{
    "type": "bundle",
    "id": "bundle--68b173f6-3850-464d-81d0-730bd1bb9a04",
    "objects": [
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.192514Z",
            "modified": "2026-08-13T15:19:18.192514Z",
            "name": "The Hunters Ledger",
            "identity_class": "organization"
        },
        {
            "type": "marking-definition",
            "spec_version": "2.1",
            "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
            "created": "2017-01-20T00:00:00.000Z",
            "definition_type": "tlp",
            "name": "TLP:WHITE",
            "definition": {
                "tlp": "white"
            }
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--9382dded-53f0-5a21-93ec-7cbb5d9d767b",
            "value": "144.172.106.236"
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--a4bec962-d1b4-5aa5-92b9-0722d341f775",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.194112Z",
            "modified": "2026-08-13T15:19:18.194112Z",
            "name": "ipv4: 144.172.106.236",
            "description": "AS14956 RouterHosting LLC / Cloudzy (US), block 144.172.96.0/20. Single dedicated operator box (only identified dedicated asset). Operator listener map: :9443 tunnel control, :1080 SOCKS5 no-auth, :8443/:4443 chisel, :8080 SSRF canary, :4444/:80/:443 ncat, :9999 open dir. SSH live through 2026-07-14; :9999 open dir pulled early July 2026.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[ipv4-addr:value = '144.172.106.236']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "valid_from": "2026-07-17T00:00:00Z",
            "confidence": 95,
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "x_opencti_detection": false,
            "x_opencti_score": 95
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--264f6b3b-2022-50c6-a87d-74933dc83e20",
            "value": "87.106.101.131"
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--b0b349fd-c7a0-5e9a-8365-9d39134b43cf",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.198462Z",
            "modified": "2026-08-13T15:19:18.198462Z",
            "name": "ipv4: 87.106.101.131",
            "description": "Extracted by VirusTotal from cat.sh. HUNT-tier; associated with the second-actor GSocket kit, not the reported operator.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[ipv4-addr:value = '87.106.101.131']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "valid_from": "2026-07-17T00:00:00Z",
            "confidence": 60,
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "x_opencti_detection": false,
            "x_opencti_score": 60
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--03ffeacb-7e51-5aea-8555-0f596b71cf56",
            "value": "localroot.sbs"
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--0ba2e85d-a6a0-513e-85c3-3d96d1ef089f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.199276Z",
            "modified": "2026-08-13T15:19:18.199276Z",
            "name": "domain: localroot.sbs",
            "description": "Cloudflare-fronted (arya/lee.ns.cloudflare.com; A 172.67.199.181, 104.21.52.137; AAAA 2606:4700:3035::). Registered 2025-08-17. VT 0/91 \u2014 completely unflagged by every engine, so no vendor will catch it. Serves cat.sh (only downloaded file per VT). BLOCK the domain; do NOT block the Cloudflare IPs.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[domain-name:value = 'localroot.sbs']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "valid_from": "2026-07-17T00:00:00Z",
            "confidence": 80,
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "x_opencti_detection": true,
            "x_opencti_score": 80
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--2e360dc4-cc6f-5d09-afdd-7e8a7e83be23",
            "value": "utah01-maas.cloudzy.com"
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--956bf4b3-3599-54d9-bea7-63e582926b2a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.200292Z",
            "modified": "2026-08-13T15:19:18.200292Z",
            "name": "domain: utah01-maas.cloudzy.com",
            "description": "Resolves to 144.172.106.236 itself (288 self-lookups in the operator's localhost DNS log). Cloudzy provider infrastructure hostname, not a C2 domain \u2014 context/hunt only, do not block.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[domain-name:value = 'utah01-maas.cloudzy.com']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "valid_from": "2026-07-17T00:00:00Z",
            "confidence": 60,
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "x_opencti_detection": false,
            "x_opencti_score": 60
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--4bf344b7-0aec-55fa-91c9-6415ec9b7efd",
            "hashes": {
                "SHA-256": "e788f829b1a0141a488afb5f82b94f13035623609ca3b83f0c6985919cd9e83b"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--81df8872-95fb-545b-9132-032edecbd142",
            "hashes": {
                "SHA-256": "23560e13d06d8153e0e7566d153ffe9eec79e08eb1ed18f8cd1417728e7dbdd6"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--e601b288-1e9e-5f8b-879e-7611935a1e7e",
            "hashes": {
                "SHA-256": "c600f8e4ee5ece27ce777fe4f69c18c6611768ee7192c74e4e66f9e236e19b1e"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--242b068c-fdba-5db4-803e-8f0beab040d1",
            "hashes": {
                "SHA-256": "8a7d387663d7f32730ed8b996f1dab7c2eed4b829b71fd48c608f51569dc4d69"
            }
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--15a311ae-d63d-526f-a4fc-49023631f11f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.202066Z",
            "modified": "2026-08-13T15:19:18.202066Z",
            "name": "webshell_zimbra_security_monitor_jsp",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "/*\n   Yara Rule Set\n   Identifier: SE-Asia Gov Exploitation Toolkit - Zimbra Webshell Decoy\n   Author: The Hunters Ledger\n   Source: https://the-hunters-ledger.com/\n   License: CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\n*/\n\nrule webshell_zimbra_security_monitor_jsp {\n   meta:\n      description = \"Detects the operator-authored JSP web shell decoy banner 'Zimbra Security Monitor v3.1 -- System Diagnostics' embedded in a Zimbra CVE-2022-41352 cpio-traversal payload, alone or combined with a Runtime.getRuntime().exec( command-execution call typical of a JSP web shell\"\n      license = \"CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\"\n      author = \"The Hunters Ledger\"\n      reference = \"https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\"\n      date = \"2026-07-17\"\n      family = \"SE-Asia Gov Exploitation Toolkit (unattributed operator)\"\n      malware_type = \"Web Shell\"\n      campaign = \"seasia-gov-exploitation-toolkit-144-172-106-236\"\n      id = \"322ec1aa-636f-502a-a7db-74f0d4f1f92c\"\n   strings:\n      $decoy_banner = \"Zimbra Security Monitor v3.1 -- System Diagnostics\" ascii wide\n      $exec_call = \"Runtime.getRuntime().exec(\" ascii\n      $jsp_tag = \"<%@ page\" ascii\n   condition:\n      filesize < 200KB and\n      (\n         $decoy_banner or\n         (all of ($exec_call, $jsp_tag))\n      )\n}",
            "pattern_type": "yara",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--d86cc40c-e152-5b13-a055-4c0cf3d7350a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.202208Z",
            "modified": "2026-08-13T15:19:18.202208Z",
            "name": "webshell_gif89a_php_polyglot",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "/*\n   Yara Rule Set\n   Identifier: SE-Asia Gov Exploitation Toolkit - GIF89a PHP Polyglot Web Shells\n   Author: The Hunters Ledger\n   Source: https://the-hunters-ledger.com/\n   License: CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\n*/\n\nrule webshell_gif89a_php_polyglot {\n   meta:\n      description = \"Detects minimal GIF89a magic-byte polyglot PHP web shells that prefix a raw PHP command-execution one-liner with the GIF file-signature bytes to defeat naive image-upload content-sniffing filters, as staged by the operator against multiple government targets\"\n      license = \"CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\"\n      author = \"The Hunters Ledger\"\n      reference = \"https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\"\n      date = \"2026-07-17\"\n      family = \"SE-Asia Gov Exploitation Toolkit (unattributed operator)\"\n      malware_type = \"Web Shell\"\n      campaign = \"seasia-gov-exploitation-toolkit-144-172-106-236\"\n      id = \"1dc828f3-d6ab-53ac-99a9-bd8f05078898\"\n   strings:\n      $gif_system = \"GIF89a<?php system($_GET[c]); ?>\" ascii\n      $gif_assert = \"GIF89a<?php assert($_REQUEST[\\\"c\\\"]); ?>\" ascii\n      $gif_magic = \"GIF89a\" ascii\n      $php_open = \"<?php\" ascii\n   condition:\n      filesize < 4KB and\n      (\n         any of ($gif_system, $gif_assert) or\n         ($gif_magic at 0 and $php_open in (4..64))\n      )\n}",
            "pattern_type": "yara",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--3c68d8fb-7f0d-5972-b80d-14cefaf1de8d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.202332Z",
            "modified": "2026-08-13T15:19:18.202332Z",
            "name": "gen_go_tunnel_proxy_mux_elf",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "/*\n   Yara Rule Set\n   Identifier: SE-Asia Gov Exploitation Toolkit - Custom Go Tunnel-Proxy Module\n   Author: The Hunters Ledger\n   Source: https://the-hunters-ledger.com/\n   License: CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\n*/\n\nrule gen_go_tunnel_proxy_mux_elf {\n   meta:\n      description = \"Detects the operator's custom Go-built reverse-tunnel and SOCKS5 multiplexing toolset (tunnel-server / tunnel-agent) via its distinctive internal module import path tunnel-proxy/pkg/mux, embedded in the Go build metadata of both paired ELF64 binaries\"\n      license = \"CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\"\n      author = \"The Hunters Ledger\"\n      reference = \"https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\"\n      date = \"2026-07-17\"\n      hash1 = \"23560e13d06d8153e0e7566d153ffe9eec79e08eb1ed18f8cd1417728e7dbdd6\"\n      hash2 = \"c640fed8c76802f2bea562ff08a0643d8f033771\"\n      hash3 = \"d96d4e7bc25704e48576ee7667d424aa\"\n      family = \"SE-Asia Gov Exploitation Toolkit (unattributed operator)\"\n      malware_type = \"Custom tunnel / SOCKS5 proxy\"\n      campaign = \"seasia-gov-exploitation-toolkit-144-172-106-236\"\n      id = \"781f4056-50fe-533c-8e0b-c8d18cc89a5d\"\n   strings:\n      $module_path = \"tunnel-proxy/pkg/mux\" ascii\n      $go_buildinf = \"Go build ID:\" ascii\n   condition:\n      uint32(0) == 0x464c457f and\n      filesize < 20MB and\n      $module_path and $go_buildinf\n}",
            "pattern_type": "yara",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--046a5f26-935f-540d-9a65-a74974bbe12c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.202451Z",
            "modified": "2026-08-13T15:19:18.202451Z",
            "name": "susp_chisel_operator_key_fingerprint",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "/*\n   Yara Rule Set\n   Identifier: SE-Asia Gov Exploitation Toolkit - Chisel Operator Host-Key Fingerprints\n   Author: The Hunters Ledger\n   Source: https://the-hunters-ledger.com/\n   License: CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\n*/\n\nrule susp_chisel_operator_key_fingerprint {\n   meta:\n      description = \"Detects the operator's two persistent Chisel server host-key fingerprints (yW2X8fCVTmfMSpVyrhZQGkSTCfBJBMSyQtgPzCMCfuw= on :8443 and rEVojNCdmii9193KJQL0CQdIcudwm3RW32BKJlUgLT4= on :4443) recorded in captured process logs, startup console output, or memory. Because Chisel derives its host key deterministically from an operator-supplied --key seed, a stable fingerprint recurring across restarts or hosts is a durable operator-specific artifact, unlike the shared commodity chisel.exe file hash\"\n      license = \"CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\"\n      author = \"The Hunters Ledger\"\n      reference = \"https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\"\n      date = \"2026-07-17\"\n      family = \"SE-Asia Gov Exploitation Toolkit (unattributed operator)\"\n      malware_type = \"Reverse tunnel infrastructure artifact\"\n      campaign = \"seasia-gov-exploitation-toolkit-144-172-106-236\"\n      id = \"722a2b0e-97ae-5b72-999a-68434258b5fe\"\n   strings:\n      $fp_8443 = \"yW2X8fCVTmfMSpVyrhZQGkSTCfBJBMSyQtgPzCMCfuw=\" ascii wide\n      $fp_4443 = \"rEVojNCdmii9193KJQL0CQdIcudwm3RW32BKJlUgLT4=\" ascii wide\n   condition:\n      filesize < 50MB and\n      any of them\n}",
            "pattern_type": "yara",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--ab7a3db7-080f-5866-a621-287b03e5d738",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.202562Z",
            "modified": "2026-08-13T15:19:18.202562Z",
            "name": "susp_operator_ssh_pubkey_root_ubuntu_utah_1gb",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "/*\n   Yara Rule Set\n   Identifier: SE-Asia Gov Exploitation Toolkit - Operator SSH Backdoor Public Key\n   Author: The Hunters Ledger\n   Source: https://the-hunters-ledger.com/\n   License: CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\n*/\n\nrule susp_operator_ssh_pubkey_root_ubuntu_utah_1gb {\n   meta:\n      description = \"Detects the operator's injection SSH public key comment 'root@ubuntu-Utah-1gb' inside an authorized_keys file or SSH configuration backup. This key (SHA256:b2sH9INFA/+b9jwMiiTmJoNFaC6SuKI3zc+SDgsBGCE, RSA-3072) was staged for injection via unauthenticated Redis CONFIG SET/SAVE abuse; its presence in any host's authorized_keys, regardless of whether that host runs Redis, indicates operator backdoor SSH access\"\n      license = \"CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\"\n      author = \"The Hunters Ledger\"\n      reference = \"https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\"\n      date = \"2026-07-17\"\n      family = \"SE-Asia Gov Exploitation Toolkit (unattributed operator)\"\n      malware_type = \"SSH backdoor key artifact\"\n      campaign = \"seasia-gov-exploitation-toolkit-144-172-106-236\"\n      id = \"2906e526-db39-5db0-ac5a-635e722d6068\"\n   strings:\n      $key_comment = \"root@ubuntu-Utah-1gb\" ascii\n      $key_type = \"ssh-rsa \" ascii\n   condition:\n      filesize < 1MB and\n      all of them\n}",
            "pattern_type": "yara",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--f13fcb2c-078a-5827-a83b-1f82114d0329",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.202862Z",
            "modified": "2026-08-13T15:19:18.202862Z",
