{
    "type": "bundle",
    "id": "bundle--b872a33a-1a7d-5373-8eed-bc3258c9fe1f",
    "objects": [
        {
            "type": "marking-definition",
            "spec_version": "2.1",
            "id": "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487",
            "created": "2022-10-01T00:00:00.000Z",
            "name": "TLP:CLEAR",
            "extensions": {
                "extension-definition--60a3c5c5-0d10-413e-aab3-9e08dde9e88d": {
                    "extension_type": "property-extension",
                    "tlp_2_0": "clear"
                }
            }
        },
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.483538Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "name": "Dispensight / SecureLeaf",
            "identity_class": "organization",
            "description": "Defensive CTI — secureleaf.dispensight.com"
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--d74c58c8-ea22-50c8-8d7e-1ddaf5dc84c3",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-10-04T18:00:00.000Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "published": "2026-10-04T18:00:00.000Z",
            "name": "SL-ADV-2026-WP-001 — WP-002 ClickFix Variants B & C (v16 + v17 unified)",
            "description": "Unified intelligence from advisories v16 (2026-09-24, freightbook365.com) and v17 (2026-09-28, gogreenlightloans.com). Chain reconstructed from embedded-keylog pcapng via independent TLS decryption.",
            "report_types": [
                "threat-report",
                "malware",
                "indicator"
            ],
            "object_refs": [
                "identity--cd9f1601-6614-59bf-b144-4205ee415898",
                "campaign--361195d6-0849-5dbb-935b-ad07043339d6",
                "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
                "attack-pattern--197213ad-deb5-514c-af1b-45044c5fd786",
                "attack-pattern--f853a6c0-c528-5885-92bb-3c3b65c6b671",
                "attack-pattern--def9347e-4e89-530d-b16e-90db04b57351",
                "attack-pattern--8e795a7b-a0cf-5629-9e29-df20c14751d9",
                "attack-pattern--8aa7ed1b-a02f-5a78-9ff5-9aeac9cf53e8",
                "attack-pattern--3ed57db8-5aff-5570-994e-e8119412e6e0",
                "attack-pattern--322ed22d-d83c-5de5-a18b-206907dcd1aa",
                "attack-pattern--3f9fd1bc-9ffe-54ce-b3af-405e1ff19f5c",
                "attack-pattern--abce81b6-a4ec-52e9-8073-20fce1d60855",
                "attack-pattern--a4177f74-bc93-5f2d-be81-329ac610a134",
                "infrastructure--b91cf883-f030-5ef5-9fc7-dd562d9a4d58",
                "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
                "infrastructure--fc85071c-39b9-5904-acb3-85fe74cc7a18",
                "infrastructure--4fca59be-ee4f-5d00-9b8b-b2be93d2c461",
                "infrastructure--5ca8785a-4b79-5e95-ac01-2833685070f5",
                "infrastructure--8afbaf36-1588-5d95-af71-f09b34905d5a",
                "infrastructure--01154441-797d-50aa-a4e1-b4e787c0fa17",
                "indicator--5ac177b6-128a-5bb1-ab64-389ee25aa4c9",
                "indicator--8d1552ea-5e2f-5525-9244-9ab29b405c38",
                "indicator--2a25f3e3-c3bf-5362-a6ef-e5b6ff1b92cd",
                "indicator--be3758b2-7209-5273-bf1c-15c5e9d182bd",
                "indicator--d61e033f-9a5f-5451-bab4-91c2e77bb803",
                "indicator--4ba6eb97-5d89-5486-b80a-791394dc7173",
                "indicator--3453ebee-9dae-5dd0-8ec9-44550901d19f",
                "indicator--0106d241-9285-559b-b8e8-62bee8eaec4b",
                "indicator--86dd4e0c-897a-53b1-8aba-f1d76ea60abd",
                "indicator--c1084f59-0447-5285-8535-89ae770f2abd",
                "indicator--147a483c-1178-5c18-945d-0bc4badb8e85",
                "indicator--62d91160-ec25-5e3f-a392-fdb9437fa8f9",
                "indicator--a13e7921-ce01-5158-b904-15ff5d917a47",
                "indicator--482a6f0a-45c0-57a8-ac77-f8b0beab378a",
                "indicator--5f9f0940-506d-5fdc-9517-c82ecd48a003",
