{
  "Event": {
    "analysis": "1",
    "date": "2024-07-16",
    "extends_uuid": "",
    "info": "[Threat Intel] TAG-100 Uses Open-Source Tools in Suspected Global Espionage Campaign, Compromising Two Asia-Pacific Intergovernmental Bodies",
    "protected": false,
    "publish_timestamp": "1780042125",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780042125",
    "uuid": "3e513f64-7c35-4a0b-8f70-0ccfa4dfd5ff",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#bf83fd",
        "local": false,
        "name": "misp-galaxy:producer=\"Recorded Future\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:threat-actor=\"Storm-2077\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Pantegana\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"SparkRAT\"",
        "relationship_type": ""
      },
      {
        "colour": "#ff841f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"",
        "relationship_type": ""
      },
      {
        "colour": "#57997c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Bidirectional Communication - T1102.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Embedded Payloads - T1027.009\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Encrypted/Encoded File - T1027.013\"",
        "relationship_type": ""
      },
      {
        "colour": "#9feaf0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#91649a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Virtual Private Server - T1583.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Diplomacy\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Trade\"",
        "relationship_type": ""
      },
      {
        "colour": "#d53577",
        "local": false,
        "name": "misp-galaxy:target-information=\"Cambodia\"",
        "relationship_type": ""
      },
      {
        "colour": "#63db91",
        "local": false,
        "name": "misp-galaxy:target-information=\"Cuba\"",
        "relationship_type": ""
      },
      {
        "colour": "#57ece2",
        "local": false,
        "name": "misp-galaxy:target-information=\"Djibouti\"",
        "relationship_type": ""
      },
      {
        "colour": "#08ee7c",
        "local": false,
        "name": "misp-galaxy:target-information=\"Dominican Republic\"",
        "relationship_type": ""
      },
      {
        "colour": "#fabbd6",
        "local": false,
        "name": "misp-galaxy:target-information=\"Fiji\"",
        "relationship_type": ""
      },
      {
        "colour": "#15ccfd",
        "local": false,
        "name": "misp-galaxy:target-information=\"France\"",
        "relationship_type": ""
      },
      {
        "colour": "#f9cdc4",
        "local": false,
        "name": "misp-galaxy:target-information=\"Indonesia\"",
        "relationship_type": ""
      },
      {
        "colour": "#4cea11",
        "local": false,
        "name": "misp-galaxy:target-information=\"Italy\"",
        "relationship_type": ""
      },
      {
        "colour": "#5887a6",
        "local": false,
        "name": "misp-galaxy:target-information=\"Japan\"",
        "relationship_type": ""
      },
      {
        "colour": "#915448",
        "local": false,
        "name": "misp-galaxy:target-information=\"Malaysia\"",
        "relationship_type": ""
      },
      {
        "colour": "#48df7e",
        "local": false,
        "name": "misp-galaxy:target-information=\"Netherlands\"",
        "relationship_type": ""
      },
      {
        "colour": "#2613b0",
        "local": false,
        "name": "misp-galaxy:target-information=\"Taiwan\"",
        "relationship_type": ""
      },
      {
        "colour": "#ce59f1",
        "local": false,
        "name": "misp-galaxy:target-information=\"United Kingdom\"",
        "relationship_type": ""
      },
      {
        "colour": "#b8ab01",
        "local": false,
        "name": "misp-galaxy:target-information=\"United States\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b8479",
        "local": false,
        "name": "misp-galaxy:target-information=\"Vietnam\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003d",
        "local": false,
        "name": "rectifyq:sub-category=\"TA-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"APT\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#dd2e44",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#3a00dd",
        "local": false,
        "name": "rectifyq:action-taken=\"diamond-model\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875553",
        "to_ids": false,
        "type": "link",
        "uuid": "164e0dad-1e65-4c74-b232-010bd4779bff",
        "value": "https://www.recordedfuture.com/research/tag-100-uses-open-source-tools-in-suspected-global-espionage-campaign"
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042079",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "6c8a99ee-4197-4871-83c2-dcd189d62b6f",
        "value": "209.141.46.83",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042081",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "93b00b18-151f-48e9-8cf5-120fda0d00de",