            "name": "mal_gsocket_catsh_installer_script",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "/*\n   Yara Rule Set\n   Identifier: SE-Asia Gov Exploitation Toolkit - GSocket cat.sh Second-Actor Loader (svr1.nast.ph)\n   Author: The Hunters Ledger\n   Source: https://the-hunters-ledger.com/\n   License: CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\n*/\n\nrule mal_gsocket_catsh_installer_script {\n   meta:\n      description = \"Detects the cat.sh GSocket/THC backdoor installer shell script via the distinctive combination of relay and notification-channel domains it embeds. Each individual domain is shared public infrastructure with legitimate uses, but their simultaneous co-occurrence inside one small shell script is not seen in benign scripts. This kit was found on a Philippine government host and is assessed as a SEPARATE second intruder, not the reported operator\"\n      license = \"CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/\"\n      author = \"The Hunters Ledger\"\n      reference = \"https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\"\n      date = \"2026-07-17\"\n      hash1 = \"8a7d387663d7f32730ed8b996f1dab7c2eed4b829b71fd48c608f51569dc4d69\"\n      hash2 = \"71760ce87e12cb881c2316034be0d016617f7628\"\n      hash3 = \"0d72d798449356ed66410f7e84c4a37a\"\n      family = \"GSocket/THC backdoor kit (second actor, NOT the reported operator)\"\n      malware_type = \"Linux backdoor installer script\"\n      campaign = \"seasia-gov-exploitation-toolkit-144-172-106-236\"\n      id = \"881ffab1-19f1-536f-8127-57840ad47217\"\n   strings:\n      $rel1 = \"gsocket.io\" ascii\n      $rel2 = \"gs.thc.org\" ascii\n      $chan1 = \"api.telegram.org\" ascii\n      $chan2 = \"discord.com\" ascii\n      $chan3 = \"webhook.site\" ascii\n      $shebang = \"#!/bin/\" ascii\n   condition:\n      filesize < 200KB and\n      $shebang at 0 and\n      3 of ($rel1, $rel2, $chan1, $chan2, $chan3)\n}",
            "pattern_type": "yara",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--1964f03a-a16a-5734-8d4e-c030b15b8972",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.20302Z",
            "modified": "2026-08-13T15:19:18.20302Z",
            "name": "Ivanti Connect Secure Auth-Bypass Path Traversal to System Information",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Ivanti Connect Secure Auth-Bypass Path Traversal to System Information\nid: 783a5aa7-0a1a-4281-b011-bb6623d16250\nstatus: experimental\ndescription: >-\n    Detects HTTP requests exploiting CVE-2023-46805 (auth-bypass) chained with\n    CVE-2024-21887 (command injection) against Ivanti Connect Secure appliances,\n    matching the operator's observed path-traversal request to the system-information\n    endpoint and shell command substitution in the cac status endpoint.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-46805\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.initial-access\n    - attack.t1190\nlogsource:\n    category: webserver\ndetection:\n    selection_traversal:\n        cs-uri-stem|contains: '/api/v1/totp/user-backup-code/../../system/system-information'\n    selection_injection:\n        cs-uri-query|contains: '/cac/status?id=$('\n    condition: 1 of selection_*\nfalsepositives:\n    - Unlikely outside authorized vulnerability-scanning or red-team activity against unpatched Ivanti Connect Secure appliances\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--4ebf86df-9590-5d76-9cbf-cd855ed98f6b",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.203178Z",
            "modified": "2026-08-13T15:19:18.203178Z",
            "name": "Exchange ProxyLogon SSRF Cookie Header on Autodiscover",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Exchange ProxyLogon SSRF Cookie Header on Autodiscover\nid: 1919a8ce-f6c2-4c53-a056-5b402cb46660\nstatus: experimental\ndescription: >-\n    Detects the CVE-2021-26855 ProxyLogon server-side request forgery idiom against\n    Microsoft Exchange autodiscover endpoints: an X-AnonResource-Backend cookie value\n    combined with a request to an autodiscover path. This is the unmistakable ProxyLogon\n    SSRF technique regardless of whether the specific backend endpoint value is known in advance.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\n    - https://proxylogon.com/\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.initial-access\n    - attack.t1190\nlogsource:\n    category: proxy\ndetection:\n    selection_uri:\n        c-uri|contains: '/autodiscover/autodiscover.'\n    selection_cookie:\n        cs-cookie|contains: 'X-AnonResource-Backend='\n    condition: selection_uri and selection_cookie\nfalsepositives:\n    - Unlikely, this cookie name has no legitimate Exchange client use\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--362ebd4c-7b8f-55a0-b76e-549849e005b8",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.203326Z",
            "modified": "2026-08-13T15:19:18.203326Z",
            "name": "Tableau Server Vizportal SSRF via getViewThumbnail or fetchBinary",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Tableau Server Vizportal SSRF via getViewThumbnail or fetchBinary\nid: b328ba03-fe1f-468f-a4bf-e6d1342b8bb9\nstatus: experimental\ndescription: >-\n    Detects server-side request forgery against Tableau Server's vizportal API using the\n    getViewThumbnail or fetchBinary actions with a url parameter pointed at cloud instance\n    metadata or loopback addresses, consistent with CVE-2024-28149 and CVE-2024-51758\n    exploitation observed against Tableau instances in this campaign.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-28149\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.initial-access\n    - attack.t1190\n    - attack.credential-access\n    - attack.t1552.005\nlogsource:\n    category: webserver\ndetection:\n    selection_path:\n        cs-uri-stem|contains: '/vizportal/api/web/'\n    selection_action:\n        cs-uri-query|contains:\n            - 'getViewThumbnail'\n            - 'fetchBinary'\n    selection_ssrf_target:\n        cs-uri-query|contains:\n            - 'url=169.254.169.254'\n            - 'url=http://169.254.169.254'\n            - 'url=127.0.0.1'\n    condition: selection_path and selection_action and selection_ssrf_target\nfalsepositives:\n    - Unlikely, legitimate Tableau thumbnail and binary-fetch requests do not target metadata or loopback addresses\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--f4fb60a2-43c3-55f9-8d33-487fef2527b2",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.203469Z",
            "modified": "2026-08-13T15:19:18.203469Z",
            "name": "Moodle Managefiles Plugin Local File Inclusion Attempt",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Moodle Managefiles Plugin Local File Inclusion Attempt\nid: 729bf3fc-2d7b-42c3-b1a6-0778082fbeb3\nstatus: experimental\ndescription: >-\n    Detects local file inclusion attempts against the Moodle Atto editor managefiles\n    plugin (load.php) using a path-traversal filearea parameter, consistent with the\n    operator's Moodle probing referencing CVE-2020-25630.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-25630\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.initial-access\n    - attack.t1190\nlogsource:\n    category: webserver\ndetection:\n    selection_path:\n        cs-uri-stem|contains: '/lib/editor/atto/plugins/managefiles/load.php'\n    selection_traversal:\n        cs-uri-query|contains:\n            - '../../../config'\n            - 'filearea=..'\n    condition: selection_path and selection_traversal\nfalsepositives:\n    - Unlikely, legitimate Atto editor file-manager requests do not include traversal sequences in the filearea parameter\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--7f304d92-2113-5ee2-920b-f7540b8619c6",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.203603Z",
            "modified": "2026-08-13T15:19:18.203603Z",
            "name": "Redis Server Process Writing to SSH Authorized Keys File",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Redis Server Process Writing to SSH Authorized Keys File\nid: 5a6dff70-3536-49cb-b14a-f39da78d417c\nstatus: experimental\ndescription: >-\n    Detects the redis-server process writing to a user's SSH authorized_keys file, the\n    signature outcome of the unauthenticated Redis CONFIG SET dir / SAVE technique used to\n    plant an attacker SSH public key for persistent access. A legitimate Redis server never\n    writes to this path.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\n    - https://book.hacktricks.xyz/network-services-pentesting/6379-pentesting-redis\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.persistence\n    - attack.privilege-escalation\n    - attack.t1098.004\nlogsource:\n    category: file_event\n    product: linux\ndetection:\n    selection:\n        Image|endswith: '/redis-server'\n        TargetFilename|endswith: '/.ssh/authorized_keys'\n    condition: selection\nfalsepositives:\n    - Unlikely, no legitimate Redis deployment configuration writes to this file\nlevel: critical",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--3c452a4e-930f-5b08-abd0-c2ffab6e262c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.203802Z",
            "modified": "2026-08-13T15:19:18.203802Z",
            "name": "Zimbra JSP Web Shell Dropped via Amavis Cpio Path Traversal",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Zimbra JSP Web Shell Dropped via Amavis Cpio Path Traversal\nid: 7c6b1677-f5c8-423d-97f1-2da351b3561d\nstatus: experimental\ndescription: >-\n    Detects creation of a JSP file at one of the seven known Zimbra webapp drop paths used\n    by the CVE-2022-41352 Amavis cpio/tar extraction path-traversal technique to plant a\n    web shell inside the Zimbra collaboration suite. A legitimate Zimbra installation never\n    creates a shell.jsp file under any of these paths.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-41352\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.persistence\n    - attack.t1505.003\nlogsource:\n    category: file_event\n    product: linux\ndetection:\n    selection:\n        TargetFilename|endswith:\n            - '/zimbra/jetty/webapps/zimbra/public/shell.jsp'\n            - '/zimbra/jetty/webapps/zimbra/shell.jsp'\n            - '/zimbra/jetty_base/webapps/zimbra/public/shell.jsp'\n            - '/zimbra/jetty_base/webapps/zimbra/shell.jsp'\n            - '/zimbra/mailboxd/webapps/zimbra/public/shell.jsp'\n            - '/zimbra/mailboxd/webapps/zimbra/shell.jsp'\n            - '/zimbra/jetty-distribution-9.4.46.v20220331/webapps/zimbra/public/shell.jsp'\n    condition: selection\nfalsepositives:\n    - Unlikely, legitimate Zimbra updates do not create a file named shell.jsp under the webapp tree\nlevel: critical",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--aeaeb3e6-47a0-5994-a2da-f70d2089eb7f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.203992Z",
            "modified": "2026-08-13T15:19:18.203992Z",
            "name": "Cron-Triggered Base64-Indirected Shell Execution With Output Suppression",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Cron-Triggered Base64-Indirected Shell Execution With Output Suppression\nid: 1eedca83-5b2a-4f6b-be2a-7234132958f9\nstatus: experimental\ndescription: >-\n    Detects a cron-spawned process whose command line decodes a base64 blob and pipes it\n    directly to a shell, or pipes a curl download directly to a shell, with both stdout\n    and stderr suppressed. This combination (base64 indirection or remote-pipe-to-shell,\n    paired with dual-stream suppression, from a cron parent) is rare in legitimate cron\n    jobs and was used by a second, separate intruder to install a Linux backdoor kit on a\n    government hosting server without exposing the payload path in the crontab.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.execution\n    - attack.persistence\n    - attack.privilege-escalation\n    - attack.t1053.003\nlogsource:\n    category: process_creation\n    product: linux\ndetection:\n    selection_parent_cron:\n        ParentImage|contains: 'cron'\n    selection_b64_indirect:\n        CommandLine|contains|all:\n            - 'base64 -d'\n            - '2>/dev/null'\n            - '>/dev/null'\n    selection_curl_pipe:\n        CommandLine|contains|all:\n            - 'curl '\n            - '| bash'\n    condition: selection_parent_cron and (selection_b64_indirect or selection_curl_pipe)\nfalsepositives:\n    - Legitimate cron-triggered installer or update scripts that pipe a remote download to a shell\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--44b0137d-05d1-5818-aab9-5ed649d80ca6",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.20415Z",
            "modified": "2026-08-13T15:19:18.20415Z",
            "name": "Known Second-Actor Daemon-Masquerade Implant Names Executing From User Home Directory",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Known Second-Actor Daemon-Masquerade Implant Names Executing From User Home Directory\nid: 4b35b0e1-5511-442f-9ab8-77828f6acb88\nstatus: experimental\ndescription: >-\n    Detects execution of a binary named netd, authd, bootcfg, or udevd-sync from inside a\n    user's home directory. These are the four daemon-masquerade implant names recovered\n    from a compromised government hosting server, installed by a second, separate intruder\n    via cron. A real system daemon never runs from a path under /home/.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.stealth\n    - attack.t1036.004\nlogsource:\n    category: process_creation\n    product: linux\ndetection:\n    selection_path:\n        Image|contains: '/home/'\n    selection_name:\n        Image|endswith:\n            - '/netd'\n            - '/authd'\n            - '/bootcfg'\n            - '/udevd-sync'\n    condition: selection_path and selection_name\nfalsepositives:\n    - Unlikely, these exact filenames combined with a /home/ execution path have no identified legitimate use\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--2675b447-d40b-5ee2-96c7-f6a25dcda5f5",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.204295Z",
            "modified": "2026-08-13T15:19:18.204295Z",
            "name": "Joomla Administrator Login Attempt Pattern",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Joomla Administrator Login Attempt Pattern\nid: dee98531-cbc8-4a06-89f8-aef7941a6fbf\nstatus: experimental\ndescription: >-\n    Detects requests to the Joomla administrator login task, the pattern used by the\n    operator's single-password-guess spray script against Joomla-based government sites.\n    This selector alone is broad (legitimate administrators and vulnerability scanners\n    also hit this endpoint), so it is intended for hunting and volumetric triage rather\n    than standalone alerting.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.credential-access\n    - attack.t1110.001\nlogsource:\n    category: webserver\ndetection:\n    selection:\n        cs-uri-stem|contains: '/administrator/index.php'\n        cs-uri-query|contains: 'task=login'\n    condition: selection\nfalsepositives:\n    - Legitimate Joomla administrator logins\n    - Internet-wide vulnerability scanners probing the standard Joomla admin path\nlevel: low",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--4cff3749-40e9-53b9-9809-89ca680ce86f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.204479Z",
