{
  "Event": {
    "analysis": "1",
    "date": "2026-07-17",
    "extends_uuid": "",
    "info": "[Threat Intel] Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain",
    "protected": false,
    "publish_timestamp": "1784588174",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1784588173",
    "uuid": "41081d81-f137-469b-a94d-3ebd48baaea5",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#57356b",
        "local": false,
        "name": "misp-galaxy:producer=\"Seqrite\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-original-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#8ee8d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"",
        "relationship_type": ""
      },
      {
        "colour": "#72ee33",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Shared Modules - T1129\"",
        "relationship_type": ""
      },
      {
        "colour": "#d74cce",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Bypass User Account Control - T1548.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#b2a633",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Service Stop - T1489\"",
        "relationship_type": ""
      },
      {
        "colour": "#47d9d3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#5539fe",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9bb6d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"",
        "relationship_type": ""
      },
      {
        "colour": "#75ec20",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#3b96ed",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"CMSTP - T1218.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#682cad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Services - T1021\"",
        "relationship_type": ""
      },
      {
        "colour": "#9f6bd9",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Network Configuration Discovery - T1016\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#62f4c1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"",
        "relationship_type": ""
      },
      {
        "colour": "#755c09",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5055a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#013748",
        "local": false,
        "name": "misp-galaxy:target-information=\"India\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#31373d",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"not-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Encrypted/Encoded File - T1027.013\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Reflective Code Loading - T1620\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Remcos\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784343648",
        "to_ids": false,
        "type": "link",
        "uuid": "ed875619-8534-4e2b-81db-0162993f0bd5",
        "value": "https://www.seqrite.com/blog/behind-the-refund-from-gst-phishing-to-remcos-rat-through-a-multi-stage-net-infection-chain/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784343648",
        "to_ids": false,
        "type": "text",
        "uuid": "6b803b09-7cc0-4efd-acc1-f55d06c14a3d",
        "value": "A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime operation specifically t..."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784343648",
        "to_ids": false,
        "type": "text",
        "uuid": "6252cfe9-e310-4297-a2e7-bad96bd037dd",
        "value": "Name: Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain\nAuthor: AlienVault\nAdversary: \nTags: [\"bitmap steganography\", \"fileless execution\", \"multi-stage loader\", \"dynamic dns\", \"india targeting\", \"credential theft\", \"gst phishing\", \"remcos rat\"]\nTgtd countries: [\"British Indian Ocean Territory\", \"India\"]\nMlwr families: [\"Remcos RAT\"]\nAttack_ids: [\"T1113\", \"T1056.001\", \"T1129\", \"T1548.002\", \"T1489\", \"T1204.002\", \"T1566.001\", \"T1082\", \"T1005\", \"T1140\", \"T1555\", \"T1036\", \"T1055\", \"T1218.003\", \"T1021\", \"T1016\", \"T1083\", \"T1057\", \"T1059.001\", \"T1547.001\", \"T1039\", \"T1027\", \"T1071.001\", \"T1105\"]\nIndustries: [\"Finance\", \"Government\"]"
      },
      {
        "category": "Payload delivery",
        "comment": "RemcosRAT No sample in VT\r\nLast check: 21/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784585140",
        "to_ids": true,
        "type": "md5",
        "uuid": "f135607a-56ec-4884-84b7-f7fe1a0a908d",
        "value": "2a34bdd25b404737ee5d3b52bf0b3b70",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 21/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784585141",
        "to_ids": true,
        "type": "md5",
        "uuid": "781c211e-776d-4767-a67e-a2cc82e27bbe",
        "value": "cc34d9760394104ad47877a0d57e9c63",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784587997",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "2b72e484-c21b-46b2-9138-558f7f4f9c5a",
        "value": "185.242.4.122",
        "Tag": [
          {
            "colour": "#64bed2",
            "local": false,
            "name": "asn:asn=\"9009\"",
            "relationship_type": ""
          },
          {
