{
  "Event": {
    "analysis": "2",
    "date": "2015-05-14",
    "extends_uuid": "",
    "info": "[Threat Intel] The Naikon APT",
    "protected": false,
    "publish_timestamp": "1780039799",
    "published": true,
    "threat_level_id": "1",
    "timestamp": "1772901974",
    "uuid": "55e34dbc-1e1c-48f7-b63d-68e857eaa3c0",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#1ebce4",
        "local": false,
        "name": "misp-galaxy:producer=\"Kaspersky\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:threat-actor=\"Naikon\"",
        "relationship_type": ""
      },
      {
        "colour": "#d53577",
        "local": false,
        "name": "misp-galaxy:target-information=\"Cambodia\"",
        "relationship_type": ""
      },
      {
        "colour": "#52d590",
        "local": false,
        "name": "misp-galaxy:target-information=\"China\"",
        "relationship_type": ""
      },
      {
        "colour": "#f9cdc4",
        "local": false,
        "name": "misp-galaxy:target-information=\"Indonesia\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:target-information=\"Laos\"",
        "relationship_type": ""
      },
      {
        "colour": "#915448",
        "local": false,
        "name": "misp-galaxy:target-information=\"Malaysia\"",
        "relationship_type": ""
      },
      {
        "colour": "#b03f2c",
        "local": false,
        "name": "misp-galaxy:target-information=\"Myanmar\"",
        "relationship_type": ""
      },
      {
        "colour": "#ff41c1",
        "local": false,
        "name": "misp-galaxy:target-information=\"Nepal\"",
        "relationship_type": ""
      },
      {
        "colour": "#fa487c",
        "local": false,
        "name": "misp-galaxy:target-information=\"Philippines\"",
        "relationship_type": ""
      },
      {
        "colour": "#7dbb86",
        "local": false,
        "name": "misp-galaxy:target-information=\"Singapore\"",
        "relationship_type": ""
      },
      {
        "colour": "#33360c",
        "local": false,
        "name": "misp-galaxy:target-information=\"Thailand\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b8479",
        "local": false,
        "name": "misp-galaxy:target-information=\"Vietnam\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Civil society\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Government, Administration\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Military\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003d",
        "local": false,
        "name": "rectifyq:sub-category=\"TA-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#d92121",
        "local": false,
        "name": "rectifyq:target=\"targeted\"",
        "relationship_type": ""
      },
      {
        "colour": "#dd2e44",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1740365899",
        "to_ids": false,
        "type": "link",
        "uuid": "5da8aac4-3261-4670-b5a1-0380f870ee42",
        "value": "https://securelist.com/the-naikon-apt/69953/"
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:08/03/2025",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741389512",
        "to_ids": true,
        "type": "md5",
        "uuid": "16983a3e-e6bf-4d7a-b39b-60001923f191",
        "value": "b4a8dc9eb26e727eafb6c8477963829c",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:08/03/2025",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741389533",
        "to_ids": true,
        "type": "md5",
        "uuid": "e1f83027-1d7f-484b-ab17-ce2aad7b13a4",
        "value": "172fd9cce78de38d8cbcad605e3d6675",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:08/03/2025",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741389554",
        "to_ids": true,
        "type": "md5",
        "uuid": "6e8222de-1b47-4bbf-9ed4-05b6f459175b",
        "value": "d74a7e7a4de0da503472f1f051b68745",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:08/03/2025",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741389575",
        "to_ids": true,
        "type": "md5",
        "uuid": "2e30c701-764d-4df8-bfc4-1232549bb9c7",
        "value": "93e84075bef7a11832d9c5aa70135dc6",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398446",
        "to_ids": true,
        "type": "hostname",
        "uuid": "cdec5c33-d416-4b6f-a8e6-8500d4a200ce",
        "value": "linda.googlenow.in",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398467",
        "to_ids": true,
        "type": "hostname",
        "uuid": "a02c4c10-be87-4e1c-94b1-4140f7ce6703",
        "value": "admin0805.gnway.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398488",
        "to_ids": true,
        "type": "hostname",
        "uuid": "3cd84d05-22ca-4c90-8a78-27846fa7ea59",
        "value": "free.googlenow.in",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398509",