            "modified": "2026-08-13T15:19:18.204479Z",
            "name": "Webmin Session Login Endpoint Access Pattern",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Webmin Session Login Endpoint Access Pattern\nid: 3f62b16d-d4e1-4336-83c1-398c50108879\nstatus: experimental\ndescription: >-\n    Detects requests to the Webmin session_login.cgi authentication endpoint, the vector\n    the operator used to reach an administrator session on a compromised Philippine\n    government hosting panel. This endpoint is hit by every legitimate Webmin login as\n    well, so this selector is intended for hunting and login-pattern triage, not standalone\n    alerting.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.credential-access\n    - attack.t1110.001\nlogsource:\n    category: webserver\ndetection:\n    selection:\n        cs-uri-stem|contains: '/session_login.cgi'\n    condition: selection\nfalsepositives:\n    - Legitimate Webmin administrator logins\nlevel: low",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--747fd33c-1d5c-5512-baab-bf5e182c7214",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.204625Z",
            "modified": "2026-08-13T15:19:18.204625Z",
            "name": "Outbound Connection to Cloud Instance Metadata Service Address",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Outbound Connection to Cloud Instance Metadata Service Address\nid: 0953dc62-3a1a-4b35-b765-86bbbac28cfa\nstatus: experimental\ndescription: >-\n    Detects a network connection to the well-known cloud instance metadata service\n    address 169.254.169.254, the SSRF target used against Tableau Server and a\n    GenAI chatbot integration in this campaign to retrieve cloud credentials. Many\n    legitimate cloud-native agents query this address routinely, so this is a broad\n    hunting signal rather than a standalone alert.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.credential-access\n    - attack.t1552.005\nlogsource:\n    category: network_connection\n    product: linux\ndetection:\n    selection:\n        DestinationIp: '169.254.169.254'\n    filter_instance_agents:\n        Image|contains:\n            - '/elastic-agent'\n            - '/agentbeat'\n            - '/metricbeat'\n            - '/filebeat'\n            - '/osquerybeat'\n            - '/cloud-init'\n            - '/amazon-ssm-agent'\n            - '/google_guest_agent'\n            - '/waagent'\n    condition: selection and not filter_instance_agents\nfalsepositives:\n    - >-\n      Cloud SDK or CLI calls from an application that legitimately reads instance\n      metadata, where the calling binary is not on the instance-agent filter list\nlevel: low",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--e740a9e6-ec50-5ea3-8108-f57839e9e805",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.204802Z",
            "modified": "2026-08-13T15:19:18.204802Z",
            "name": "Chisel Reverse Tunnel Client or Server Execution",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Chisel Reverse Tunnel Client or Server Execution\nid: fa8f3555-62f9-42b7-8820-0806b3c73872\nstatus: experimental\ndescription: >-\n    Detects execution of the Chisel TCP/UDP tunneling tool in server or client mode.\n    Chisel is a dual-use, publicly available tool with legitimate uses by administrators\n    and security testers, so this is a broad hunting signal for tunnel-tool usage rather\n    than a standalone alert. The Chisel binary hash itself is a shared commodity build\n    used by hundreds of unrelated parties and is not a reliable attribution or blocking\n    anchor: this rule detects the behavior of running the tool, not a specific file.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\n    - https://github.com/jpillora/chisel\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.command-and-control\n    - attack.t1572\nlogsource:\n    category: process_creation\n    product: windows\ndetection:\n    selection_name:\n        Image|contains: 'chisel'\n    selection_mode:\n        CommandLine|contains:\n            - ' server '\n            - ' client '\n    condition: selection_name and selection_mode\nfalsepositives:\n    - Authorized red-team or security-testing use of Chisel\n    - Legitimate administrator use of Chisel for NAT traversal or firewall bypass\nlevel: medium",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--423eec8d-dc44-5e4c-90e4-be2e896bbd8b",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.204987Z",
            "modified": "2026-08-13T15:19:18.204987Z",
            "name": "Joomla FTP-Staged Web Shell Filename Probe",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Joomla FTP-Staged Web Shell Filename Probe\nid: 54109047-3768-44a3-9ff9-90d593c4b179\nstatus: experimental\ndescription: >-\n    Detects a request for the specific staged web shell filename pwned.php under a Joomla\n    images directory, the payload filename convention this operator reused across multiple\n    Joomla targets. The filename itself is attacker-chosen and could be renamed for a future\n    intrusion, so this is a hunting lead rather than a high-confidence standalone alert.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.persistence\n    - attack.t1505.003\nlogsource:\n    category: webserver\ndetection:\n    selection:\n        cs-uri-stem|endswith: '/images/pwned.php'\n    condition: selection\nfalsepositives:\n    - Unlikely, this filename has no legitimate Joomla use, but is a renameable attacker convention rather than a durable identifier\nlevel: medium",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--c0bce940-af7f-5c33-90de-a5400692e089",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.205141Z",
            "modified": "2026-08-13T15:19:18.205141Z",
            "name": "Executable With System-Daemon-Style Name Running From User Home Directory",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Executable With System-Daemon-Style Name Running From User Home Directory\nid: a01bf89b-4ab0-448f-b51e-f0c781176fe4\nstatus: experimental\ndescription: >-\n    Detects execution of a binary whose name follows common system-daemon naming\n    conventions (ending in d, or a sync/config-style suffix) from inside a user's home\n    directory, generalizing beyond the four specific implant names already known from this\n    campaign. This is a broad structural heuristic intended for hunting across other hosts\n    and future variants, not standalone alerting: legitimate personal scripts and\n    third-party agents can coincidentally match the naming pattern.\nreferences:\n    - https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/\nauthor: The Hunters Ledger\ndate: 2026-07-17\ntags:\n    - attack.stealth\n    - attack.t1036.004\nlogsource:\n    category: process_creation\n    product: linux\ndetection:\n    selection_path:\n        Image|contains: '/home/'\n    selection_name:\n        Image|re: '.*/(netd|authd|bootd|bootcfg|udevd.*|systemd-.*sync|.*-sync)$'\n    condition: selection_path and selection_name\nfalsepositives:\n    - Legitimate user-installed sync utilities or personal scripts that happen to match the naming pattern\nlevel: low",
            "pattern_type": "sigma",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--31393ea2-ff0a-529b-8668-dbc8f0f7616f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.205288Z",
            "modified": "2026-08-13T15:19:18.205288Z",
            "name": "THL DETECT Ivanti-Connect-Secure CVE-2023-46805 Auth-Bypass Path Traversal to system-information (Initial Access Attempt)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert http $EXTERNAL_NET any -> $HOME_NET any (msg:\"THL DETECT Ivanti-Connect-Secure CVE-2023-46805 Auth-Bypass Path Traversal to system-information (Initial Access Attempt)\"; flow:established,to_server; http.uri; content:\"/api/v1/totp/user-backup-code/../../system/system-information\"; classtype:web-application-attack; sid:1000001; rev:1; metadata:author The_Hunters_Ledger, date 2026-07-17, reference https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/;)",
            "pattern_type": "suricata",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--271c14db-2770-59fc-8c4c-b3af7f5edf04",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.205421Z",
            "modified": "2026-08-13T15:19:18.205421Z",
            "name": "THL DETECT Ivanti-Connect-Secure CVE-2024-21887 Command Injection via cac-status (Post-Auth-Bypass Command Execution Attempt)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert http $EXTERNAL_NET any -> $HOME_NET any (msg:\"THL DETECT Ivanti-Connect-Secure CVE-2024-21887 Command Injection via cac-status (Post-Auth-Bypass Command Execution Attempt)\"; flow:established,to_server; http.uri; content:\"/cac/status?id=$(\"; classtype:web-application-attack; sid:1000002; rev:1; metadata:author The_Hunters_Ledger, date 2026-07-17, reference https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/;)",
            "pattern_type": "suricata",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--77b3f25e-b013-54ec-b00a-5c1873e016d4",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.205549Z",
            "modified": "2026-08-13T15:19:18.205549Z",
            "name": "THL DETECT Exchange-ProxyLogon CVE-2021-26855 SSRF Cookie Header on Autodiscover (Initial Access Attempt)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert http $EXTERNAL_NET any -> $HOME_NET any (msg:\"THL DETECT Exchange-ProxyLogon CVE-2021-26855 SSRF Cookie Header on Autodiscover (Initial Access Attempt)\"; flow:established,to_server; http.uri; content:\"/autodiscover/autodiscover.\"; http.header; content:\"X-AnonResource-Backend=\"; classtype:web-application-attack; sid:1000003; rev:1; metadata:author The_Hunters_Ledger, date 2026-07-17, reference https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/;)",
            "pattern_type": "suricata",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--23df1181-495f-54d8-b9e6-928c9ceadae7",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.20566Z",
            "modified": "2026-08-13T15:19:18.20566Z",
            "name": "THL BLOCK Second-Actor-GSocket-Kit localroot.sbs Loader Domain DNS Query (C2 Staging Indicator)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert dns $HOME_NET any -> any any (msg:\"THL BLOCK Second-Actor-GSocket-Kit localroot.sbs Loader Domain DNS Query (C2 Staging Indicator)\"; dns_query; content:\"localroot.sbs\"; nocase; isdataat:!1,relative; threshold:type limit,track by_src,count 1,seconds 3600; classtype:trojan-activity; sid:1000004; rev:1; metadata:author The_Hunters_Ledger, date 2026-07-17, reference https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/;)",
            "pattern_type": "suricata",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--6bf59778-bfca-5d06-abcb-d750164d359c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.205772Z",
            "modified": "2026-08-13T15:19:18.205772Z",
            "name": "THL BLOCK Second-Actor-GSocket-Kit cat.sh Loader Payload Retrieval (Persistence Staging)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert http $HOME_NET any -> any any (msg:\"THL BLOCK Second-Actor-GSocket-Kit cat.sh Loader Payload Retrieval (Persistence Staging)\"; flow:established,to_server; http.host; content:\"localroot.sbs\"; http.uri; content:\"/cat.sh\"; endswith; classtype:trojan-activity; sid:1000005; rev:1; metadata:author The_Hunters_Ledger, date 2026-07-17, reference https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/;)",
            "pattern_type": "suricata",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--ed28209d-319e-5840-b72e-effd2175da35",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.205884Z",
            "modified": "2026-08-13T15:19:18.205884Z",
            "name": "THL HUNT GSocket-THC-Relay gs.thc.org NAT-Traversal Domain Query (Hunt-Only - Do Not Block - Shared Public Infrastructure)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert dns $HOME_NET any -> any any (msg:\"THL HUNT GSocket-THC-Relay gs.thc.org NAT-Traversal Domain Query (Hunt-Only - Do Not Block - Shared Public Infrastructure)\"; dns_query; content:\".gs.thc.org\"; nocase; isdataat:!1,relative; threshold:type limit,track by_src,count 1,seconds 3600; classtype:misc-activity; sid:1000006; rev:1; metadata:author The_Hunters_Ledger, date 2026-07-17, reference https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/, signature_severity Informational;)",
            "pattern_type": "suricata",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--3656b863-04ac-5092-ab42-e9d845d4346a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.206012Z",
            "modified": "2026-08-13T15:19:18.206012Z",
            "name": "THL HUNT GSocket-THC-Relay gsocket.io Domain Query (Hunt-Only - Do Not Block - Shared Public Infrastructure)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert dns $HOME_NET any -> any any (msg:\"THL HUNT GSocket-THC-Relay gsocket.io Domain Query (Hunt-Only - Do Not Block - Shared Public Infrastructure)\"; dns_query; content:\"gsocket.io\"; nocase; isdataat:!1,relative; threshold:type limit,track by_src,count 1,seconds 3600; classtype:misc-activity; sid:1000007; rev:1; metadata:author The_Hunters_Ledger, date 2026-07-17, reference https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/, signature_severity Informational;)",
            "pattern_type": "suricata",
            "valid_from": "2026-07-17T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "malware",
            "spec_version": "2.1",
            "id": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.206158Z",
            "modified": "2026-08-13T15:19:18.206158Z",
            "name": "bespoke n-day exploitation toolkit",
            "is_family": true,
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "malware",
            "spec_version": "2.1",
            "id": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.206274Z",
            "modified": "2026-08-13T15:19:18.206274Z",
            "name": "commodity chisel tunnel",
            "is_family": true,
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "malware",
            "spec_version": "2.1",
            "id": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.206377Z",
            "modified": "2026-08-13T15:19:18.206377Z",
            "name": "custom Go tunnel-proxy",