            "colour": "#41c276",
            "local": false,
            "name": "asn:as-owner=\"M247\"",
            "relationship_type": ""
          },
          {
            "colour": "#26f3a1",
            "local": false,
            "name": "asn:as-country=\"RO\"",
            "relationship_type": ""
          },
          {
            "colour": "#026417",
            "local": false,
            "name": "misp-galaxy:country=\"romania\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "The email originated from the address",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784551995",
        "to_ids": true,
        "type": "email-src",
        "uuid": "ca52300f-9d4b-43f6-bb4b-128e92f64505",
        "value": "donotreply.@gst.gov.in"
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "first_seen": "2026-07-09T06:21:42+00:00",
        "last_seen": "2026-07-09T15:29:58+00:00",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1784588018",
        "uuid": "4cdaffe0-fb03-4fc9-a6b1-3288258e4e5c",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:21:42+00:00",
            "last_seen": "2026-07-09T15:29:58+00:00",
            "object_relation": "md5",
            "timestamp": "1784588018",
            "to_ids": true,
            "type": "md5",
            "uuid": "4b1b56ec-d774-4ab0-b814-4f52dbac5aa4",
            "value": "07d7d21c2c0920d198efb9ea54900a80",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:21:42+00:00",
            "last_seen": "2026-07-09T15:29:58+00:00",
            "object_relation": "sha1",
            "timestamp": "1784585135",
            "to_ids": true,
            "type": "sha1",
            "uuid": "ec73aedd-dc64-45fa-9a2c-149261ee0653",
            "value": "e2d5c8ff442e4a52025ba10a64f14ea35c255fcd",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:21:42+00:00",
            "last_seen": "2026-07-09T15:29:58+00:00",
            "object_relation": "sha256",
            "timestamp": "1784585136",
            "to_ids": true,
            "type": "sha256",
            "uuid": "fd117d32-721c-4db7-973a-e413d71b3335",
            "value": "e29a665cd6f2567f651880b2f5a054d474d639de8ed9005c52268bd0b49487ba",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Other",
            "comment": "Checked: 21/07/2026\nLast-scan: 19/07/2026",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-09T06:21:42+00:00",
            "last_seen": "2026-07-09T15:29:58+00:00",
            "object_relation": "text",
            "timestamp": "1784584653",
            "to_ids": false,
            "type": "text",
            "uuid": "101aca1d-f76b-4402-832f-9a395f5d9e3a",
            "value": "Type Description: RAR\nMicrosoft: Trojan:Win32/Vigorf.A\nClamAV: None\nVT Total Detection: 45/74\nFirst Submission: 2026-07-09T06:21:42+00:00\nLast Submission: 2026-07-09T15:29:58+00:00"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:21:42+00:00",
            "last_seen": "2026-07-09T15:29:58+00:00",
            "object_relation": "ssdeep",
            "timestamp": "1784584653",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "d3b7462e-19e9-4a15-ad67-980548f6e43f",
            "value": "12288:xd+j3yeMRlesMm/coIYt8YtzD1J13AJqKEscT+ttJzzU733U+03MK/IPnoRyhnk:X+jCzRYsyNYLZD1s0PH+zJM73q3MloRV"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-09T06:21:42+00:00",
            "last_seen": "2026-07-09T15:29:58+00:00",
            "object_relation": "size-in-bytes",
            "timestamp": "1784584653",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "a91d5d49-d794-4a07-b029-d5d27dcc3b1f",
            "value": "772660"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-09T06:21:42+00:00",
            "last_seen": "2026-07-09T15:29:58+00:00",
            "object_relation": "filename",
            "timestamp": "1784584653",
            "to_ids": true,
            "type": "filename",
            "uuid": "dfd6d521-7cc7-4e46-a56b-3a172a12c94b",
            "value": "GST-Refund_July-26_AL27052600952P.rar"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "first_seen": "2026-07-09T06:24:00+00:00",
        "last_seen": "2026-07-09T06:24:00+00:00",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1784588039",
        "uuid": "a52ead5f-b4e3-44da-8fb3-2b914bf4acf9",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:24:00+00:00",
            "last_seen": "2026-07-09T06:24:00+00:00",
            "object_relation": "md5",
            "timestamp": "1784588039",
            "to_ids": true,
            "type": "md5",
            "uuid": "34c4eae3-a5c6-4635-9ff8-216d4c4f61f3",
            "value": "20476f3a51dfddf3dc0603fc7858d894",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:24:00+00:00",
            "last_seen": "2026-07-09T06:24:00+00:00",
            "object_relation": "sha1",
            "timestamp": "1784585137",
            "to_ids": true,
            "type": "sha1",
            "uuid": "37c557bc-c7d0-4c61-9946-29700986e338",
            "value": "8473528eae1e7cfaae6099b45260b9c576275bbe",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:24:00+00:00",
            "last_seen": "2026-07-09T06:24:00+00:00",
            "object_relation": "sha256",
