{
  "Event": {
    "analysis": "1",
    "date": "2026-05-28",
    "extends_uuid": "",
    "info": "[Threat Intel] Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT",
    "protected": false,
    "publish_timestamp": "1780521449",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780521448",
    "uuid": "f5cbcf38-1444-44ec-ba04-af735b61b5b4",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#4d62fa",
        "local": false,
        "name": "misp-galaxy:producer=\"eSentire\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Archive via Utility - T1560.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#8ee8d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Screen Capture - T1113\"",
        "relationship_type": ""
      },
      {
        "colour": "#e7d48a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"",
        "relationship_type": ""
      },
      {
        "colour": "#bb2745",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Standard Encoding - T1132.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#110e53",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DNS - T1071.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c8fe6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Email Collection - T1114.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#47d9d3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#56c932",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Symmetric Cryptography - T1573.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#c202a1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5a258",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9bb6d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"",
        "relationship_type": ""
      },
      {
        "colour": "#e00500",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Access Tools - T1219\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#17c030",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Application Window Discovery - T1010\"",
        "relationship_type": ""
      },
      {
        "colour": "#bf01b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"",
        "relationship_type": ""
      },
      {
        "colour": "#9f6bd9",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Network Configuration Discovery - T1016\"",
        "relationship_type": ""
      },
      {
        "colour": "#36a9d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Account Discovery - T1087\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#62f4c1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d1dab",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Internal Spearphishing - T1534\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#c84641",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"GUI Input Capture - T1056.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#57997c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Bidirectional Communication - T1102.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#02475d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#120044",
        "local": false,
        "name": "rectifyq:sub-category=\"intrusion-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#d92121",
        "local": false,
        "name": "rectifyq:target=\"targeted\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780398006",
        "to_ids": false,
        "type": "link",
        "uuid": "7baf46b5-527e-4651-b46f-579d2334e0e0",
        "value": "https://www.esentire.com/blog/nimbus-rat-how-threat-actors-are-abusing-microsoft-teams-and-google-drive-to-deploy-a-java-rat"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780398006",
        "to_ids": false,
        "type": "text",
        "uuid": "6482d2b5-a8b4-47b2-a57c-a7a46dc98e4e",
        "value": "In April 2026, threat actors deployed Nimbus RAT against a legal industry target using Microsoft Teams voice phishing. The attack began with email bombing (282 emails in 90 minutes), followed by a fake IT helpdesk contact via Teams who convinced the victim to grant Quick Assist remote access. Within 20 minutes, a Java-based RAT was deployed that uses Google Drive and Google Sheets for command-and-control, making network traffic appear benign. Analysis of 1,540 suspicious Teams messages across 172 customer environments over 12 months revealed 65% originated from throwaway onmicrosoft.com tenants with IT-themed names. The malware bundles its own Java runtime, implements two credential theft mechanisms, and allows in-memory second-stage code execution. Post-compromise targeting included Signal Desktop attachments and Outlook mailboxes."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780398006",
        "to_ids": false,
        "type": "text",
        "uuid": "187f9f25-4603-48c0-a135-9b004f8aa252",
        "value": "Name: Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT\nAuthor: AlienVault\nAdversary: \nTags: [\"vishing\", \"quick assist\", \"email bombing\", \"microsoft teams\", \"google drive c2\", \"java rat\", \"social engineering\", \"nimbus rat\"]\nTgtd countries: []\nMlwr families: [\"Nimbus RAT\"]\nAttack_ids: [\"T1560.001\", \"T1113\", \"T1033\", \"T1132.001\", \"T1071.004\", \"T1114.001\", \"T1204.002\", \"T1573.001\", \"T1566.002\", \"T1082\", \"T1106\", \"T1005\", \"T1140\", \"T1555\", \"T1219\", \"T1055\", \"T1010\", \"T1112\", \"T1016\", \"T1087\", \"T1083\", \"T1057\", \"T1041\", \"T1534\", \"T1547.001\", \"T1056.002\", \"T1027\", \"T1102.002\", \"T1059.003\", \"T1071.001\"]\nIndustries: [\"Legal\"]"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780500111",
        "to_ids": true,
        "type": "domain",
        "uuid": "66eecc8c-cda5-41d6-9025-c7f868d00d11",
        "value": "helpdock.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780500132",
