[copy]
{
"type": "bundle",
"id": "bundle--1d0e4795-5514-433b-b7de-0f74b9659b27",
"objects": [
{
"type": "marking-definition",
"spec_version": "2.1",
"id": "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487",
"created": "2022-10-01T00:00:00.000Z",
"definition_type": "tlp:2.0",
"name": "TLP:CLEAR",
"definition": {
"tlp": "clear"
}
},
{
"type": "identity",
"spec_version": "2.1",
"id": "identity--a6ec8b2e-fd4e-4c7e-8324-bc1083c9f019",
"created": "2026-03-01T23:58:22.082Z",
"modified": "2026-03-01T23:58:22.083Z",
"name": "MikeGPT Intelligence Platform",
"description": "AI-powered threat intelligence collection and analysis platform providing automated cybersecurity intelligence feeds",
"identity_class": "organization",
"sectors": [
"technology",
"defense"
],
"contact_information": "Website: https://mikegptai.com | Email: intel@mikegptai.com",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"type": "report",
"spec_version": "2.1",
"id": "report--9da9ddb8-59b6-462d-8b71-578ea5fa91ef",
"created": "2026-03-01T23:58:22.083Z",
"modified": "2026-03-01T23:58:22.083Z",
"name": "Threat Intelligence Report - 2026-03-01",
"description": "Threat Intelligence Report - 2026-03-01\n\nThis report consolidates actionable cybersecurity intelligence from 36 sources, processed through automated threat analysis and relationship extraction.\n\nKEY FINDINGS:\n• Web Single Sign-On: Understanding WS-Federation (Score: 100)\n• CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances (Score: 100)\n• Hacker Uses Claude, ChatGPT AI Chatbots to Breach Mexican Government Systems (Score: 92.7)\n• Upcoming updates on IG-DETECTIVE (Score: 90.4)\n• Claude code abused to steal 150GB in cyberattack on Mexican agencies (Score: 90.3)\n\nEXTRACTED ENTITIES:\n• 12 Attack Pattern(s)\n• 21 Domain Name(s)\n• 1 Email Addr(s)\n• 28 File(s)\n• 49 Indicator(s)\n• 1 Marking Definition(s)\n• 51 Relationship(s)\n• 1 Threat Actor(s)\n• 11 Tool(s)\n\nCONFIDENCE ASSESSMENT:\nVariable confidence scoring applied based on entity type and intelligence source reliability. Confidence ranges from 30-95% reflecting professional intelligence assessment practices.\n\nGENERATION METADATA:\n- Processing Time: Automated\n- Validation: Three-LLM consensus committee\n- Standards Compliance: STIX 2.1\n",
"published": "2026-03-01T23:58:22.083Z",
"object_refs": [
"identity--a6ec8b2e-fd4e-4c7e-8324-bc1083c9f019",
"identity--a701bce6-5a88-4421-9f4b-d196320675d4",
"tool--c952c59b-33d7-4a38-b14c-ed7f09c782fc",
"identity--7fbef74f-2be1-43ae-8dd4-d12891301d4e",
"identity--83a69066-c503-40e1-97ef-bc4063877d19",
"threat-actor--6f3c00f4-85f6-4c92-8da4-8ae90fb83c43",
"tool--fee11f68-68c2-4e71-8ab1-d50e44ac4b83",
"tool--5eafd103-25eb-4a6a-8d45-4b97a0924946",
"identity--311f1f5c-b610-4d3b-8891-f084700e7671",
"identity--94e0847e-aa05-40b4-a146-a0dc3747ef30",
"identity--12c1bdbc-48a9-4d96-b4ca-7f4fb9bff54d",
"identity--6f80d49e-e8c4-40f8-bf8a-a6dfc1f8c91d",
"identity--164635dd-f273-4201-bf73-d4bc1a556b3a",
"identity--0a231163-6342-43a7-b5da-440ebe597500",
"identity--c4889768-f612-4316-b9c7-ec98fb244487",
"identity--ab70e18f-79b6-4f20-a19f-ed089567a7b0",
"identity--7570000d-89d2-4493-89ef-3e2923bac5c0",
"tool--383c298b-479d-4f4e-af70-5991f9784a61",
"identity--f4ad9671-f1bc-4906-9424-26d434e939e4",
"tool--2716225a-7fa8-4073-a2c0-69c5c2fc6dce",
"identity--84cc9f98-37d8-4790-bdcd-597ce6a2e6ac",
"tool--28f95d4c-d415-4daa-ab60-389485e5ce04",
"tool--35859f25-5501-4dcb-9159-3a19aa2ce05c",
"identity--ecdb58c2-6b44-44be-803d-2e8b7d44dbc2",
"tool--8f6d10e9-46e3-4d03-968a-9d06b39072a8",
"tool--287c1a7f-c599-4765-94ee-1656c4b9d84c",
"identity--80220a5c-02f2-425a-a9a3-d15e3ccd4832",
"tool--170bc69e-d2f8-4350-8555-eab65dcbdb67",
"tool--8cc0e050-f421-47a3-be79-3d91208e917b",
"attack-pattern--280ebd89-59bc-4ae2-a9db-1c01a56e50dc",
"attack-pattern--e5974f70-5745-450a-908a-6483ad9c4678",
"attack-pattern--4c8bcb56-2a96-4393-a41f-3829ab20b9ba",
"attack-pattern--dd0edf90-8f96-4a15-852b-ba611cd81716",
"attack-pattern--3785d15d-1c0c-4464-9200-10b744888e29",
"attack-pattern--a45b8295-9056-4ed5-b811-6e7d2a71483e",
"attack-pattern--d2a77ce3-d278-4f77-97f0-227b744a33d3",
"attack-pattern--a6ff86fe-f269-42e5-9428-ab17d04e30e2",
"attack-pattern--e8d516a9-a107-4c4b-806f-bc9c612eef18",
"attack-pattern--27b36b6d-ae90-4767-b07a-563ecef589ea",
"attack-pattern--ed3369e1-8515-458a-99e3-cb9283fb73d1",
"attack-pattern--5cf0f3fb-3459-4a3d-ad3c-4700efcfecd8",
"relationship--f1983954-eeb4-44e6-abad-b04b4b8da992",
"relationship--86cb505e-71b5-4302-a65d-c7235ffdcfaf",
"domain-name--4e2c2386-d56c-4cf6-a192-659a55762b97",
"file--d29f7847-c1a9-448b-997c-af240da9966d",
"file--10141e8d-af8e-4909-b972-6a596ae23ff7",
"file--cda39981-f3d8-40b5-8db2-08b9608c1197",
"file--1d4a03a3-4045-4449-8620-cf2d984a488b",
"file--fc57cbda-f7aa-4ab6-b992-671c3f0a9bc3",
"file--96f083f2-b3d6-4e8d-8193-4de2e191e1f6",
"file--53f50220-6b1a-409f-aa02-746adf697c04",
"file--c0034411-b81a-4ab5-91cc-042999497e48",
"file--6018bd4a-1b56-435a-ab76-99f106e0a503",
"file--9a737c1d-ccf0-48e9-8b94-b64c440a4230",
"file--ca7f6059-1f8d-4375-8c21-9a9a362a2d97",
"file--b1e0ff90-64b0-48ad-8645-f6ccefd0f15b",
"file--5bd66437-2f2d-45bd-975b-ba658d26155d",
"file--64628eb3-aefe-4d34-97ca-f91a157e535a",
"file--9b86ac08-d740-41d0-80de-08ce83ee26ca",
"file--ab4d0d40-093b-4289-a9e6-56414cb01ed6",
"file--883dd817-fe7c-49b5-954e-fb64d3a050b2",
"file--5f05db4a-e639-4cdf-8f00-cbb3c60e701e",
"file--9c011752-7766-43cf-bfd1-8610f19f1679",
"domain-name--83f07f0a-1a16-4b46-abed-46c81f8417f8",
"domain-name--68ef85cb-84e4-4872-be82-a6dfb77a52c0",
"domain-name--af0b4929-3e14-419f-9147-fc50118a7ae7",
"domain-name--5291c9ee-1966-49f5-96fd-2dda8a2cb307",
"domain-name--6ce18b4b-c909-43dc-94e2-9e4be88ef5d8",
"domain-name--3de96d5e-7d5a-4a70-ab43-8133f1b3e478",
"email-addr--00a1f30c-f712-4dbd-8a41-84c182d25807",
"domain-name--8ef7d1e6-b287-4e14-b439-e65af1bdc45b",
"file--f2d27801-e10d-4063-ae30-cf7f485fcee2",
"file--ddb3e0e5-344b-4f62-8147-0aa3f7a5b02f",
"file--1745d6e9-225b-46fe-9dc5-66831375bbda",
"file--21170e7b-2456-41e2-86b2-2a71ccfebb27",
"file--ca6bc88f-a54d-4386-8474-6121fde9ab5b",
"file--4699d335-7060-4063-91c1-e91fc5373c3d",
"file--b5dccc50-3ae7-49b0-87c4-cafe8a3f85af",
"file--b5c3b76a-bc84-436a-ab57-71b908c2ed98",
"file--38fee6b3-bdce-481c-9404-3c5edd4d78a2",
"domain-name--8f9b24c3-87c5-4de2-a6a3-0e0d30318ada",
"domain-name--c06ff45b-0740-491e-bd1e-1c4f55edfb58",
"domain-name--8854c578-f14b-4570-8bbd-a0ec624e8111",
"domain-name--9baf199e-0f8c-4bc1-82aa-1de63ebc94a9",
"domain-name--c573348e-3e66-44fa-ade0-33227bd70d2d",
"domain-name--08d6347c-ddd3-42f6-9657-18b3976da073",
"domain-name--807fed64-d4de-4500-a598-7d6ed0d0859c",
"domain-name--1acceb58-eaeb-448c-b110-fd2b2194d4b4",
"domain-name--5293f326-d29c-40d9-a6ad-4b214e6fc897",
"domain-name--491415f4-9d2a-402e-90a1-cc77be52a170",
"domain-name--a8cf501f-040b-4353-b919-ccf4545124ac",
"domain-name--0128e662-5327-4cb8-86a4-cd5f457c4e08",
"domain-name--2e6aaefd-dc04-4ea8-951c-738635ccf4fa",
"indicator--d4bbb849-0e43-4a1a-9cb8-db3ea5984b53",
"relationship--068d9f5e-e974-47ee-8854-9bc006f1d0a0",
"indicator--63f00587-4b89-4621-abae-079a32f785e6",
"relationship--6959496c-870c-4f7f-b901-61ff747f0bbb",
"indicator--ecbe65ac-46a7-482f-afce-b5ff5f721370",
"relationship--09119c32-a40e-498d-9b70-7e059a38c9df",
"indicator--083f37fd-1305-4b77-870e-3882d3c41516",
"relationship--dcc732d5-d2e5-47b2-a893-269f8589d567",
"indicator--26ec8131-8080-495c-8c3d-26db70c09b5c",
"relationship--b9a42d5e-f073-4183-8cd6-0a86585bb405",
"indicator--2bcff397-f738-483a-a191-2be3b22439d6",
"relationship--2a858f32-ca08-438f-8887-280999325674",
"indicator--57f6d493-3c2e-4a4d-9b20-2c073f93a70a",
"relationship--cd2891d9-8c6c-45bc-a2db-fd1737578fbe",
