{
  "Event": {
    "analysis": "1",
    "date": "2026-05-25",
    "extends_uuid": "",
    "info": "[Threat Intel] RemotePE: The Lazarus RAT that lives in memory",
    "protected": false,
    "publish_timestamp": "1780293121",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780293121",
    "uuid": "97638d90-a35a-4490-80dd-f2e3d548c42e",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-original-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#5c57c8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5a258",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Archive Collected Data - T1560\"",
        "relationship_type": ""
      },
      {
        "colour": "#461928",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Indicator Blocking - T1562.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b0fe1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Masquerade Task or Service - T1036.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#1cbe6b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"",
        "relationship_type": ""
      },
      {
        "colour": "#62f4c1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#356c41",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"",
        "relationship_type": ""
      },
      {
        "colour": "#07a4a1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Encoding - T1132\"",
        "relationship_type": ""
      },
      {
        "colour": "#3c0f50",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e1e63b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DLL Side-Loading - T1574.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Environmental Keying - T1480.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:threat-actor=\"Lazarus Group\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#110041",
        "local": false,
        "name": "rectifyq:sub-category=\"malware-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"APT\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#220082",
        "local": false,
        "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779764405",
        "to_ids": false,
        "type": "link",
        "uuid": "32100202-6363-4e95-920d-bdace4b30668",
        "value": "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779764405",
        "to_ids": false,
        "type": "text",
        "uuid": "7d728676-a6dd-4ac6-b030-d8bf3a44d29b",
        "value": "A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779764405",
        "to_ids": false,
        "type": "text",
        "uuid": "b01902e8-f9e4-4384-8787-5ec4eb3e58d9",
        "value": "Name: RemotePE: The Lazarus RAT that lives in memory\nAuthor: AlienVault\nAdversary: Lazarus\nTags: [\"poolrat\", \"pondrat\", \"dpapiloader\", \"themeforestrat\", \"hellsgate\", \"remotepeloader\", \"remotepe\"]\nTgtd countries: []\nMlwr families: [\"DPAPILoader\", \"RemotePELoader\", \"RemotePE\", \"ThemeForestRAT\", \"PondRAT\", \"POOLRAT\"]\nAttack_ids: [\"T1543.003\", \"T1082\", \"T1106\", \"T1005\", \"T1140\", \"T1055\", \"T1560\", \"T1562.006\", \"T1083\", \"T1036.004\", \"T1497\", \"T1057\", \"T1562.001\", \"T1027\", \"T1573\", \"T1132\", \"T1027.002\", \"T1071.001\", \"T1574.002\", \"T1480.001\"]\nIndustries: [\"Finance\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779764405",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "c3d8370b-6e3a-47bc-a96e-3d064bb2ddf2",
        "value": "Lazarus"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291497",
        "to_ids": true,
        "type": "domain",
        "uuid": "59880712-91ea-4724-8426-2759d9141264",
        "value": "file.name",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291518",
        "to_ids": true,
        "type": "domain",
        "uuid": "f61d77cd-419f-4f61-ac4a-24de83345551",
        "value": "akamaicloud.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291539",
        "to_ids": true,
        "type": "domain",
        "uuid": "e471f5d5-7c31-4958-a8c5-ed72f971da3e",
        "value": "event.name",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291560",
        "to_ids": true,
        "type": "domain",
        "uuid": "e1bc2015-e228-4321-9df0-843d737fe2e4",
        "value": "aes-secure.net",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291582",
        "to_ids": true,
        "type": "domain",
        "uuid": "95f00ca4-08ad-4fde-9532-cc89be171cc8",
