{
  "Event": {
    "analysis": "1",
    "date": "2026-06-24",
    "extends_uuid": "",
    "info": "[Threat Intel] StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon",
    "protected": false,
    "publish_timestamp": "1782459186",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1782459186",
    "uuid": "9af07dd8-dbe3-4b3c-83cb-247740c564b4",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:producer=\"Kaspersky\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#705cef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Domain Account - T1087.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#56c932",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Symmetric Cryptography - T1573.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#2c1d2e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Checks - T1497.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Domain Groups - T1069.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Network Share Discovery - T1135\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5a258",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#9feaf0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#fe1ef0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#07ff3c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#461928",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Indicator Blocking - T1562.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#62f4c1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"",
        "relationship_type": ""
      },
      {
        "colour": "#d82db7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Query Registry - T1012\"",
        "relationship_type": ""
      },
      {
        "colour": "#3c0f50",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#3970d7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"",
        "relationship_type": ""
      },
      {
        "colour": "#e1e63b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DLL Side-Loading - T1574.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#b9e5c8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"NTDS - T1003.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:target-information=\"Colombia\"",
        "relationship_type": ""
      },
      {
        "colour": "#e459c3",
        "local": false,
        "name": "misp-galaxy:target-information=\"Hong Kong\"",
        "relationship_type": ""
      },
      {
        "colour": "#f9cdc4",
        "local": false,
        "name": "misp-galaxy:target-information=\"Indonesia\"",
        "relationship_type": ""
      },
      {
        "colour": "#4cebc3",
        "local": false,
        "name": "misp-galaxy:target-information=\"Lebanon\"",
        "relationship_type": ""
      },
      {
        "colour": "#b4dfcd",
        "local": false,
        "name": "misp-galaxy:target-information=\"North Macedonia\"",
        "relationship_type": ""
      },
      {
        "colour": "#ff41c1",
        "local": false,
        "name": "misp-galaxy:target-information=\"Nepal\"",
        "relationship_type": ""
      },
      {
        "colour": "#199542",
        "local": false,
        "name": "misp-galaxy:target-information=\"Serbia\"",
        "relationship_type": ""
      },
      {
        "colour": "#2613b0",
        "local": false,
        "name": "misp-galaxy:target-information=\"Taiwan\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:target-information=\"Syria\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Cobalt Strike\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Government, Administration\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#110041",
        "local": false,
        "name": "rectifyq:sub-category=\"malware-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:country=\"china\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "link",
        "uuid": "bfb49f10-4fc2-434c-afd8-a812d2abc43e",
        "value": "https://securelist.com/strikeshark-campaign/120326/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "text",
        "uuid": "86b6b739-649f-45a7-8932-7983e83a6884",
        "value": "A previously undocumented malware family named SharkLoader has been discovered delivering Cobalt Strike Beacon to targets worldwide. The threat actor deploys SharkLoader through exploitation of internet-facing applications including Microsoft Exchange, SharePoint, and Openfire Server, as well as through malicious droppers disguised as legitimate software. SharkLoader employs sophisticated techniques including Perfect DLL Hijacking to bypass Windows loader locks, multi-stage decryption using Blowfish and AES encryption, and extensive API hooking via Microsoft Detours and MinHook libraries. Victims include government entities and software development companies across Taiwan, Indonesia, Hong Kong, Lebanon, Syria, Colombia, Macedonia, Nepal, and Serbia. Post-compromise activities focus on Active Directory enumeration, credential dumping, and system reconnaissance. The campaign demonstrates both targeted and opportunistic characteristics, with potential cyber-espionage objectives, though attribution remains unc..."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "text",