"indicator--259bb0ae-f7a8-4aea-b823-097b76c2f9e0",
"relationship--1678e323-ff14-42e1-bc99-defc2c174fd0",
"indicator--ef0f97a9-ad82-4af4-87fd-af13bb5ce4bb",
"relationship--3387eb5a-4b42-42a7-a951-3c1ce553ed96",
"indicator--123c8bfd-8afa-4794-8ef9-f1d60a81f032",
"relationship--c25ede88-5364-49c3-912b-a48921992e4e",
"indicator--9ee9b42b-23e5-418c-8a36-8f32de3642d5",
"relationship--89ccaeb9-b348-4a0d-abaf-e3667171815a",
"indicator--8ac9f017-0bbe-4a32-a2ea-cefc6f77c3a0",
"relationship--b8c253ea-c3ec-40b0-83f5-5f1f585db761",
"indicator--577a0a6a-9780-419a-8d9e-dd7ef66acf61",
"relationship--2b054add-75c2-45fb-9e53-72dc9776fce1",
"indicator--5a1ea69c-3790-47e9-8022-9cd932ca91f6",
"relationship--8e9fbdbb-0355-43ab-9c70-a4f7349658a1",
"indicator--60582689-f273-4910-b6d1-d9ce7a91ee74",
"relationship--fe1e76b8-bb16-4f8c-a50e-7953d4c9a8f1",
"indicator--6170dfeb-9595-488e-8206-6f8c6f9e70e0",
"relationship--1f24988f-62a7-4fb4-ab1d-75cafcbff7b0",
"indicator--409bfc7f-40e9-4a74-9c96-29c328853c91",
"relationship--2ae5e085-5771-4651-bf33-f1ed640c1283",
"indicator--5891c833-3fc9-40cc-b607-1ca3da4b5185",
"relationship--e67aa63e-73f4-4e00-9e51-6b0f7c10451b",
"indicator--6278d742-14f2-4258-b3d3-78cb8ee14912",
"relationship--c3343700-6813-4bdf-abc1-78e425d9ee52",
"indicator--5da44091-6544-43e4-95a0-bbc372342ef4",
"relationship--fef96a21-1508-4436-95e2-3034504e6342",
"indicator--4fb972a7-5f83-467c-8908-d59be5e1653a",
"relationship--71caae1d-6674-442b-b4dd-620673c4dfb5",
"indicator--5a284aaf-a103-4b41-90f9-368192bf688d",
"relationship--3c48e286-9514-4021-ab04-e5d94df849fd",
"indicator--37efad6d-6db8-42be-8fd3-d5bc7d178c68",
"relationship--a3094e83-d0d6-4ca5-b102-11bcca678617",
"indicator--c1fb7060-e073-4992-b1a8-f76f53d986e5",
"relationship--45f3ccf8-4975-4307-9d84-3ee01775908b",
"indicator--a5db180b-6b94-4448-a3ce-4e36ad14f56a",
"relationship--9fddc57a-a1c8-4d91-8120-be0a38ae1340",
"indicator--ab4c3ff8-f76b-4811-9b7b-169bd73e7169",
"relationship--61d7dc10-40aa-4e0f-a155-dfde9ccb80d4",
"indicator--a0642b4c-1d76-4cfc-a49b-f76ce9a67811",
"relationship--7250da41-d7f3-4be0-b289-b92c3313c427",
"indicator--0d059cd9-51fd-4df8-88dd-8ad7af09c1f8",
"relationship--fe4dfa71-d422-48e8-a225-5c6dce0b159b",
"indicator--0a3f5121-1671-4ec2-8486-7005ad37e8dc",
"relationship--cc0dda94-7c2d-4866-b389-250ab7dfba99",
"indicator--ab9cb08f-cfe0-4136-9184-8d5a6b3e1b75",
"relationship--c4c1f022-1215-4cae-9b17-f086ecaa1cb7",
"indicator--c94c5f7f-9d29-4368-b8ea-7cabf4070d62",
"relationship--3d42774e-b411-42f5-b3cc-88a4cd51d738",
"indicator--7d3bcde5-f763-4f38-b539-7812f64c30e9",
"relationship--b9e45121-8bac-47c3-a61b-4a22d25be126",
"indicator--462a9520-5a55-41b4-9c53-69d50e6bf7b9",
"relationship--527c7bd0-332b-4703-a081-55f393b92928",
"indicator--036f10f2-d234-4272-b997-0717db6d4c2a",
"relationship--e0292a45-4e89-425a-a99b-ec3fb2394b02",
"indicator--ff53e531-2b70-4be3-99e2-06c873dce3fa",
"relationship--1be25d6a-7426-464a-90cd-84a2ed876fa2",
"indicator--31d7b411-e52f-452a-9676-0d89a9d9c560",
"relationship--a4ea23e0-f30f-4b96-b718-b8b3711dc62a",
"indicator--b4229d03-eca1-4a55-b587-b6322e04c1fa",
"relationship--e706764c-9128-4381-9b4e-d1c6b018994d",
"indicator--927c4f5e-62b0-42ab-b71d-f2d1fffe6ae0",
"relationship--027bba19-df0a-4397-bf61-75fc90d908e9",
"indicator--a8e0e4c9-ff38-40ed-90a9-428e6298e423",
"relationship--4a088c3d-9fd8-4508-a35d-2aa5e529a8a8",
"indicator--411fc941-c980-4b34-98f5-111d7626f6e8",
"relationship--01a6cac5-c75a-43fa-90b7-566967ca9189",
"indicator--45dad0d1-9f5b-44e9-8734-819da9a1eaac",
"relationship--51db11a0-6e31-4bdf-9cb4-60ee1bc79976",
"indicator--1275068a-9c8d-4f2b-bda8-1b459f885273",
"relationship--d2b7e3e1-5843-4238-8338-114fba18a901",
"indicator--6f35747a-a0f7-490d-a811-8b5295a595b3",
"relationship--3785db43-740d-4eb1-aa1f-14b41629594f",
"indicator--f3eeed16-9c40-45e5-a269-12b0932468fa",
"relationship--517543b5-d207-4f86-be42-c08189472815",
"indicator--c872b902-3208-4c20-be85-aecadfa89816",
"relationship--025583a3-ac3e-4bc5-821b-588c3a35ecc5",
"indicator--1e7b6d63-3e99-4670-b4d1-721f7290b77d",
"relationship--b80cbfb1-287f-42fd-ab6e-118d52d6aaae",
"indicator--4f43f2c8-9f55-40ea-a447-d5068b169e94",
"relationship--01dd800c-b4ec-40a4-a6ee-7d584f691ff7",
"indicator--e559ff53-b234-4591-ac7d-edaebb29f226",
"relationship--039ba70b-82bf-480c-9411-4b8fb237ff28",
"indicator--19baa79f-17b7-4bae-b98f-b9610083a094",
"relationship--4455feeb-68f7-430c-89c7-93457bfe9c09"
],
"labels": [
"threat-report",
"threat-intelligence"
],
"created_by_ref": "identity--a6ec8b2e-fd4e-4c7e-8324-bc1083c9f019",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.457Z",
"modified": "2026-03-01T23:58:20.457Z",
"confidence": 95,
"type": "identity",
"id": "identity--a701bce6-5a88-4421-9f4b-d196320675d4",
"name": "KrebsOnSecurity",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "KrebsOnSecurity is a cybersecurity news and investigation website run by Brian Krebs.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.457Z",
"modified": "2026-03-01T23:58:20.457Z",
"confidence": 95,
"type": "tool",
"id": "tool--c952c59b-33d7-4a38-b14c-ed7f09c782fc",
"name": "Anthropic’s AI",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "Anthropic’s AI refers to the AI models developed by Anthropic, which were exploited in a cyber attack.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.457Z",
"modified": "2026-03-01T23:58:20.457Z",
"confidence": 95,
"type": "identity",
"id": "identity--7fbef74f-2be1-43ae-8dd4-d12891301d4e",
"name": "Jen Easterly",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "The Director of the Cybersecurity and Infrastructure Security Agency (CISA).",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.457Z",
"modified": "2026-03-01T23:58:20.457Z",
"confidence": 95,
"type": "identity",
"id": "identity--83a69066-c503-40e1-97ef-bc4063877d19",
"name": "Mohamad Yassine",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.457Z",
"modified": "2026-03-01T23:58:20.457Z",
"confidence": 95,
"type": "threat-actor",
"id": "threat-actor--6f3c00f4-85f6-4c92-8da4-8ae90fb83c43",
"name": "Hezbollah",
"threat_actor_types": [
"hacker"
],
"labels": [
"threat-actor"
],
"description": "A known terrorist organization with cyber capabilities.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.457Z",
"modified": "2026-03-01T23:58:20.457Z",
"confidence": 95,
"type": "tool",
"id": "tool--fee11f68-68c2-4e71-8ab1-d50e44ac4b83",
"name": "DMARC Solution",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "A solution for implementing DMARC (Domain-based Message Authentication, Reporting, and Conformance) for email security.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.457Z",
"modified": "2026-03-01T23:58:20.457Z",
"confidence": 95,
"type": "tool",
"id": "tool--5eafd103-25eb-4a6a-8d45-4b97a0924946",
"name": "EasyDMARC",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "EasyDMARC is a tool designed to help organizations implement DMARC (Domain-based Message Authentication, Reporting, and Conformance) to protect against email spoofing.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--311f1f5c-b610-4d3b-8891-f084700e7671",
"name": "Yue Xiao",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--94e0847e-aa05-40b4-a146-a0dc3747ef30",
"name": "IBM Research",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "The research arm of IBM, involved in various cybersecurity initiatives.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--12c1bdbc-48a9-4d96-b4ca-7f4fb9bff54d",
"name": "Dhilung Kirat",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--6f80d49e-e8c4-40f8-bf8a-a6dfc1f8c91d",
"name": "Douglas Lee Schales",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--164635dd-f273-4201-bf73-d4bc1a556b3a",