        "to_ids": true,
        "type": "hostname",
        "uuid": "8238ba93-81a4-4352-8a21-f10f73b38ac3",
        "value": "frankhere.oicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398530",
        "to_ids": true,
        "type": "hostname",
        "uuid": "4347625e-4f03-4518-bc02-15158fb5f9ed",
        "value": "telcom.dhtu.info",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398551",
        "to_ids": true,
        "type": "hostname",
        "uuid": "fe4e9166-9dd6-4618-9df9-27f4cbdc851d",
        "value": "laotel08.vicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398572",
        "to_ids": true,
        "type": "hostname",
        "uuid": "f19edf58-f025-4191-9f03-fab47bbd1c29",
        "value": "greensky27.vicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398594",
        "to_ids": true,
        "type": "hostname",
        "uuid": "f1e889da-b8ba-45ed-abc0-5572cb0be6df",
        "value": "googlemm.vicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398615",
        "to_ids": true,
        "type": "hostname",
        "uuid": "97065e47-67e9-4835-9956-36ba5d98b7b1",
        "value": "peacesyou.imwork.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398637",
        "to_ids": true,
        "type": "hostname",
        "uuid": "743a8296-98a4-42cd-baac-4bbf77a5b8e8",
        "value": "sayakyaw.xicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398658",
        "to_ids": true,
        "type": "hostname",
        "uuid": "4dce02a5-f9fc-435d-8a57-df33db63e217",
        "value": "ubaoyouxiang.gicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398679",
        "to_ids": true,
        "type": "hostname",
        "uuid": "f5b4e11a-5429-4be1-ab6d-e7b23217df47",
        "value": "htkg009.gicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398700",
        "to_ids": true,
        "type": "hostname",
        "uuid": "fd3e3175-3e99-43c7-b889-ba0dafb68ea2",
        "value": "kyawthumyin.xicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398721",
        "to_ids": true,
        "type": "hostname",
        "uuid": "237369c4-d791-4808-bfed-7902b4f17ff7",
        "value": "myanmartech.vicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398747",
        "to_ids": true,
        "type": "hostname",
        "uuid": "031f61a5-112a-4fd7-9527-ed152a75f471",
        "value": "test-user123.vicp.cc",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398768",
        "to_ids": true,
        "type": "hostname",
        "uuid": "982c8af6-2c36-4b53-ac5e-af95c0c7845e",
        "value": "us.googlereader.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398790",
        "to_ids": true,
        "type": "hostname",
        "uuid": "bbf522dd-3f73-4aa8-a2ee-397e6565a16d",
        "value": "net.googlereader.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398811",
        "to_ids": true,
        "type": "hostname",
        "uuid": "2b920dda-9117-46aa-ab47-db9a964c50a2",
        "value": "lovethai.vicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398832",
        "to_ids": true,
        "type": "hostname",
        "uuid": "5b3762ee-f3df-4b81-876a-2f3c801609a9",
        "value": "yahoo.goodns.in",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398853",
        "to_ids": true,
        "type": "hostname",
        "uuid": "0ff2ca17-1e90-48b2-aa1c-7d70f01fa750",
        "value": "xl.findmy.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398874",
        "to_ids": true,
        "type": "hostname",
        "uuid": "fbc2c03b-83c7-4188-ac99-a8cb4de02f94",
        "value": "xl.kevins.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398895",
        "to_ids": true,
        "type": "hostname",
        "uuid": "912a62d1-901b-4e3d-b339-e0ba8860acc8",
        "value": "oraydns.googlesec.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398916",
        "to_ids": true,
        "type": "hostname",
        "uuid": "33e16507-29ea-4d52-973e-ebe4ae660485",
        "value": "gov.yahoomail.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398938",
        "to_ids": true,
        "type": "hostname",
        "uuid": "1d42abd0-94fc-4c81-883f-cb2801640d8f",
        "value": "pp.googledata.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398959",
        "to_ids": true,
        "type": "hostname",
        "uuid": "0d73665e-cdd2-47e3-a749-e92f5fbe83fe",
        "value": "mlfjcjssl.gicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741398980",
        "to_ids": true,
        "type": "hostname",
        "uuid": "ccd487af-96f8-46de-9959-bf00c371223b",
        "value": "o.wm.ggpw.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399001",
        "to_ids": true,
        "type": "hostname",
        "uuid": "5c70efe2-0936-4afa-bfaf-d35aab43990f",
        "value": "oooppp.findmy.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399022",
