{
  "Event": {
    "analysis": "1",
    "date": "2026-05-13",
    "extends_uuid": "",
    "info": "[Threat Intel] APT Targets Azerbaijani Oil and Gas Industry",
    "protected": false,
    "publish_timestamp": "1780284557",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780284557",
    "uuid": "4513c651-0f6c-417a-8390-6a800dc28872",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#44212b",
        "local": false,
        "name": "misp-galaxy:producer=\"Bitdefender\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-original-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#9feaf0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"",
        "relationship_type": ""
      },
      {
        "colour": "#fe1ef0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#5c57c8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#e1e63b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DLL Side-Loading - T1574.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#d4fd6f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Impair Defenses - T1562\"",
        "relationship_type": ""
      },
      {
        "colour": "#fae37b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Service Execution - T1569.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#755c09",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#370063",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#041edc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"SMB/Windows Admin Shares - T1021.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#91ee5f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Rootkit - T1014\"",
        "relationship_type": ""
      },
      {
        "colour": "#d802cf",
        "local": false,
        "name": "misp-galaxy:target-information=\"Azerbaijan\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:threat-actor=\"GhostEmperor\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003d",
        "local": false,
        "name": "rectifyq:sub-category=\"TA-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"APT\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#31373d",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"not-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:country=\"china\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"SNAPPYBEE\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Gas\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Oil\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418873",
        "to_ids": false,
        "type": "link",
        "uuid": "20281ed7-5651-4675-9972-40e5d2179f59",
        "value": "https://businessinsights.bitdefender.com/famoussparrow-apt-targets-azerbaijani-oil-gas-industry"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418873",
        "to_ids": false,
        "type": "text",
        "uuid": "97c939aa-bc31-4c65-900c-ca9a39722c58",
        "value": "A sophisticated multi-wave intrusion campaign targeted an Azerbaijani oil and gas company from late December 2025 through late February 2026, attributed with moderate-to-high confidence to the Chinese APT group FamousSparrow. The operation exploited unpatched Microsoft Exchange servers via ProxyShell and ProxyNotShell vulnerabilities to establish initial access. Attackers deployed two distinct backdoor families - Deed RAT and Terndoor - across three separate waves, demonstrating operational persistence by repeatedly exploiting the same entry point despite remediation attempts. Technical analysis revealed an evolved DLL sideloading technique using a two-stage trigger mechanism that gates execution through legitimate application control flow, effectively evading automated sandbox analysis. The campaign extended FamousSparrow's known targeting to South Caucasus energy infrastructure, coinciding with Azerbaijan's increased strategic importance to European energy security following disruptions in Russian and Mi..."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418873",
        "to_ids": false,
        "type": "text",
        "uuid": "cfaa7fca-ace9-4a67-883f-3def565890fd",
        "value": "Name: APT Targets Azerbaijani Oil and Gas Industry\nAuthor: AlienVault\nAdversary: GhostEmperor\nTags: [\"FamousSparrow\", \"Earth Estries\", \"Deed RAT\", \"Terndoor\", \"DLL sideloading\", \"Azerbaijan\", \"energy sector\", \"Chinese APT\", \"Exchange exploitation\"]\nTgtd countries: [\"Azerbaijan\"]\nMlwr families: [\"Deed RAT\", \"Terndoor\", \"Mofu\"]\nAttack_ids: [\"T1190\", \"T1505.003\", \"T1543.003\", \"T1574.002\", \"T1140\", \"T1562\", \"T1569.002\", \"T1059.001\", \"T1021.001\", \"T1021.002\", \"T1071.001\", \"T1014\", \"T1055\", \"T1027\", \"T1055.012\", \"T1112\", \"T1070\", \"T1036\", \"T1218\", \"T1082\"]\nIndustries: [\"Energy\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780178912",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "26fc3c92-7396-4085-aa75-02aaa0b5c4f7",