"name": "Jiyong Jang",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--0a231163-6342-43a7-b5da-440ebe597500",
"name": "Luyi Xing",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--c4889768-f612-4316-b9c7-ec98fb244487",
"name": "Indiana University Bloomington",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A university with a cybersecurity program or research focus.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--ab70e18f-79b6-4f20-a19f-ed089567a7b0",
"name": "Xiaojing Liao",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--7570000d-89d2-4493-89ef-3e2923bac5c0",
"name": "Indiana University",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A university with a cybersecurity program or research focus.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "tool",
"id": "tool--383c298b-479d-4f4e-af70-5991f9784a61",
"name": "NetBlocks",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "NetBlocks is a tool that monitors and reports on internet connectivity and censorship.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 90,
"type": "identity",
"id": "identity--f4ad9671-f1bc-4906-9424-26d434e939e4",
"name": "Canadian Tire",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A Canadian retail company, possibly related to cybersecurity through its online presence.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "tool",
"id": "tool--2716225a-7fa8-4073-a2c0-69c5c2fc6dce",
"name": "Adaptive MFA Decisioning",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "A security tool that uses machine learning to make adaptive multi-factor authentication decisions.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.458Z",
"confidence": 95,
"type": "identity",
"id": "identity--84cc9f98-37d8-4790-bdcd-597ce6a2e6ac",
"name": "Security Boulevard",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A cybersecurity-focused online publication",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.458Z",
"modified": "2026-03-01T23:58:20.459Z",
"confidence": 95,
"type": "tool",
"id": "tool--28f95d4c-d415-4daa-ab60-389485e5ce04",
"name": "Advanced Python OSINT",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "A Python-based tool for Open-Source Intelligence (OSINT) gathering and analysis.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.459Z",
"modified": "2026-03-01T23:58:20.459Z",
"confidence": 95,
"type": "tool",
"id": "tool--35859f25-5501-4dcb-9159-3a19aa2ce05c",
"name": "Forensic Framework",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "A framework for digital forensic analysis and investigation.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.459Z",
"modified": "2026-03-01T23:58:20.459Z",
"confidence": 95,
"type": "identity",
"id": "identity--ecdb58c2-6b44-44be-803d-2e8b7d44dbc2",
"name": "Sangoma",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A company that provides communication solutions, including FreePBX.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.459Z",
"modified": "2026-03-01T23:58:20.459Z",
"confidence": 95,
"type": "tool",
"id": "tool--8f6d10e9-46e3-4d03-968a-9d06b39072a8",
"name": "FreePBX",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "A popular open-source IP PBX software",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.459Z",
"modified": "2026-03-01T23:58:20.459Z",
"confidence": 95,
"type": "tool",
"id": "tool--287c1a7f-c599-4765-94ee-1656c4b9d84c",
"name": "OpenClaw",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "OpenClaw is a security tool that has addressed a high-severity vulnerability that could have allowed unauthorized access.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.459Z",
"modified": "2026-03-01T23:58:20.459Z",
"confidence": 95,
"type": "identity",
"id": "identity--80220a5c-02f2-425a-a9a3-d15e3ccd4832",
"name": "Verizon",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A telecommunications company with a cybersecurity division.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.459Z",
"modified": "2026-03-01T23:58:20.459Z",
"confidence": 95,
"type": "tool",
"id": "tool--170bc69e-d2f8-4350-8555-eab65dcbdb67",
"name": "DMARC",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "Domain-based Message Authentication, Reporting, and Conformance (DMARC) is an email authentication protocol.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.459Z",
"modified": "2026-03-01T23:58:20.459Z",
"confidence": 95,
"type": "tool",
"id": "tool--8cc0e050-f421-47a3-be79-3d91208e917b",
"name": "Forensic",
"tool_types": [
"unknown"
],
"labels": [
"tool"
],
"description": "Digital forensic analysis tool.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:20.459Z",
"modified": "2026-03-01T23:58:20.459Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--280ebd89-59bc-4ae2-a9db-1c01a56e50dc",
"name": "Exploit Public-Facing Application",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "initial-access"
}
],
"x_mitre_id": "T1190",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1190/",
"external_id": "T1190"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--e5974f70-5745-450a-908a-6483ad9c4678",
"name": "Exploitation for Client Execution",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "execution"
}
],
"x_mitre_id": "T1203",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1203/",
"external_id": "T1203"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--4c8bcb56-2a96-4393-a41f-3829ab20b9ba",
"name": "Web Shell",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
}
],
"x_mitre_id": "T1505.003",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1505/003/",
"external_id": "T1505.003"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 85,
"type": "attack-pattern",
"id": "attack-pattern--dd0edf90-8f96-4a15-852b-ba611cd81716",
"name": "Python",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "execution"
}
],
"x_mitre_id": "T1059.006",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1059/006/",
"external_id": "T1059.006"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 82,
"type": "attack-pattern",
"id": "attack-pattern--3785d15d-1c0c-4464-9200-10b744888e29",
"name": "Python Startup Hooks",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1546.018",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1546/018/",
"external_id": "T1546.018"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 76,
"type": "attack-pattern",
"id": "attack-pattern--a45b8295-9056-4ed5-b811-6e7d2a71483e",
"name": "Multi-Factor Authentication",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "credential-access"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "defense-evasion"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
}
],
"x_mitre_id": "T1556.006",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1556/006/",
"external_id": "T1556.006"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--d2a77ce3-d278-4f77-97f0-227b744a33d3",
"name": "Archive via Utility",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "collection"
}
],
"x_mitre_id": "T1560.001",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1560/001/",
"external_id": "T1560.001"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--a6ff86fe-f269-42e5-9428-ab17d04e30e2",
"name": "Screen Capture",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "collection"
}
],
"x_mitre_id": "T1113",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1113/",
"external_id": "T1113"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--e8d516a9-a107-4c4b-806f-bc9c612eef18",
"name": "Adversary-in-the-Middle",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "credential-access"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "collection"
}
],
"x_mitre_id": "T1557",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1557/",