        "uuid": "9e03afd6-10cb-490e-b805-70536abcc562",
        "value": "Name: StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon\nAuthor: AlienVault\nAdversary: \nTags: [\"searchall\", \"cve-2025-55182\", \"software development\", \"cve-2021-36260\", \"sharkloader\", \"sharpgpoabuse\", \"cve-2023-20198\", \"cve-2022-40684\", \"cve-2024-36401\", \"fscan\", \"api hooking\", \"credential dumping\", \"cve-2024-21762\", \"pillager\", \"cve-2023-46747\", \"cve-2022-41082\", \"southeast asia\", \"cve-2021-26855\", \"dll hijacking\", \"cobalt strike\", \"cve-2021-27076\", \"government targeting\", \"cve-2023-32315\", \"cve-2016-4437\", \"cve-2022-27925\"]\nTgtd countries: [\"Colombia\", \"Hong Kong\", \"Indonesia\", \"Lebanon\", \"North Macedonia\", \"Nepal\", \"Serbia\", \"Syrian Arab Republic\", \"Taiwan\"]\nMlwr families: [\"SharkLoader\", \"Cobalt Strike - S0154\", \"FScan\", \"Searchall\", \"Pillager\", \"SharpGPOAbuse\"]\nAttack_ids: [\"T1053.005\", \"T1087.002\", \"T1573.001\", \"T1497.001\", \"T1069.002\", \"T1135\", \"T1082\", \"T1106\", \"T1140\", \"T1190\", \"T1055\", \"T1505.003\", \"T1003.001\", \"T1562.006\", \"T1083\", \"T1057\", \"T1012\", \"T1027.002\", \"T1071.001\", \"T1018\", \"T1574.002\", \"T1003.003\"]\nIndustries: [\"Government\", \"Technology\"]"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "6553b573-8833-4559-beed-d49ba3907c6a",
        "value": "CVE-2016-4437"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "3363c00f-54d3-40ad-87c6-4d93503e49e5",
        "value": "CVE-2021-26855"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "111a6aa7-7507-4c6f-ad97-0cbcd4f9588e",
        "value": "CVE-2021-27076"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "d72e6e0b-faae-42bc-b62d-b8902c5a0d78",
        "value": "CVE-2021-36260"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782457064",
        "to_ids": true,
        "type": "domain",
        "uuid": "2eb6de7e-ba75-4746-8d15-c0b00bc0db78",
        "value": "connect-microsoft.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "8029549e-f299-484c-8f6f-526151626575",
        "value": "CVE-2022-27925"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "d4e0ecd2-e219-4750-8f45-e966cc50bd37",
        "value": "CVE-2022-41082"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "7a99f415-93f9-48e5-9381-52af8630d20b",
        "value": "CVE-2022-40684"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "1fc8a0de-e3ab-492a-a57f-ced1b0d73de3",
        "value": "CVE-2023-32315"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "1bec9e70-4786-4ed7-b467-798f13387ce1",
        "value": "CVE-2023-20198"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "24e6cdd0-a6df-4a00-bbec-d53c1a4110ef",
        "value": "CVE-2023-46747"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "8978847f-39df-43a0-a733-4b1a25eeb76c",
        "value": "CVE-2024-21762"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "bf5afe2d-abf9-410d-89de-b4a8d83af923",
        "value": "CVE-2024-36401"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356412",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "ace61a60-8d28-4bac-b53d-814d8d5fd2c0",
        "value": "CVE-2025-55182"
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456052",
        "to_ids": true,
        "type": "md5",
        "uuid": "d8403849-71cd-4b78-a3cb-074224c4e708",
        "value": "24fcebdeecba65004fdb0923763d74fd",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456054",
        "to_ids": true,
        "type": "md5",
        "uuid": "a9f93c7e-16f9-43a8-ab39-e21321aaba02",
        "value": "9cbd560f820c95d7c38342cd558cb5c6",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456055",
        "to_ids": true,
        "type": "md5",
        "uuid": "c0e95945-091d-406e-a20a-edb5468a057c",
        "value": "a514d1bb62d7916475946fe7c07ac0aa",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456056",
        "to_ids": true,
        "type": "md5",
        "uuid": "ca1b6bee-fe51-400e-a70a-b121c9d37f8d",
        "value": "aa3086be652c8b20b0b29b2730d57119",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456057",
        "to_ids": true,
        "type": "md5",
        "uuid": "1a5ef735-a13c-4ab4-a0fb-5666ae0f48b6",
        "value": "b3352b42432dedc4a519f011dc8b5d5a",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782457085",
        "to_ids": true,
        "type": "domain",
        "uuid": "ed394fcb-cd11-4cb4-89fc-e914cd363ae4",
        "value": "ms-record.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782457106",
        "to_ids": true,
        "type": "domain",
        "uuid": "9c10ff70-b49c-42e6-9c03-14e5a8d2ad9b",