            "is_family": true,
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "malware",
            "spec_version": "2.1",
            "id": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.206477Z",
            "modified": "2026-08-13T15:19:18.206477Z",
            "name": "GSocket/THC backdoor kit (second actor)",
            "is_family": true,
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "tool",
            "spec_version": "2.1",
            "id": "tool--f21deb6f-f583-514d-8f11-cbf4cf9c47f2",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.206635Z",
            "modified": "2026-08-13T15:19:18.206635Z",
            "name": "Commodity Chisel tunnel",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "tool",
            "spec_version": "2.1",
            "id": "tool--a7c1a48e-52e7-5647-af43-e06d9be8a76b",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.206751Z",
            "modified": "2026-08-13T15:19:18.206751Z",
            "name": "Operator's self-built multi-agent reverse-tunnel + SOCKS5 server",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "tool",
            "spec_version": "2.1",
            "id": "tool--963f3579-6b16-5390-ad0f-d308ac5a04fe",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.206849Z",
            "modified": "2026-08-13T15:19:18.206849Z",
            "name": "Operator's paired tunnel agent",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "tool",
            "spec_version": "2.1",
            "id": "tool--b33807e9-5748-5c1e-9d3c-2f59422a034f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.206946Z",
            "modified": "2026-08-13T15:19:18.206946Z",
            "name": "SECOND-ACTOR",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--6214841b-936d-5da2-b5c8-4bed4cf9aee0",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.207036Z",
            "modified": "2026-08-13T15:19:18.207036Z",
            "name": "Exploit Public-Facing Application",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1190",
                    "external_id": "T1190"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--770465f6-d1b8-5285-9c27-a5a9569aa97b",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.207184Z",
            "modified": "2026-08-13T15:19:18.207184Z",
            "name": "External Remote Services",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1133",
                    "external_id": "T1133"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--856a360d-8aca-55ff-949d-fee64905d0a8",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.207317Z",
            "modified": "2026-08-13T15:19:18.207317Z",
            "name": "Valid Accounts",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1078",
                    "external_id": "T1078"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--6ef82ce6-fcae-5c08-99b6-3ad30baa6bfb",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.207434Z",
            "modified": "2026-08-13T15:19:18.207434Z",
            "name": "Spearphishing Attachment",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1566/001",
                    "external_id": "T1566.001"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--73364e03-8914-541e-a33c-877b656c37e4",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.207549Z",
            "modified": "2026-08-13T15:19:18.207549Z",
            "name": "Unix Shell",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1059/004",
                    "external_id": "T1059.004"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--fd8dd968-9ef8-5d44-9278-54e070789645",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.207663Z",
            "modified": "2026-08-13T15:19:18.207663Z",
            "name": "Web Shell",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1505/003",
                    "external_id": "T1505.003"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--be0beb0c-2499-5178-a012-309e486ef121",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.207777Z",
            "modified": "2026-08-13T15:19:18.207777Z",
            "name": "Cloud Instance Metadata API",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1552/005",
                    "external_id": "T1552.005"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--16d93383-9cd3-53c0-94a2-a75a3a9e3a9e",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.207892Z",
            "modified": "2026-08-13T15:19:18.207892Z",
            "name": "Steal Web Session Cookie",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1539",
                    "external_id": "T1539"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--e143cf40-c9b0-5118-8096-34d60698c27b",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.208005Z",
            "modified": "2026-08-13T15:19:18.208005Z",
            "name": "Password Guessing",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1110/001",
                    "external_id": "T1110.001"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--e42939d6-6332-5a6c-8dac-6195c79081bc",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.208118Z",
            "modified": "2026-08-13T15:19:18.208118Z",
            "name": "Data from Information Repositories",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1213",
                    "external_id": "T1213"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--d6b8aa8c-cfd9-5f42-a8ac-2573005abb2f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.20823Z",
            "modified": "2026-08-13T15:19:18.20823Z",
            "name": "Automated Collection",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1119",
                    "external_id": "T1119"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--81ac1dd0-a8ac-50ba-bd1a-cec2886340d5",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.208341Z",
            "modified": "2026-08-13T15:19:18.208341Z",
            "name": "Protocol Tunneling",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1572",
                    "external_id": "T1572"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--c4d23a10-7ecd-543e-af65-13160caed625",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.208451Z",
            "modified": "2026-08-13T15:19:18.208451Z",
            "name": "Multi-hop Proxy",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1090/003",
                    "external_id": "T1090.003"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--06cbe52b-abcb-5b54-a3ec-c553a82c7374",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.208563Z",
            "modified": "2026-08-13T15:19:18.208563Z",
            "name": "Exfiltration Over C2 Channel",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1041",
                    "external_id": "T1041"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--1635f86c-b5b5-5339-b31b-87ce05013408",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.208674Z",
            "modified": "2026-08-13T15:19:18.208674Z",
            "name": "Cron (second actor)",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1053/003",
                    "external_id": "T1053.003"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--f38353ba-cfac-577c-ac86-5e3f0c5fb314",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.208785Z",
            "modified": "2026-08-13T15:19:18.208785Z",
            "name": "Masquerade Task or Service (second actor)",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1036/004",
                    "external_id": "T1036.004"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--351c2bb8-092f-5863-b623-f9ca08b16432",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.208931Z",
            "modified": "2026-08-13T15:19:18.208931Z",
            "name": "Web Service C2 (second actor)",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "url": "https://attack.mitre.org/techniques/T1102",
                    "external_id": "T1102"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "infrastructure",
            "spec_version": "2.1",
            "id": "infrastructure--08fb24a7-655f-5ba8-928e-68f8d72cedee",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.209123Z",
            "modified": "2026-08-13T15:19:18.209123Z",
            "name": "seasia-gov-exploitation-toolkit-144-172-106-236 infrastructure",
            "infrastructure_types": [
                "command-and-control",
                "hosting"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--105b23b3-ee5c-5990-a3f9-7562902d3dba",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.209584Z",
            "modified": "2026-08-13T15:19:18.209584Z",
            "name": "CVE-2020-25627",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25627",
                    "external_id": "CVE-2020-25627"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--5158a7b0-8bde-5edf-a688-78da33dbf2cb",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.209779Z",
            "modified": "2026-08-13T15:19:18.209779Z",
            "name": "CVE-2020-25629",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25629",
                    "external_id": "CVE-2020-25629"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--d2130def-6b14-55d3-b9ce-4e4c5116baa6",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.20998Z",
            "modified": "2026-08-13T15:19:18.20998Z",
            "name": "CVE-2020-25630",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25630",
                    "external_id": "CVE-2020-25630"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--efbaf1ef-fb8b-5318-9923-0b1d38f75b6e",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.210131Z",
            "modified": "2026-08-13T15:19:18.210131Z",
            "name": "CVE-2021-26855",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26855",
                    "external_id": "CVE-2021-26855"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--45f51e52-120a-5238-8e39-3104c38f2e07",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.210317Z",
            "modified": "2026-08-13T15:19:18.210317Z",
            "name": "CVE-2022-41352",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41352",
                    "external_id": "CVE-2022-41352"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--cb4f5044-02fd-54b9-b82d-a5abad4e7869",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.210463Z",
            "modified": "2026-08-13T15:19:18.210463Z",
            "name": "CVE-2023-46805",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46805",
                    "external_id": "CVE-2023-46805"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--67c27543-6d8c-5ff5-955a-94664d0e98eb",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.21061Z",
            "modified": "2026-08-13T15:19:18.21061Z",
            "name": "CVE-2024-21887",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21887",
                    "external_id": "CVE-2024-21887"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--08ef11cb-c802-5d05-8b25-b02299ed788f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.210744Z",
            "modified": "2026-08-13T15:19:18.210744Z",
            "name": "CVE-2024-28149",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28149",
                    "external_id": "CVE-2024-28149"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--aa2529cc-aae5-5a31-9518-2a4dbd668230",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.210879Z",
            "modified": "2026-08-13T15:19:18.210879Z",
            "name": "CVE-2024-51758",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51758",
                    "external_id": "CVE-2024-51758"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "vulnerability",
            "spec_version": "2.1",
            "id": "vulnerability--7c8dd94a-2a60-568a-a600-bf3f35ffc925",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.211014Z",
            "modified": "2026-08-13T15:19:18.211014Z",
            "name": "CVE-2026-68645",
            "external_references": [
                {
                    "source_name": "cve",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68645",
                    "external_id": "CVE-2026-68645"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8379cc14-2dc3-5e71-8e32-3379a0156f41",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.211383Z",
            "modified": "2026-08-13T15:19:18.211383Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--a4bec962-d1b4-5aa5-92b9-0722d341f775",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a889ff21-1bf9-5bbd-9c46-63b1d8963fd2",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.211511Z",
            "modified": "2026-08-13T15:19:18.211511Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--b0b349fd-c7a0-5e9a-8365-9d39134b43cf",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--1640103d-e303-55da-b89b-93610d5d017c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.211623Z",
            "modified": "2026-08-13T15:19:18.211623Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--0ba2e85d-a6a0-513e-85c3-3d96d1ef089f",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d71866c6-8ccd-59a3-827d-c4a10a185882",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.211737Z",
            "modified": "2026-08-13T15:19:18.211737Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--956bf4b3-3599-54d9-bea7-63e582926b2a",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a0d1660e-8abd-5a07-aa4c-1e962a5b874e",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.21183Z",
            "modified": "2026-08-13T15:19:18.21183Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--15a311ae-d63d-526f-a4fc-49023631f11f",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d64c671c-e0d8-5eac-a680-2eb53bb7bfda",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.211925Z",
            "modified": "2026-08-13T15:19:18.211925Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--d86cc40c-e152-5b13-a055-4c0cf3d7350a",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--cfbeb529-c5e6-53d1-be87-9d90de3876e6",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212018Z",
            "modified": "2026-08-13T15:19:18.212018Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--3c68d8fb-7f0d-5972-b80d-14cefaf1de8d",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8b364a6d-cd32-543a-b733-b5688a595cb7",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212133Z",
            "modified": "2026-08-13T15:19:18.212133Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--046a5f26-935f-540d-9a65-a74974bbe12c",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--4997ef0b-6bf9-53a1-a46f-5cee543bad6d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212239Z",