"external_id": "T1557"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--27b36b6d-ae90-4767-b07a-563ecef589ea",
"name": "Scheduled Task",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "execution"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1053.005",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1053/005/",
"external_id": "T1053.005"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--ed3369e1-8515-458a-99e3-cb9283fb73d1",
"name": "Socket Filters",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "defense-evasion"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "command-and-control"
}
],
"x_mitre_id": "T1205.002",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1205/002/",
"external_id": "T1205.002"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-03-01T23:58:22.079Z",
"modified": "2026-03-01T23:58:22.079Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--5cf0f3fb-3459-4a3d-ad3c-4700efcfecd8",
"name": "Boot or Logon Initialization Scripts",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1037",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1037/",
"external_id": "T1037"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--f1983954-eeb4-44e6-abad-b04b4b8da992",
"created": "2026-03-01T23:58:22.080Z",
"modified": "2026-03-01T23:58:22.080Z",
"relationship_type": "related-to",
"source_ref": "identity--ecdb58c2-6b44-44be-803d-2e8b7d44dbc2",
"target_ref": "tool--8f6d10e9-46e3-4d03-968a-9d06b39072a8",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' \\n About 900 Sangoma FreePBX systems were infected with web shells after attackers exploited a command injection flaw. \\n\\n\\n\\n Hundreds of Sangoma FreePBX instances are still infected with web shells following attacks that began in Dece...",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--86cb505e-71b5-4302-a65d-c7235ffdcfaf",
"created": "2026-03-01T23:58:22.080Z",
"modified": "2026-03-01T23:58:22.080Z",
"relationship_type": "related-to",
"source_ref": "tool--8f6d10e9-46e3-4d03-968a-9d06b39072a8",
"target_ref": "attack-pattern--4c8bcb56-2a96-4393-a41f-3829ab20b9ba",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' \\n About 900 Sangoma FreePBX systems were infected with web shells after attackers exploited a command injection flaw. \\n\\n\\n\\n Hundreds of Sangoma FreePBX instances are still infected with web shells following attacks that began in Dece...",
"x_validation_method": "three-llm-consensus"
},
{
"type": "domain-name",
"value": "progamevl.ru",
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "domain-name--4e2c2386-d56c-4cf6-a192-659a55762b97"
},
{
"type": "file",
"value": "5249503900c735425130477649872dfb",
"hashes": {
"MD5": "5249503900c735425130477649872dfb"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--d29f7847-c1a9-448b-997c-af240da9966d"
},
{
"type": "file",
"value": "75fec5afb2deebab6dd9c16d9de35032",
"hashes": {
"MD5": "75fec5afb2deebab6dd9c16d9de35032"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--10141e8d-af8e-4909-b972-6a596ae23ff7"
},
{
"type": "file",
"value": "9d896e0e3e369c2edf1c8fb070f49c22",
"hashes": {
"MD5": "9d896e0e3e369c2edf1c8fb070f49c22"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--cda39981-f3d8-40b5-8db2-08b9608c1197"
},
{
"type": "file",
"value": "a727362416834fa63672b87820ff7f27",
"hashes": {
"MD5": "a727362416834fa63672b87820ff7f27"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--1d4a03a3-4045-4449-8620-cf2d984a488b"
},
{
"type": "file",
"value": "c4379da51e8b9e86ec3de934f9373f4a",
"hashes": {
"MD5": "c4379da51e8b9e86ec3de934f9373f4a"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--fc57cbda-f7aa-4ab6-b992-671c3f0a9bc3"
},
{
"type": "file",
"value": "f5271a6d909091527ed9f30eafa0ded6",
"hashes": {
"MD5": "f5271a6d909091527ed9f30eafa0ded6"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--96f083f2-b3d6-4e8d-8193-4de2e191e1f6"
},
{
"type": "file",
"value": "410c8a57fe6e09edbfebaba7d5d3e4797ca80a19",
"hashes": {
"SHA-1": "410c8a57fe6e09edbfebaba7d5d3e4797ca80a19"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--53f50220-6b1a-409f-aa02-746adf697c04"
},
{
"type": "file",
"value": "472ca448f82a7ff6f373a32fdb9586fd7c38b631",
"hashes": {
"SHA-1": "472ca448f82a7ff6f373a32fdb9586fd7c38b631"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--c0034411-b81a-4ab5-91cc-042999497e48"
},
{
"type": "file",
"value": "4ec3c90846af6b79ee1a5188eefa3fd21f6d4cf6",
"hashes": {
"SHA-1": "4ec3c90846af6b79ee1a5188eefa3fd21f6d4cf6"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--6018bd4a-1b56-435a-ab76-99f106e0a503"
},
{
"type": "file",
"value": "4f8e9336a784a196353023133e0f8fa54f6a92e2",
"hashes": {
"SHA-1": "4f8e9336a784a196353023133e0f8fa54f6a92e2"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--9a737c1d-ccf0-48e9-8b94-b64c440a4230"
},
{
"type": "file",
"value": "69ede7e341fd26fa0577692b601d80cb44778d93",
"hashes": {
"SHA-1": "69ede7e341fd26fa0577692b601d80cb44778d93"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--ca7f6059-1f8d-4375-8c21-9a9a362a2d97"
},
{
"type": "file",
"value": "86596a5c5b05a8bfbd14876de7404702f7d0d61b",
"hashes": {
"SHA-1": "86596a5c5b05a8bfbd14876de7404702f7d0d61b"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--b1e0ff90-64b0-48ad-8645-f6ccefd0f15b"
},
{
"type": "file",
"value": "9ec4c38394ea2048ca81d48b1bd66de48d8bd4e8",
"hashes": {
"SHA-1": "9ec4c38394ea2048ca81d48b1bd66de48d8bd4e8"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--5bd66437-2f2d-45bd-975b-ba658d26155d"
},
{
"type": "file",
"value": "40a4b5e54fecce52c9d8ef5b2fa3973a3dd748c5bcedd7bde1154aa4a936c2e1",
"hashes": {
"SHA-256": "40a4b5e54fecce52c9d8ef5b2fa3973a3dd748c5bcedd7bde1154aa4a936c2e1"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--64628eb3-aefe-4d34-97ca-f91a157e535a"
},
{
"type": "file",
"value": "60c70cdcb1e998bffed2e6e7298e1ab6bb3d90df04e437486c04e77c411cae4b",
"hashes": {
"SHA-256": "60c70cdcb1e998bffed2e6e7298e1ab6bb3d90df04e437486c04e77c411cae4b"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--9b86ac08-d740-41d0-80de-08ce83ee26ca"
},
{
"type": "file",
"value": "648c2067ef3d59eb94b54c43e798707b030e0383b3651bcc6840dae41808d3a9",
"hashes": {
"SHA-256": "648c2067ef3d59eb94b54c43e798707b030e0383b3651bcc6840dae41808d3a9"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--ab4d0d40-093b-4289-a9e6-56414cb01ed6"
},
{
"type": "file",
"value": "835b0d87ed2d49899ab6f9479cddb8b4e03f5aeb2365c50a51f9088dcede68d5",
"hashes": {
"SHA-256": "835b0d87ed2d49899ab6f9479cddb8b4e03f5aeb2365c50a51f9088dcede68d5"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--883dd817-fe7c-49b5-954e-fb64d3a050b2"
},
{
"type": "file",
"value": "bfda142bc5c44913eed9ef1cf2a8ad07b7a71312a26e4c7c519bf1a3fedeb6a0",
"hashes": {
"SHA-256": "bfda142bc5c44913eed9ef1cf2a8ad07b7a71312a26e4c7c519bf1a3fedeb6a0"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--5f05db4a-e639-4cdf-8f00-cbb3c60e701e"
},
{
"type": "file",
"value": "d1389a1ff652f8ca5576f10e9fa2bf8e8398699ddfc87ddd3e26adb201242160",
"hashes": {
"SHA-256": "d1389a1ff652f8ca5576f10e9fa2bf8e8398699ddfc87ddd3e26adb201242160"
},
"source": "OTX-Subscribed",
"pulse_name": "DynoWiper update: Technical analysis",
"id": "file--9c011752-7766-43cf-bfd1-8610f19f1679"
},
{
"type": "domain-name",
"value": "asangiklan.top",
"source": "OTX-Subscribed",
"pulse_name": "Threat Intelligence Dossier: TOXICSNAKE",
"id": "domain-name--83f07f0a-1a16-4b46-abed-46c81f8417f8"
},
{
"type": "domain-name",
"value": "ourasolid.com",
"source": "OTX-Subscribed",
"pulse_name": "Threat Intelligence Dossier: TOXICSNAKE",
"id": "domain-name--68ef85cb-84e4-4872-be82-a6dfb77a52c0"
},
{
"type": "domain-name",
"value": "pasangiklan.top",
"source": "OTX-Subscribed",
"pulse_name": "Threat Intelligence Dossier: TOXICSNAKE",