                "note--304aca18-340d-52fb-984e-a8b3ce2c53e7",
                "relationship--01d60f0c-5499-51a1-9cff-6a5d076cce3d",
                "relationship--02fe195a-f677-5e9d-b4a2-58aba156cbed",
                "relationship--0a7f25a5-2e7b-5cdd-abe9-12e0ad9a2287",
                "relationship--1c7ee531-9555-5a10-818b-ba0de913cc9b",
                "relationship--1eae7216-da6b-5f3d-8573-b7feff95564f",
                "relationship--27604c2c-fc45-5b8a-9131-00951ed1eb94",
                "relationship--2add4c19-c1d4-5caf-8833-a0fdde032cbc",
                "relationship--43c65d85-0614-5513-bd6a-2cf44f9134ad",
                "relationship--47a2bbea-483b-5309-9171-e55a01cbddfb",
                "relationship--4a6952b5-9550-5d67-a338-28672f31a3b2",
                "relationship--6a8a84cc-f96f-5f2a-ac85-2d2a8efb8558",
                "relationship--6bc27d6a-4f35-5040-8120-1b0a50a94687",
                "relationship--6fe67ccc-f741-56f1-bf7d-9b3f071a91d5",
                "relationship--71782451-984d-55fa-97b4-1dafc44ba2ad",
                "relationship--7620889d-4a49-52f7-becb-4c4229b70b32",
                "relationship--77b33e31-477f-529f-bfa9-865137c8dfb2",
                "relationship--78b8e147-9a46-524c-8666-9b0e3569dbc8",
                "relationship--8188422e-2f38-5eb1-b6a8-bf99047a5fef",
                "relationship--83d13507-2db9-58c3-a8b4-fd62b5bdac9a",
                "relationship--8cab6a16-a790-560f-8f64-7e44cf4eb5b8",
                "relationship--926010c2-9534-5fcc-b250-0eca979e0e74",
                "relationship--a08e8a48-6421-53f3-91a1-705c7f4ff106",
                "relationship--a37ef585-0d75-5c2e-af83-dbffce539063",
                "relationship--a3a5e4ec-f861-5ba5-a0f4-836887f5a70a",
                "relationship--a551badb-c9cc-549f-b1f6-f5de14686381",
                "relationship--b354d4cd-b82b-5c6c-9311-c446a22db477",
                "relationship--c4ae40fc-912d-586c-ac67-9fd9c56a3e9d",
                "relationship--c72cd30e-9903-5952-82ff-b0db9f9d97f9",
                "relationship--d004dbb0-91e2-5870-8684-84c9a832821b",
                "relationship--d2d3e537-5e31-5437-b07d-fa2793d797b8",
                "relationship--d69f8fc2-5af2-52a6-b0a7-deccb5491861",
                "relationship--d6e3640f-eeaa-5fd1-83c0-2066b1dd57aa",
                "relationship--d78fc41a-c6f0-5fd7-8b31-80930c1a2928",
                "relationship--ded5ebb2-0d5b-5d17-b4e1-3d7177e75714",
                "relationship--e30877c0-4e27-58b0-ae04-615b4875f785",
                "relationship--e40c0cc5-feaa-5d7f-99c6-748f291157c8",
                "relationship--e9ec6008-42f4-53c3-95b8-0bd2a35a1ab7",
                "relationship--f43aa04c-0aad-5e65-bc06-fc2ae6c99953",
                "relationship--f9b59a59-4534-5ce5-8948-6295437a0e97"
            ],
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "campaign",
            "spec_version": "2.1",
            "id": "campaign--361195d6-0849-5dbb-935b-ad07043339d6",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-10-04T18:00:00.000Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "name": "SL-ADV-2026-WP-001 — WP-002 ClickFix on compromised WordPress",
            "description": "Omegatech (AS202412)-hosted ClickFix/EtherHiding campaign tracked by SecureLeaf since March 2026. Attribution is infrastructure-level only; no named-group or nation-state assertion.",
            "objective": "Credential and wallet theft via clipboard-poisoned elevated PowerShell",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "malware",
            "spec_version": "2.1",
            "id": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.483808Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "name": "Remus Stealer / WP-002 (ClickFix Variants B & C)",
            "is_family": true,
            "malware_types": [
                "spyware",
                "stealer"
            ],
            "aliases": [
                "WP-002",
                "Remus",
                "ClickFix Variant B",
