{
  "Event": {
    "analysis": "1",
    "date": "2026-05-20",
    "extends_uuid": "",
    "info": "[Threat Intel] New burrowing techniques",
    "protected": false,
    "publish_timestamp": "1780196719",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780196719",
    "uuid": "55a58703-da62-4330-bd76-3189d2635e28",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#8675c7",
        "local": false,
        "name": "misp-galaxy:producer=\"ESET\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-original-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#a7b0e0",
        "local": false,
        "name": "misp-galaxy:target-information=\"Belgium\"",
        "relationship_type": ""
      },
      {
        "colour": "#74d147",
        "local": false,
        "name": "misp-galaxy:target-information=\"Czech Republic\"",
        "relationship_type": ""
      },
      {
        "colour": "#620e4e",
        "local": false,
        "name": "misp-galaxy:target-information=\"Hungary\"",
        "relationship_type": ""
      },
      {
        "colour": "#4cea11",
        "local": false,
        "name": "misp-galaxy:target-information=\"Italy\"",
        "relationship_type": ""
      },
      {
        "colour": "#bedb1f",
        "local": false,
        "name": "misp-galaxy:target-information=\"Nigeria\"",
        "relationship_type": ""
      },
      {
        "colour": "#809a25",
        "local": false,
        "name": "misp-galaxy:target-information=\"Poland\"",
        "relationship_type": ""
      },
      {
        "colour": "#199542",
        "local": false,
        "name": "misp-galaxy:target-information=\"Serbia\"",
        "relationship_type": ""
      },
      {
        "colour": "#35a578",
        "local": false,
        "name": "misp-galaxy:target-information=\"South Africa\"",
        "relationship_type": ""
      },
      {
        "colour": "#f439e5",
        "local": false,
        "name": "misp-galaxy:target-information=\"Spain\"",
        "relationship_type": ""
      },
      {
        "colour": "#5300bd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Application Access Token - T1550.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#08b028",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Asymmetric Cryptography - T1573.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#57997c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Bidirectional Communication - T1102.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#37c019",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Services - T1021.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Encrypted/Encoded File - T1027.013\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#280b0e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"External Proxy - T1090.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#30cc3b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#c295b4",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Internal Proxy - T1090.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#3eb869",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Data Staging - T1074.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#bf01b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Multi-hop Proxy - T1090.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#fcc86e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Data Staging - T1074.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#705cef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#b9ca9e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Server - T1583.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#bb2745",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Standard Encoding - T1132.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#edf46c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Timestomp - T1070.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Upload Tool - T1608.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#91649a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Virtual Private Server - T1583.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Vulnerabilities - T1588.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#add7fd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Services - T1584.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#02475d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Wordlist Scanning - T1595.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:threat-actor=\"Webworm\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:online-service=\"7347d685-8e08-4ed9-9f34-264e5e4b567a\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:online-service=\"3b16bb5a-eb4f-4603-a909-bebc5df4a46d\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003d",
        "local": false,
        "name": "rectifyq:sub-category=\"TA-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"APT\"",
        "relationship_type": ""
      },
      {
        "colour": "#220082",
        "local": false,
        "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418807",
        "to_ids": false,
        "type": "link",
