{
  "Event": {
    "analysis": "1",
    "date": "2026-04-17",
    "extends_uuid": "",
    "info": "[Threat Intel] Operation PhantomCLR: Stealth Execution via AppDomain Hijacking and In-Memory .NET Abuse",
    "protected": false,
    "publish_timestamp": "1776767276",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1776767275",
    "uuid": "10a2d604-b9bc-46f2-b00e-856aa235d222",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#f9b12b",
        "local": false,
        "name": "misp-galaxy:producer=\"Cyfirma\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-original-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Shared Modules - T1129\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#47d9d3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#2c1d2e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Checks - T1497.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#5539fe",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5a258",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#45f3d5",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Thread Execution Hijacking - T1055.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#c8f8ef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Binary Proxy Execution - T1218\"",
        "relationship_type": ""
      },
      {
        "colour": "#b24806",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Indicator Removal - T1070\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Execution Guardrails - T1480\"",
        "relationship_type": ""
      },
      {
        "colour": "#62f4c1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#9db548",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Domain Fronting - T1090.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#3c0f50",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#cb2c9b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Finance\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:region=\"145 - Western Asia\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#110041",
        "local": false,
        "name": "rectifyq:sub-category=\"malware-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#120044",
        "local": false,
        "name": "rectifyq:sub-category=\"intrusion-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#31373d",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"not-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"AppDomainManager - T1574.014\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776682832",
        "to_ids": false,
        "type": "link",
        "uuid": "2dbb11e9-e214-4fa3-b2e0-ed3eeeffef07",
        "value": "https://www.cyfirma.com/research/operation-phantomclr-stealth-execution-via-appdomain-hijacking-and-in-memory-net-abuse/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776682832",
        "to_ids": false,
        "type": "text",
        "uuid": "1ad2359d-21b7-4022-a705-b7c86cf094d2",
        "value": "A highly sophisticated multi-stage post-exploitation framework targeting organizations in the Middle East and EMEA financial sectors exploits legitimate digitally signed Intel utilities through .NET AppDomainManager mechanism abuse. The attack leverages trusted binary proxy execution, bypassing EDR and antivirus solutions through JIT-based memory execution and sandbox evasion using computational delays and cryptographic key derivation loops. Initial access occurs via spear-phishing with Arabic-language decoys impersonating Saudi government documents. Once executed, the framework establishes command-and-control communication through Amazon CloudFront CDN domain fronting, employing reflective DLL loading, direct syscall usage, and anti-forensic memory cleanup techniques. The modular plugin-based architecture demonstrates capabilities consistent with advanced persistent threat actors, featuring sophisticated evasion mechanisms including PEB-based API resolution, custom PE export walking, and heap-walking cont..."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776682832",
        "to_ids": false,
        "type": "text",
        "uuid": "3be1b668-853c-418f-948a-477e41f0b04c",
        "value": "Name: Operation PhantomCLR: Stealth Execution via AppDomain Hijacking and In-Memory .NET Abuse\nAuthor: AlienVault\nAdversary: \nTags: [\"financial sector\", \"reflective loading\", \"jit trampolining\", \"middle east targeting\", \"cloudfront domain fronting\", \"syscall usage\", \"sandbox evasion\", \"appdomainmanager hijacking\"]\nTgtd countries: []\nMlwr families: []\nAttack_ids: [\"T1129\", \"T1036.005\", \"T1204.002\", \"T1497.001\", \"T1566.001\", \"T1082\", \"T1106\", \"T1140\", \"T1055.003\", \"T1218\", \"T1070\", \"T1480\", \"T1057\", \"T1562.001\", \"T1027\", \"T1090.004\", \"T1027.002\", \"T1071.001\", \"T1055.001\"]\nIndustries: [\"Finance\", \"Government\"]"