        "value": "FamousSparrow",
        "Tag": [
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:threat-actor=\"GhostEmperor\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418873",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "6872d42e-9b9e-470b-8d8d-bdd081fdd029",
        "value": "CVE-2021-34473"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418873",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "f5d5e6b9-90c0-40b9-af37-bbdffc3a8b1d",
        "value": "CVE-2021-34523"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418873",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "324426ca-e6a4-4044-89ee-4b0d44abb8e9",
        "value": "CVE-2021-31207"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418873",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "5adfc013-405b-41fd-a093-d4d662ef4207",
        "value": "CVE-2022-41040"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418873",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "9c499b3e-2115-4f81-847e-0d0efbd39fe9",
        "value": "CVE-2022-41082"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780280413",
        "to_ids": true,
        "type": "domain",
        "uuid": "ad2acc83-fb57-4381-b74a-91e2d0aa9722",
        "value": "sentinelonepro.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780280434",
        "to_ids": true,
        "type": "url",
        "uuid": "9afe9dda-2e9c-4125-b504-6f865e997779",
        "value": "http://sentinelonepro.com:443",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780280455",
        "to_ids": true,
        "type": "url",
        "uuid": "f6a40d19-c3a2-42a5-84e5-dca4e73136cd",
        "value": "https://sentinelonepro.com:443",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780280476",
        "uuid": "de8580c9-a7d8-4308-aac4-226010dbf0d9",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780280476",
            "to_ids": true,
            "type": "md5",
            "uuid": "7a722b3d-ee08-4bd1-8c58-fdc61ea35321",
            "value": "505b55c2b68e32acb5ad13588e1491a5",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780197869",
            "to_ids": true,
            "type": "sha1",
            "uuid": "d809acac-5143-4741-99dd-b2fef6ffcff8",
            "value": "9218e2c37c339527736cdc9d9aad88de728931a3",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780197869",
            "to_ids": true,
            "type": "sha256",
            "uuid": "bfaa3abc-20f2-4141-aa08-4b165f6def93",
            "value": "25b9fdef3061c7dfea744830774ca0e289dba7c14be85f0d4695d382763b409b",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780197590",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "631f485a-77aa-4b41-8325-ae4d06b194d2",
            "value": "3072:lS4xNcfANGOTod1j1ripLdfXnu6+iS733aHQC2mCokXXOlzInVYZ/SeCN8hDwFn8:lZxNcoNsCcnaoHOlUn6HsTv"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780197590",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "f1a0ff7f-24ed-472f-84a9-bd1e566c6110",
            "value": "220672"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780197590",
            "to_ids": true,
            "type": "vhash",
            "uuid": "08e3b366-13d0-4632-8559-4e4cadca4656",
            "value": "125046655d156038z4bvza6z3"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780197590",
            "to_ids": true,
            "type": "filename",
            "uuid": "f87da5d4-2b32-4f0a-af00-a9aebfd2c654",
            "value": "25b9fdef3061c7dfea744830774ca0e289dba7c14be85f0d4695d382763b409b-Trojan.Win32.SNAPPYBEE.ZMLJ"
          },
          {
            "category": "Other",
            "comment": "Checked: 31/05/2026\nLast-scan\t:  31/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780197590",
            "to_ids": false,
            "type": "text",
            "uuid": "3789e40c-f75a-4998-97f1-da548a0c579a",
            "value": "Type Description: Win32 DLL\nMicrosoft: Trojan:Win32/Malgent!MSR\nVT Total Detection:52/71\nFirst Submission:2023-11-19T22:42:24.000000+00:00\nLast Submission:2025-11-12T01:58:55.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780280498",
        "uuid": "5a2fb276-96cf-4b8a-ae20-f3e089629b67",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780280498",
            "to_ids": true,
            "type": "md5",
            "uuid": "91312d30-8ae0-4d3d-a340-67dec4447c78",
            "value": "0554f3b69d39d175dd110d765c11347a",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#2c2142",
