{
  "Event": {
    "analysis": "1",
    "date": "2026-05-19",
    "extends_uuid": "",
    "info": "[Threat Intel] Inside Banana RAT: From Build Server to Banking Fraud",
    "protected": false,
    "publish_timestamp": "1780138998",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1780138997",
    "uuid": "0b84e4bb-274b-4d06-a180-f52c8b474e6d",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#717bc3",
        "local": false,
        "name": "misp-galaxy:producer=\"Trend Micro\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#705cef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#8ee8d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"",
        "relationship_type": ""
      },
      {
        "colour": "#72ee33",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#47d9d3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#56c932",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Symmetric Cryptography - T1573.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#9dc839",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Clipboard Data - T1115\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#62e1b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Browser Session Hijacking - T1185\"",
        "relationship_type": ""
      },
      {
        "colour": "#bf01b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#755c09",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b95cd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"",
        "relationship_type": ""
      },
      {
        "colour": "#cc5e96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Obfuscation - T1001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#44b2c2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Hidden Files and Directories - T1564.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#c94db5",
        "local": false,
        "name": "misp-galaxy:target-information=\"Brazil\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#110041",
        "local": false,
        "name": "rectifyq:sub-category=\"malware-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#31373d",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"not-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779332411",
        "to_ids": false,
        "type": "link",
        "uuid": "a5c073c4-2d5e-4859-828f-17f28cb647fe",
        "value": "https://www.trendmicro.com/en_us/research/26/e/banana-rat.html"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779332411",
        "to_ids": false,
        "type": "text",
        "uuid": "16b4e73f-98ec-4f1b-9649-e0d18381ac28",
        "value": "An MDR investigation successfully mapped the complete operational infrastructure of Banana RAT, a Brazilian banking trojan operated by threat cluster SHADOW-WATER-063. The investigation uncovered both server-side and client-side components, revealing a sophisticated FastAPI-based polymorphic payload generation system that produces hash-unique builds to evade detection. The malware employs layered obfuscation, AES-wrapped payloads, and fileless PowerShell execution. Once deployed, it enables operator-driven fraud through remote input control, keylogging, screen streaming, bank-branded overlays, and Pix QR code interception specifically targeting Brazilian financial institutions. The tooling exclusively targets 16 Brazilian banks and crypto exchanges, with all operator artifacts written in Brazilian Portuguese, indicating a financially motivated actor operating within the Tetrade banking trojan ecosystem."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779332411",
        "to_ids": false,
        "type": "text",
        "uuid": "f66477e4-c879-45cf-8160-b2c39a9941fc",
        "value": "Name: Inside Banana RAT: From Build Server to Banking Fraud\nAuthor: AlienVault\nAdversary: SHADOW-WATER-063\nTags: [\"fastapi\", \"pix qr interception\", \"mekotio\", \"grandoreiro\", \"brazilian banking trojan\", \"guildma\", \"tetrade\", \"powershell\", \"financial fraud\", \"casbaneiro\", \"banana rat\", \"chavecloak\", \"polymorphic payload\"]\nTgtd countries: [\"Brazil\"]\nMlwr families: [\"Banana RAT\", \"Grandoreiro - S0531\", \"Mekotio\", \"Metamorfo - S0455\", \"Casbaneiro\", \"Astaroth - S0373\", \"Guildma\", \"CHAVECLOAK\"]\nAttack_ids: [\"T1053.005\", \"T1113\", \"T1056.001\", \"T1036.005\", \"T1204.002\", \"T1573.001\", \"T1115\", \"T1082\", \"T1140\", \"T1055\", \"T1185\", \"T1112\", \"T1083\", \"T1041\", \"T1059.001\", \"T1566\", \"T1001\", \"T1027\", \"T1071.001\", \"T1564.001\"]\nIndustries: [\"Finance\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780125163",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "e84b5117-6989-4f8d-b14d-31c21176be17",