            "timestamp": "1784585137",
            "to_ids": true,
            "type": "sha256",
            "uuid": "b0bc46b5-a608-481d-8018-cf0b0e419edd",
            "value": "279e14ad7bad135f7b63e17c355c969116c2db600967061bbab107f66d62dbb6",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Other",
            "comment": "Checked: 21/07/2026\nLast-scan: 19/07/2026",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-09T06:24:00+00:00",
            "last_seen": "2026-07-09T06:24:00+00:00",
            "object_relation": "text",
            "timestamp": "1784584675",
            "to_ids": false,
            "type": "text",
            "uuid": "46cd319b-45eb-41e2-a43d-c99a7f8965ed",
            "value": "Type Description: Win32 EXE\nOriginal name: vmfr.exe\nMicrosoft: Trojan:MSIL/FormBook.PGFL!MTB\nClamAV: None\nVT Total Detection: 53/74\nFirst Seen In The Wild: 2026-07-09T05:52:25+00:00\nFirst Submission: 2026-07-09T06:24:00+00:00\nLast Submission: 2026-07-09T06:24:00+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:24:00+00:00",
            "last_seen": "2026-07-09T06:24:00+00:00",
            "object_relation": "creation-time",
            "timestamp": "1784584675",
            "to_ids": false,
            "type": "datetime",
            "uuid": "d6d7fdd3-df7a-42db-a74d-4440dd3efa1b",
            "value": "2075-12-05T10:45:37+00:00"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:24:00+00:00",
            "last_seen": "2026-07-09T06:24:00+00:00",
            "object_relation": "ssdeep",
            "timestamp": "1784584675",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "93d16a72-9e98-44ff-8175-2afeedaabc18",
            "value": "12288:c3ZIaopA+Vuvmwt715Qm+b9ggacQ2qCAm4n1K+n4n3SfozoOyzgN:cpIaopFK9oT9gg2nCAm4n1L4nCfozgs"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-09T06:24:00+00:00",
            "last_seen": "2026-07-09T06:24:00+00:00",
            "object_relation": "size-in-bytes",
            "timestamp": "1784584675",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "65aeeacd-84ac-4078-8544-d014dfa3d818",
            "value": "817664"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T06:24:00+00:00",
            "last_seen": "2026-07-09T06:24:00+00:00",
            "object_relation": "vhash",
            "timestamp": "1784584675",
            "to_ids": true,
            "type": "vhash",
            "uuid": "2ed04ba6-d012-4204-88e3-f811bb92daf0",
            "value": "285036751511b08223143011f"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-09T06:24:00+00:00",
            "last_seen": "2026-07-09T06:24:00+00:00",
            "object_relation": "filename",
            "timestamp": "1784584675",
            "to_ids": true,
            "type": "filename",
            "uuid": "a0a80b4f-24aa-4f35-b8c3-0f793dd77aff",
            "value": "vmfr.exe"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "first_seen": "2026-07-09T10:20:23+00:00",
        "last_seen": "2026-07-09T10:20:23+00:00",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1784588060",
        "uuid": "45cc2b91-e8ff-48cd-9f56-9e11d53d129a",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "Eml",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T10:20:23+00:00",
            "last_seen": "2026-07-09T10:20:23+00:00",
            "object_relation": "md5",
            "timestamp": "1784588060",
            "to_ids": true,
            "type": "md5",
            "uuid": "7739be0c-2097-41d4-b612-46996437048e",
            "value": "3757dccb2adae65ccdf8d5e5c948b927",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Eml",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T10:20:23+00:00",
            "last_seen": "2026-07-09T10:20:23+00:00",
            "object_relation": "sha1",
            "timestamp": "1784585138",
            "to_ids": true,
            "type": "sha1",
            "uuid": "15973da3-c034-448d-a233-6aa2dc99b1b9",
            "value": "46979bfd4bfe29b7dc142a631ac440b0cf7d9d3b",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Eml",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T10:20:23+00:00",
            "last_seen": "2026-07-09T10:20:23+00:00",
            "object_relation": "sha256",
            "timestamp": "1784585138",
            "to_ids": true,
            "type": "sha256",
            "uuid": "02026269-af0b-4010-864c-971e50fc4ce7",
            "value": "f9853d0bea5c8bdedfa15dc258ac3c8415532c8ad780a679914788f368000ef7",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Other",
            "comment": "Checked: 21/07/2026\nLast-scan: 19/07/2026",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-09T10:20:23+00:00",
            "last_seen": "2026-07-09T10:20:23+00:00",
            "object_relation": "text",
            "timestamp": "1784584717",
            "to_ids": false,
            "type": "text",
            "uuid": "0adb098b-fec9-490a-8414-9a544409388e",
            "value": "Eml\r\nType Description: Email\nMicrosoft: None\nClamAV: None\nVT Total Detection: 31/74\nFirst Submission: 2026-07-09T10:20:23+00:00\nLast Submission: 2026-07-09T10:20:23+00:00"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-09T10:20:23+00:00",