        "to_ids": true,
        "type": "domain",
        "uuid": "0f1d4054-2aee-4c0f-8962-1e4b57c2f9af",
        "value": "scanseq.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780500153",
        "to_ids": true,
        "type": "domain",
        "uuid": "b7cf2f3b-ab4f-4660-a7d5-576f80c7b142",
        "value": "serviceprohub.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780500174",
        "to_ids": true,
        "type": "domain",
        "uuid": "265df2e4-f9f9-41ff-8251-96a77d1e381b",
        "value": "system-clean.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:03/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780498051",
        "to_ids": true,
        "type": "sha256",
        "uuid": "03d7f5ca-ef74-44b1-8c8c-2fc4b2866efc",
        "value": "91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bc",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:03/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780498052",
        "to_ids": true,
        "type": "sha256",
        "uuid": "7306f888-eb4f-44b5-8c45-38127a416d96",
        "value": "9e5b1e10ad6904d3f5b48d38470cd57263974640a27d13cf793ef026d3d6b886",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780500195",
        "to_ids": true,
        "type": "domain",
        "uuid": "1b5897f0-da36-4e9c-a7e1-6f8b877c3de9",
        "value": "info-secure.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780500217",
        "to_ids": true,
        "type": "domain",
        "uuid": "e3c06038-3ed7-47b8-9504-7c2fd8e1db26",
        "value": "scan-security.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780500238",
        "to_ids": true,
        "type": "domain",
        "uuid": "9383ec7f-544c-4a69-aa24-49bf4a95f547",
        "value": "updt-scansecurity.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780438598",
        "to_ids": false,
        "type": "malware-type",
        "uuid": "0bfb8046-3df2-420c-929f-a0090726782e",
        "value": "Nimbus RAT",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780500259",
        "to_ids": true,
        "type": "url",
        "uuid": "db73ca14-d070-4fbe-9624-b85d7b42e5d5",
        "value": "docs.google.com/spreadsheets/d/1Eaj1_UZNjz2CIUa_t1yYGeGvaiby0oIRj8-Oq1lVqkI/export?format=csv",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Financial fraud",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780438750",
        "to_ids": true,
        "type": "btc",
        "uuid": "5c369c61-5e12-4d9f-897d-ab1f8a5305dd",
        "value": "1g7DgU7cVnVIEiRVAXILMUbdF7h06OhWm"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780438750",
        "to_ids": true,
        "type": "email-src",
        "uuid": "5b6fc7b8-a815-4925-9bfa-25769a0ebe0c",
        "value": "onlyember@automated-atlas-492514-d5.iam.gserviceaccount.com"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780438750",
        "to_ids": true,
        "type": "email-src",
        "uuid": "a817d9ee-e3d5-4021-a2ce-4c9581aafe66",
        "value": "pronopro@helpful-topic-492515-g1.iam.gserviceaccount.com"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780438750",
        "to_ids": true,
        "type": "email-src",
        "uuid": "e0027bca-5d59-4f4c-970c-b8650333b51f",
        "value": "ironicblade@warm-access-490711-s6.iam.gserviceaccount.com"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780500280",
        "to_ids": true,
        "type": "url",
        "uuid": "36754c30-7420-4071-a65c-e47e56144358",
        "value": "pastebin.com/G6jA0PLU",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780500301",
        "uuid": "0278e401-ab73-4fba-8bf7-c1ef39e28373",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780500301",
            "to_ids": true,
            "type": "md5",
            "uuid": "aca9111b-205b-4b73-9a87-864480128510",
            "value": "44f6101dd8171133f53317bfd752300e",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780498050",
            "to_ids": true,
            "type": "sha1",
            "uuid": "6805d8d0-1c27-4314-8350-b06df93bd96d",
            "value": "fab69acd743f4111b749e3268690825c38822e62",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780498050",
            "to_ids": true,
            "type": "sha256",
            "uuid": "10275529-a3d7-4b2b-b6f3-e99f33e9f19f",
            "value": "99813f3d0625e880158c68039c0e2fbf488db0be3db77cd1ce6d382644193f0e",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780497278",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "968a9981-0987-4422-8cfe-9839bdf8ed5e",
            "value": "768:9HcNW2EM5R2TyJ5R3s8D/bkt5Ruz3Vb3v350Yi1VRzv/5ALI:JcNoM5RdJ5R3sozkt5RA3v35071VRbF"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780497278",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "8b36567b-2215-48f8-9097-c0a532865e59",
            "value": "50336"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780497278",
            "to_ids": true,
            "type": "vhash",
            "uuid": "ab340c7f-fe42-4bdf-9a66-d8bc551f4cf7",
            "value": "054066551d1515651az1-z"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780497278",
            "to_ids": true,
            "type": "filename",
            "uuid": "b5e8af54-d013-449b-b9e0-88b512e9a03f",
            "value": "javaw.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 03/06/2026\nLast-scan\t:  30/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780497278",
            "to_ids": false,
            "type": "text",
            "uuid": "986b2712-9bb4-484e-97b0-c3e007017d8b",
            "value": "Type Description: Win32 EXE\nMicrosoft: None\nVT Total Detection:0/71\nFirst Submission:2025-10-21T18:17:38.000000+00:00\nLast Submission:2026-04-23T10:01:28.000000+00:00"
          }
        ]
      }
    ]
  }
}