        "value": "209.141.57.75",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042083",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "9f322c42-4aa4-4e81-ae6e-5a66e90a8662",
        "value": "205.185.126.208",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042084",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "0b058700-07f1-47f0-b233-7f35e21d3aec",
        "value": "38.54.115.34",
        "Tag": [
          {
            "colour": "#e7643a",
            "local": false,
            "name": "asn:asn=\"138915\"",
            "relationship_type": ""
          },
          {
            "colour": "#1ec497",
            "local": false,
            "name": "asn:as-owner=\"KAOPU-HK Kaopu Cloud HK Limited\"",
            "relationship_type": ""
          },
          {
            "colour": "#fbf8fb",
            "local": false,
            "name": "asn:as-country=\"HK\"",
            "relationship_type": ""
          },
          {
            "colour": "#daa28c",
            "local": false,
            "name": "misp-galaxy:country=\"hong kong\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042086",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "0d183ec5-fef7-4e2c-b861-bfeebc43fd4e",
        "value": "209.141.42.131",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042088",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "035f9ac5-5633-4ce2-937c-09ad8f10aee2",
        "value": "104.244.79.119",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042089",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "9c9940e5-0881-47c4-b2dd-22bd73322e15",
        "value": "207.246.108.119",
        "Tag": [
          {
            "colour": "#133012",
            "local": false,
            "name": "asn:asn=\"20473\"",
            "relationship_type": ""
          },
          {
            "colour": "#650025",
            "local": false,
            "name": "asn:as-owner=\"AS-VULTR\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042091",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "c5d7f8b2-2c02-480d-8aae-278ec35efb60",
        "value": "38.54.15.164",
        "Tag": [
          {
            "colour": "#e7643a",
            "local": false,
            "name": "asn:asn=\"138915\"",
            "relationship_type": ""
          },
          {
            "colour": "#1ec497",
            "local": false,
            "name": "asn:as-owner=\"KAOPU-HK Kaopu Cloud HK Limited\"",
            "relationship_type": ""
          },
          {
            "colour": "#fbf8fb",
            "local": false,
            "name": "asn:as-country=\"HK\"",
            "relationship_type": ""
          },
          {
            "colour": "#daa28c",
            "local": false,
            "name": "misp-galaxy:country=\"hong kong\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042092",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "ccdd2006-519b-48c7-9d5a-430bf72c9a92",
        "value": "198.98.49.41",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042094",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "16aa3dd9-1dc0-4b4d-9455-6fd5dab29750",
        "value": "209.141.50.215",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042095",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "a6ca63f0-fdf5-4b6b-8ada-1cbefa6135a8",
        "value": "205.185.127.12",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042097",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "497ca159-ef60-4d2e-ac47-9aeec4c47359",
        "value": "205.185.117.73",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042099",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "0cb6e94c-da18-46ab-8972-280e2eaadcbb",
        "value": "216.238.68.36",
        "Tag": [
          {
            "colour": "#133012",
            "local": false,
            "name": "asn:asn=\"20473\"",
            "relationship_type": ""
          },
          {
            "colour": "#650025",
            "local": false,
            "name": "asn:as-owner=\"AS-VULTR\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042101",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "daec0dd8-702d-49bb-9fc6-ba76adeffb24",
        "value": "209.141.37.217",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042105",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "b9c139ab-34e4-4f86-b5da-d1c28a1ac5e4",
        "value": "205.185.121.169",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042107",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "42f1c1d7-9884-4576-b345-e0c0055b820d",
        "value": "144.202.125.201",
        "Tag": [
          {
            "colour": "#133012",
            "local": false,
            "name": "asn:asn=\"20473\"",
            "relationship_type": ""
          },
          {
            "colour": "#650025",
            "local": false,
            "name": "asn:as-owner=\"AS-VULTR\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 C2 Infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042109",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "5161f152-8932-49ff-a788-9c798a60fc72",