        "value": "ms-record.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782457128",
        "to_ids": true,
        "type": "domain",
        "uuid": "701c41e8-705e-4585-951e-263f6f70082f",
        "value": "ms-tray.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1782457149",
        "uuid": "18885901-4454-4cc0-97a7-cd3100cb8add",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1782457149",
            "to_ids": true,
            "type": "md5",
            "uuid": "cdaed8f1-fcde-4520-a0ff-79b170d47bea",
            "value": "1f65544978b8ea0e745e573b8ee9684b",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1782456047",
            "to_ids": true,
            "type": "sha1",
            "uuid": "c504b252-8a04-4ade-b4f6-1fbf45122929",
            "value": "139c7a9f824bcf6db4407f38413ef817ebef64a8",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1782456047",
            "to_ids": true,
            "type": "sha256",
            "uuid": "1478b7ba-0d47-4534-9e98-9d2618334f71",
            "value": "e534d9032141555d21be8b23f30d8f6dd156d61e986bbeed019d9316973b1ba9",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1782454919",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "2c25e4ab-df90-475d-b0e3-84b67e3988ca",
            "value": "98304:aZNPk6sokUUS5iWlAXIxKWX/XBYFLOAkGkzdnEVomFHKnP:adsoXiIQEfBYFLOyomFHKnP"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1782454919",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "e6ebb8cd-7433-4e0b-a06e-d611ac5efb97",
            "value": "4982584"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1782454919",
            "to_ids": true,
            "type": "vhash",
            "uuid": "c79c3d8d-cb62-4d43-958d-3ef19c5140a0",
            "value": "046076655d7565157550b012z6100a96z160d5za0800de3z19z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1782454919",
            "to_ids": true,
            "type": "filename",
            "uuid": "fda62cad-3274-452d-89cd-be821a1a5f53",
            "value": "GoogleUpdateStepup.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 26/06/2026\nLast-scan\t:  24/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1782454919",
            "to_ids": false,
            "type": "text",
            "uuid": "9ac27cce-2710-4f4c-9ed9-ee8d42f66ccc",
            "value": "Type Description: Win32 EXE\nMicrosoft: Trojan:Win64/CobaltStrike!rfn\nVT Total Detection:31/70\nFirst Submission:2024-02-22T16:44:34.000000+00:00\nLast Submission:2024-02-23T18:14:30.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1782457170",
        "uuid": "cedec904-bd75-42eb-ad9c-4d0c53d505f3",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1782457170",
            "to_ids": true,
            "type": "md5",
            "uuid": "d1879dbe-def8-4ff0-a884-b17d8da0013d",
            "value": "9c872a0d5d5a38950e8b9ac9b488be3f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1782456048",
            "to_ids": true,
            "type": "sha1",
            "uuid": "be92be10-4fff-4ef4-ae6f-c9b1a8a7eecb",
            "value": "25b6e2e6e2f4e8a5bf9601e224fb95331ce961f0",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1782456048",
            "to_ids": true,
            "type": "sha256",
            "uuid": "647b7125-9308-4ed7-8359-63ffcfd57bf5",
            "value": "fd24171da9e0d9530e53717244fe6dde6220c61a9961143757a2d033f087b4cd",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1782454962",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "f8e052f9-4a97-4535-bd85-58dc30b5a4c0",
            "value": "3072:kr2Vh7BdHU49ENS0Pa9ifogqCbJkrLb32iHbLjartxk07c1ehZ+:/Vtn0OOgQXZbJkrP3R7LjCw"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1782454962",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "335cde06-249b-4154-b88b-8302d4a621fd",
            "value": "246784"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1782454962",
            "to_ids": true,
            "type": "vhash",
            "uuid": "da3da8c6-c4d0-4bd0-99fc-a8a6b804c600",
            "value": "125086655d15551d05155az513z5bz1lz"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1782454962",
            "to_ids": true,
            "type": "filename",
            "uuid": "f5552fdf-eb1d-4fcd-92fa-c4d1c2fe70d3",
            "value": "SystemSetting.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 26/06/2026\nLast-scan\t:  26/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1782454962",
            "to_ids": false,
            "type": "text",
            "uuid": "3a5e1177-9894-4e89-96d0-2edea99c0159",
            "value": "Type Description: Win32 DLL\nMicrosoft: Trojan:Win32/Ravartar!rfn\nVT Total Detection:27/71\nFirst Submission:2025-07-30T09:37:56.000000+00:00\nLast Submission:2025-07-30T09:37:56.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1782457191",
        "uuid": "702964d8-de4f-40b2-ab9b-0197c8d02202",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1782457191",
            "to_ids": true,
