendors, detection signatures, and MITRE ATT&CK ICS techniques. Covers PIPEDREAM, TRITON, INDUSTROYER2, CRASHOVERRIDE, FROSTYLOOP, BLACKENERGY.","lastUpdated":"2026-09-11T23:53:33.687Z","x402Version":2}]}}