{
  "Event": {
    "analysis": "1",
    "date": "2026-05-19",
    "extends_uuid": "",
    "info": "[Threat Intel] Exposing Fox Tempest: A malware-signing service operation",
    "protected": false,
    "publish_timestamp": "1780139024",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780139024",
    "uuid": "7d52bcc6-a889-4f8a-a841-d5ae3b3714c5",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#96f4f6",
        "local": false,
        "name": "misp-galaxy:producer=\"Microsoft\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#47d9d3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#3bc6ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Code Signing - T1553.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#bce57a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Web Service - T1567\"",
        "relationship_type": ""
      },
      {
        "colour": "#c8f8ef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Binary Proxy Execution - T1218\"",
        "relationship_type": ""
      },
      {
        "colour": "#ecc598",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Account - T1136.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#755c09",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b95cd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#59699c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#4f539c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Invalid Code Signature - T1036.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#36d931",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Drive-by Compromise - T1189\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#370063",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#b8ab01",
        "local": false,
        "name": "misp-galaxy:target-information=\"United States\"",
        "relationship_type": ""
      },
      {
        "colour": "#098efb",
        "local": false,
        "name": "misp-galaxy:target-information=\"British Indian Ocean Territory\"",
        "relationship_type": ""
      },
      {
        "colour": "#52d590",
        "local": false,
        "name": "misp-galaxy:target-information=\"China\"",
        "relationship_type": ""
      },
      {
        "colour": "#15ccfd",
        "local": false,
        "name": "misp-galaxy:target-information=\"France\"",
        "relationship_type": ""
      },
      {
        "colour": "#013748",
        "local": false,
        "name": "misp-galaxy:target-information=\"India\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003f",
        "local": false,
        "name": "rectifyq:sub-category=\"tool-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"Cybercrime\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"Ransomware\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779332419",
        "to_ids": false,
        "type": "link",
        "uuid": "a93f0238-d8bd-495e-8946-c7edba49bf42",
        "value": "https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779332419",
        "to_ids": false,
        "type": "text",
        "uuid": "1052739b-127a-4cdf-92a6-89f9ae235c29",
        "value": "Fox Tempest is a financially motivated threat actor operating a malware-signing-as-a-service (MSaaS) business used by cybercriminals to distribute malicious code, including ransomware. The actor abuses Microsoft Artifact Signing to generate fraudulent code-signing certificates, allowing malware to evade security controls. Fox Tempest created over a thousand certificates and established hundreds of Azure tenants to support operations. Microsoft revoked over one thousand certificates and disrupted the service in May 2026 through the Digital Crimes Unit. The operation enabled ransomware deployment including Rhysida by threat actors like Vanilla Tempest, and distributed malware families including Oyster, Lumma Stealer, and Vidar. The MSaaS was available through signspace[.]cloud, charging between $5000-$9000 USD. Attacks impacted healthcare, education, government, and financial services sectors globally."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779332419",
        "to_ids": false,
        "type": "text",
        "uuid": "e7b66ca5-2514-4660-a80c-aa01e18c3300",
        "value": "Name: Exposing Fox Tempest: A malware-signing service operation\nAuthor: AlienVault\nAdversary: Fox Tempest\nTags: [\"azure abuse\", \"akira\", \"code-signing certificates\", \"msaas\", \"oyster\", \"vidar\", \"ransomware enabler\", \"lumma stealer\", \"oyster backdoor\", \"blackbyte\", \"qilin\", \"malware-signing-as-a-service\", \"rhysida\", \"inc\", \"vanilla tempest\"]\nTgtd countries: [\"United States of America\", \"British Indian Ocean Territory\", \"China\", \"France\", \"India\"]\nMlwr families: [\"Rhysida\", \"Oyster\", \"Lumma Stealer\", \"Vidar\", \"Brave Prince - S0252\", \"Qilin\", \"Akira\", \"BlackByte\"]\nAttack_ids: [\"T1204.002\", \"T1553.002\", \"T1082\", \"T1140\", \"T1567\", \"T1218\", \"T1136.001\", \"T1083\", \"T1059.001\", \"T1566\", \"T1562.001\", \"T1078\", \"T1027\", \"T1036.001\", \"T1486\", \"T1195.002\", \"T1189\", \"T1071.001\", \"T1105\", \"T1021.001\"]\nIndustries: [\"Healthcare\", \"Education\", \"Government\", \"Finance\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780125816",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "6a6de82b-2b69-420e-92a0-6cbbc415cd39",
        "value": "Fox Tempest",
        "Tag": [
          {
            "colour": "#96f4f6",
            "local": false,
            "name": "misp-galaxy:producer=\"Microsoft\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780125942",
        "to_ids": true,
        "type": "x509-fingerprint-sha1",
        "uuid": "51b9496a-c757-4178-89df-8cbd002a1bf8",
        "value": "7e6d9dac619c04ae1b3c8c0906123e752ed66d63"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780125952",
        "to_ids": true,
        "type": "x509-fingerprint-sha1",
        "uuid": "9b8cf30b-a09d-46b9-8194-844588c3fd31",
        "value": "dc0acb01e3086ea8a9cb144a5f97810d291020ce"
      },
      {
        "category": "Network activity",
        "comment": "Attacker-controlled domain hosting MSaaS",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780136084",
        "to_ids": true,
        "type": "domain",
        "uuid": "4bbe06a0-1440-4264-921b-811250f00b69",
        "value": "signspace.cloud",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780136105",
        "uuid": "c73dda4e-fe77-43f8-b25b-d54af6e1f40e",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780136105",