"id": "domain-name--af0b4929-3e14-419f-9147-fc50118a7ae7"
},
{
"type": "domain-name",
"value": "refanprediction.shop",
"source": "OTX-Subscribed",
"pulse_name": "Threat Intelligence Dossier: TOXICSNAKE",
"id": "domain-name--5291c9ee-1966-49f5-96fd-2dda8a2cb307"
},
{
"type": "domain-name",
"value": "toxicsnake-wifes.com",
"source": "OTX-Subscribed",
"pulse_name": "Threat Intelligence Dossier: TOXICSNAKE",
"id": "domain-name--6ce18b4b-c909-43dc-94e2-9e4be88ef5d8"
},
{
"type": "domain-name",
"value": "xelesex.top",
"source": "OTX-Subscribed",
"pulse_name": "Threat Intelligence Dossier: TOXICSNAKE",
"id": "domain-name--3de96d5e-7d5a-4a70-ab43-8133f1b3e478"
},
{
"type": "email-addr",
"value": "oreshnik@mailum.com",
"source": "OTX-Subscribed",
"pulse_name": "Threat Intelligence Dossier: TOXICSNAKE",
"id": "email-addr--00a1f30c-f712-4dbd-8a41-84c182d25807"
},
{
"type": "domain-name",
"value": "advisory.md",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--8ef7d1e6-b287-4e14-b439-e65af1bdc45b"
},
{
"type": "file",
"value": "adf4976a229c70df5a404c45ef9f6680",
"hashes": {
"MD5": "adf4976a229c70df5a404c45ef9f6680"
},
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "file--f2d27801-e10d-4063-ae30-cf7f485fcee2"
},
{
"type": "file",
"value": "2d5f88c396553669bd50183644d77ad3c71d72bb",
"hashes": {
"SHA-1": "2d5f88c396553669bd50183644d77ad3c71d72bb"
},
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "file--ddb3e0e5-344b-4f62-8147-0aa3f7a5b02f"
},
{
"type": "file",
"value": "3b9b2d5934f9ed1e3a000a760a6fa90422e8a555",
"hashes": {
"SHA-1": "3b9b2d5934f9ed1e3a000a760a6fa90422e8a555"
},
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "file--1745d6e9-225b-46fe-9dc5-66831375bbda"
},
{
"type": "file",
"value": "63fd5e0811c0bcc7df9fc3d712f39f829a8d6ff0",
"hashes": {
"SHA-1": "63fd5e0811c0bcc7df9fc3d712f39f829a8d6ff0"
},
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "file--21170e7b-2456-41e2-86b2-2a71ccfebb27"
},
{
"type": "file",
"value": "6445e5ce51da03934395abb5411d3200d12ed7b3",
"hashes": {
"SHA-1": "6445e5ce51da03934395abb5411d3200d12ed7b3"
},
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "file--ca6bc88f-a54d-4386-8474-6121fde9ab5b"
},
{
"type": "file",
"value": "7556ae58c215b8245a43f764f0676c7a8f0fdd1a",
"hashes": {
"SHA-1": "7556ae58c215b8245a43f764f0676c7a8f0fdd1a"
},
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "file--4699d335-7060-4063-91c1-e91fc5373c3d"
},
{
"type": "file",
"value": "ad77fbdbb2fcbdb440428eed3e76d106e1119fcf",
"hashes": {
"SHA-1": "ad77fbdbb2fcbdb440428eed3e76d106e1119fcf"
},
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "file--b5dccc50-3ae7-49b0-87c4-cafe8a3f85af"
},
{
"type": "file",
"value": "f5c6bd4e9686afb0c4e7c1c1733febb4065d514f",
"hashes": {
"SHA-1": "f5c6bd4e9686afb0c4e7c1c1733febb4065d514f"
},
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "file--b5c3b76a-bc84-436a-ab57-71b908c2ed98"
},
{
"type": "file",
"value": "b88605d7cb0501a26438b94b99479200a3088e2297a741e6dec3a4d4d44cd753",
"hashes": {
"SHA-256": "b88605d7cb0501a26438b94b99479200a3088e2297a741e6dec3a4d4d44cd753"
},
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "file--38fee6b3-bdce-481c-9404-3c5edd4d78a2"
},
{
"type": "domain-name",
"value": "assets-msnds.org",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--8f9b24c3-87c5-4de2-a6a3-0e0d30318ada"
},
{
"type": "domain-name",
"value": "cf1-winows-ww.com",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--c06ff45b-0740-491e-bd1e-1c4f55edfb58"
},
{
"type": "domain-name",
"value": "dns-teams-windows.live",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--8854c578-f14b-4570-8bbd-a0ec624e8111"
},
{
"type": "domain-name",
"value": "eventsdatamicrosoft.org",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--9baf199e-0f8c-4bc1-82aa-1de63ebc94a9"
},
{
"type": "domain-name",
"value": "hedle.seek",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--c573348e-3e66-44fa-ade0-33227bd70d2d"
},
{
"type": "domain-name",
"value": "microsoft-iplcloud.com",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--08d6347c-ddd3-42f6-9657-18b3976da073"
},
{
"type": "domain-name",
"value": "settings-datamicrosoft.org",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--807fed64-d4de-4500-a598-7d6ed0d0859c"
},
{
"type": "domain-name",
"value": "settings-win-datamicrosoft.org",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--1acceb58-eaeb-448c-b110-fd2b2194d4b4"
},
{
"type": "domain-name",
"value": "sync-time-win.live",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--5293f326-d29c-40d9-a6ad-4b214e6fc897"
},
{
"type": "domain-name",
"value": "time-syncmicrosoft.com",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--491415f4-9d2a-402e-90a1-cc77be52a170"
},
{
"type": "domain-name",
"value": "champagne-businesses-hand-theta.trycloudflare.com",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--a8cf501f-040b-4353-b919-ccf4545124ac"
},
{
"type": "domain-name",
"value": "mortgage-i-concrete-origins.trycloudflare.com",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--0128e662-5327-4cb8-86a4-cd5f457c4e08"
},
{
"type": "domain-name",
"value": "musicians-implied-less-model.trycloudflare.com",
"source": "OTX-Subscribed",
"pulse_name": "Interlock Ransomware: New Techniques, Same Old Tricks",
"id": "domain-name--2e6aaefd-dc04-4ea8-951c-738635ccf4fa"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--d4bbb849-0e43-4a1a-9cb8-db3ea5984b53",
"created": "2026-03-01T23:56:59.912Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'progamevl.ru']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--068d9f5e-e974-47ee-8854-9bc006f1d0a0",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--d4bbb849-0e43-4a1a-9cb8-db3ea5984b53",
"target_ref": "domain-name--4e2c2386-d56c-4cf6-a192-659a55762b97"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--63f00587-4b89-4621-abae-079a32f785e6",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'MD5' = '5249503900c735425130477649872dfb']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--6959496c-870c-4f7f-b901-61ff747f0bbb",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--63f00587-4b89-4621-abae-079a32f785e6",
"target_ref": "file--d29f7847-c1a9-448b-997c-af240da9966d"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ecbe65ac-46a7-482f-afce-b5ff5f721370",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'MD5' = '75fec5afb2deebab6dd9c16d9de35032']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--09119c32-a40e-498d-9b70-7e059a38c9df",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--ecbe65ac-46a7-482f-afce-b5ff5f721370",
"target_ref": "file--10141e8d-af8e-4909-b972-6a596ae23ff7"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--083f37fd-1305-4b77-870e-3882d3c41516",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'MD5' = '9d896e0e3e369c2edf1c8fb070f49c22']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--dcc732d5-d2e5-47b2-a893-269f8589d567",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--083f37fd-1305-4b77-870e-3882d3c41516",
"target_ref": "file--cda39981-f3d8-40b5-8db2-08b9608c1197"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--26ec8131-8080-495c-8c3d-26db70c09b5c",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'MD5' = 'a727362416834fa63672b87820ff7f27']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b9a42d5e-f073-4183-8cd6-0a86585bb405",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--26ec8131-8080-495c-8c3d-26db70c09b5c",
"target_ref": "file--1d4a03a3-4045-4449-8620-cf2d984a488b"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--2bcff397-f738-483a-a191-2be3b22439d6",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'MD5' = 'c4379da51e8b9e86ec3de934f9373f4a']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--2a858f32-ca08-438f-8887-280999325674",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--2bcff397-f738-483a-a191-2be3b22439d6",
