{
  "Event": {
    "analysis": "1",
    "date": "2026-05-28",
    "extends_uuid": "",
    "info": "[Threat Intel] A miner with a side of RAT: the unintended gift with your TV show or book",
    "protected": false,
    "publish_timestamp": "1780377446",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1780377446",
    "uuid": "92c2564d-b7dd-46df-94ff-b63fa34fed48",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:producer=\"Kaspersky\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#bb2745",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Standard Encoding - T1132.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Domain Generation Algorithms - T1568.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#110e53",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DNS - T1071.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#56c932",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Symmetric Cryptography - T1573.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#5c57c8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#2c1d2e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Checks - T1497.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#e00500",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Access Tools - T1219\"",
        "relationship_type": ""
      },
      {
        "colour": "#75ec20",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"",
        "relationship_type": ""
      },
      {
        "colour": "#bf01b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#62f4c1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4bc785",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Security Software Discovery - T1518.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#02475d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#e1e63b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DLL Side-Loading - T1574.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#120044",
        "local": false,
        "name": "rectifyq:sub-category=\"intrusion-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"Cybercrime\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780023616",
        "to_ids": false,
        "type": "link",
        "uuid": "71fee224-d5e4-46db-864d-2e48b5213f18",
        "value": "https://securelist.com/video-books-pirates-miners-rat/119943/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780023616",
        "to_ids": false,
        "type": "text",
        "uuid": "729af05f-d5a6-44aa-ab6f-1eebfb5ef3ab",
        "value": "A cybercrime campaign active since at least 2022 has been distributing cryptocurrency miners and RAT malware through illegal streaming sites and digital libraries. Victims are tricked via fake video player plugin updates or browser crash pages into downloading ZIP archives containing legitimate executables and malicious DLLs. The malware employs DLL side-loading, establishes persistence through Windows services, and deploys multiple components including XMRig-based CPU miners, GPU miners, a watchdog module, and a RAT agent with remote control capabilities. The campaign leverages highly popular pirated content sites with monthly traffic reaching up to 40 million visits, significantly expanding the potential victim pool. The malware includes sophisticated anti-detection features, DNS tunneling for command-and-control, and domain generation algorithms based on dates."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780023616",
        "to_ids": false,
        "type": "text",
        "uuid": "f43ba7e0-315c-49ca-81d5-7b0d9ffc1548",
        "value": "Name: A miner with a side of RAT: the unintended gift with your TV show or book\nAuthor: AlienVault\nAdversary: \nTags: [\"domain generation algorithm\", \"fake updates\", \"xmrig\", \"dns tunneling\", \"silentcryptominer\", \"cryptocurrency miner\", \"dll side-loading\", \"piracy sites\"]\nTgtd countries: []\nMlwr families: [\"XMRig\", \"SilentCryptoMiner\"]\nAttack_ids: [\"T1132.001\", \"T1568.002\", \"T1071.004\", \"T1573.001\", \"T1543.003\", \"T1497.001\", \"T1082\", \"T1140\", \"T1219\", \"T1036\", \"T1112\", \"T1083\", \"T1057\", \"T1547.001\", \"T1562.001\", \"T1055.012\", \"T1027\", \"T1518.001\", \"T1059.003\", \"T1574.002\", \"T1105\"]\nIndustries: []"
      },
      {
        "category": "Payload delivery",
        "comment": "initialization vector",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780204110",
        "to_ids": true,
        "type": "other",
        "uuid": "adefb93c-9e6d-49a5-917f-b8427d0b6d93",
        "value": "000102030405060708090a0b0c0d0e0f"
      },
      {
        "category": "Payload delivery",
        "comment": "AES-CBC with the key",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780204113",
        "to_ids": true,
        "type": "other",
        "uuid": "a34d9dc9-ab8a-454f-930b-32722b317616",
        "value": "0123456789abcdef0123456789abcdef"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780372877",
        "to_ids": true,
        "type": "domain",
        "uuid": "27fed5e9-300b-4973-9b3f-a5407297735b",
        "value": "urush1bar4.online",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "Malicious DLL libraries No sample in VT\r\nLast check:02/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780370724",
        "to_ids": true,
        "type": "md5",
        "uuid": "80debb9f-5f9e-4296-b0a9-ec1217944d7c",
        "value": "02a43b3423367b9dddc24cc7dfc070df",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780372899",
        "to_ids": true,
        "type": "domain",
        "uuid": "589a13c8-b64a-4e45-b049-db754b9fe108",
        "value": "5d14vnfb.space",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780372920",
        "to_ids": true,
        "type": "domain",
        "uuid": "523a8f40-8586-430c-b182-caad19090e1c",
        "value": "jeaw520i.space",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780372941",
        "to_ids": true,
        "type": "domain",
        "uuid": "58d7151b-64c4-4a9b-9f68-24cdf9fb289c",
        "value": "qdmagva5.space",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780372962",
        "to_ids": true,
        "type": "domain",
        "uuid": "bfd7c8b1-0903-48cb-82e6-3d1496505220",
        "value": "r7mvjl67.space",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780372983",
        "to_ids": true,
        "type": "domain",
        "uuid": "b8189aed-23fe-4bf5-b6d8-a9fabb6e052f",