            "to_ids": true,
            "type": "md5",
            "uuid": "a6a2d086-62d7-43c5-9bc0-07c2a42b05ba",
            "value": "95c5341a4bc52b040b07de6739d0646d",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780131027",
            "to_ids": true,
            "type": "sha1",
            "uuid": "ddef464a-c955-410e-b659-21645e5362d6",
            "value": "91d203c2178307970f6b2ffc1d573baea441d200",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780131027",
            "to_ids": true,
            "type": "sha256",
            "uuid": "f7ef07ee-78ec-4325-944d-a18ceaa505f8",
            "value": "11af4566539ad3224e968194c7a9ad7b596460d8f6e423fc62d1ea5fc0724326",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780126580",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "38155f2a-b665-41a4-8698-4ad010457a90",
            "value": "3145728:vLK/oazPL5hnLfIO9iyQ1aqQUNBIH8WIpOxTqErobnnq:vLKDf5lzIIiB1aqQMK8WhTqhnq"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780126580",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "212567bf-66dd-4025-9a87-af10c8c27065",
            "value": "122704336"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780126580",
            "to_ids": true,
            "type": "vhash",
            "uuid": "bce02fdd-1f8b-413f-8d4c-ff06b866b813",
            "value": "018056655d157561z16z64jz1jz"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780126580",
            "to_ids": true,
            "type": "filename",
            "uuid": "a2d2d13c-bcc3-45c0-8e3d-36914bf668de",
            "value": "Desktop.3.5.6.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  30/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780126580",
            "to_ids": false,
            "type": "text",
            "uuid": "8f7c9a70-0559-49d0-a244-d1f9fca04373",
            "value": "Type Description: Win32 EXE\nMicrosoft: Trojan:Win32/LummaStealer\nVT Total Detection:23/69\nFirst Submission:2026-03-21T17:43:00.000000+00:00\nLast Submission:2026-05-29T15:41:07.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780136126",
        "uuid": "42257135-0f36-4abb-adb9-d8f0855cc5b8",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780136126",
            "to_ids": true,
            "type": "md5",
            "uuid": "800941a3-757b-43d6-9d14-510e143a3831",
            "value": "6ac660b0053d07037a7fefe9997fe165",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780131028",
            "to_ids": true,
            "type": "sha1",
            "uuid": "e83d525f-9178-4219-97c1-f37a498bb5e0",
            "value": "2e191c70eb274e16162b27f4282ca51c1ba2fcbd",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780131028",
            "to_ids": true,
            "type": "sha256",
            "uuid": "14ed6947-1c89-4c03-a0a6-438b23976a55",
            "value": "f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780126601",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "57c4e274-3a16-4756-aaf3-b0db9a98e5d5",
            "value": "3145728:C/0SjWYua68jDHZBgYT+GenHazMWvuyzYEI2vBvcSUaQrCs:C/pSS6m5BBT+5HazMgdYE1UPus"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780126601",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "b1bf2672-1b70-4e05-b0a7-2f175067e9a5",
            "value": "122591208"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780126601",
            "to_ids": true,
            "type": "vhash",
            "uuid": "4f6817fa-69be-4c72-9c01-c14b8c14415b",
            "value": "018056655d157561z16z64jz1jz"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780126601",
            "to_ids": true,
            "type": "filename",
            "uuid": "dfbdb177-7be6-417c-981d-8b9c08f43711",
            "value": "Setup.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  29/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780126601",
            "to_ids": false,
            "type": "text",
            "uuid": "488aff50-b799-41d7-9ad2-dfc445634cf0",
            "value": "Type Description: Win32 EXE\nMicrosoft: Trojan:Win32/LummaStealer\nVT Total Detection:17/69\nFirst Submission:2026-03-19T19:03:41.000000+00:00\nLast Submission:2026-04-20T15:34:21.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780136147",
        "uuid": "565660e7-a777-4ae9-a375-f59522f00700",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780136147",
            "to_ids": true,
            "type": "md5",
            "uuid": "0ed4cbe5-bd66-40e3-a7fa-430c3ceae3f8",
            "value": "c310eab8bcc855473c69f77abd8bdb71",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780131028",
            "to_ids": true,
            "type": "sha1",
            "uuid": "cc5cefc0-fb61-49a4-92a7-dab9e289f9c9",
            "value": "ba197e35fc18e31b9cafe59b7d18d63da4564285",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780131028",
            "to_ids": true,
            "type": "sha256",
            "uuid": "6f76e551-31c1-47ae-aeb3-fe21da9d1f17",
            "value": "f0a6b89ec7eee83274cd484cea526b970a3ef28038799b0a5774bb33c5793b55",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780126623",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "051c37aa-4874-4a3c-b7ad-5c3cd5d73339",
            "value": "3145728:VPp8uwd0MK6aH5Y3pK2+G42nlshsCEOxLDrxl8ULNn:4dK6aH5epK2+JylIRLrzL5"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780126623",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "36f6a6cc-e5e5-432b-b19b-cd3e7b23174f",
            "value": "118219800"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780126623",
            "to_ids": true,
            "type": "vhash",
            "uuid": "73ab3d5a-3491-4a5e-af07-69d798c6cd33",
            "value": "018066655d1d05156az953z6gz2dfz"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780126623",
            "to_ids": true,
            "type": "filename",
            "uuid": "8a27007a-072d-4aa5-be1c-3c0184b67f3a",
            "value": "ProfluxeflowAiRC-win-Setup.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  29/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780126623",
            "to_ids": false,
            "type": "text",
            "uuid": "cc92b2e5-1690-4e45-b837-7e0013f565bd",
            "value": "Type Description: Win32 EXE\nMicrosoft: Trojan:Win32/LummaStealer\nVT Total Detection:30/70\nFirst Submission:2026-03-12T19:40:29.000000+00:00\nLast Submission:2026-05-23T22:37:41.000000+00:00"
          }
        ]
      }
    ]
  }
}