"target_ref": "file--fc57cbda-f7aa-4ab6-b992-671c3f0a9bc3"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--57f6d493-3c2e-4a4d-9b20-2c073f93a70a",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'MD5' = 'f5271a6d909091527ed9f30eafa0ded6']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--cd2891d9-8c6c-45bc-a2db-fd1737578fbe",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--57f6d493-3c2e-4a4d-9b20-2c073f93a70a",
"target_ref": "file--96f083f2-b3d6-4e8d-8193-4de2e191e1f6"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--259bb0ae-f7a8-4aea-b823-097b76c2f9e0",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '410c8a57fe6e09edbfebaba7d5d3e4797ca80a19']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--1678e323-ff14-42e1-bc99-defc2c174fd0",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--259bb0ae-f7a8-4aea-b823-097b76c2f9e0",
"target_ref": "file--53f50220-6b1a-409f-aa02-746adf697c04"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ef0f97a9-ad82-4af4-87fd-af13bb5ce4bb",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '472ca448f82a7ff6f373a32fdb9586fd7c38b631']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--3387eb5a-4b42-42a7-a951-3c1ce553ed96",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--ef0f97a9-ad82-4af4-87fd-af13bb5ce4bb",
"target_ref": "file--c0034411-b81a-4ab5-91cc-042999497e48"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--123c8bfd-8afa-4794-8ef9-f1d60a81f032",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '4ec3c90846af6b79ee1a5188eefa3fd21f6d4cf6']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--c25ede88-5364-49c3-912b-a48921992e4e",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--123c8bfd-8afa-4794-8ef9-f1d60a81f032",
"target_ref": "file--6018bd4a-1b56-435a-ab76-99f106e0a503"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--9ee9b42b-23e5-418c-8a36-8f32de3642d5",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '4f8e9336a784a196353023133e0f8fa54f6a92e2']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--89ccaeb9-b348-4a0d-abaf-e3667171815a",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--9ee9b42b-23e5-418c-8a36-8f32de3642d5",
"target_ref": "file--9a737c1d-ccf0-48e9-8b94-b64c440a4230"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--8ac9f017-0bbe-4a32-a2ea-cefc6f77c3a0",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '69ede7e341fd26fa0577692b601d80cb44778d93']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b8c253ea-c3ec-40b0-83f5-5f1f585db761",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--8ac9f017-0bbe-4a32-a2ea-cefc6f77c3a0",
"target_ref": "file--ca7f6059-1f8d-4375-8c21-9a9a362a2d97"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--577a0a6a-9780-419a-8d9e-dd7ef66acf61",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '86596a5c5b05a8bfbd14876de7404702f7d0d61b']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--2b054add-75c2-45fb-9e53-72dc9776fce1",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--577a0a6a-9780-419a-8d9e-dd7ef66acf61",
"target_ref": "file--b1e0ff90-64b0-48ad-8645-f6ccefd0f15b"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5a1ea69c-3790-47e9-8022-9cd932ca91f6",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '9ec4c38394ea2048ca81d48b1bd66de48d8bd4e8']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--8e9fbdbb-0355-43ab-9c70-a4f7349658a1",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--5a1ea69c-3790-47e9-8022-9cd932ca91f6",
"target_ref": "file--5bd66437-2f2d-45bd-975b-ba658d26155d"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--60582689-f273-4910-b6d1-d9ce7a91ee74",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '40a4b5e54fecce52c9d8ef5b2fa3973a3dd748c5bcedd7bde1154aa4a936c2e1']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--fe1e76b8-bb16-4f8c-a50e-7953d4c9a8f1",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--60582689-f273-4910-b6d1-d9ce7a91ee74",
"target_ref": "file--64628eb3-aefe-4d34-97ca-f91a157e535a"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--6170dfeb-9595-488e-8206-6f8c6f9e70e0",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '60c70cdcb1e998bffed2e6e7298e1ab6bb3d90df04e437486c04e77c411cae4b']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--1f24988f-62a7-4fb4-ab1d-75cafcbff7b0",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--6170dfeb-9595-488e-8206-6f8c6f9e70e0",
"target_ref": "file--9b86ac08-d740-41d0-80de-08ce83ee26ca"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--409bfc7f-40e9-4a74-9c96-29c328853c91",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '648c2067ef3d59eb94b54c43e798707b030e0383b3651bcc6840dae41808d3a9']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--2ae5e085-5771-4651-bf33-f1ed640c1283",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--409bfc7f-40e9-4a74-9c96-29c328853c91",
"target_ref": "file--ab4d0d40-093b-4289-a9e6-56414cb01ed6"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5891c833-3fc9-40cc-b607-1ca3da4b5185",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '835b0d87ed2d49899ab6f9479cddb8b4e03f5aeb2365c50a51f9088dcede68d5']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--e67aa63e-73f4-4e00-9e51-6b0f7c10451b",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--5891c833-3fc9-40cc-b607-1ca3da4b5185",
"target_ref": "file--883dd817-fe7c-49b5-954e-fb64d3a050b2"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--6278d742-14f2-4258-b3d3-78cb8ee14912",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'bfda142bc5c44913eed9ef1cf2a8ad07b7a71312a26e4c7c519bf1a3fedeb6a0']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--c3343700-6813-4bdf-abc1-78e425d9ee52",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--6278d742-14f2-4258-b3d3-78cb8ee14912",
"target_ref": "file--5f05db4a-e639-4cdf-8f00-cbb3c60e701e"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5da44091-6544-43e4-95a0-bbc372342ef4",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'd1389a1ff652f8ca5576f10e9fa2bf8e8398699ddfc87ddd3e26adb201242160']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.913Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--fef96a21-1508-4436-95e2-3034504e6342",
"created": "2026-03-01T23:56:59.913Z",
"modified": "2026-03-01T23:56:59.913Z",
"relationship_type": "based-on",
"source_ref": "indicator--5da44091-6544-43e4-95a0-bbc372342ef4",
"target_ref": "file--9c011752-7766-43cf-bfd1-8610f19f1679"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--4fb972a7-5f83-467c-8908-d59be5e1653a",
"created": "2026-03-01T23:56:59.932Z",
"modified": "2026-03-01T23:56:59.932Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'asangiklan.top']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.932Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--71caae1d-6674-442b-b4dd-620673c4dfb5",
"created": "2026-03-01T23:56:59.932Z",
"modified": "2026-03-01T23:56:59.932Z",
"relationship_type": "based-on",
"source_ref": "indicator--4fb972a7-5f83-467c-8908-d59be5e1653a",
"target_ref": "domain-name--83f07f0a-1a16-4b46-abed-46c81f8417f8"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5a284aaf-a103-4b41-90f9-368192bf688d",
"created": "2026-03-01T23:56:59.945Z",
"modified": "2026-03-01T23:56:59.945Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'ourasolid.com']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.945Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--3c48e286-9514-4021-ab04-e5d94df849fd",
"created": "2026-03-01T23:56:59.945Z",
"modified": "2026-03-01T23:56:59.945Z",
"relationship_type": "based-on",
"source_ref": "indicator--5a284aaf-a103-4b41-90f9-368192bf688d",