            "modified": "2026-08-13T15:19:18.212239Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--ab7a3db7-080f-5866-a621-287b03e5d738",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--20c1acba-9843-5833-9a15-4fd1d46c7e5d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.21233Z",
            "modified": "2026-08-13T15:19:18.21233Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--f13fcb2c-078a-5827-a83b-1f82114d0329",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f6830ffc-8f25-5a10-887c-e310e31668dc",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212421Z",
            "modified": "2026-08-13T15:19:18.212421Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--1964f03a-a16a-5734-8d4e-c030b15b8972",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--b191020f-b5f9-57aa-9de0-77ced553c559",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212513Z",
            "modified": "2026-08-13T15:19:18.212513Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--4ebf86df-9590-5d76-9cbf-cd855ed98f6b",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d21b0e89-0a0a-5ddc-97af-5e66bbd009eb",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212603Z",
            "modified": "2026-08-13T15:19:18.212603Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--362ebd4c-7b8f-55a0-b76e-549849e005b8",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--205ca8cf-2523-5110-be6a-f39409e99bcb",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212694Z",
            "modified": "2026-08-13T15:19:18.212694Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--f4fb60a2-43c3-55f9-8d33-487fef2527b2",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--db771888-4d8e-5cf7-9cab-e2199069cef2",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212784Z",
            "modified": "2026-08-13T15:19:18.212784Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--7f304d92-2113-5ee2-920b-f7540b8619c6",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--87e97264-035d-5227-8afc-3007bbfe14d7",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212877Z",
            "modified": "2026-08-13T15:19:18.212877Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--3c452a4e-930f-5b08-abd0-c2ffab6e262c",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--73760317-5ce3-54e7-986e-a7e8de8f7b4c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.212968Z",
            "modified": "2026-08-13T15:19:18.212968Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--aeaeb3e6-47a0-5994-a2da-f70d2089eb7f",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6a9cf91f-fa2d-582e-8ff5-db03282ce267",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.213076Z",
            "modified": "2026-08-13T15:19:18.213076Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--44b0137d-05d1-5818-aab9-5ed649d80ca6",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--fd078f82-a770-5e98-abcc-fd6408f80786",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.213183Z",
            "modified": "2026-08-13T15:19:18.213183Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--2675b447-d40b-5ee2-96c7-f6a25dcda5f5",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8916730b-127b-5697-8fdb-6b8eec17c653",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.21328Z",
            "modified": "2026-08-13T15:19:18.21328Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--4cff3749-40e9-53b9-9809-89ca680ce86f",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--301fceb4-9f1a-5ebd-830d-24e6539cbd51",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.213372Z",
            "modified": "2026-08-13T15:19:18.213372Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--747fd33c-1d5c-5512-baab-bf5e182c7214",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--4e6869ee-5cf8-5c25-ad2e-6c5b314f6344",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.213464Z",
            "modified": "2026-08-13T15:19:18.213464Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--e740a9e6-ec50-5ea3-8108-f57839e9e805",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--22af34cc-a2f4-51ca-8512-58b2bbdad55d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.213555Z",
            "modified": "2026-08-13T15:19:18.213555Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--423eec8d-dc44-5e4c-90e4-be2e896bbd8b",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--2d1db5e4-bdfc-551a-bb33-4d43189f0c4f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.213645Z",
            "modified": "2026-08-13T15:19:18.213645Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--c0bce940-af7f-5c33-90de-a5400692e089",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--de2a3c4a-31f4-5953-a5cb-774ee6a00ee8",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.213737Z",
            "modified": "2026-08-13T15:19:18.213737Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--31393ea2-ff0a-529b-8668-dbc8f0f7616f",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--e6bf8cb3-461e-5198-ade1-dbc9b2b7e6a1",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.213829Z",
            "modified": "2026-08-13T15:19:18.213829Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--271c14db-2770-59fc-8c4c-b3af7f5edf04",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--994c7328-1873-5b57-8e51-2f50c2a8986a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.21392Z",
            "modified": "2026-08-13T15:19:18.21392Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--77b3f25e-b013-54ec-b00a-5c1873e016d4",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--e5877348-2ac1-5ca4-9ba0-fc79428c8483",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.21401Z",
            "modified": "2026-08-13T15:19:18.21401Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--23df1181-495f-54d8-b9e6-928c9ceadae7",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--5b74cb02-afe6-5439-9f82-441b9f638736",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.214132Z",
            "modified": "2026-08-13T15:19:18.214132Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--6bf59778-bfca-5d06-abcb-d750164d359c",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8b489338-fb95-5487-969a-291e5d2b7f37",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.214223Z",
            "modified": "2026-08-13T15:19:18.214223Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--ed28209d-319e-5840-b72e-effd2175da35",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--156c897e-ffb4-5db1-aceb-2a297ae9c587",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.214313Z",
            "modified": "2026-08-13T15:19:18.214313Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--3656b863-04ac-5092-ab42-e9d845d4346a",
            "target_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--61ae6d20-db37-50fa-bd34-95775e3f9d9c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.214405Z",
            "modified": "2026-08-13T15:19:18.214405Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--6214841b-936d-5da2-b5c8-4bed4cf9aee0",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6f3492f7-c81e-5fba-9295-66891051dd5a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.214498Z",
            "modified": "2026-08-13T15:19:18.214498Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--770465f6-d1b8-5285-9c27-a5a9569aa97b",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--e6ba6df9-60af-50f4-a710-89e310dc1148",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.214608Z",
            "modified": "2026-08-13T15:19:18.214608Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--856a360d-8aca-55ff-949d-fee64905d0a8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--470c414f-2696-5421-b276-f791d2592eef",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.214752Z",
            "modified": "2026-08-13T15:19:18.214752Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--6ef82ce6-fcae-5c08-99b6-3ad30baa6bfb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f8e0b81e-2eef-5533-a15c-8a95b5b588e1",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.214877Z",
            "modified": "2026-08-13T15:19:18.214877Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--73364e03-8914-541e-a33c-877b656c37e4",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--9798823d-0d06-5f6b-925c-efcd096175a8",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.215006Z",
            "modified": "2026-08-13T15:19:18.215006Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--fd8dd968-9ef8-5d44-9278-54e070789645",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--617e5fa7-759b-5c83-bffe-1cf7d420b1e0",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.215133Z",
            "modified": "2026-08-13T15:19:18.215133Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--be0beb0c-2499-5178-a012-309e486ef121",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d6dc1778-4649-5a15-a56a-26e594d2bece",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.215267Z",
            "modified": "2026-08-13T15:19:18.215267Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--16d93383-9cd3-53c0-94a2-a75a3a9e3a9e",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--993b6853-89f7-5d1a-83ec-622867be949f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.215402Z",
            "modified": "2026-08-13T15:19:18.215402Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--e143cf40-c9b0-5118-8096-34d60698c27b",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--14839f2e-513f-582b-8402-31d28d8416a6",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.21556Z",
            "modified": "2026-08-13T15:19:18.21556Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--e42939d6-6332-5a6c-8dac-6195c79081bc",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--959ee8a4-b403-5072-8764-18d935193058",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.215732Z",
            "modified": "2026-08-13T15:19:18.215732Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--d6b8aa8c-cfd9-5f42-a8ac-2573005abb2f",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8cfe77d2-e9e8-5274-bba3-8dd46e4ea88a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.21587Z",
            "modified": "2026-08-13T15:19:18.21587Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--81ac1dd0-a8ac-50ba-bd1a-cec2886340d5",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f906b920-d2f6-5f23-b644-255669185871",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.216023Z",
            "modified": "2026-08-13T15:19:18.216023Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--c4d23a10-7ecd-543e-af65-13160caed625",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--31f4188e-d95e-5d24-a717-4f24a9df06fa",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.216153Z",
            "modified": "2026-08-13T15:19:18.216153Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--06cbe52b-abcb-5b54-a3ec-c553a82c7374",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--ef50aa3f-90f3-54b6-bba6-72ca97554d65",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.216331Z",
            "modified": "2026-08-13T15:19:18.216331Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--1635f86c-b5b5-5339-b31b-87ce05013408",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a0dd4b25-fe6e-5575-adab-2914309047c2",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.216447Z",
            "modified": "2026-08-13T15:19:18.216447Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--f38353ba-cfac-577c-ac86-5e3f0c5fb314",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--2f667d5c-5e76-57a4-9876-1071867e5817",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.216592Z",
            "modified": "2026-08-13T15:19:18.216592Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "attack-pattern--351c2bb8-092f-5863-b623-f9ca08b16432",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--55a907ec-e3ca-58f1-8061-72f979b2607e",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.216709Z",
            "modified": "2026-08-13T15:19:18.216709Z",
            "relationship_type": "uses",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "infrastructure--08fb24a7-655f-5ba8-928e-68f8d72cedee",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--1eaef6a5-4c49-5854-98e4-c1bd885c7dbd",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.216854Z",
            "modified": "2026-08-13T15:19:18.216854Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--105b23b3-ee5c-5990-a3f9-7562902d3dba",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--98576aec-90e7-529f-aa4c-11380eceb7bf",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.216973Z",
            "modified": "2026-08-13T15:19:18.216973Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--5158a7b0-8bde-5edf-a688-78da33dbf2cb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--89298051-023b-5429-86e4-922a91b239f2",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.217094Z",
            "modified": "2026-08-13T15:19:18.217094Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--d2130def-6b14-55d3-b9ce-4e4c5116baa6",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--11c87eac-72c1-5a47-b949-221c1ed14339",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.217202Z",
            "modified": "2026-08-13T15:19:18.217202Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--efbaf1ef-fb8b-5318-9923-0b1d38f75b6e",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--fa286110-ac34-5222-abcf-af5815e11b51",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.217346Z",
            "modified": "2026-08-13T15:19:18.217346Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--45f51e52-120a-5238-8e39-3104c38f2e07",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f19d8c56-81b8-5e03-9d4a-9c2e01fdd344",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.217451Z",
            "modified": "2026-08-13T15:19:18.217451Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--cb4f5044-02fd-54b9-b82d-a5abad4e7869",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6843f964-f2dc-501f-ade5-9806bdbddda6",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.217553Z",
            "modified": "2026-08-13T15:19:18.217553Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--67c27543-6d8c-5ff5-955a-94664d0e98eb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--7032f181-d33a-5e60-8f3f-8d963e8e01cd",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.217666Z",
            "modified": "2026-08-13T15:19:18.217666Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--08ef11cb-c802-5d05-8b25-b02299ed788f",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--33d00bb0-7ecb-5ea9-b5cc-b044fd1d76e6",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.217805Z",
            "modified": "2026-08-13T15:19:18.217805Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--aa2529cc-aae5-5a31-9518-2a4dbd668230",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--89f373e5-1670-57ad-93cb-853be3839c2f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.217924Z",