            "last_seen": "2026-07-09T10:20:23+00:00",
            "object_relation": "ssdeep",
            "timestamp": "1784584717",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "17e19475-141a-4519-8b03-313fcadc60fc",
            "value": "12288:+FD/W1mdmWLnACaqbVrqHafbCwCauQBzh/D+qgC9afi4DHwU918Z6gg2sutVFZcl:IngWLAoIaPdBzND+EuDRD8g6tVbcrZ"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-09T10:20:23+00:00",
            "last_seen": "2026-07-09T10:20:23+00:00",
            "object_relation": "size-in-bytes",
            "timestamp": "1784584717",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "0ec0e3b3-0427-4d66-8899-a0721cfc4768",
            "value": "1063404"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-09T10:20:23+00:00",
            "last_seen": "2026-07-09T10:20:23+00:00",
            "object_relation": "filename",
            "timestamp": "1784584717",
            "to_ids": true,
            "type": "filename",
            "uuid": "7d906f2c-f47b-48ac-9e91-e5816b11c8e9",
            "value": "SRV041_6a4f73e145_"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "first_seen": "2026-07-08T01:58:34+00:00",
        "last_seen": "2026-07-13T18:32:49+00:00",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1784588081",
        "uuid": "45a01410-b9d3-4f00-a5cb-ab014c556f95",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-08T01:58:34+00:00",
            "last_seen": "2026-07-13T18:32:49+00:00",
            "object_relation": "md5",
            "timestamp": "1784588081",
            "to_ids": true,
            "type": "md5",
            "uuid": "daf34f4a-adf7-4db8-9c75-6e50c1208949",
            "value": "7842d12d9e37c75076133be5b9904cb2",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-08T01:58:34+00:00",
            "last_seen": "2026-07-13T18:32:49+00:00",
            "object_relation": "sha1",
            "timestamp": "1784585139",
            "to_ids": true,
            "type": "sha1",
            "uuid": "b2625050-8237-42af-a872-67ad06cb471f",
            "value": "425f1edac0b53d62a20749a6a69e5a3b260c595f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-08T01:58:34+00:00",
            "last_seen": "2026-07-13T18:32:49+00:00",
            "object_relation": "sha256",
            "timestamp": "1784585139",
            "to_ids": true,
            "type": "sha256",
            "uuid": "798478aa-e247-4613-b5a9-6d42f48f562e",
            "value": "b857821ade3427a9fd9d83f42150344bc905bda8328fa66ba49d499af64f23ee",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Other",
            "comment": "Checked: 21/07/2026\nLast-scan: 19/07/2026",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-08T01:58:34+00:00",
            "last_seen": "2026-07-13T18:32:49+00:00",
            "object_relation": "text",
            "timestamp": "1784584739",
            "to_ids": false,
            "type": "text",
            "uuid": "a043b788-8dc7-42a5-a17f-7b71b3c1bf42",
            "value": "Type Description: Win32 DLL\nOriginal nam%WINDIR%\\Health Optimizer Plus.dll\nMicrosoft: Trojan:MSIL/Heracles.DMV!MTB\nClamAV: None\nVT Total Detection: 36/74\nFirst Submission: 2026-07-08T01:58:34+00:00\nLast Submission: 2026-07-13T18:32:49+00:00"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-08T01:58:34+00:00",
            "last_seen": "2026-07-13T18:32:49+00:00",
            "object_relation": "creation-time",
            "timestamp": "1784584739",
            "to_ids": false,
            "type": "datetime",
            "uuid": "dade8877-d030-46eb-951f-ecf5903854a4",
            "value": "2026-07-08T04:17:47+00:00"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-08T01:58:34+00:00",
            "last_seen": "2026-07-13T18:32:49+00:00",
            "object_relation": "ssdeep",
            "timestamp": "1784584739",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "640776ac-ac0d-4792-a4a2-0a0379314fef",
            "value": "1536:Xu0OQGTXXLSR6V+Xs/BIKn1gSm/GSz9kD5FzH1vfq9Oz:xGTXTIJ/59m7vfq+"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-08T01:58:34+00:00",
            "last_seen": "2026-07-13T18:32:49+00:00",
            "object_relation": "size-in-bytes",
            "timestamp": "1784584739",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "7af5f08e-1e0f-4049-888a-13523f95da85",
            "value": "64000"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-08T01:58:34+00:00",
            "last_seen": "2026-07-13T18:32:49+00:00",
            "object_relation": "vhash",
            "timestamp": "1784584739",
            "to_ids": true,
            "type": "vhash",
            "uuid": "0860a64b-e5e9-44bb-89b2-214ed0aa7653",
            "value": "36403665151e06126254060"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-08T01:58:34+00:00",
            "last_seen": "2026-07-13T18:32:49+00:00",
            "object_relation": "filename",
            "timestamp": "1784584739",
            "to_ids": true,
            "type": "filename",
            "uuid": "f1b47097-84b0-4837-9600-a92f52dc7f72",
            "value": "Windows Health Optimizer Plus.dll"
          }
        ]
      }
    ]
  }
}