"target_ref": "domain-name--68ef85cb-84e4-4872-be82-a6dfb77a52c0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--37efad6d-6db8-42be-8fd3-d5bc7d178c68",
"created": "2026-03-01T23:56:59.960Z",
"modified": "2026-03-01T23:56:59.960Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'pasangiklan.top']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.960Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--a3094e83-d0d6-4ca5-b102-11bcca678617",
"created": "2026-03-01T23:56:59.960Z",
"modified": "2026-03-01T23:56:59.960Z",
"relationship_type": "based-on",
"source_ref": "indicator--37efad6d-6db8-42be-8fd3-d5bc7d178c68",
"target_ref": "domain-name--af0b4929-3e14-419f-9147-fc50118a7ae7"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c1fb7060-e073-4992-b1a8-f76f53d986e5",
"created": "2026-03-01T23:56:59.982Z",
"modified": "2026-03-01T23:56:59.982Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'refanprediction.shop']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:56:59.982Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--45f3ccf8-4975-4307-9d84-3ee01775908b",
"created": "2026-03-01T23:56:59.982Z",
"modified": "2026-03-01T23:56:59.982Z",
"relationship_type": "based-on",
"source_ref": "indicator--c1fb7060-e073-4992-b1a8-f76f53d986e5",
"target_ref": "domain-name--5291c9ee-1966-49f5-96fd-2dda8a2cb307"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--a5db180b-6b94-4448-a3ce-4e36ad14f56a",
"created": "2026-03-01T23:57:00.000Z",
"modified": "2026-03-01T23:57:00.000Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'toxicsnake-wifes.com']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.000Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--9fddc57a-a1c8-4d91-8120-be0a38ae1340",
"created": "2026-03-01T23:57:00.000Z",
"modified": "2026-03-01T23:57:00.000Z",
"relationship_type": "based-on",
"source_ref": "indicator--a5db180b-6b94-4448-a3ce-4e36ad14f56a",
"target_ref": "domain-name--6ce18b4b-c909-43dc-94e2-9e4be88ef5d8"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ab4c3ff8-f76b-4811-9b7b-169bd73e7169",
"created": "2026-03-01T23:57:00.021Z",
"modified": "2026-03-01T23:57:00.021Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'xelesex.top']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.021Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--61d7dc10-40aa-4e0f-a155-dfde9ccb80d4",
"created": "2026-03-01T23:57:00.021Z",
"modified": "2026-03-01T23:57:00.021Z",
"relationship_type": "based-on",
"source_ref": "indicator--ab4c3ff8-f76b-4811-9b7b-169bd73e7169",
"target_ref": "domain-name--3de96d5e-7d5a-4a70-ab43-8133f1b3e478"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--a0642b4c-1d76-4cfc-a49b-f76ce9a67811",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'advisory.md']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--7250da41-d7f3-4be0-b289-b92c3313c427",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--a0642b4c-1d76-4cfc-a49b-f76ce9a67811",
"target_ref": "domain-name--8ef7d1e6-b287-4e14-b439-e65af1bdc45b"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--0d059cd9-51fd-4df8-88dd-8ad7af09c1f8",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'MD5' = 'adf4976a229c70df5a404c45ef9f6680']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--fe4dfa71-d422-48e8-a225-5c6dce0b159b",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--0d059cd9-51fd-4df8-88dd-8ad7af09c1f8",
"target_ref": "file--f2d27801-e10d-4063-ae30-cf7f485fcee2"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--0a3f5121-1671-4ec2-8486-7005ad37e8dc",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '2d5f88c396553669bd50183644d77ad3c71d72bb']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--cc0dda94-7c2d-4866-b389-250ab7dfba99",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--0a3f5121-1671-4ec2-8486-7005ad37e8dc",
"target_ref": "file--ddb3e0e5-344b-4f62-8147-0aa3f7a5b02f"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ab9cb08f-cfe0-4136-9184-8d5a6b3e1b75",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '3b9b2d5934f9ed1e3a000a760a6fa90422e8a555']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--c4c1f022-1215-4cae-9b17-f086ecaa1cb7",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--ab9cb08f-cfe0-4136-9184-8d5a6b3e1b75",
"target_ref": "file--1745d6e9-225b-46fe-9dc5-66831375bbda"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c94c5f7f-9d29-4368-b8ea-7cabf4070d62",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '63fd5e0811c0bcc7df9fc3d712f39f829a8d6ff0']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--3d42774e-b411-42f5-b3cc-88a4cd51d738",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--c94c5f7f-9d29-4368-b8ea-7cabf4070d62",
"target_ref": "file--21170e7b-2456-41e2-86b2-2a71ccfebb27"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--7d3bcde5-f763-4f38-b539-7812f64c30e9",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '6445e5ce51da03934395abb5411d3200d12ed7b3']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b9e45121-8bac-47c3-a61b-4a22d25be126",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--7d3bcde5-f763-4f38-b539-7812f64c30e9",
"target_ref": "file--ca6bc88f-a54d-4386-8474-6121fde9ab5b"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--462a9520-5a55-41b4-9c53-69d50e6bf7b9",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '7556ae58c215b8245a43f764f0676c7a8f0fdd1a']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--527c7bd0-332b-4703-a081-55f393b92928",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--462a9520-5a55-41b4-9c53-69d50e6bf7b9",
"target_ref": "file--4699d335-7060-4063-91c1-e91fc5373c3d"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--036f10f2-d234-4272-b997-0717db6d4c2a",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = 'ad77fbdbb2fcbdb440428eed3e76d106e1119fcf']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--e0292a45-4e89-425a-a99b-ec3fb2394b02",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--036f10f2-d234-4272-b997-0717db6d4c2a",
"target_ref": "file--b5dccc50-3ae7-49b0-87c4-cafe8a3f85af"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ff53e531-2b70-4be3-99e2-06c873dce3fa",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = 'f5c6bd4e9686afb0c4e7c1c1733febb4065d514f']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--1be25d6a-7426-464a-90cd-84a2ed876fa2",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--ff53e531-2b70-4be3-99e2-06c873dce3fa",
"target_ref": "file--b5c3b76a-bc84-436a-ab57-71b908c2ed98"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--31d7b411-e52f-452a-9676-0d89a9d9c560",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'b88605d7cb0501a26438b94b99479200a3088e2297a741e6dec3a4d4d44cd753']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.040Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--a4ea23e0-f30f-4b96-b718-b8b3711dc62a",
"created": "2026-03-01T23:57:00.040Z",
"modified": "2026-03-01T23:57:00.040Z",
"relationship_type": "based-on",
"source_ref": "indicator--31d7b411-e52f-452a-9676-0d89a9d9c560",
"target_ref": "file--38fee6b3-bdce-481c-9404-3c5edd4d78a2"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--b4229d03-eca1-4a55-b587-b6322e04c1fa",
"created": "2026-03-01T23:57:00.056Z",
"modified": "2026-03-01T23:57:00.056Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'assets-msnds.org']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.056Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--e706764c-9128-4381-9b4e-d1c6b018994d",
"created": "2026-03-01T23:57:00.056Z",
"modified": "2026-03-01T23:57:00.056Z",
"relationship_type": "based-on",
"source_ref": "indicator--b4229d03-eca1-4a55-b587-b6322e04c1fa",
"target_ref": "domain-name--8f9b24c3-87c5-4de2-a6a3-0e0d30318ada"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--927c4f5e-62b0-42ab-b71d-f2d1fffe6ae0",