        "value": "azureglobalaccelerator.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291603",
        "to_ids": true,
        "type": "url",
        "uuid": "9cb68110-fd27-498b-b9f0-c6d75ed09512",
        "value": "https://docs.dissect.tools/en/stable",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291624",
        "to_ids": true,
        "type": "url",
        "uuid": "ccc142a2-1c3d-463e-9076-e6fa33522871",
        "value": "https://docs.dissect.tools/en/stable/",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291645",
        "to_ids": true,
        "type": "domain",
        "uuid": "a5c140f6-5484-45bc-84f2-cbf692f98729",
        "value": "devicelinkintel.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291666",
        "to_ids": true,
        "type": "domain",
        "uuid": "4d93739d-b6aa-4591-85e0-ca3548907cb1",
        "value": "intelcloudinsights.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291687",
        "to_ids": true,
        "type": "domain",
        "uuid": "8a8ee2cb-4471-4b09-b6b1-1177448982b2",
        "value": "msdeliverycontent.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291708",
        "to_ids": true,
        "type": "hostname",
        "uuid": "9d3e842a-9d23-4f75-83b5-b23c83ce5f5d",
        "value": "docs.dissect.tools",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780291729",
        "to_ids": true,
        "type": "domain",
        "uuid": "15efce83-9d6d-4d42-9759-03584f6d5bd3",
        "value": "livedrivefiles.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1780197370",
        "uuid": "ac9ecad1-722f-4091-94c5-4f972df1c23b",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1780197370",
            "to_ids": false,
            "type": "text",
            "uuid": "f6611aae-1a8b-4f59-bda0-d7434c75ef39",
            "value": "Lazarus_DPAPILoader_Hunting"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1780197370",
            "to_ids": false,
            "type": "comment",
            "uuid": "3c99febb-7941-4e25-b5ab-c948665aea32",
            "value": "Hunting rule to detect DPAPILoader, a loader used to load RemotePE"
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1780197370",
            "to_ids": true,
            "type": "yara",
            "uuid": "c643e1d0-e0fd-4e44-8906-2ed573c10bf3",
            "value": "rule Lazarus_DPAPILoader_Hunting {\r\n  meta:\r\n    description = \"Hunting rule to detect DPAPILoader, a loader used to load RemotePE.\"\r\n    author      = \"Fox-IT / NCC Group\"\r\n  \r\n  strings:\r\n    $msg_1 = \"[!] Could not allocate memory at the desired base!\\n\"\r\n    $msg_2 = \"[!] Virtual section size is out ouf bounds: \"\r\n    $msg_3 = \"[!] Invalid relocDir pointer\\n\"\r\n    $msg_4 = \"[-] Not supported relocations format at %d: %d\\n\"\r\n    $msg_5 = \"[!] Cannot fill imports into 32 bit PE via 64 bit loader!\\n\"\r\n  \r\n  condition:\r\n    any of them and pe.imports(\"Crypt32.dll\", \"CryptUnprotectData\")\r\n}"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1780197395",
        "uuid": "e098d95c-b815-4bd9-9d00-0b63a93898d5",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1780197395",
            "to_ids": false,
            "type": "text",
            "uuid": "bc333d09-3141-45b0-890b-6a99cf928c3a",
            "value": "Lazarus_RemotePE_C2_strings"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1780197395",
            "to_ids": false,
            "type": "comment",
            "uuid": "6029b228-49fa-42be-ad67-50f532490e19",
            "value": "RemotePE strings used for C2"
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1780197395",
            "to_ids": true,
            "type": "yara",
            "uuid": "9f8def83-6ae8-4f67-a87b-05a6d957f4d2",
            "value": "rule Lazarus_RemotePE_C2_strings {\r\n  meta:\r\n    description = \"RemotePE strings used for C2.\"\r\n    author      = \"Fox-IT / NCC Group\"\r\n  \r\n  strings:\r\n    $a = \"MicrosoftApplicationsTelemetryDeviceId\" wide ascii xor\r\n    $b = \"armAuthorization\" wide ascii xor\r\n    $c = \"ai_session\" wide ascii xor\r\n  \r\n  condition:\r\n    uint16(0) == 0x5A4D and all of them\r\n}"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1780197414",
        "uuid": "24d94113-e568-4d60-a99b-81c7d46855dd",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1780197414",
            "to_ids": false,
            "type": "text",
            "uuid": "10c5e09c-5e34-41cf-85a8-1ceeb8c66e4c",