        "uuid": "8953b964-27c0-4370-83b3-7f3fe2c8c82f",
        "value": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418807",
        "to_ids": false,
        "type": "text",
        "uuid": "23508adf-09b0-414d-9414-345a505c340d",
        "value": "Webworm is a China-aligned APT group that has evolved its tactics since first being discovered in 2022, shifting focus from Asian targets to European governmental organizations. In 2025, the group deployed two new backdoors: EchoCreep, which uses Discord for command and control, and GraphWorm, which leverages Microsoft Graph API. Researchers decrypted over 400 Discord messages revealing four victims and analyzed a compromised Amazon S3 bucket used for data exfiltration. The group stages tools in GitHub repositories and uses multiple custom proxy solutions including WormFrp, ChainWorm, SmuxProxy, and WormSocket to create hidden networks. Webworm appears to exploit web vulnerabilities using tools like nuclei and dirsearch for initial access, targeting government entities and educational institutions across Europe and South Africa."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418807",
        "to_ids": false,
        "type": "text",
        "uuid": "2e24dd1e-1036-46ca-be97-7f756a7727a6",
        "value": "Name: New burrowing techniques\nAuthor: AlienVault\nAdversary: Webworm\nTags: [\"wormfrp\", \"github staging\", \"discord c&c\", \"cloud infrastructure\", \"wormsocket\", \"apt\", \"china-aligned\", \"mcrat\", \"chainworm\", \"proxy tools\", \"vulnerability scanning\", \"smuxproxy\", \"trochilus\", \"echocreep\", \"cve-2017-7692\", \"microsoft graph api\", \"graphworm\"]\nTgtd countries: [\"Belgium\", \"Czechia\", \"Hungary\", \"Italy\", \"Nigeria\", \"Poland\", \"Serbia\", \"South Africa\", \"Spain\"]\nMlwr families: [\"EchoCreep\", \"GraphWorm\", \"WormFrp\", \"ChainWorm\", \"SmuxProxy\", \"WormSocket\", \"Hydraq - S0203\", \"Roarur\", \"MdmBot\", \"HomeUnix\", \"Homux\", \"HidraQ\", \"HydraQ\", \"McRat\", \"Aurora\", \"9002 RAT\", \"Trochilus\"]\nAttack_ids: []\nIndustries: [\"Government\", \"Education\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780140093",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "118560a0-1b4e-415b-bc7d-10e422f7ea77",
        "value": "Webworm",
        "Tag": [
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:threat-actor=\"Webworm\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:threat-actor=\"Earth Lusca\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:threat-actor=\"Vicious Panda\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"china\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418807",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "0048f266-6c71-4ac3-9f5b-1e6845855367",
        "value": "CVE-2017-7692"
      },
      {
        "category": "Payload delivery",
        "comment": "WormSocket proxy tool. No sample in VT\r\nLast check:30/05/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780149881",
        "to_ids": true,
        "type": "sha1",
        "uuid": "dffc9a0e-84e9-4a75-8e9a-d06f63c0c12c",
        "value": "948159a7fc2e688386864bea59fd40dffc4b24d6",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "SmuxProxy, a custom iox with hardcoded IP. No sample in VT\r\nLast check:30/05/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780149883",
        "to_ids": true,
        "type": "sha1",
        "uuid": "c519291b-6e2c-4dbc-9f46-f8c59283ede7",
        "value": "a3c077bdf8898e612ccd65bc82e7960834adb2a9",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "EchoCreep backdoor using Discord for C&C. No sample in VT\r\nLast check:30/05/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780149884",
        "to_ids": true,
        "type": "sha1",
        "uuid": "0d73cf9a-c764-459a-b943-2b542a9067f3",
        "value": "cb4e50433336707381429707f59c3cbe8d497d98",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Compromised S3 for frp configurations and data exfiltration.",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150130",
        "to_ids": true,
        "type": "hostname",
        "uuid": "dfe53ad2-1da5-4865-84b9-ca5d90b30724",
        "value": "wamanharipethe.s3.ap-south-1.amazonaws.com",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "WormSocket web socket server.",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150151",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "e2254c3f-1f0e-4833-aa7a-4c36a3974aff",
        "value": "45.77.13.67",
        "Tag": [
          {
            "colour": "#133012",
            "local": false,
            "name": "asn:asn=\"20473\"",
            "relationship_type": ""
          },
          {
            "colour": "#650025",
            "local": false,
            "name": "asn:as-owner=\"AS-VULTR\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "SmuxProxy server.",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150173",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "9d19fe5b-56d6-4c1d-ba39-d458f7257d37",
        "value": "64.176.85.158",
        "Tag": [
          {
            "colour": "#133012",
            "local": false,