"created": "2026-03-01T23:57:00.082Z",
"modified": "2026-03-01T23:57:00.082Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'cf1-winows-ww.com']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.082Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--027bba19-df0a-4397-bf61-75fc90d908e9",
"created": "2026-03-01T23:57:00.082Z",
"modified": "2026-03-01T23:57:00.082Z",
"relationship_type": "based-on",
"source_ref": "indicator--927c4f5e-62b0-42ab-b71d-f2d1fffe6ae0",
"target_ref": "domain-name--c06ff45b-0740-491e-bd1e-1c4f55edfb58"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--a8e0e4c9-ff38-40ed-90a9-428e6298e423",
"created": "2026-03-01T23:57:00.105Z",
"modified": "2026-03-01T23:57:00.105Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'dns-teams-windows.live']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.105Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--4a088c3d-9fd8-4508-a35d-2aa5e529a8a8",
"created": "2026-03-01T23:57:00.105Z",
"modified": "2026-03-01T23:57:00.105Z",
"relationship_type": "based-on",
"source_ref": "indicator--a8e0e4c9-ff38-40ed-90a9-428e6298e423",
"target_ref": "domain-name--8854c578-f14b-4570-8bbd-a0ec624e8111"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--411fc941-c980-4b34-98f5-111d7626f6e8",
"created": "2026-03-01T23:57:00.125Z",
"modified": "2026-03-01T23:57:00.125Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'eventsdatamicrosoft.org']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.125Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--01a6cac5-c75a-43fa-90b7-566967ca9189",
"created": "2026-03-01T23:57:00.125Z",
"modified": "2026-03-01T23:57:00.125Z",
"relationship_type": "based-on",
"source_ref": "indicator--411fc941-c980-4b34-98f5-111d7626f6e8",
"target_ref": "domain-name--9baf199e-0f8c-4bc1-82aa-1de63ebc94a9"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--45dad0d1-9f5b-44e9-8734-819da9a1eaac",
"created": "2026-03-01T23:57:00.139Z",
"modified": "2026-03-01T23:57:00.139Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'hedle.seek']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.139Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--51db11a0-6e31-4bdf-9cb4-60ee1bc79976",
"created": "2026-03-01T23:57:00.139Z",
"modified": "2026-03-01T23:57:00.139Z",
"relationship_type": "based-on",
"source_ref": "indicator--45dad0d1-9f5b-44e9-8734-819da9a1eaac",
"target_ref": "domain-name--c573348e-3e66-44fa-ade0-33227bd70d2d"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--1275068a-9c8d-4f2b-bda8-1b459f885273",
"created": "2026-03-01T23:57:00.155Z",
"modified": "2026-03-01T23:57:00.155Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'microsoft-iplcloud.com']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.155Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--d2b7e3e1-5843-4238-8338-114fba18a901",
"created": "2026-03-01T23:57:00.155Z",
"modified": "2026-03-01T23:57:00.155Z",
"relationship_type": "based-on",
"source_ref": "indicator--1275068a-9c8d-4f2b-bda8-1b459f885273",
"target_ref": "domain-name--08d6347c-ddd3-42f6-9657-18b3976da073"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--6f35747a-a0f7-490d-a811-8b5295a595b3",
"created": "2026-03-01T23:57:00.169Z",
"modified": "2026-03-01T23:57:00.169Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'settings-datamicrosoft.org']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.169Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--3785db43-740d-4eb1-aa1f-14b41629594f",
"created": "2026-03-01T23:57:00.169Z",
"modified": "2026-03-01T23:57:00.169Z",
"relationship_type": "based-on",
"source_ref": "indicator--6f35747a-a0f7-490d-a811-8b5295a595b3",
"target_ref": "domain-name--807fed64-d4de-4500-a598-7d6ed0d0859c"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--f3eeed16-9c40-45e5-a269-12b0932468fa",
"created": "2026-03-01T23:57:00.184Z",
"modified": "2026-03-01T23:57:00.184Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'settings-win-datamicrosoft.org']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.184Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--517543b5-d207-4f86-be42-c08189472815",
"created": "2026-03-01T23:57:00.184Z",
"modified": "2026-03-01T23:57:00.184Z",
"relationship_type": "based-on",
"source_ref": "indicator--f3eeed16-9c40-45e5-a269-12b0932468fa",
"target_ref": "domain-name--1acceb58-eaeb-448c-b110-fd2b2194d4b4"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c872b902-3208-4c20-be85-aecadfa89816",
"created": "2026-03-01T23:57:00.200Z",
"modified": "2026-03-01T23:57:00.200Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'sync-time-win.live']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.200Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--025583a3-ac3e-4bc5-821b-588c3a35ecc5",
"created": "2026-03-01T23:57:00.200Z",
"modified": "2026-03-01T23:57:00.200Z",
"relationship_type": "based-on",
"source_ref": "indicator--c872b902-3208-4c20-be85-aecadfa89816",
"target_ref": "domain-name--5293f326-d29c-40d9-a6ad-4b214e6fc897"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--1e7b6d63-3e99-4670-b4d1-721f7290b77d",
"created": "2026-03-01T23:57:00.223Z",
"modified": "2026-03-01T23:57:00.223Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'time-syncmicrosoft.com']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.223Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b80cbfb1-287f-42fd-ab6e-118d52d6aaae",
"created": "2026-03-01T23:57:00.223Z",
"modified": "2026-03-01T23:57:00.223Z",
"relationship_type": "based-on",
"source_ref": "indicator--1e7b6d63-3e99-4670-b4d1-721f7290b77d",
"target_ref": "domain-name--491415f4-9d2a-402e-90a1-cc77be52a170"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--4f43f2c8-9f55-40ea-a447-d5068b169e94",
"created": "2026-03-01T23:57:00.289Z",
"modified": "2026-03-01T23:57:00.290Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'champagne-businesses-hand-theta.trycloudflare.com']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.290Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--01dd800c-b4ec-40a4-a6ee-7d584f691ff7",
"created": "2026-03-01T23:57:00.290Z",
"modified": "2026-03-01T23:57:00.290Z",
"relationship_type": "based-on",
"source_ref": "indicator--4f43f2c8-9f55-40ea-a447-d5068b169e94",
"target_ref": "domain-name--a8cf501f-040b-4353-b919-ccf4545124ac"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e559ff53-b234-4591-ac7d-edaebb29f226",
"created": "2026-03-01T23:57:00.325Z",
"modified": "2026-03-01T23:57:00.326Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'mortgage-i-concrete-origins.trycloudflare.com']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.326Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--039ba70b-82bf-480c-9411-4b8fb237ff28",
"created": "2026-03-01T23:57:00.326Z",
"modified": "2026-03-01T23:57:00.326Z",
"relationship_type": "based-on",
"source_ref": "indicator--e559ff53-b234-4591-ac7d-edaebb29f226",
"target_ref": "domain-name--0128e662-5327-4cb8-86a4-cd5f457c4e08"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--19baa79f-17b7-4bae-b98f-b9610083a094",
"created": "2026-03-01T23:57:00.342Z",
"modified": "2026-03-01T23:57:00.342Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'musicians-implied-less-model.trycloudflare.com']",
"pattern_type": "stix",
"valid_from": "2026-03-01T23:57:00.342Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--4455feeb-68f7-430c-89c7-93457bfe9c09",
"created": "2026-03-01T23:57:00.342Z",
"modified": "2026-03-01T23:57:00.342Z",
"relationship_type": "based-on",
"source_ref": "indicator--19baa79f-17b7-4bae-b98f-b9610083a094",
"target_ref": "domain-name--2e6aaefd-dc04-4ea8-951c-738635ccf4fa"
}
]
}