        "value": "173.254.229.93",
        "Tag": [
          {
            "colour": "#363e5c",
            "local": false,
            "name": "asn:asn=\"203020\"",
            "relationship_type": ""
          },
          {
            "colour": "#91da63",
            "local": false,
            "name": "asn:as-owner=\"HOSTROYALE\"",
            "relationship_type": ""
          },
          {
            "colour": "#8569b9",
            "local": false,
            "name": "asn:as-country=\"IN\"",
            "relationship_type": ""
          },
          {
            "colour": "#5b5fae",
            "local": false,
            "name": "misp-galaxy:country=\"india\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 Exploitation Servers",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042110",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "be3ee85d-7be7-4511-9ce5-c971a224ff2c",
        "value": "205.185.122.35",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 Exploitation Servers",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780042125",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "03bf7171-a1b6-4ea3-bdb9-824cdacd2e70",
        "value": "209.141.47.6",
        "Tag": [
          {
            "colour": "#075f7f",
            "local": false,
            "name": "asn:asn=\"53667\"",
            "relationship_type": ""
          },
          {
            "colour": "#ae50d2",
            "local": false,
            "name": "asn:as-owner=\"PONYNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "TAG-100 Cobalt Strike C2 Domain",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875758",
        "to_ids": true,
        "type": "hostname",
        "uuid": "1a0e879e-cbe5-4040-b92a-2b58969f4ad6",
        "value": "www.megtech.xyz"
      },
      {
        "category": "Payload delivery",
        "comment": "Pantegana Self-signed TLS Certificate Fingerprint",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875758",
        "to_ids": true,
        "type": "x509-fingerprint-sha256",
        "uuid": "5c5635ea-990f-4499-b08a-8e11853057d6",
        "value": "9b6bc9e7ed924900e5dfb8df2ac0916fbe6913a7717c341152f5c17ae017278c"
      },
      {
        "category": "Payload delivery",
        "comment": "Cobalt Strike",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875758",
        "to_ids": true,
        "type": "sha256",
        "uuid": "9c80b1f6-08db-4171-866e-ca09f8386442",
        "value": "e3aab908800cb4601bc4a87ac9ac48d816ced57cdb409b6e2468956cc50bdf04"
      },
      {
        "category": "Payload delivery",
        "comment": "Cobalt Strike",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875758",
        "to_ids": true,
        "type": "sha256",
        "uuid": "3c1171b8-c707-40d7-8a08-65befa808385",
        "value": "8eb3617768ce4693b726bb8187e5cccea3359de0196d6f2bbe555c31f12d1234"
      },
      {
        "category": "Payload delivery",
        "comment": "SparkRAT/LESLIELOADER",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875758",
        "to_ids": true,
        "type": "sha256",
        "uuid": "b1278e87-460d-4319-966b-176148c5d07f",
        "value": "23efecc03506a9428175546a4b7d40c8a943c252110e83dec132c6a5db8c4dd6"
      },
      {
        "category": "Payload delivery",
        "comment": "SparkRAT/LESLIELOADER",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875758",
        "to_ids": true,
        "type": "sha256",
        "uuid": "9241d28b-5a8b-4d94-85ff-19e0e4c986af",
        "value": "ec45da0ca70a9b71652cc95d51665f7ad568294bd5652c395a119bccd613e9b4"
      },
      {
        "category": "Payload delivery",
        "comment": "SparkRAT/LESLIELOADER",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875758",
        "to_ids": true,
        "type": "sha256",
        "uuid": "68a8b590-ade1-42fb-963e-20c8b8029230",
        "value": "b8cab11421eb4731c16cf3c34ca2b3f2a758d5e112f877b90a18b3e146c8add0"
      },
      {
        "category": "Other",
        "comment": "diamond-model",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875944",
        "to_ids": false,
        "type": "comment",
        "uuid": "6c5850c4-8ae2-470c-a14f-ab41b3d374d4",
        "value": "https://raw.githubusercontent.com/rectifyq/Collections/refs/heads/main/Diamond-Models/2024/240716-TAG-100/46.png"
      },
      {
        "category": "Other",
        "comment": "diamond-model",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875944",
        "to_ids": false,
        "type": "comment",
        "uuid": "3ec381dc-c4e5-4aad-a627-f7c576538042",
        "value": "https://raw.githubusercontent.com/rectifyq/Collections/refs/heads/main/Diamond-Models/2024/240716-TAG-100/47.png"
      },
      {
        "category": "Other",
        "comment": "diamond-model",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1770875944",
        "to_ids": false,
        "type": "comment",
        "uuid": "9ca74669-f328-4a6e-ac60-6c951b329770",
        "value": "https://raw.githubusercontent.com/rectifyq/Collections/refs/heads/main/Diamond-Models/2024/240716-TAG-100/48.png"
      }
    ]
  }
}