            "name": "asn:asn=\"20473\"",
            "relationship_type": ""
          },
          {
            "colour": "#650025",
            "local": false,
            "name": "asn:as-owner=\"AS-VULTR\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "SmuxProxy server.",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150194",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "ce41e117-9d80-4abc-beb6-c0c1326a7918",
        "value": "104.243.23.43",
        "Tag": [
          {
            "colour": "#bf982b",
            "local": false,
            "name": "asn:asn=\"25820\"",
            "relationship_type": ""
          },
          {
            "colour": "#4a30c9",
            "local": false,
            "name": "asn:as-owner=\"IT7NET\"",
            "relationship_type": ""
          },
          {
            "colour": "#1273fb",
            "local": false,
            "name": "asn:as-country=\"CA\"",
            "relationship_type": ""
          },
          {
            "colour": "#813aa0",
            "local": false,
            "name": "misp-galaxy:country=\"canada\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "WormFrp proxy server.",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150215",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "8491084c-e91a-4290-83d7-635b2dac663e",
        "value": "108.61.200.151",
        "Tag": [
          {
            "colour": "#133012",
            "local": false,
            "name": "asn:asn=\"20473\"",
            "relationship_type": ""
          },
          {
            "colour": "#650025",
            "local": false,
            "name": "asn:as-owner=\"AS-VULTR\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Reverse shell IP discovered on SmuxProxy server.",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150237",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "36b77b75-ae2c-4d40-b0bf-0f17ad3c0ba4",
        "value": "144.168.60.233",
        "Tag": [
          {
            "colour": "#bf982b",
            "local": false,
            "name": "asn:asn=\"25820\"",
            "relationship_type": ""
          },
          {
            "colour": "#4a30c9",
            "local": false,
            "name": "asn:as-owner=\"IT7NET\"",
            "relationship_type": ""
          },
          {
            "colour": "#1273fb",
            "local": false,
            "name": "asn:as-country=\"CA\"",
            "relationship_type": ""
          },
          {
            "colour": "#813aa0",
            "local": false,
            "name": "misp-galaxy:country=\"canada\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780150258",
        "uuid": "029a7f4d-6943-434b-b83a-de1eded0f89c",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "WormFrp proxy tool.",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780150258",
            "to_ids": true,
            "type": "md5",
            "uuid": "da0b0b51-4989-4ee2-b05b-7b32365735d2",
            "value": "ce06d071e7e3b47fac26cc2b97059be7",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "WormFrp proxy tool.",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780149877",
            "to_ids": true,
            "type": "sha1",
            "uuid": "e6b11796-5354-494c-ac6d-919d0b57725f",
            "value": "1df40a4a31b30b62ec33dc6fecc2c4408302adc7",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "WormFrp proxy tool.",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780149877",
            "to_ids": true,
            "type": "sha256",
            "uuid": "98b04fe1-cbd2-4650-a5c2-9448930df090",
            "value": "97a8e5b2bc51f3b3f7cd2117cf0da8fc49bee2e597ecc04637dcfdccfbf7e8e0",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780147305",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "708ba602-c2c6-4417-88bc-b4c3d6965929",
            "value": "98304:f1a4NpkI4Bmk7dYun5lqKkqweWPpU9u/2JeNLhZWTm88nAz+ES:f1zpamkRYunj3+UI+iAz7"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780147305",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "9d204cc9-e69a-494f-840c-a4d22971831a",
            "value": "16189952"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780147305",
            "to_ids": true,
            "type": "vhash",
            "uuid": "de603ac0-c53d-475c-99ee-0118a844032c",
            "value": "017086655d55551d15541az3-z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780147305",
            "to_ids": true,
            "type": "filename",
            "uuid": "635aaa5e-d845-4459-9786-8e02e12e0e2a",
            "value": "_97a8e5b2bc51f3b3f7cd2117cf0da8fc49bee2e597ecc04637dcfdccfbf7e8e0.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  30/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780147305",
            "to_ids": false,
            "type": "text",
            "uuid": "cf562398-b06a-4fd6-8a45-c7096bb325ea",
            "value": "WormFrp proxy tool.\r\nType Description: Win32 EXE\nMicrosoft: PUA:Win64/FRProxy\nVT Total Detection:38/71\nFirst Submission:2025-04-14T07:09:19.000000+00:00\nLast Submission:2026-05-28T07:14:08.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780150279",