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:21/04/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776735734",
        "to_ids": true,
        "type": "sha1",
        "uuid": "0b9cda30-7f09-4091-ac0c-f3440db6e8cc",
        "value": "34e4360d79257f6caae573be7e03b92163ac4af3",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:21/04/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776735735",
        "to_ids": true,
        "type": "sha1",
        "uuid": "837b1842-bd1d-4249-96da-54504ff8aa73",
        "value": "da346cb32cacd215b9f0b245ad0048815a718dee",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776736198",
        "to_ids": true,
        "type": "hostname",
        "uuid": "31c33d32-f569-406c-a784-628d000b44fa",
        "value": "dp8519iqiftub.cloudfront.net",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776736219",
        "to_ids": true,
        "type": "hostname",
        "uuid": "7a88ff01-df61-42ba-892b-986c6f38ed36",
        "value": "dunamis-ethos508-prod-va6-856defacfb833db1.elb.us-east-1.amazonaws.com",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1776690036",
        "uuid": "c478f00e-0bfb-4112-ac9a-25cf95466352",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1776690036",
            "to_ids": false,
            "type": "text",
            "uuid": "f68b9eba-7052-4099-a228-ef087126f74a",
            "value": "CYFIRMA_APT_AppDomainManager_Mosquitoproof"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1776690036",
            "to_ids": false,
            "type": "comment",
            "uuid": "a212c127-b152-445e-a035-96c697dc173b",
            "value": "Detects the malicious .NET loader and AppDomainManager injection artifacts"
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1776690036",
            "to_ids": true,
            "type": "yara",
            "uuid": "818ba0c6-6b28-4c85-8e75-842f01d0eda4",
            "value": "rule CYFIRMA_APT_AppDomainManager_Mosquitoproof {\r\nmeta:\r\ndescription = \u201cDetects the malicious .NET loader and AppDomainManager injection artifacts\u201d\r\nauthor = \u201cCYFIRMA Research\u201d\r\ndate = \u201c2026-04-11\u201d\r\nseverity = \u201cCritical\u201d\r\n\r\nstrings:\r\n$config_appdomain = \u201c<appDomainManagerAssembly\u201d nocase ascii wide\r\n$config_type = \u201cappDomainManagerType\u201d nocase ascii wide\r\n$hijack_class = \u201cstylohyoideus\u201d ascii wide\r\n$class_graphoth = \u201cGraphoth.Relsful\u201d ascii wide\r\n$class_beartibly = \u201cBeartibly\u201d ascii wide\r\n$class_bartifert = \u201cBartifert\u201d ascii wide\r\n$class_haenacean = \u201cHaenacean\u201d ascii wide\r\n$class_simminatest = \u201cSimminatest\u201d ascii wide\r\n$class_gasmium = \u201cGasmium\u201d ascii wide\r\n$magic_val = \u201cOccidentalism\u201d ascii wide\r\n$pinvoke = \u201cElectorided\u201d ascii wide\r\n$guid = \u201cD6FA9088-E127-24AE-5257-6F298DB72787\u201d ascii wide\r\n\r\ncondition:\r\nuint16(0) == 0x5A4D and (\r\n(2 of ($config_*)) or\r\n$hijack_class or\r\n(3 of ($class_*)) or\r\n$magic_val or\r\n$guid or\r\n($pinvoke and 1 of ($class_*))\r\n)\r\n}"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1776690053",
        "uuid": "b3c0d021-f073-4eab-b201-ba2a4272ea1d",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1776690053",
            "to_ids": false,
            "type": "text",
            "uuid": "94544178-50dd-48ae-a43f-26ca2f6c118f",
            "value": "CYFIRMA_APT_ReflectiveLoader_StageLaunch"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1776690053",
            "to_ids": false,
            "type": "comment",
            "uuid": "7e2ebb95-0b5d-4ed7-a720-234823faa36c",
            "value": "Detects reflective stager shellcode with stage/launch convention and API table magic"
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1776690053",
            "to_ids": true,
            "type": "yara",
            "uuid": "d227c8d1-ec6c-493e-9e3f-4831798b11ad",
            "value": "rule CYFIRMA_APT_ReflectiveLoader_StageLaunch {\r\nmeta:\r\ndescription = \u201cDetects reflective stager shellcode with stage/launch convention and API table magic\u201d\r\nauthor = \u201cCYFIRMA Research\u201d\r\ndate = \u201c2026-04-11\u201d\r\nseverity = \u201cCritical\u201d\r\n\r\nstrings:\r\n$magic_ctx = { 81 3D 66 00 }\r\n$nt_alloc = \u201cNtAllocateVirtualMemory\u201d ascii\r\n$nt_section = \u201cNtCreateSection\u201d ascii\r\n$nt_mapview = \u201cNtMapViewOfSection\u201d ascii\r\n$nt_protect = \u201cNtProtectVirtualMemory\u201d ascii\r\n$export_stage = \u201cstage\u201d ascii\r\n$export_launch = \u201claunch\u201d ascii\r\n$dispatch_hdr = { 82 A1 50 00 A1 56 00 }\r\n\r\ncondition:\r\n(2 of ($nt_*)) or\r\n($magic_ctx and 1 of ($export_*)) or\r\n($dispatch_hdr) or\r\n(all of ($export_*) and 1 of ($nt_*))\r\n}"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1776736240",