        "value": "SHADOW-WATER-063",
        "Tag": [
          {
            "colour": "#717bc3",
            "local": false,
            "name": "misp-galaxy:producer=\"Trend Micro\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135660",
        "to_ids": true,
        "type": "domain",
        "uuid": "973c0fd8-5f13-4a74-822e-6d90cf4c39bc",
        "value": "windowsk-cdn.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C&C server",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135681",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "7774eb12-64fe-460d-a035-f9677122a780",
        "value": "162.141.111.227",
        "Tag": [
          {
            "colour": "#33e79a",
            "local": false,
            "name": "asn:asn=\"272547\"",
            "relationship_type": ""
          },
          {
            "colour": "#8dc405",
            "local": false,
            "name": "asn:as-owner=\"Servicos de Infraestrutura e Datacenter\"",
            "relationship_type": ""
          },
          {
            "colour": "#178852",
            "local": false,
            "name": "asn:as-country=\"BR\"",
            "relationship_type": ""
          },
          {
            "colour": "#d46af0",
            "local": false,
            "name": "misp-galaxy:country=\"brazil\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C&C server",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135702",
        "to_ids": true,
        "type": "hostname",
        "uuid": "dc9a3b82-1826-40d8-9679-2e75f6a4218b",
        "value": "c.windowsk-cdn.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:30/05/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780131018",
        "to_ids": true,
        "type": "sha256",
        "uuid": "aca5b7e6-1a26-4301-8f6b-6b18ec39b828",
        "value": "4912b1134e69ade7266e8508eec33ccb2d80ad693f1dbc4f1f4344c6dfcf2ff1",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:30/05/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780131019",
        "to_ids": true,
        "type": "sha256",
        "uuid": "c2b93a78-631e-4dca-8168-689c2ca7f790",
        "value": "ecdc8fade561a75d68235859ad8b1fe131db2c458b4894268e38e90ecab1c47f",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135723",
        "to_ids": true,
        "type": "url",
        "uuid": "7066664e-7831-4ffc-b8ad-b2b59077f10b",
        "value": "http://24.199.90.58/payload.php",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135744",
        "to_ids": true,
        "type": "url",
        "uuid": "b8c2a1c3-deb7-4d58-b973-21ac00c1eae4",
        "value": "http://24.199.90.58:80/payload.php",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135765",
        "to_ids": true,
        "type": "url",
        "uuid": "a96b7953-cd2f-4591-9444-3963e13f4dd7",
        "value": "https://convitemundial2026.com/Consultar_NF-e.bat",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135786",
        "to_ids": true,
        "type": "domain",
        "uuid": "d0fb0fba-e7e7-4d14-b292-07d233f4484a",
        "value": "convitemundial2026.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780125190",
        "to_ids": false,
        "type": "malware-type",
        "uuid": "e4670c37-4894-4f23-86ff-94a0c062b0ad",
        "value": "Banana RAT"
      },
      {
        "category": "Network activity",
        "comment": "Disease vector",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135807",
        "to_ids": true,
        "type": "url",
        "uuid": "bc804098-7902-4e4c-8224-2a4473ba02fa",
        "value": "http://24.199.90.58:80/",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Disease vector",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135828",
        "to_ids": true,
        "type": "url",
        "uuid": "d2d17a74-1ad0-490d-831b-79cfd6024c61",
        "value": "http://24.199.90.58:80/st.txt",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C&C server",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780125311",
        "to_ids": true,
        "type": "ip-dst|port",
        "uuid": "2e5bc10c-0bd1-4a1c-9c77-bca5860464a4",
        "value": "162.141.111.227|443"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135849",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "d219e6a9-80c6-45aa-91a4-231faf4f94f0",
        "value": "24.199.90.58",
        "Tag": [
          {
            "colour": "#c2074e",
            "local": false,
            "name": "asn:asn=\"14061\"",
            "relationship_type": ""