            "modified": "2026-08-13T15:19:18.217924Z",
            "relationship_type": "exploits",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "vulnerability--7c8dd94a-2a60-568a-a600-bf3f35ffc925",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f37f71a2-bb7b-5599-a99d-ca30866ac46c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218042Z",
            "modified": "2026-08-13T15:19:18.218042Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--6214841b-936d-5da2-b5c8-4bed4cf9aee0",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f918d531-0d62-5730-b588-40a17e13cb14",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218134Z",
            "modified": "2026-08-13T15:19:18.218134Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--770465f6-d1b8-5285-9c27-a5a9569aa97b",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--2d50c04b-5a25-5735-89e3-ef069dfd7a94",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218227Z",
            "modified": "2026-08-13T15:19:18.218227Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--856a360d-8aca-55ff-949d-fee64905d0a8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--fea65e4a-c709-5e9a-88d7-60cf6e44d06b",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218337Z",
            "modified": "2026-08-13T15:19:18.218337Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--6ef82ce6-fcae-5c08-99b6-3ad30baa6bfb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--7e59a4d0-f86b-5dca-8a4c-7f0d8ac1c3c9",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218448Z",
            "modified": "2026-08-13T15:19:18.218448Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--73364e03-8914-541e-a33c-877b656c37e4",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--b07aeb17-6c14-5730-9c96-8dcef7190fc8",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218542Z",
            "modified": "2026-08-13T15:19:18.218542Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--fd8dd968-9ef8-5d44-9278-54e070789645",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8c7c7bb8-e7ad-5d2c-ae74-a4fdf9a872cc",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218636Z",
            "modified": "2026-08-13T15:19:18.218636Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--be0beb0c-2499-5178-a012-309e486ef121",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d7d4bfc7-6cb5-5ff6-9d38-faad3fccde62",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218725Z",
            "modified": "2026-08-13T15:19:18.218725Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--16d93383-9cd3-53c0-94a2-a75a3a9e3a9e",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--bfd82157-900e-5fe1-bc16-343858a82f6c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218815Z",
            "modified": "2026-08-13T15:19:18.218815Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--e143cf40-c9b0-5118-8096-34d60698c27b",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--57e5aa71-a0bb-5573-b85f-31a3b165032c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218903Z",
            "modified": "2026-08-13T15:19:18.218903Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--e42939d6-6332-5a6c-8dac-6195c79081bc",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--2609e723-25ab-5982-80f2-5ea95ee0e3a5",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.218994Z",
            "modified": "2026-08-13T15:19:18.218994Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--d6b8aa8c-cfd9-5f42-a8ac-2573005abb2f",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--e5adea7b-4d1c-56d2-8fcd-8acf0a61c94d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219084Z",
            "modified": "2026-08-13T15:19:18.219084Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--81ac1dd0-a8ac-50ba-bd1a-cec2886340d5",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--860fe670-6668-5e88-bc27-86baf2d356cb",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219175Z",
            "modified": "2026-08-13T15:19:18.219175Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--c4d23a10-7ecd-543e-af65-13160caed625",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--09aed2af-606e-5153-b1d2-e3524691cc83",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.21927Z",
            "modified": "2026-08-13T15:19:18.21927Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--06cbe52b-abcb-5b54-a3ec-c553a82c7374",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--c00e9311-b319-52b3-b8f3-1a9abcdffbf0",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219362Z",
            "modified": "2026-08-13T15:19:18.219362Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--1635f86c-b5b5-5339-b31b-87ce05013408",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--991832af-f1ce-56e3-8810-ba2323294619",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219451Z",
            "modified": "2026-08-13T15:19:18.219451Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--f38353ba-cfac-577c-ac86-5e3f0c5fb314",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f4db9ab2-92e9-59b1-b59a-1355bee3e92c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219541Z",
            "modified": "2026-08-13T15:19:18.219541Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "attack-pattern--351c2bb8-092f-5863-b623-f9ca08b16432",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--0ec1311b-f7a3-5148-bcaa-59d1f146b72b",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219631Z",
            "modified": "2026-08-13T15:19:18.219631Z",
            "relationship_type": "uses",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "infrastructure--08fb24a7-655f-5ba8-928e-68f8d72cedee",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--3183e116-1206-5a9a-9937-78c7c89e9eb1",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219723Z",
            "modified": "2026-08-13T15:19:18.219723Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--105b23b3-ee5c-5990-a3f9-7562902d3dba",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8eb35e05-413e-5691-a529-e942695d2911",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219813Z",
            "modified": "2026-08-13T15:19:18.219813Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--5158a7b0-8bde-5edf-a688-78da33dbf2cb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--c97e7e09-4923-52fa-835d-af90dea1e6ec",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219902Z",
            "modified": "2026-08-13T15:19:18.219902Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--d2130def-6b14-55d3-b9ce-4e4c5116baa6",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d4457bd9-96cd-5405-8dc4-f7482b3b6c8d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.219994Z",
            "modified": "2026-08-13T15:19:18.219994Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--efbaf1ef-fb8b-5318-9923-0b1d38f75b6e",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--355c5ed0-f1b9-582f-8971-d91de360beeb",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.220083Z",
            "modified": "2026-08-13T15:19:18.220083Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--45f51e52-120a-5238-8e39-3104c38f2e07",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--853ff919-67e5-573c-9382-79f3fb04dc5c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.220173Z",
            "modified": "2026-08-13T15:19:18.220173Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--cb4f5044-02fd-54b9-b82d-a5abad4e7869",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--aa497ebf-937a-558d-b967-3b2f5a47b0d7",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.220262Z",
            "modified": "2026-08-13T15:19:18.220262Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--67c27543-6d8c-5ff5-955a-94664d0e98eb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--b3224ebf-151e-5d59-acaa-4c88e70eb023",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.220352Z",
            "modified": "2026-08-13T15:19:18.220352Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--08ef11cb-c802-5d05-8b25-b02299ed788f",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--daccd23b-9233-5252-979b-d2b3b1a78d8c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.220442Z",
            "modified": "2026-08-13T15:19:18.220442Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--aa2529cc-aae5-5a31-9518-2a4dbd668230",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a8853992-633d-5963-9c80-79f7d9a401aa",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.220531Z",
            "modified": "2026-08-13T15:19:18.220531Z",
            "relationship_type": "exploits",
            "source_ref": "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
            "target_ref": "vulnerability--7c8dd94a-2a60-568a-a600-bf3f35ffc925",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d70ae85c-f4dc-551e-8cd9-9cb81db5af8a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.22062Z",
            "modified": "2026-08-13T15:19:18.22062Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--6214841b-936d-5da2-b5c8-4bed4cf9aee0",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f1666747-42ae-564e-be77-3ff488b36ca5",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.220709Z",
            "modified": "2026-08-13T15:19:18.220709Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--770465f6-d1b8-5285-9c27-a5a9569aa97b",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--b4392afe-f864-5efc-9a97-212ab007516f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.2208Z",
            "modified": "2026-08-13T15:19:18.2208Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--856a360d-8aca-55ff-949d-fee64905d0a8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8c115b76-45c4-582c-a6cd-5d96688acdd0",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.220893Z",
            "modified": "2026-08-13T15:19:18.220893Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--6ef82ce6-fcae-5c08-99b6-3ad30baa6bfb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--654f1ca9-0387-5e5b-a46c-b6bffe65054e",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.221001Z",
            "modified": "2026-08-13T15:19:18.221001Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--73364e03-8914-541e-a33c-877b656c37e4",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d0d0cbe3-8792-55b3-a288-ce9366c06127",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.221118Z",
            "modified": "2026-08-13T15:19:18.221118Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--fd8dd968-9ef8-5d44-9278-54e070789645",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a19bc9a4-9410-512d-b1ef-53a4bb0a1bb5",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.221256Z",
            "modified": "2026-08-13T15:19:18.221256Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--be0beb0c-2499-5178-a012-309e486ef121",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--3ad33fa3-11d2-5b84-9444-b6bc4c263734",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.221551Z",
            "modified": "2026-08-13T15:19:18.221551Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--16d93383-9cd3-53c0-94a2-a75a3a9e3a9e",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--dd896da7-4846-5474-911a-3b6c80294548",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.221661Z",
            "modified": "2026-08-13T15:19:18.221661Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--e143cf40-c9b0-5118-8096-34d60698c27b",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a3617c10-000f-5898-af67-1cbb3ba330fa",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.221778Z",
            "modified": "2026-08-13T15:19:18.221778Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--e42939d6-6332-5a6c-8dac-6195c79081bc",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--47302562-87fc-5af7-aaa2-a1c2c4d88e37",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.221896Z",
            "modified": "2026-08-13T15:19:18.221896Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--d6b8aa8c-cfd9-5f42-a8ac-2573005abb2f",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--814533fd-48a9-5f0c-b3d5-200abaa9c0c9",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.222029Z",
            "modified": "2026-08-13T15:19:18.222029Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--81ac1dd0-a8ac-50ba-bd1a-cec2886340d5",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--70ebfbd2-b001-5f64-976d-908707618a78",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.222173Z",
            "modified": "2026-08-13T15:19:18.222173Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--c4d23a10-7ecd-543e-af65-13160caed625",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--921a6078-77b8-515a-b6f1-a44f787f9932",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.222282Z",
            "modified": "2026-08-13T15:19:18.222282Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--06cbe52b-abcb-5b54-a3ec-c553a82c7374",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--98b6b42d-d6a5-515a-ae87-3494e5b7ddff",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.2224Z",
            "modified": "2026-08-13T15:19:18.2224Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--1635f86c-b5b5-5339-b31b-87ce05013408",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--7d2c5e1e-3db7-50fd-b043-a9a31b5d38ec",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.22252Z",
            "modified": "2026-08-13T15:19:18.22252Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--f38353ba-cfac-577c-ac86-5e3f0c5fb314",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--001f9280-c2a1-52eb-96bb-6ec0471c33f7",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.222638Z",
            "modified": "2026-08-13T15:19:18.222638Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "attack-pattern--351c2bb8-092f-5863-b623-f9ca08b16432",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--752cf3bb-197f-5c93-a9fb-497b8ea2836e",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.222774Z",
            "modified": "2026-08-13T15:19:18.222774Z",
            "relationship_type": "uses",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "infrastructure--08fb24a7-655f-5ba8-928e-68f8d72cedee",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--48fbb382-777e-5af8-9198-38f74b8a95a5",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.222908Z",
            "modified": "2026-08-13T15:19:18.222908Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--105b23b3-ee5c-5990-a3f9-7562902d3dba",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--eee6137e-4fe1-524d-84e2-99319cec8398",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.223054Z",