        "to_ids": true,
        "type": "hostname",
        "uuid": "69162291-bb8e-4b84-8f78-a494497df7ac",
        "value": "cipta.kevins.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399043",
        "to_ids": true,
        "type": "hostname",
        "uuid": "e68cf77b-137f-442b-9b7c-3cf438ffd4d4",
        "value": "phi.yahoomail.pw",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399064",
        "to_ids": true,
        "type": "hostname",
        "uuid": "31e64684-fefe-45d5-9736-6a3836f2d0eb",
        "value": "dd.googleoffice.in",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399086",
        "to_ids": true,
        "type": "hostname",
        "uuid": "179ef785-5247-4431-816f-c9bd1bb71231",
        "value": "moziliafirefox.wicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399108",
        "to_ids": true,
        "type": "hostname",
        "uuid": "92b25128-8de0-4653-a33b-d990bf4dc8d5",
        "value": "bkav.imshop.in",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399129",
        "to_ids": true,
        "type": "hostname",
        "uuid": "5f6fc4cb-db95-482e-8c57-048f4026f1cb",
        "value": "baomoi.coyo.eu",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399151",
        "to_ids": true,
        "type": "hostname",
        "uuid": "7439bacf-f53c-4768-a1ad-01c87aa00fd0",
        "value": "macstore.vicp.cc",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399172",
        "to_ids": true,
        "type": "hostname",
        "uuid": "2c7c5e08-6caa-4130-8e65-55d982331c05",
        "value": "downloadwindows.imwork.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399193",
        "to_ids": true,
        "type": "hostname",
        "uuid": "ec391cd4-d608-450e-95aa-c83a59a7b630",
        "value": "vietkey.xicp.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399215",
        "to_ids": true,
        "type": "hostname",
        "uuid": "51edebe6-ea74-4fd0-b2a8-8f61ea2ae227",
        "value": "baomoi.vicp.cc",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399237",
        "to_ids": true,
        "type": "hostname",
        "uuid": "cd5935bf-321d-4013-b97b-c3f2751ee200",
        "value": "downloadwindow.imwork.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399258",
        "to_ids": true,
        "type": "hostname",
        "uuid": "3e1870f5-5766-4ba7-826d-2ef4a0d44c62",
        "value": "www.ttxvn.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1741399279",
        "to_ids": true,
        "type": "hostname",
        "uuid": "54b8b9f1-e76d-45e2-8e15-dcd4fbf4b45f",
        "value": "vietlex.gnway.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1741399300",
        "uuid": "5011eb2f-28ff-429c-8872-572a748a182b",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1741399300",
            "to_ids": true,
            "type": "md5",
            "uuid": "2e46fdc2-a15d-421b-b2b9-7aa7a4f9383b",
            "value": "d085ba82824c1e61e93e113a705b8e9a",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1741389471",
            "to_ids": true,
            "type": "sha1",
            "uuid": "aaad896f-2614-4530-9766-a129633117a6",
            "value": "b6c4ef1273eac860a6e16a9b60f78b6bfcf13b9d",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1741389471",
            "to_ids": true,
            "type": "sha256",
            "uuid": "62bec155-7de7-4720-a2cd-dc661d4b210c",
            "value": "09412575bceda6923f01d029a25536750e9feaa4130d4f91f6a372c554168737",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1741389470",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "abd363b0-c42a-4f74-8d3c-6a10e5fc62b7",
            "value": "3072:Gb0Kv3+UooJz3jX4Im/h9dSIV7/jVvH5:Gbh3+6Jz3jX4P/DwIVVv"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1741389470",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "229dd4b1-e56e-47a6-85e6-663229d77925",
            "value": "118272"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1741389470",
            "to_ids": true,
            "type": "vhash",
            "uuid": "cc39ef90-6ae9-4b19-83c9-0facb409abe9",
            "value": "115056655d15555168z6f1z13z11z43z32z111za1z56z1"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1741389470",
            "to_ids": true,
            "type": "filename",
            "uuid": "fd5455f0-8d18-401f-af55-5436bc440b00",
            "value": "d085ba82824c1e61e93e113a705b8e9a.bender.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 08/03/2025\nLast-scan\t:  17/02/2025",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1741389470",
            "to_ids": false,
            "type": "text",
            "uuid": "befe0a7f-7da9-4bae-b541-ef426b74c373",
            "value": "Type Description: Win32 DLL\n\nMicrosoft: Trojan:Win32/Tiggre!rfn\nVT Total Detection:55/72"
          }
        ]
      }
    ]
  }
}