          },
          {
            "colour": "#d7952a",
            "local": false,
            "name": "asn:as-owner=\"DIGITALOCEAN-ASN\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780135870",
        "uuid": "612b0b04-4bfe-421a-acd5-80aa526b4ad7",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780135870",
            "to_ids": true,
            "type": "md5",
            "uuid": "47e769cb-023a-4e3e-98f0-cd4467a18519",
            "value": "6adbc7032c1f2f8e4688fbec2d0be4f5",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780131016",
            "to_ids": true,
            "type": "sha1",
            "uuid": "cb996cd3-f99a-4985-b611-8499b6606895",
            "value": "f428b0d2d2dc2ec320a1ced1254a03d8bd09325f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780131016",
            "to_ids": true,
            "type": "sha256",
            "uuid": "f9bc47d7-0da4-460a-9495-42b37d9822d2",
            "value": "38dfeb772afbd01c04eddda120d283acfb1147a6dc3d54ac62fe23ad06e39d8f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780126404",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "4f75ddee-a966-42e3-9251-7a32d5eb8417",
            "value": "12:IaDIBfcQ9e3G3q2puB9WApdmrvPqp5q7qUR:DDI9nSDddHKHR"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780126404",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "9f02cef9-17d2-4f45-a952-ff9a2a9ddc76",
            "value": "490"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780126404",
            "to_ids": true,
            "type": "vhash",
            "uuid": "dd57618a-6b6c-4cae-97b0-35f74bfaffd1",
            "value": "32c693bcb25f653df769ecc1e7d4c928"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780126404",
            "to_ids": true,
            "type": "filename",
            "uuid": "752c7759-297b-40b4-af30-bb1bfc51e6d7",
            "value": "st.txt"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  29/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780126404",
            "to_ids": false,
            "type": "text",
            "uuid": "0e7d7b44-2e69-41b3-b3ed-f0f175dd1e66",
            "value": "Type Description: Powershell\nMicrosoft: Trojan:Script/Wacatac.B!ml\nVT Total Detection:27/62\nFirst Submission:2026-04-23T19:42:53.000000+00:00\nLast Submission:2026-04-23T19:42:53.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780135891",
        "uuid": "083af844-c17c-405d-a912-69edb3783dd5",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780135891",
            "to_ids": true,
            "type": "md5",
            "uuid": "a8fbe2ae-eb3c-423e-a4f4-3a3bffe056ab",
            "value": "220053dd525221fed52af781e000d45c",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780131017",
            "to_ids": true,
            "type": "sha1",
            "uuid": "3c87dba7-7148-4ae3-9546-633194d86efb",
            "value": "732b6ebb8835559bf05cbf2a6e85c2a3ad1f1657",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780131017",
            "to_ids": true,
            "type": "sha256",
            "uuid": "c3fef4cf-15b6-41c2-b5a9-a30c8b005d45",
            "value": "d7545b6dacebdae27effb3c778c5e349027ec789c76ae4f777bd9ba56a70cdaa",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780126448",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "e748768d-6c05-48cd-84fb-f2323bfe46f0",
            "value": "3072:QliazPO3yca9Fu6rtsunyajtoGQn1r51xHnF/V0XRD6ahw7chXTEB5HnsZm2gciB:vazPEycmeGKltjOoNchTEB9yszI1DJqV"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780126448",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "f95274c5-dc3c-4a76-8861-e5a3372b7d75",
            "value": "454180"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780126448",
            "to_ids": true,
            "type": "vhash",
            "uuid": "2fdc5a1c-0a5e-442d-9039-cad68694def0",
            "value": "889da95cda8c9fe937d4da8d1986cfc9"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780126448",
            "to_ids": true,
            "type": "filename",
            "uuid": "1dda5a2e-4fad-445e-b6ed-36597bc1d703",
            "value": "msedge.txt"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  29/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780126448",
            "to_ids": false,
            "type": "text",
            "uuid": "e9b184ee-36a8-479d-a93d-a40115f68806",
            "value": "Type Description: Powershell\nMicrosoft: Trojan:Win32/Qwexlafiba!rfn\nVT Total Detection:21/61\nFirst Submission:2026-05-19T16:11:35.000000+00:00\nLast Submission:2026-05-19T16:11:35.000000+00:00"
          }
        ]
      }
    ]
  }
}