        "uuid": "e9dcdfc1-108d-4116-a00f-58cda3079b47",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "GraphWorm backdoor using the Microsoft Graph API for C&C.",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780150279",
            "to_ids": true,
            "type": "md5",
            "uuid": "ac8ffc6d-c2ba-4bed-96c8-f57ece14796c",
            "value": "f06ad246658c9e002c93f80c835f6a56",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "GraphWorm backdoor using the Microsoft Graph API for C&C.",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780149879",
            "to_ids": true,
            "type": "sha1",
            "uuid": "60d631fb-a5b3-43d5-9bb2-bb30c0d7f8a0",
            "value": "77f1970d620216c5fff4e14a6ccc13fccc267217",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "GraphWorm backdoor using the Microsoft Graph API for C&C.",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780149879",
            "to_ids": true,
            "type": "sha256",
            "uuid": "b63a4f0c-57c1-4a13-b33c-2a91046f92a0",
            "value": "6eb6a34252195ddc7f5fb94c4fb382dedde227c4dfee4a80e9e0ee6f80c8bcb1",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780147327",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "7061bb86-4033-4752-9595-cdae8ceb9051",
            "value": "49152:asjXDMnFm2rTGdPaCjFIpIWv54O6RgJXNhx7QFuk:XIGBagF"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780147327",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "b0d16276-aea3-4e1e-9a61-83e21d152d17",
            "value": "2257920"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780147327",
            "to_ids": true,
            "type": "vhash",
            "uuid": "49513109-b442-455b-a587-7b84697f1573",
            "value": "026086551d155d15151560f8za71z23z6085z1bz67z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780147327",
            "to_ids": true,
            "type": "filename",
            "uuid": "bc8711aa-6893-4aa6-b4c1-5f9f4c092683",
            "value": "6eb6a34252195ddc7f5fb94c4fb382dedde227c4dfee4a80e9e0ee6f80c8bcb1.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  30/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780147327",
            "to_ids": false,
            "type": "text",
            "uuid": "1191fa87-8aad-45a8-adc0-1b6c875a431c",
            "value": "GraphWorm backdoor using the Microsoft Graph API for C&C.\r\nType Description: Win32 EXE\nMicrosoft: Trojan:Win32/EchoCreep.Z!MTB\nVT Total Detection:40/71\nFirst Submission:2025-03-20T01:22:47.000000+00:00\nLast Submission:2026-05-25T15:59:31.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780150300",
        "uuid": "8f2719a8-25b5-446e-a932-b4b95ed80fde",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "WormHole proxy tool.",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780150300",
            "to_ids": true,
            "type": "md5",
            "uuid": "f9f1fe44-fb02-4934-a247-2659d43dd064",
            "value": "efa6c7cc38e94a1d3e5e6b7f52181de4",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "WormHole proxy tool.",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780149880",
            "to_ids": true,
            "type": "sha1",
            "uuid": "f4bfac5d-a43a-4765-8981-1de177aa0d5a",
            "value": "7dcfe9ee25841dfd58d3d6871bf867fe32141dfb",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "WormHole proxy tool.",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780149880",
            "to_ids": true,
            "type": "sha256",
            "uuid": "d926ec39-13c4-4c25-91f4-447882cf7b32",
            "value": "bd93fd7c18fdb514d451f8faf64a68584e967403ef5f75886ccafbadb203f422",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780147349",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "399b0d32-25cc-4d48-b100-50074d977149",
            "value": "96:mXrlvuNvSgtgIdLukUupTFQIkdmou4n/J0pFW9moPPYW3Ew5H+KEAOjUBo7No/zj:gukbIBUu92IIZJ0A1zH+KKjUo7+p"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780147349",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "a2ca6fa5-1a2d-4991-a22f-ccd66814e693",
            "value": "10240"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780147349",
            "to_ids": true,
            "type": "vhash",
            "uuid": "0bdfd83d-0ec9-4933-aa25-e439baec97b1",
            "value": "21403655151a08151z26"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780147349",
            "to_ids": true,
            "type": "filename",
            "uuid": "81e8b16a-87c5-4199-8533-519a519479c9",
            "value": "csocks.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  30/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780147349",
            "to_ids": false,
            "type": "text",
            "uuid": "0988cffe-2f82-4dd6-b481-e71713a31668",
            "value": "WormHole proxy tool.\r\nType Description: Win32 EXE\nMicrosoft: HackTool:Win32/FRProxy!MSR\nVT Total Detection:34/71\nFirst Submission:2025-10-31T08:00:45.000000+00:00\nLast Submission:2026-05-28T07:11:33.000000+00:00"
          }
        ]
      }
    ]
  }
}