            "value": "Lazarus_RemotePE_class_strings"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1780197414",
            "to_ids": false,
            "type": "comment",
            "uuid": "29597b6a-3e24-412b-b8b7-ab325bd5deca",
            "value": "RemotePE class strings"
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1780197414",
            "to_ids": true,
            "type": "yara",
            "uuid": "82b1fed5-c81e-4696-a5c1-3c3ce68498f2",
            "value": "rule Lazarus_RemotePE_class_strings {\r\n  meta:\r\n    description = \"RemotePE class strings.\"\r\n    author      = \"Fox-IT / NCC Group\"\r\n  \r\n  strings:\r\n    $a = \"IMiddleController\" ascii wide xor\r\n    $b = \"IChannelController\" ascii wide xor\r\n    $c = \"IConfigProfile\" ascii wide xor\r\n    $d = \"IKernelModule\" ascii wide xor\r\n  \r\n  condition:\r\n    all of them\r\n}"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1780197429",
        "uuid": "464649a9-a0cd-4abd-84e0-6157ba2eea71",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1780197429",
            "to_ids": false,
            "type": "text",
            "uuid": "35e87bfa-439d-470c-819b-def6433b07fd",
            "value": "Lazarus_RemotePE_DPAPI_Encrypted_config"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1780197429",
            "to_ids": false,
            "type": "comment",
            "uuid": "c093aac8-4bab-4612-bab7-feae9e08458f",
            "value": "Detects RemotePE DPAPI-encrypted config on disk"
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1780197429",
            "to_ids": true,
            "type": "yara",
            "uuid": "5d3455f6-c89a-4e8f-9510-e963fa5beb4d",
            "value": "rule Lazarus_RemotePE_DPAPI_Encrypted_config {\r\n  meta:\r\n    description = \"Detects RemotePE DPAPI-encrypted config on disk\"\r\n    author      = \"Fox-IT Security Research Team\"\r\n  condition:\r\n    filesize == 3094\r\n    and uint32(0) == 0x00000001      // DPAPI blob version = 1\r\n    and uint32(0x8E) == 0x00000B40   // dwDataLen = 0xB40 (padded config)\r\n}"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780291750",
        "uuid": "99308dbd-96d1-4204-96d0-abe31416e4b2",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "DPAPILoader (sspicli.dll)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780291750",
            "to_ids": true,
            "type": "md5",
            "uuid": "bbb25101-212d-4d9e-81ea-302411ed02c4",
            "value": "23c2569a65870a9e412d98d5b3bdc554",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "DPAPILoader (sspicli.dll)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780287808",
            "to_ids": true,
            "type": "sha1",
            "uuid": "2e6e6662-4b1d-46c9-9baf-bfcb5e85187a",
            "value": "91def0a4dd9b35510d7f8897bc114f975a5d7e2b",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "DPAPILoader (sspicli.dll)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780287808",
            "to_ids": true,
            "type": "sha256",
            "uuid": "9b5092ca-ecb6-4a14-86dd-400acd0d2730",
            "value": "159471e1abc9adf6733af9d24781fbf27a776b81d182901c2e04e28f3fe2e6f3",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780287179",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "cd8eada0-940b-4083-9d47-1172949a7de9",
            "value": "6144:PgBn6NlE0c6H3vY0bDTn/fqveD2BNww/uqKMR477eew8NR591/Xz5:oBnYY0bDT/fulDwwWARo/Zj"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780287179",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "b8fafe47-1422-4d8e-81a2-98d276bef774",
            "value": "418304"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780287179",
            "to_ids": true,
            "type": "vhash",
            "uuid": "0a9bc55a-4d66-449a-bde1-ee62736573f4",
            "value": "145076655d1555155515z12z653z4xz6c"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780287179",
            "to_ids": true,
            "type": "filename",
            "uuid": "8875bf07-afd1-48bb-8c91-2ab20ba71e42",
            "value": "sspicli.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 01/06/2026\nLast-scan\t:  27/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780287179",
            "to_ids": false,
            "type": "text",
            "uuid": "5e13395b-cb23-46d2-92d7-de3f84ef8420",