        "value": "zgj1tam9.space",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780373004",
        "to_ids": true,
        "type": "hostname",
        "uuid": "8de7b811-556c-41c2-900d-68dcd0ebec41",
        "value": "file.ipfs.us.69.mu",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Configuration retrieval address",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780373025",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "24621710-6492-40f9-8838-5d3401fd4c0b",
        "value": "107.172.212.235",
        "Tag": [
          {
            "colour": "#6a53a7",
            "local": false,
            "name": "asn:asn=\"36352\"",
            "relationship_type": ""
          },
          {
            "colour": "#9daeac",
            "local": false,
            "name": "asn:as-owner=\"AS-COLOCROSSING\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "UnamWebPanel control panel addresses",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780373046",
        "to_ids": true,
        "type": "domain",
        "uuid": "63aed2e0-f8cd-4e24-8b27-a66b79cabeac",
        "value": "m4yuri.online",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "UnamWebPanel control panel addresses",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780373067",
        "to_ids": true,
        "type": "domain",
        "uuid": "4c00db5f-5170-470a-a44f-d16c0a6240b9",
        "value": "kristina.quest",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780373089",
        "uuid": "35d488fd-d082-43ad-83c8-b3108d911b5d",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "Malicious DLL libraries",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780373089",
            "to_ids": true,
            "type": "md5",
            "uuid": "67422e70-81f6-4953-a39b-1f8c09ecf498",
            "value": "6a0fe6065d76715feebc1526d456db73",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Malicious DLL libraries",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780370722",
            "to_ids": true,
            "type": "sha1",
            "uuid": "a17c0561-b0c2-4f25-8753-1f2472247588",
            "value": "c8f131642c62f5d83010442102e58a51804e479d",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Malicious DLL libraries",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780370722",
            "to_ids": true,
            "type": "sha256",
            "uuid": "f0a86d87-7b86-4d0f-910e-f653d9a6ad09",
            "value": "ae67183bb2d2a33c9f9e36f7c7e68a886bc66927a7d0048d836bead88a11c29f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780368860",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "938dd9c1-411a-49cc-93d6-da984741e397",
            "value": "1572864:q1KQAOLI2nZ7Tw8JCaCp4rMF4aW/mytUPdwZ2oYsvhMaF0p:q1H3XtTdJZCp4rMyWrdlxsBWp"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780368860",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "51910357-e5bb-4710-8edc-cb40d02528a9",
            "value": "83618336"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780368860",
            "to_ids": true,
            "type": "vhash",
            "uuid": "a18f84c2-b91d-4b0e-9784-c84fae9ddbb6",
            "value": "187096655d5555155c7d1bz1=z36"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780368860",
            "to_ids": true,
            "type": "filename",
            "uuid": "4f7a2faf-a4d3-4d2c-96fd-1b6f58efae11",
            "value": "SbieDll.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 02/06/2026\nLast-scan\t:  01/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780368860",
            "to_ids": false,
            "type": "text",
            "uuid": "3c1aece9-6d11-42fb-8bed-d1d96dba6a6b",
            "value": "Malicious DLL libraries\r\nType Description: Win32 DLL\nMicrosoft: None\nVT Total Detection:32/70\nFirst Submission:2025-08-06T10:04:27.000000+00:00\nLast Submission:2025-08-06T10:04:27.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780373110",
        "uuid": "ad360b4e-3297-470d-8baa-748d6c91c682",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "Malicious DLL libraries",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780373110",
            "to_ids": true,
            "type": "md5",
            "uuid": "b280fada-c83c-4ccc-8397-eb4e65c742d5",
            "value": "7f624407ae489324e96a708a09c17e6f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Malicious DLL libraries",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780370723",
            "to_ids": true,
            "type": "sha1",
            "uuid": "9b21ae77-ec2c-4e86-b4a3-a9b593bac401",
            "value": "05d88f914d121018beb6b725b52a39a9eb05e1b1",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Malicious DLL libraries",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780370723",
            "to_ids": true,
            "type": "sha256",
            "uuid": "be2896fd-7b56-4466-92a1-1c06a2aedbe8",
            "value": "30e6206e0a959a8a601130190cdec72e6dfc08494644cc89542e571ee7e37e5a",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780368881",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "51f8ff29-74e8-4046-b1bc-093c7114ecff",
            "value": "1572864:LK53YYEJfWtglSW2Pm7hL2mErDvvjWcizjX9vPH4iHimMtt4HRj7ueLLABEV:G5oYE1W6SW2nmErTj+HXxPH44stt4H1X"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780368881",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "0e741aee-52ac-44e7-8768-0da1a27557dc",
            "value": "83618336"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780368881",
            "to_ids": true,
            "type": "vhash",
            "uuid": "40dc15b6-794d-46db-ab71-5c3604c77e35",
            "value": "187096655d5555155c7d1bz1=z36"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780368881",
            "to_ids": true,
            "type": "filename",
            "uuid": "f58152a7-9794-419e-b194-9e1cf0533dbe",
            "value": "SbieDll.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 02/06/2026\nLast-scan\t:  01/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780368881",
            "to_ids": false,
            "type": "text",
            "uuid": "0b24d8f9-4286-4055-9513-b3455b9ade19",
            "value": "Malicious DLL libraries\r\nType Description: Win32 DLL\nMicrosoft: None\nVT Total Detection:32/69\nFirst Submission:2025-08-06T10:59:22.000000+00:00\nLast Submission:2025-08-06T10:59:22.000000+00:00"
          }
        ]
      }
    ]
  }
}