        "uuid": "ab07dc89-df8c-4a86-975a-09bcab414262",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1776736240",
            "to_ids": true,
            "type": "md5",
            "uuid": "f9dcd5bf-8d6e-4693-bdc7-f87266f49862",
            "value": "4505fa9fc5b2dca053bbcc55f02a7fac",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1776735730",
            "to_ids": true,
            "type": "sha1",
            "uuid": "b903a268-70dd-4b74-9c65-f9643a900d56",
            "value": "c4644e86f81e973d0e1ad296cfee9daa640d2bb2",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1776735730",
            "to_ids": true,
            "type": "sha256",
            "uuid": "2ad7db21-30ac-4d12-a049-b404678a6a3d",
            "value": "f2266b45d60f5443c5c9304b5f0246348ad82ca4f63c7554c46642311e3f8b83",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1776733588",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "641d7318-063c-4fd9-9ff9-1335bacc70ad",
            "value": "3072:yMNjB+VORF9Sgkg7rVycqj9/Khdz1CjDboEOeLIMNNBK9RM7d9ZIvpHCh:/B+q6g7RBC9/cdzYDb7L/8RMLge"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1776733588",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "9a3543a3-d7c7-4ce2-97ed-11e7640fe497",
            "value": "180052"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1776733588",
            "to_ids": true,
            "type": "vhash",
            "uuid": "48b3752b-e1b9-4683-a2ed-577dd4ddaa90",
            "value": "9ca929e9a50f56ffa5a666f4120526019"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1776733588",
            "to_ids": true,
            "type": "filename",
            "uuid": "7adc4acb-bd05-4440-b18e-718f8a329dc0",
            "value": "Work From Home Policy Update.pdf"
          },
          {
            "category": "Other",
            "comment": "Checked: 21/04/2026\nLast-scan\t:  03/04/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1776733588",
            "to_ids": false,
            "type": "text",
            "uuid": "d99b1182-4734-4e2f-b062-26a16b2af47c",
            "value": "Type Description: PDF\nMicrosoft: None\nVT Total Detection:0/64\nFirst Submission:2026-04-03T11:46:35.000000+00:00\nLast Submission:2026-04-03T11:46:35.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1776736262",
        "uuid": "b7f4b3dd-648d-43bf-8cca-b1bea717e849",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1776736262",
            "to_ids": true,
            "type": "md5",
            "uuid": "7a55d702-8621-4dab-8069-cd5bdec99705",
            "value": "51d0d1482d0e034b3ef2ee6fc83719a4",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1776735731",
            "to_ids": true,
            "type": "sha1",
            "uuid": "f424a73a-cd63-4cba-9416-826736e39ca6",
            "value": "fe9ad4a7af08803ead89148067a2736c335fe020",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1776735731",
            "to_ids": true,
            "type": "sha256",
            "uuid": "da775357-ec17-4c69-88e3-05f270211635",
            "value": "5d784d3ca02ab0015b028f34aa54bc8c50db39f9671dc787bc2a84f0987043b2",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1776733610",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "b48502ce-7229-4cfe-8561-09f6369bdf05",
            "value": "6144:XVgCVuMTz4VZgDLMlLYWabt+z91LxjbxMRp3wLZ:neMVK9/"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1776733610",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "603560c4-46c2-4f1c-9c14-715ca2bf79f1",
            "value": "359424"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1776733610",
            "to_ids": true,
            "type": "vhash",
            "uuid": "acfafab8-77f3-4195-8744-43bece920d78",
            "value": "135026551\"z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1776733610",
            "to_ids": true,
            "type": "filename",
            "uuid": "55f6d57b-84ae-477e-b2e4-553bcdcfa963",
            "value": "IAStorHelpMosquitoproof.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 21/04/2026\nLast-scan\t:  21/04/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1776733610",
            "to_ids": false,
            "type": "text",
            "uuid": "6e1c24dc-4a25-4e1a-82e2-d76ac99ba660",