            "type": "md5",
            "uuid": "7acc9ed1-29a0-41f0-b5f2-3b600e9abd48",
            "value": "c559cc68986933200fd5d9e4388e2f58",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1782456050",
            "to_ids": true,
            "type": "sha1",
            "uuid": "a73a1486-da48-4d91-9ea6-e08f4b0f635b",
            "value": "23fd50b3bcc06f5adcbd0122c32260786ec3b98a",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1782456050",
            "to_ids": true,
            "type": "sha256",
            "uuid": "d05dc462-49ad-45e3-aff6-2c7621b14606",
            "value": "6a5f9bd0e4a0c385b98cc7b528be53a95ff9c4ccffa8c1f65448ab792a46186c",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1782455068",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "5e9288b2-8fa9-4a4a-b9e5-feaa79608f04",
            "value": "393216:I7w3GcyVXOCNcZ7g7HnmoM4YIPT+pBrvBTcpbYUx+7xQxzCau010Y4F:tAXcJgjm+Y+iB9w6UxKxbaB"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1782455068",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "e08f3c78-2acc-4d3d-b61b-653d61a99565",
            "value": "24626688"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1782455068",
            "to_ids": true,
            "type": "vhash",
            "uuid": "097a8db9-6cdb-466e-90a4-aca8dacde1e8",
            "value": "027086655d75651d057550b012z6100aa6z160d5zb0800dd3z19z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1782455068",
            "to_ids": true,
            "type": "filename",
            "uuid": "b894a66d-3eb6-4d37-95f9-e8a5c08cbb4a",
            "value": "AnyConnect-win-4.10.04071-predeploy-k9.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 26/06/2026\nLast-scan\t:  26/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1782455068",
            "to_ids": false,
            "type": "text",
            "uuid": "fe99b382-00ec-43b7-a1c6-903a625e9176",
            "value": "Type Description: Win32 EXE\nMicrosoft: Trojan:Win64/CobaltStrike!rfn\nVT Total Detection:42/71\nFirst Submission:2025-11-04T06:02:17.000000+00:00\nLast Submission:2025-11-04T06:02:17.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1782457212",
        "uuid": "7d0bed5a-945a-480a-9b9a-99aff78b4c74",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1782457212",
            "to_ids": true,
            "type": "md5",
            "uuid": "f0c5e72a-c3b6-4452-98d2-97cd8bc1ec55",
            "value": "d98f568496512e4f98670c61c97cb07a",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#2c2142",
                "local": false,
                "name": "false-positive:risk=\"high\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1782456051",
            "to_ids": true,
            "type": "sha1",
            "uuid": "0401d326-4e08-46e8-aba0-77bca9866a6a",
            "value": "31052fe26b7e08e0e02137cf1d54c40d704378cd",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#2c2142",
                "local": false,
                "name": "false-positive:risk=\"high\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1782456051",
            "to_ids": true,
            "type": "sha256",
            "uuid": "66eb0204-c551-4144-88d9-076dc5e30347",
            "value": "aff35cc83ff53eca577d6fcdf68f90e5e2f648d33e2fb28b93ae7906cfd1544b",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#2c2142",
                "local": false,
                "name": "false-positive:risk=\"high\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1782455090",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "05ae4aee-0662-4ed9-ac12-f89fbcda8b40",
            "value": "1536:+2RifH09UTamiVQSPpTr2fFLe7qomIcoKCE45nHQM7rTPk9Hn:+2RifH0fWFcQIctoTCH"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1782455090",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "3ed2eea2-4b27-4c49-89d0-5770021444cf",
            "value": "97080"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1782455090",
            "to_ids": true,
            "type": "vhash",
            "uuid": "25008b3f-5e8f-479e-a0db-30f97d71cdcb",
            "value": "0940765c051d1515151cz15=z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1782455090",
            "to_ids": true,
            "type": "filename",
            "uuid": "43b1584e-aeee-47d8-83b2-61ab7c0a40fd",
            "value": "SystemSettings.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 26/06/2026\nLast-scan\t:  24/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1782455090",
            "to_ids": false,
            "type": "text",
            "uuid": "650217cc-9593-4b8c-a1d5-a54f88c0cd5d",
            "value": "Type Description: Win32 EXE\nFile distributed by: ['Microsoft']\nData sources: ['National Software Reference Library (NSRL)']\nVerdict filename: ['SystemSettings.exe']\nMicrosoft: None\nVT Total Detection:0/70\nFirst Submission:2021-08-31T22:39:33.000000+00:00\nLast Submission:2026-05-21T23:04:38.000000+00:00"
          }
        ]
      }
    ]
  }
}