            "modified": "2026-08-13T15:19:18.223054Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--5158a7b0-8bde-5edf-a688-78da33dbf2cb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--c2d4d706-2b25-5b2c-86aa-80cf1d9aecb0",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.223201Z",
            "modified": "2026-08-13T15:19:18.223201Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--d2130def-6b14-55d3-b9ce-4e4c5116baa6",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--c04d543f-817c-56be-a10a-59683ea68e6f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.223334Z",
            "modified": "2026-08-13T15:19:18.223334Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--efbaf1ef-fb8b-5318-9923-0b1d38f75b6e",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--75505261-14ac-58f8-a584-46e8914a118b",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.223458Z",
            "modified": "2026-08-13T15:19:18.223458Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--45f51e52-120a-5238-8e39-3104c38f2e07",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8be5a19a-fc4d-51be-b573-9354c2b9b7cd",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.223569Z",
            "modified": "2026-08-13T15:19:18.223569Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--cb4f5044-02fd-54b9-b82d-a5abad4e7869",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--3de98bfd-b877-5487-9546-031124e4d962",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.223661Z",
            "modified": "2026-08-13T15:19:18.223661Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--67c27543-6d8c-5ff5-955a-94664d0e98eb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--b35ca4f8-259f-5d04-8edb-cdc6725e0205",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.223753Z",
            "modified": "2026-08-13T15:19:18.223753Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--08ef11cb-c802-5d05-8b25-b02299ed788f",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8ae32f3d-e7bd-5c52-8f88-866c6906ce12",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.223845Z",
            "modified": "2026-08-13T15:19:18.223845Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--aa2529cc-aae5-5a31-9518-2a4dbd668230",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--182a2372-ba4d-5ab1-be0c-8691682549ab",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.223938Z",
            "modified": "2026-08-13T15:19:18.223938Z",
            "relationship_type": "exploits",
            "source_ref": "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
            "target_ref": "vulnerability--7c8dd94a-2a60-568a-a600-bf3f35ffc925",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--98b7767b-53a4-555b-ab94-40e3f8628cf8",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224029Z",
            "modified": "2026-08-13T15:19:18.224029Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--6214841b-936d-5da2-b5c8-4bed4cf9aee0",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--ded4e5fc-4211-5a61-9fd9-a11f030cfac4",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224148Z",
            "modified": "2026-08-13T15:19:18.224148Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--770465f6-d1b8-5285-9c27-a5a9569aa97b",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--40f368f6-0c4d-56f1-9aee-4914a7c441c2",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224268Z",
            "modified": "2026-08-13T15:19:18.224268Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--856a360d-8aca-55ff-949d-fee64905d0a8",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--2cde40a6-4b6d-5f9a-8e1a-21602f542d6c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224357Z",
            "modified": "2026-08-13T15:19:18.224357Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--6ef82ce6-fcae-5c08-99b6-3ad30baa6bfb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--3d138118-df92-5000-8a51-8dc110e73e44",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224446Z",
            "modified": "2026-08-13T15:19:18.224446Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--73364e03-8914-541e-a33c-877b656c37e4",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--b0bd9350-9ea6-5f50-9058-39778be8e815",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224536Z",
            "modified": "2026-08-13T15:19:18.224536Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--fd8dd968-9ef8-5d44-9278-54e070789645",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--ffdc4539-d8ca-55b8-a555-77cae4dfa76d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224625Z",
            "modified": "2026-08-13T15:19:18.224625Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--be0beb0c-2499-5178-a012-309e486ef121",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--28d3d253-caf8-5f97-bc3b-0d49940aca9f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224713Z",
            "modified": "2026-08-13T15:19:18.224713Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--16d93383-9cd3-53c0-94a2-a75a3a9e3a9e",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6213aed3-f59c-5086-b05a-7ec76360b36f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224818Z",
            "modified": "2026-08-13T15:19:18.224818Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--e143cf40-c9b0-5118-8096-34d60698c27b",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--39e31602-aedd-5f97-b564-25d153df28fc",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.224943Z",
            "modified": "2026-08-13T15:19:18.224943Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--e42939d6-6332-5a6c-8dac-6195c79081bc",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6c8379ef-1a1c-5c7c-b26f-caf3d8faa38d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225049Z",
            "modified": "2026-08-13T15:19:18.225049Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--d6b8aa8c-cfd9-5f42-a8ac-2573005abb2f",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f71c7504-3899-505f-92cc-61a8cffd202e",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225139Z",
            "modified": "2026-08-13T15:19:18.225139Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--81ac1dd0-a8ac-50ba-bd1a-cec2886340d5",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8e1cdf32-9c1f-5091-bc14-2d00067d1ca5",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225229Z",
            "modified": "2026-08-13T15:19:18.225229Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--c4d23a10-7ecd-543e-af65-13160caed625",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--e4543046-1c47-5cad-9d3a-1e4e8f286a04",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225326Z",
            "modified": "2026-08-13T15:19:18.225326Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--06cbe52b-abcb-5b54-a3ec-c553a82c7374",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6c146c57-e9a4-5d61-9c96-fc51e2dda220",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225419Z",
            "modified": "2026-08-13T15:19:18.225419Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--1635f86c-b5b5-5339-b31b-87ce05013408",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--cb981691-bae3-553d-a104-d0c329347787",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225509Z",
            "modified": "2026-08-13T15:19:18.225509Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--f38353ba-cfac-577c-ac86-5e3f0c5fb314",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--43ab9cd6-717d-51e4-9d75-49e848e41edb",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225599Z",
            "modified": "2026-08-13T15:19:18.225599Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "attack-pattern--351c2bb8-092f-5863-b623-f9ca08b16432",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--16703bfa-50d5-5a0a-8db0-9b3b2eb2884e",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225689Z",
            "modified": "2026-08-13T15:19:18.225689Z",
            "relationship_type": "uses",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "infrastructure--08fb24a7-655f-5ba8-928e-68f8d72cedee",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--21c3ed68-ccca-5cdd-bc02-7c415c8f099f",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225778Z",
            "modified": "2026-08-13T15:19:18.225778Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--105b23b3-ee5c-5990-a3f9-7562902d3dba",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--b34bf024-e832-5b92-8d07-9a2c53d80769",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225868Z",
            "modified": "2026-08-13T15:19:18.225868Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--5158a7b0-8bde-5edf-a688-78da33dbf2cb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--3872e642-bff8-547b-973d-51fca02774e2",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.225957Z",
            "modified": "2026-08-13T15:19:18.225957Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--d2130def-6b14-55d3-b9ce-4e4c5116baa6",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--0a44a583-1157-51f9-9dfb-642ec3f9fd36",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226047Z",
            "modified": "2026-08-13T15:19:18.226047Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--efbaf1ef-fb8b-5318-9923-0b1d38f75b6e",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--55debbc9-33d5-5a1f-a3d5-78412aaf82bc",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226136Z",
            "modified": "2026-08-13T15:19:18.226136Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--45f51e52-120a-5238-8e39-3104c38f2e07",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6f39f69b-eda0-578f-8841-14c3b33dabb5",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226226Z",
            "modified": "2026-08-13T15:19:18.226226Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--cb4f5044-02fd-54b9-b82d-a5abad4e7869",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--198a90ac-81d5-5a0a-a892-cfdb0c09abcb",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226316Z",
            "modified": "2026-08-13T15:19:18.226316Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--67c27543-6d8c-5ff5-955a-94664d0e98eb",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--03443078-94c6-5bdd-a93f-be7fb304b93d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226405Z",
            "modified": "2026-08-13T15:19:18.226405Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--08ef11cb-c802-5d05-8b25-b02299ed788f",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--e7a22f5b-d6f0-51a8-a680-feddf4725e21",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226495Z",
            "modified": "2026-08-13T15:19:18.226495Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--aa2529cc-aae5-5a31-9518-2a4dbd668230",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8aa39283-8626-585f-9416-cf6bff39f868",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226584Z",
            "modified": "2026-08-13T15:19:18.226584Z",
            "relationship_type": "exploits",
            "source_ref": "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
            "target_ref": "vulnerability--7c8dd94a-2a60-568a-a600-bf3f35ffc925",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--baec8981-35af-5550-b93c-0a5ffeb65df1",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226675Z",
            "modified": "2026-08-13T15:19:18.226675Z",
            "relationship_type": "related-to",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "tool--f21deb6f-f583-514d-8f11-cbf4cf9c47f2",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--3fcc8158-2a2f-5c30-94b3-46a65c2051b3",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226766Z",
            "modified": "2026-08-13T15:19:18.226766Z",
            "relationship_type": "related-to",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "tool--a7c1a48e-52e7-5647-af43-e06d9be8a76b",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--0625961d-d9d1-5b06-81bf-28dcc0eac282",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226857Z",
            "modified": "2026-08-13T15:19:18.226857Z",
            "relationship_type": "related-to",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "tool--963f3579-6b16-5390-ad0f-d308ac5a04fe",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--011da5ad-2afb-5096-8c4c-0e71b3980e2a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.226947Z",
            "modified": "2026-08-13T15:19:18.226947Z",
            "relationship_type": "related-to",
            "source_ref": "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
            "target_ref": "tool--b33807e9-5748-5c1e-9d3c-2f59422a034f",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--24bb536a-5f81-59ee-b0a6-69371772c782",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-08-13T15:19:18.227159Z",
            "modified": "2026-08-13T15:19:18.227159Z",
            "name": "The Middle Tier: A Non-APT Operator's Reach Into Four Southeast Asian Governments",
            "description": "Two distinct actor sets are represented and MUST be kept separate. (1) The reported operator: a single hands-on-keyboard operator running a four-country (ID/TH/MY/PH) government-targeting campaign from 144.172.106.236. (2) A co-located, MODERATE-likely SEPARATE second intruder whose GSocket/THC backdoor kit (localroot.sbs / cat.sh + /home/nast/* implants) was found on the shared victim svr1.nast.ph. Second-actor indicators are flagged 'second_actor': true and must not be folded into the operator's TTP set. Commodity chisel.exe hash is shared by 179 VT submitters \u2014 HUNT only, not an attribution or block anchor; its VT relationships are shared-tool noise. See stage1-malware-analyst.md Section 7.4 for the full hard-exclusion list enforced here.",
            "report_types": [
                "threat-report"
            ],
            "published": "2026-07-17T00:00:00Z",
            "object_refs": [
                "ipv4-addr--9382dded-53f0-5a21-93ec-7cbb5d9d767b",
                "indicator--a4bec962-d1b4-5aa5-92b9-0722d341f775",
                "ipv4-addr--264f6b3b-2022-50c6-a87d-74933dc83e20",
                "indicator--b0b349fd-c7a0-5e9a-8365-9d39134b43cf",
                "domain-name--03ffeacb-7e51-5aea-8555-0f596b71cf56",
                "indicator--0ba2e85d-a6a0-513e-85c3-3d96d1ef089f",
                "domain-name--2e360dc4-cc6f-5d09-afdd-7e8a7e83be23",
                "indicator--956bf4b3-3599-54d9-bea7-63e582926b2a",
                "file--4bf344b7-0aec-55fa-91c9-6415ec9b7efd",
                "file--81df8872-95fb-545b-9132-032edecbd142",
                "file--e601b288-1e9e-5f8b-879e-7611935a1e7e",
                "file--242b068c-fdba-5db4-803e-8f0beab040d1",
                "indicator--15a311ae-d63d-526f-a4fc-49023631f11f",
                "indicator--d86cc40c-e152-5b13-a055-4c0cf3d7350a",
                "indicator--3c68d8fb-7f0d-5972-b80d-14cefaf1de8d",