            "value": "Type Description: Win32 DLL\nMicrosoft: Trojan:MSIL/Agent!AMTB\nVT Total Detection:20/72\nFirst Submission:2026-04-03T11:46:36.000000+00:00\nLast Submission:2026-04-03T11:46:36.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1776736283",
        "uuid": "8dc43e67-2c48-4268-bf2a-c2dcf83c5125",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1776736283",
            "to_ids": true,
            "type": "md5",
            "uuid": "92e27587-7a70-4855-b46f-957973e5a9b3",
            "value": "85cd2aa498a943d4c07ce75d30f6e68d",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1776735732",
            "to_ids": true,
            "type": "sha1",
            "uuid": "6f058c02-0e44-4417-8f14-f7ee77493f38",
            "value": "63ba456b853e8c24fad02ca399be4ccc8b4e5b80",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1776735732",
            "to_ids": true,
            "type": "sha256",
            "uuid": "3381fe8d-29ee-4466-89b8-6139d86b7fda",
            "value": "4f353b9634509a5e1456e54ccb4ce64c1e6d95094df96048ef79b30cc2fda6cb",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1776733632",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "aa417498-ac21-4713-b102-6d8e812adf9e",
            "value": "98304:MKMLeRvu7FIrkEMyvqo7K8GecEyyrXnq/y6srb0:v+oLbMqeTdEq/y9w"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1776733632",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "56c43e62-bb0a-4fc8-ae71-fc590f53bcac",
            "value": "3523013"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1776733632",
            "to_ids": true,
            "type": "vhash",
            "uuid": "f23af7ec-4672-4fb5-aeea-2a8bb439f38e",
            "value": "e18f4b8189bbb7cccbe28739dd20c3d1"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1776733632",
            "to_ids": true,
            "type": "filename",
            "uuid": "96356def-5a59-4dc0-a24e-1a4f7fd1242d",
            "value": "Work.zip"
          },
          {
            "category": "Other",
            "comment": "Checked: 21/04/2026\nLast-scan\t:  21/04/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1776733632",
            "to_ids": false,
            "type": "text",
            "uuid": "afb82faa-1fb7-4e1a-bac3-1e211d28aba4",
            "value": "Type Description: ZIP\nMicrosoft: Trojan:Win32/Suschil!rfn\nVT Total Detection:20/69\nFirst Submission:2026-04-03T11:46:09.000000+00:00\nLast Submission:2026-04-03T11:46:09.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1776736304",
        "uuid": "cc291e9a-f164-40ae-85fe-2941c8d139e5",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1776736304",
            "to_ids": true,
            "type": "md5",
            "uuid": "7a3f0699-cc35-4c3c-8933-b383ab05211e",
            "value": "c84e5bb76d90607bc03de133215f800e",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1776735733",
            "to_ids": true,
            "type": "sha1",
            "uuid": "6dbfb701-636e-4afe-bcee-1396578f914a",
            "value": "e3977bf1f4d31ba7a7d93accead7a4cee527d49c",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1776735733",
            "to_ids": true,
            "type": "sha256",
            "uuid": "5628fc1a-df31-4093-8980-c8e5553b9ac8",
            "value": "8ba1b0392a8fbfb455c43c4e1408352d0e5fc281148810143a5b64938fb0982f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1776733653",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "b32ee8f2-0263-4f12-805b-fa9944d373be",
            "value": "12288:LFtjdl86km0WeWe+F3+q7w1y7Nl20t29P:LFtBl864lm+6Wy7XnuP"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1776733653",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "dda1a222-97ba-4d76-8a6a-c76e12ab0fc4",
            "value": "1094416"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1776733653",
            "to_ids": true,
            "type": "vhash",
            "uuid": "7a50d43d-d972-464b-9438-e832439b1eee",
            "value": "016026555\"z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1776733653",
            "to_ids": true,
            "type": "filename",
            "uuid": "b77d99af-06f5-47a8-ba6d-9915d17a2b38",
            "value": "IAStorHelp.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 21/04/2026\nLast-scan\t:  21/04/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1776733653",
            "to_ids": false,
            "type": "text",
            "uuid": "cf3bfaee-8161-4cc5-8b50-df172a9bf500",
            "value": "Type Description: Win32 EXE\nMicrosoft: None\nVT Total Detection:0/72\nFirst Submission:2022-03-02T18:42:29.000000+00:00\nLast Submission:2026-04-02T20:44:06.000000+00:00"
          }
        ]
      }
    ]
  }
}