            "value": "DPAPILoader (sspicli.dll)\r\nType Description: Win32 DLL\nMicrosoft: Trojan:Win32/Alevaul!rfn\nVT Total Detection:48/71\nFirst Submission:2024-03-11T11:12:09.000000+00:00\nLast Submission:2025-09-03T10:35:12.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780291771",
        "uuid": "d81831bf-4702-4f97-b2ed-a32991393538",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "DPAPILoader (wmiclnt.dll)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780291771",
            "to_ids": true,
            "type": "md5",
            "uuid": "50029bb9-a418-4a0c-ba84-88aa83db0fc3",
            "value": "75a46b23825ce7aa4ca297d93450f4e2",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "DPAPILoader (wmiclnt.dll)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780287809",
            "to_ids": true,
            "type": "sha1",
            "uuid": "13afb3f7-44bd-4653-a6a6-07416876b205",
            "value": "3b994549ab4fd9024b2f0155094d7aa43b70bb8f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "DPAPILoader (wmiclnt.dll)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780287809",
            "to_ids": true,
            "type": "sha256",
            "uuid": "e36e1aa8-e187-4e93-9cd2-8f229801726b",
            "value": "aa4a2d1215f864481994234f13ab485b95150161b4566c180419d93dda7ac039",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780287202",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "07b8f2a7-937c-4079-8f00-b335c4963b28",
            "value": "6144:9nz0pq3O6sU6s1USOkObwlXrsiHWYLw/KwLv:Z/3O6sU60OkObw3HWY0/K"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780287202",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "a4ead13b-61da-403c-bba9-afc767fe0cfc",
            "value": "316928"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780287202",
            "to_ids": true,
            "type": "vhash",
            "uuid": "2a63a1f6-3e4f-4382-abb9-436e3a698bba",
            "value": "135076655d155515155083z12z5b1z3043z23z15z1dz1e"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780287202",
            "to_ids": true,
            "type": "filename",
            "uuid": "bf18ef8f-b7c2-40f3-869d-7f568fde31d1",
            "value": "wmiclnt.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 01/06/2026\nLast-scan\t:  28/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780287202",
            "to_ids": false,
            "type": "text",
            "uuid": "6c5b5038-0e50-46e5-a0be-c2a75d5886d5",
            "value": "DPAPILoader (wmiclnt.dll)\r\nType Description: Win32 DLL\nMicrosoft: Trojan:Win32/Alevaul!rfn\nVT Total Detection:45/71\nFirst Submission:2024-08-21T23:39:52.000000+00:00\nLast Submission:2024-08-21T23:41:54.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780291792",
        "uuid": "6c161023-5292-4ef7-a2d7-cf8e8ad4aa3e",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2023-07-04)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780291792",
            "to_ids": true,
            "type": "md5",
            "uuid": "95e12cff-9f07-4d5a-ba9b-5011dd313480",
            "value": "781e02b32ed5dff6e512d9850a5b5403",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2023-07-04)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780287810",
            "to_ids": true,
            "type": "sha1",
            "uuid": "e13bcd10-b9c0-4fde-a6b8-6331b44c0c71",
            "value": "ea5cfdcab1e4894bebdb8f0a9652c4a4ae190933",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2023-07-04)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780287810",
            "to_ids": true,
            "type": "sha256",
            "uuid": "2bcb2ff8-34dd-4c41-bae0-6cf77e528c89",
            "value": "37f5afb9ed3761e73feb95daceb7a1fdbb13c8b5fc1a2ba22e0ef7994c7920ef",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780287224",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "e027aecf-b6ac-458a-af89-385da5ff4c7c",
            "value": "6144:v0TRv97oOrE9Py7tXztt4LStDLt5xvcgA2VQd8L55Wf0Kg0R68b23/UEZcSa/TB3:8TrZtDZAnuV5Wf0I6d1ZBgTmQ95omr"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780287224",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "48e9e5af-9272-49d7-93e9-93c8256cae2d",
            "value": "550912"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780287224",
            "to_ids": true,
            "type": "vhash",
            "uuid": "e3d8dda8-8c24-47e8-8f44-dc575fb8a330",