                "indicator--046a5f26-935f-540d-9a65-a74974bbe12c",
                "indicator--ab7a3db7-080f-5866-a621-287b03e5d738",
                "indicator--f13fcb2c-078a-5827-a83b-1f82114d0329",
                "indicator--1964f03a-a16a-5734-8d4e-c030b15b8972",
                "indicator--4ebf86df-9590-5d76-9cbf-cd855ed98f6b",
                "indicator--362ebd4c-7b8f-55a0-b76e-549849e005b8",
                "indicator--f4fb60a2-43c3-55f9-8d33-487fef2527b2",
                "indicator--7f304d92-2113-5ee2-920b-f7540b8619c6",
                "indicator--3c452a4e-930f-5b08-abd0-c2ffab6e262c",
                "indicator--aeaeb3e6-47a0-5994-a2da-f70d2089eb7f",
                "indicator--44b0137d-05d1-5818-aab9-5ed649d80ca6",
                "indicator--2675b447-d40b-5ee2-96c7-f6a25dcda5f5",
                "indicator--4cff3749-40e9-53b9-9809-89ca680ce86f",
                "indicator--747fd33c-1d5c-5512-baab-bf5e182c7214",
                "indicator--e740a9e6-ec50-5ea3-8108-f57839e9e805",
                "indicator--423eec8d-dc44-5e4c-90e4-be2e896bbd8b",
                "indicator--c0bce940-af7f-5c33-90de-a5400692e089",
                "indicator--31393ea2-ff0a-529b-8668-dbc8f0f7616f",
                "indicator--271c14db-2770-59fc-8c4c-b3af7f5edf04",
                "indicator--77b3f25e-b013-54ec-b00a-5c1873e016d4",
                "indicator--23df1181-495f-54d8-b9e6-928c9ceadae7",
                "indicator--6bf59778-bfca-5d06-abcb-d750164d359c",
                "indicator--ed28209d-319e-5840-b72e-effd2175da35",
                "indicator--3656b863-04ac-5092-ab42-e9d845d4346a",
                "malware--453c1972-23c0-5142-b760-bf80fb4737e8",
                "malware--d9a958c1-ae08-58d8-9780-0c953edaec52",
                "malware--330efd84-c6a5-5431-94c2-3f47ddba925d",
                "malware--0b19a6ee-6d34-5f2b-925c-06cce266d0f0",
                "tool--f21deb6f-f583-514d-8f11-cbf4cf9c47f2",
                "tool--a7c1a48e-52e7-5647-af43-e06d9be8a76b",
                "tool--963f3579-6b16-5390-ad0f-d308ac5a04fe",
                "tool--b33807e9-5748-5c1e-9d3c-2f59422a034f",
                "attack-pattern--6214841b-936d-5da2-b5c8-4bed4cf9aee0",
                "attack-pattern--770465f6-d1b8-5285-9c27-a5a9569aa97b",
                "attack-pattern--856a360d-8aca-55ff-949d-fee64905d0a8",
                "attack-pattern--6ef82ce6-fcae-5c08-99b6-3ad30baa6bfb",
                "attack-pattern--73364e03-8914-541e-a33c-877b656c37e4",
                "attack-pattern--fd8dd968-9ef8-5d44-9278-54e070789645",
                "attack-pattern--be0beb0c-2499-5178-a012-309e486ef121",
                "attack-pattern--16d93383-9cd3-53c0-94a2-a75a3a9e3a9e",
                "attack-pattern--e143cf40-c9b0-5118-8096-34d60698c27b",
                "attack-pattern--e42939d6-6332-5a6c-8dac-6195c79081bc",
                "attack-pattern--d6b8aa8c-cfd9-5f42-a8ac-2573005abb2f",
                "attack-pattern--81ac1dd0-a8ac-50ba-bd1a-cec2886340d5",
                "attack-pattern--c4d23a10-7ecd-543e-af65-13160caed625",
                "attack-pattern--06cbe52b-abcb-5b54-a3ec-c553a82c7374",
                "attack-pattern--1635f86c-b5b5-5339-b31b-87ce05013408",
                "attack-pattern--f38353ba-cfac-577c-ac86-5e3f0c5fb314",
                "attack-pattern--351c2bb8-092f-5863-b623-f9ca08b16432",
                "infrastructure--08fb24a7-655f-5ba8-928e-68f8d72cedee",
                "vulnerability--105b23b3-ee5c-5990-a3f9-7562902d3dba",
                "vulnerability--5158a7b0-8bde-5edf-a688-78da33dbf2cb",
                "vulnerability--d2130def-6b14-55d3-b9ce-4e4c5116baa6",
                "vulnerability--efbaf1ef-fb8b-5318-9923-0b1d38f75b6e",
                "vulnerability--45f51e52-120a-5238-8e39-3104c38f2e07",
                "vulnerability--cb4f5044-02fd-54b9-b82d-a5abad4e7869",
                "vulnerability--67c27543-6d8c-5ff5-955a-94664d0e98eb",
                "vulnerability--08ef11cb-c802-5d05-8b25-b02299ed788f",
                "vulnerability--aa2529cc-aae5-5a31-9518-2a4dbd668230",
                "vulnerability--7c8dd94a-2a60-568a-a600-bf3f35ffc925",
                "relationship--8379cc14-2dc3-5e71-8e32-3379a0156f41",
                "relationship--a889ff21-1bf9-5bbd-9c46-63b1d8963fd2",
                "relationship--1640103d-e303-55da-b89b-93610d5d017c",
                "relationship--d71866c6-8ccd-59a3-827d-c4a10a185882",
                "relationship--a0d1660e-8abd-5a07-aa4c-1e962a5b874e",
                "relationship--d64c671c-e0d8-5eac-a680-2eb53bb7bfda",
                "relationship--cfbeb529-c5e6-53d1-be87-9d90de3876e6",
                "relationship--8b364a6d-cd32-543a-b733-b5688a595cb7",
                "relationship--4997ef0b-6bf9-53a1-a46f-5cee543bad6d",
                "relationship--20c1acba-9843-5833-9a15-4fd1d46c7e5d",
                "relationship--f6830ffc-8f25-5a10-887c-e310e31668dc",
                "relationship--b191020f-b5f9-57aa-9de0-77ced553c559",
                "relationship--d21b0e89-0a0a-5ddc-97af-5e66bbd009eb",
                "relationship--205ca8cf-2523-5110-be6a-f39409e99bcb",
                "relationship--db771888-4d8e-5cf7-9cab-e2199069cef2",
                "relationship--87e97264-035d-5227-8afc-3007bbfe14d7",
                "relationship--73760317-5ce3-54e7-986e-a7e8de8f7b4c",
                "relationship--6a9cf91f-fa2d-582e-8ff5-db03282ce267",
                "relationship--fd078f82-a770-5e98-abcc-fd6408f80786",
                "relationship--8916730b-127b-5697-8fdb-6b8eec17c653",
                "relationship--301fceb4-9f1a-5ebd-830d-24e6539cbd51",
                "relationship--4e6869ee-5cf8-5c25-ad2e-6c5b314f6344",
                "relationship--22af34cc-a2f4-51ca-8512-58b2bbdad55d",
                "relationship--2d1db5e4-bdfc-551a-bb33-4d43189f0c4f",
                "relationship--de2a3c4a-31f4-5953-a5cb-774ee6a00ee8",
                "relationship--e6bf8cb3-461e-5198-ade1-dbc9b2b7e6a1",
                "relationship--994c7328-1873-5b57-8e51-2f50c2a8986a",
                "relationship--e5877348-2ac1-5ca4-9ba0-fc79428c8483",
                "relationship--5b74cb02-afe6-5439-9f82-441b9f638736",
                "relationship--8b489338-fb95-5487-969a-291e5d2b7f37",
                "relationship--156c897e-ffb4-5db1-aceb-2a297ae9c587",
                "relationship--61ae6d20-db37-50fa-bd34-95775e3f9d9c",
                "relationship--6f3492f7-c81e-5fba-9295-66891051dd5a",
                "relationship--e6ba6df9-60af-50f4-a710-89e310dc1148",
                "relationship--470c414f-2696-5421-b276-f791d2592eef",
                "relationship--f8e0b81e-2eef-5533-a15c-8a95b5b588e1",
                "relationship--9798823d-0d06-5f6b-925c-efcd096175a8",
                "relationship--617e5fa7-759b-5c83-bffe-1cf7d420b1e0",
                "relationship--d6dc1778-4649-5a15-a56a-26e594d2bece",
                "relationship--993b6853-89f7-5d1a-83ec-622867be949f",
                "relationship--14839f2e-513f-582b-8402-31d28d8416a6",
                "relationship--959ee8a4-b403-5072-8764-18d935193058",
                "relationship--8cfe77d2-e9e8-5274-bba3-8dd46e4ea88a",
                "relationship--f906b920-d2f6-5f23-b644-255669185871",
                "relationship--31f4188e-d95e-5d24-a717-4f24a9df06fa",
                "relationship--ef50aa3f-90f3-54b6-bba6-72ca97554d65",
                "relationship--a0dd4b25-fe6e-5575-adab-2914309047c2",
                "relationship--2f667d5c-5e76-57a4-9876-1071867e5817",
                "relationship--55a907ec-e3ca-58f1-8061-72f979b2607e",
                "relationship--1eaef6a5-4c49-5854-98e4-c1bd885c7dbd",
                "relationship--98576aec-90e7-529f-aa4c-11380eceb7bf",
                "relationship--89298051-023b-5429-86e4-922a91b239f2",
                "relationship--11c87eac-72c1-5a47-b949-221c1ed14339",
                "relationship--fa286110-ac34-5222-abcf-af5815e11b51",
                "relationship--f19d8c56-81b8-5e03-9d4a-9c2e01fdd344",
                "relationship--6843f964-f2dc-501f-ade5-9806bdbddda6",
                "relationship--7032f181-d33a-5e60-8f3f-8d963e8e01cd",
                "relationship--33d00bb0-7ecb-5ea9-b5cc-b044fd1d76e6",
                "relationship--89f373e5-1670-57ad-93cb-853be3839c2f",
                "relationship--f37f71a2-bb7b-5599-a99d-ca30866ac46c",
                "relationship--f918d531-0d62-5730-b588-40a17e13cb14",
                "relationship--2d50c04b-5a25-5735-89e3-ef069dfd7a94",
                "relationship--fea65e4a-c709-5e9a-88d7-60cf6e44d06b",
                "relationship--7e59a4d0-f86b-5dca-8a4c-7f0d8ac1c3c9",
                "relationship--b07aeb17-6c14-5730-9c96-8dcef7190fc8",
                "relationship--8c7c7bb8-e7ad-5d2c-ae74-a4fdf9a872cc",
                "relationship--d7d4bfc7-6cb5-5ff6-9d38-faad3fccde62",
                "relationship--bfd82157-900e-5fe1-bc16-343858a82f6c",
                "relationship--57e5aa71-a0bb-5573-b85f-31a3b165032c",
                "relationship--2609e723-25ab-5982-80f2-5ea95ee0e3a5",
                "relationship--e5adea7b-4d1c-56d2-8fcd-8acf0a61c94d",
                "relationship--860fe670-6668-5e88-bc27-86baf2d356cb",
                "relationship--09aed2af-606e-5153-b1d2-e3524691cc83",
                "relationship--c00e9311-b319-52b3-b8f3-1a9abcdffbf0",
                "relationship--991832af-f1ce-56e3-8810-ba2323294619",
                "relationship--f4db9ab2-92e9-59b1-b59a-1355bee3e92c",
                "relationship--0ec1311b-f7a3-5148-bcaa-59d1f146b72b",
                "relationship--3183e116-1206-5a9a-9937-78c7c89e9eb1",
                "relationship--8eb35e05-413e-5691-a529-e942695d2911",
                "relationship--c97e7e09-4923-52fa-835d-af90dea1e6ec",
                "relationship--d4457bd9-96cd-5405-8dc4-f7482b3b6c8d",
                "relationship--355c5ed0-f1b9-582f-8971-d91de360beeb",
                "relationship--853ff919-67e5-573c-9382-79f3fb04dc5c",
                "relationship--aa497ebf-937a-558d-b967-3b2f5a47b0d7",
                "relationship--b3224ebf-151e-5d59-acaa-4c88e70eb023",
                "relationship--daccd23b-9233-5252-979b-d2b3b1a78d8c",
                "relationship--a8853992-633d-5963-9c80-79f7d9a401aa",
                "relationship--d70ae85c-f4dc-551e-8cd9-9cb81db5af8a",
                "relationship--f1666747-42ae-564e-be77-3ff488b36ca5",
                "relationship--b4392afe-f864-5efc-9a97-212ab007516f",
                "relationship--8c115b76-45c4-582c-a6cd-5d96688acdd0",
                "relationship--654f1ca9-0387-5e5b-a46c-b6bffe65054e",
                "relationship--d0d0cbe3-8792-55b3-a288-ce9366c06127",
                "relationship--a19bc9a4-9410-512d-b1ef-53a4bb0a1bb5",
                "relationship--3ad33fa3-11d2-5b84-9444-b6bc4c263734",
                "relationship--dd896da7-4846-5474-911a-3b6c80294548",
                "relationship--a3617c10-000f-5898-af67-1cbb3ba330fa",
                "relationship--47302562-87fc-5af7-aaa2-a1c2c4d88e37",
                "relationship--814533fd-48a9-5f0c-b3d5-200abaa9c0c9",
                "relationship--70ebfbd2-b001-5f64-976d-908707618a78",
                "relationship--921a6078-77b8-515a-b6f1-a44f787f9932",
                "relationship--98b6b42d-d6a5-515a-ae87-3494e5b7ddff",
                "relationship--7d2c5e1e-3db7-50fd-b043-a9a31b5d38ec",
                "relationship--001f9280-c2a1-52eb-96bb-6ec0471c33f7",
                "relationship--752cf3bb-197f-5c93-a9fb-497b8ea2836e",
                "relationship--48fbb382-777e-5af8-9198-38f74b8a95a5",
                "relationship--eee6137e-4fe1-524d-84e2-99319cec8398",
                "relationship--c2d4d706-2b25-5b2c-86aa-80cf1d9aecb0",
                "relationship--c04d543f-817c-56be-a10a-59683ea68e6f",
                "relationship--75505261-14ac-58f8-a584-46e8914a118b",
                "relationship--8be5a19a-fc4d-51be-b573-9354c2b9b7cd",
                "relationship--3de98bfd-b877-5487-9546-031124e4d962",
                "relationship--b35ca4f8-259f-5d04-8edb-cdc6725e0205",
                "relationship--8ae32f3d-e7bd-5c52-8f88-866c6906ce12",
                "relationship--182a2372-ba4d-5ab1-be0c-8691682549ab",
                "relationship--98b7767b-53a4-555b-ab94-40e3f8628cf8",
                "relationship--ded4e5fc-4211-5a61-9fd9-a11f030cfac4",
                "relationship--40f368f6-0c4d-56f1-9aee-4914a7c441c2",
                "relationship--2cde40a6-4b6d-5f9a-8e1a-21602f542d6c",
                "relationship--3d138118-df92-5000-8a51-8dc110e73e44",
                "relationship--b0bd9350-9ea6-5f50-9058-39778be8e815",
                "relationship--ffdc4539-d8ca-55b8-a555-77cae4dfa76d",
                "relationship--28d3d253-caf8-5f97-bc3b-0d49940aca9f",
                "relationship--6213aed3-f59c-5086-b05a-7ec76360b36f",
                "relationship--39e31602-aedd-5f97-b564-25d153df28fc",
                "relationship--6c8379ef-1a1c-5c7c-b26f-caf3d8faa38d",
                "relationship--f71c7504-3899-505f-92cc-61a8cffd202e",
                "relationship--8e1cdf32-9c1f-5091-bc14-2d00067d1ca5",
                "relationship--e4543046-1c47-5cad-9d3a-1e4e8f286a04",
                "relationship--6c146c57-e9a4-5d61-9c96-fc51e2dda220",
                "relationship--cb981691-bae3-553d-a104-d0c329347787",
                "relationship--43ab9cd6-717d-51e4-9d75-49e848e41edb",
                "relationship--16703bfa-50d5-5a0a-8db0-9b3b2eb2884e",
                "relationship--21c3ed68-ccca-5cdd-bc02-7c415c8f099f",
                "relationship--b34bf024-e832-5b92-8d07-9a2c53d80769",
                "relationship--3872e642-bff8-547b-973d-51fca02774e2",
                "relationship--0a44a583-1157-51f9-9dfb-642ec3f9fd36",
                "relationship--55debbc9-33d5-5a1f-a3d5-78412aaf82bc",
                "relationship--6f39f69b-eda0-578f-8841-14c3b33dabb5",
                "relationship--198a90ac-81d5-5a0a-a892-cfdb0c09abcb",
                "relationship--03443078-94c6-5bdd-a93f-be7fb304b93d",
                "relationship--e7a22f5b-d6f0-51a8-a680-feddf4725e21",
                "relationship--8aa39283-8626-585f-9416-cf6bff39f868",
                "relationship--baec8981-35af-5550-b93c-0a5ffeb65df1",
                "relationship--3fcc8158-2a2f-5c30-94b3-46a65c2051b3",
                "relationship--0625961d-d9d1-5b06-81bf-28dcc0eac282",
                "relationship--011da5ad-2afb-5096-8c4c-0e71b3980e2a"
            ],
            "labels": [
                "Government",
                "Exploitation",
                "OpenDirectory",
                "SE-Asia"
            ],
            "external_references": [
                {
                    "source_name": "The Hunters Ledger",
                    "url": "https://the-hunters-ledger.com/reports/seasia-gov-exploitation-toolkit-144-172-106-236/"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        }
    ]
}