                "local": false,
                "name": "false-positive:risk=\"high\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780197870",
            "to_ids": true,
            "type": "sha1",
            "uuid": "3b4c2266-6d85-4bdb-ac34-a15d2352dc48",
            "value": "131bc6ca3960476e16fbaad091d26e92f2093437",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#2c2142",
                "local": false,
                "name": "false-positive:risk=\"high\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780197870",
            "to_ids": true,
            "type": "sha256",
            "uuid": "e16cfa5a-b7a7-4d96-9e4f-ddf1f8b07d34",
            "value": "a57d5ce0cba04806eb0c6d8943d85c5ab63119a99fa8f8000bdf54cccd1c1bf9",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#2c2142",
                "local": false,
                "name": "false-positive:risk=\"high\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780197612",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "ef30f34c-c7db-499f-a4de-1f6c68d21879",
            "value": "3072:BxDBGoB+fTlSSyGBhi5OG/IXF2IlPuKakhYbXurcxA84/LFtZdQ:BxDBHYfTFt7i5OGkplWj8/BtY"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780197612",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "e6afde3b-b78c-4832-a7e6-4d9fce0f320d",
            "value": "419248"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780197612",
            "to_ids": true,
            "type": "vhash",
            "uuid": "f15759e8-266e-4756-bcc7-dff93614c963",
            "value": "045066651d1555555az42!z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780197612",
            "to_ids": true,
            "type": "filename",
            "uuid": "985c3efe-8df1-44e2-8a7f-611cd7b69f73",
            "value": "LMIGuardianSvc.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 31/05/2026\nLast-scan\t:  22/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780197612",
            "to_ids": false,
            "type": "text",
            "uuid": "28704d97-79d6-4864-adb7-ed8e97c76fb0",
            "value": "Type Description: Win32 EXE\nFile distributed by: ['LogMeIn']\nData sources: ['LogMeIn']\nVerdict filename: ['LMIGuardianSvc.exe']\nMicrosoft: None\nVT Total Detection:0/71\nFirst Submission:2016-07-19T08:43:54.000000+00:00\nLast Submission:2026-05-29T10:55:05.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780280521",
        "uuid": "c834ab90-7ace-4eae-a853-d43783b863f5",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780280521",
            "to_ids": true,
            "type": "md5",
            "uuid": "11bc386c-494f-4932-8ab5-a43eb226decd",
            "value": "762f787534a891eca8aa9b41330b4108",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780197871",
            "to_ids": true,
            "type": "sha1",
            "uuid": "c56e8da0-5be4-4934-ac11-8a90dfb569f5",
            "value": "1a4002e3d547ed7ef9ca32f68fdd8e9f11ad0e6d",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780197871",
            "to_ids": true,
            "type": "sha256",
            "uuid": "ec96195a-503c-4188-945f-ce983ec1b68e",
            "value": "67ce8c7a255724ae1ccd2fa6c4ea50183a848f3aaef4152064dbc444159b8f13",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780197634",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "20bcec98-c671-42b4-9c55-af528a822e00",
            "value": "12288:Zz04vnLeRlqemTnDLBav1NrMGz7xMLT+Fsb2yC/FxpYo5eL5+naVCKkR:BDyqemTDLB+73wvqrFxKZ"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780197634",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "31fc04f7-f3f2-4720-964a-7cc32fea808e",
            "value": "1940832"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780197634",
            "to_ids": true,
            "type": "vhash",
            "uuid": "1169b621-40f7-425d-bb49-bc2399421845",
            "value": "0160b6655d155510161d10c5z100947z17z33z53z18z1"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780197634",
            "to_ids": true,
            "type": "filename",
            "uuid": "ca841315-4a47-4c42-bb3e-36e0d22ae1bd",
            "value": "dbghelp.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 31/05/2026\nLast-scan\t:  22/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780197634",
            "to_ids": false,
            "type": "text",
            "uuid": "f6f78bac-0c19-4e72-87c4-f661815d0128",
            "value": "Type Description: Win32 EXE\nMicrosoft: None\nVT Total Detection:0/71\nFirst Submission:2022-06-23T06:24:30.000000+00:00\nLast Submission:2024-12-05T07:05:42.000000+00:00"
          }
        ]
      }
    ]
  }
}