            "value": "155066655d15551550b3z42z79jz35zabz"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780287224",
            "to_ids": true,
            "type": "filename",
            "uuid": "2f60b053-270f-4446-bcdb-33ad813708ca",
            "value": "37f5afb9ed3761e73feb95daceb7a1fdbb13c8b5fc1a2ba22e0ef7994c7920ef.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 01/06/2026\nLast-scan\t:  31/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780287224",
            "to_ids": false,
            "type": "text",
            "uuid": "fea40450-6f64-45fc-a786-2b5eee05b70d",
            "value": "RemotePE (2023-07-04)\r\nType Description: Win32 DLL\nMicrosoft: Trojan:Win32/Qwexlafiba!rfn\nVT Total Detection:32/71\nFirst Submission:2026-05-22T15:07:51.000000+00:00\nLast Submission:2026-05-24T07:33:39.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780291813",
        "uuid": "1a6aa08e-2acf-4a06-90f5-35f2872d85c0",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "DPAPILoader (Iassvc.dll)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780291813",
            "to_ids": true,
            "type": "md5",
            "uuid": "f4375fdb-efb5-4bf3-b515-4d9bde9f0159",
            "value": "40c45ad6fef563af8a73dd48a38dc8ba",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "DPAPILoader (Iassvc.dll)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780287811",
            "to_ids": true,
            "type": "sha1",
            "uuid": "7caa921f-b761-4699-9a56-171f9bc05c5d",
            "value": "81c744562d568a0e8a6938df0abc5fba7cfcb3b4",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "DPAPILoader (Iassvc.dll)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780287811",
            "to_ids": true,
            "type": "sha256",
            "uuid": "8ff16057-768c-479e-b0dd-49ea5d2d7df3",
            "value": "4f6ae0110cf652264293df571d66955f7109e3424a070423b5e50edc3eb43874",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780287246",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "ea16af60-bf28-4fc1-b930-e404f8abe8e2",
            "value": "6144:JWXvIZ8t6iLoRrQo12IF0XQ4avP3RZm1TdIEHxW1rH5sF:J8AZ+6pF8QV3RZmxdRiNs"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780287246",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "0747e12c-2d1f-4c14-8575-3e78865923ed",
            "value": "401920"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780287246",
            "to_ids": true,
            "type": "vhash",
            "uuid": "bf3e2851-662f-4d29-aee9-9e383a3ecd7c",
            "value": "145076655d155515551023z12z683z4yz1"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780287246",
            "to_ids": true,
            "type": "filename",
            "uuid": "b910f4a1-9f5b-4123-9738-ea3aec288d75",
            "value": "Iassvc.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 01/06/2026\nLast-scan\t:  31/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780287246",
            "to_ids": false,
            "type": "text",
            "uuid": "da8cd4e2-f24b-4602-b671-b29a757f69d9",
            "value": "DPAPILoader (Iassvc.dll)\r\nType Description: Win32 DLL\nMicrosoft: Trojan:Win32/Qwexlafiba!rfn\nVT Total Detection:49/71\nFirst Submission:2026-05-22T15:07:47.000000+00:00\nLast Submission:2026-05-22T15:07:47.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780291834",
        "uuid": "3f6d4048-1586-4238-927d-329b847a19af",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "RemotePELoader (decrypted from disk)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780291834",
            "to_ids": true,
            "type": "md5",
            "uuid": "46bd594a-7751-4391-b515-312790a0e10e",
            "value": "85766786fd00957737f1c88632ab9e0d",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePELoader (decrypted from disk)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780287812",
            "to_ids": true,
            "type": "sha1",
            "uuid": "cd13a76c-86a8-46a4-96d2-e67503e956b6",
            "value": "3142704d014ed89d1b4d538b6aa796bd371b6990",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePELoader (decrypted from disk)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780287812",
            "to_ids": true,
            "type": "sha256",
            "uuid": "d4e3c213-c370-427f-913f-8a0eacbe0f11",
            "value": "7a05188ab0129b0b4f38e2e7599c5c52149ce0131140db33feb251d926428d68",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780287267",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "00cb5237-79bb-4eb5-8478-6899df1cf2e8",
            "value": "6144:76/98c77QqvnI6kJd9jeVy0Bq13jM5FTNZ7ohMC27U:7eDQII1JdVee13w5PZ7oa"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780287267",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "288909ea-c669-488b-8f8c-5aa2ce990066",
            "value": "374272"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780287267",
            "to_ids": true,
            "type": "vhash",
            "uuid": "a14db3e3-ddcd-4f18-a594-303b6589656e",
            "value": "135066655d1555155033z32z633z4lzabz"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780287267",
            "to_ids": true,
            "type": "filename",
            "uuid": "b329fc17-89cc-4433-9f8d-3ea97dfd1c1d",
            "value": "7a05188ab0129b0b4f38e2e7599c5c52149ce0131140db33feb251d926428d68.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 01/06/2026\nLast-scan\t:  31/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780287267",
            "to_ids": false,
            "type": "text",
            "uuid": "c313ed3b-23ab-41f4-bab5-2af8f2413c07",
            "value": "RemotePELoader (decrypted from disk)\r\nType Description: Win32 DLL\nMicrosoft: Trojan:Win32/Qwexlafiba!rfn\nVT Total Detection:51/71\nFirst Submission:2026-05-22T15:07:47.000000+00:00\nLast Submission:2026-05-23T15:36:58.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780291855",
        "uuid": "8662b52f-91b4-480e-857a-d6a77ebbebfb",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2023-10-17)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780291855",
            "to_ids": true,
            "type": "md5",
            "uuid": "62917226-11ca-4792-9ca3-bd796fea10b5",
            "value": "ac468b5536a0b3f8c6b88968a7f3761f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2023-10-17)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780287813",
            "to_ids": true,
            "type": "sha1",
            "uuid": "afc39838-7521-4d58-b5ec-f31ed635450a",
            "value": "111904fcc3e2f0fba7b24913a8f54d2b3fd9de06",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2023-10-17)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780287813",
            "to_ids": true,
            "type": "sha256",
            "uuid": "6a353281-3190-402f-b332-1e1bcbdab5bc",
            "value": "6b33d20196267b0d64bca815ca863558d26b17cee77caf62a6cce8eae555ac8d",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780287289",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "758db7cd-178e-4fbf-b81e-a873b9f3d9ef",
            "value": "12288:c9UtuqMzrKMjkQm/WqTYSN5Bfs2qT+Q6oNH:E4udPVjkQG5TLH0Tj6m"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780287289",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "dc358379-5304-4798-bf63-66d5cc8e66ae",
            "value": "553030"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780287289",
            "to_ids": true,
            "type": "vhash",
            "uuid": "9cad6f96-60ce-444f-8843-914fd23dfb58",
            "value": "155066655d15551550b3z22z79hz1035zaaz1"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780287289",
            "to_ids": true,
            "type": "filename",
            "uuid": "fc31e17b-0d4f-4543-b4b7-3584cdf0d5c0",
            "value": "tc2px.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 01/06/2026\nLast-scan\t:  31/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780287289",
            "to_ids": false,
            "type": "text",
            "uuid": "f3ef1df7-c901-458a-beae-2824abd303e5",
            "value": "RemotePE (2023-10-17)\r\nType Description: Win32 DLL\nMicrosoft: Trojan:Win32/Yomal!rfn\nVT Total Detection:47/71\nFirst Submission:2026-05-22T15:07:43.000000+00:00\nLast Submission:2026-05-25T05:35:11.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780291877",
        "uuid": "9127fafe-18e1-4660-afe0-4735760ef332",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2024-04-18)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780291877",
            "to_ids": true,
            "type": "md5",
            "uuid": "577f8fc3-d5df-4ff3-b8b6-c2939e9e4207",
            "value": "6f15a1f78380d204f7f2369749c72b4b",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2024-04-18)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780287814",
            "to_ids": true,
            "type": "sha1",
            "uuid": "a9e50090-77dd-45a4-803c-ff0cfd2a1e47",
            "value": "d32753d7dac47032f96542d6120f101a5cadbb39",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2024-04-18)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780287814",
            "to_ids": true,
            "type": "sha256",
            "uuid": "76e98737-acd6-4373-ad01-273428f530e9",
            "value": "62e040a32aac2d2faa8d2bffa2cf7ab662228cebf9bb78eaa0a633c0b729d119",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780287311",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "5ea38bdf-6585-4971-8489-36bf56579857",
            "value": "6144:gR+A5YeWdGy+QxzmG5uvYjbjtiOdLwrqVXgz+fvW6y4QY1lzuwasW4xGu2aiTB0U:8KwgjbQqVXgaXW6y4Qqfs4NiTmQNpoe"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780287311",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "5fcac868-4db1-4124-a2e2-debbf4de35f1",
            "value": "531456"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780287311",
            "to_ids": true,
            "type": "vhash",
            "uuid": "96272023-ce63-4f03-a100-4cf95e4486d5",
            "value": "155066655d15551550b3z42z7ajz35zabz"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780287311",
            "to_ids": true,
            "type": "filename",
            "uuid": "c0cbcc9d-3f11-44d9-b109-499ea20378a3",
            "value": "62e040a32aac2d2faa8d2bffa2cf7ab662228cebf9bb78eaa0a633c0b729d119.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 01/06/2026\nLast-scan\t:  31/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780287311",
            "to_ids": false,
            "type": "text",
            "uuid": "b8513649-e5b2-4e32-9551-f2fb7ad62d00",
            "value": "RemotePE (2024-04-18)\r\nType Description: Win32 DLL\nMicrosoft: Trojan:Win32/Qwexlafiba!rfn\nVT Total Detection:32/71\nFirst Submission:2026-05-22T15:07:47.000000+00:00\nLast Submission:2026-05-23T15:35:56.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780291898",
        "uuid": "7b630bae-7dcf-4961-b497-a9d61d630d74",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2024-05-11)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780291898",
            "to_ids": true,
            "type": "md5",
            "uuid": "d1723e83-abd6-45af-bd0b-3b29247cc239",
            "value": "557551f8468b55e64af8969e71f9246f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2024-05-11)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780287815",
            "to_ids": true,
            "type": "sha1",
            "uuid": "2d659f5d-8ca3-408e-8692-a57f5a84b49a",
            "value": "2eaefd5a62a3a0d0181f1bee5a5aa0979fa51cf4",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "RemotePE (2024-05-11)",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780287815",
            "to_ids": true,
            "type": "sha256",
            "uuid": "6b51845c-4b69-4d4a-8388-b9fb49419661",
            "value": "710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780287333",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "c69adee2-8b45-41a7-9517-af0afa77d303",
            "value": "12288:9MD3GunM7dSTk4orbeK0dPj/BTSQyQSn+E:98dnHk4O/8VTH6+E"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780287333",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "6f6c1a27-978e-4600-bd35-76aff68ff15e",
            "value": "528896"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780287333",
            "to_ids": true,
            "type": "vhash",
            "uuid": "ab44cc50-b178-4e5f-9d1a-030e282ed656",
            "value": "155066655d15551550b3z42z7ajz35zabz"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780287333",
            "to_ids": true,
            "type": "filename",
            "uuid": "6b01e25d-06f4-4cfd-b658-8c2cdce59d3d",
            "value": "710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 01/06/2026\nLast-scan\t:  01/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780287333",
            "to_ids": false,
            "type": "text",
            "uuid": "639da10c-b72a-43cb-bcba-5f8803bdfca7",
            "value": "RemotePE (2024-05-11)\r\nType Description: Win32 DLL\nMicrosoft: Trojan:Win32/Yomal!rfn\nVT Total Detection:44/71\nFirst Submission:2026-05-22T15:07:47.000000+00:00\nLast Submission:2026-05-22T15:07:47.000000+00:00"
          }
        ]
      }
    ]
  }
}