                "ClickFix Variant C"
            ],
            "description": "WP-002 ClickFix chain delivered from compromised WordPress sites. Variant B (v16, freightbook365.com): BSC-testnet EtherHiding -> 3-domain failover loader (asseload->cfsubs->helauth) -> XOR/base64 clipboard-arming stage; elevated Win+X PowerShell(Admin) lure (RU); independent html2canvas screenshot exfil to helauth.com that fires on every visit; clipboard delivery TDS-gated. Variant C (v17, gogreenlightloans.com): EtherHiding migrated to Polygon; C2 moved off Cloudflare fronting to self-hosted api.php on AS202412 (178.16.52.101, Spamhaus DROP); on-chain command retrieval failed in the captured session (degraded delivery). Final clipboard command not extracted in either version.",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--197213ad-deb5-514c-af1b-45044c5fd786",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.485381Z",
            "modified": "2026-09-25T02:56:28.485381Z",
            "name": "C2 beacon / fingerprint",
            "description": "GET/POST /cdn/widget/hit?s=cdn:X&h=<lure>&o=<os>&k=<clip>; /cdn/widget/a/done polled repeatedly.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1071.001"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--f853a6c0-c528-5885-92bb-3c3b65c6b671",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.484498Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "name": "ClickFix elevated shell (Win+X -> PowerShell Admin)",
            "description": "Fake Cloudflare Turnstile instructs victim Win+X -> I (PowerShell/Terminal as Admin) -> Ctrl+V -> Enter, running a clipboard-poisoned command with Administrator rights from the first instruction. Observed in both v16 (Russian-localized fake Turnstile) and v17.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1204.004"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--def9347e-4e89-530d-b16e-90db04b57351",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.485045Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "name": "Clipboard poisoning (ClickFix)",
            "description": "Arming stage writes a PowerShell command to the clipboard (execCommand / Clipboard API) for the victim to paste into an elevated shell. v16: XOR/base64 stage, key qEXvNnc5bx0U. v17: 658 KB obfuscator.io stage; command sourced on-chain via EtherHiding.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1059.001"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--8e795a7b-a0cf-5629-9e29-df20c14751d9",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.435401Z",
            "modified": "2026-09-29T01:05:42.435401Z",
            "name": "Encoded JSON beacon",
            "description": "GET/POST /api.php with base64-JSON {action:dl,k,os,vid,ref,ray}; ?s=<k>&_v config, ?k=<k>&d=<b64> tasking.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1071.001"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--8aa7ed1b-a02f-5a78-9ff5-9aeac9cf53e8",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.484731Z",
            "modified": "2026-09-25T02:56:28.484731Z",
            "name": "EtherHiding (BSC-testnet contract)",
            "description": "BSC-testnet contract 0x5bc946cd5121431c7a43549aee7f567e15176f9c (selector 0xe2179b8e) returns base64 JS that injects the asseload cdn.js failover loader.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1102"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--3ed57db8-5aff-5570-994e-e8119412e6e0",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.434851Z",
            "modified": "2026-09-29T01:05:42.434851Z",
            "name": "EtherHiding on Polygon",
            "description": "Injector/command hosted in a Polygon smart contract, retrieved via polygon-bor-rpc.publicnode.com (eth_call selector 0xe2179b8e). Retrieval failed in the captured session.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1102"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--322ed22d-d83c-5de5-a18b-206907dcd1aa",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.484894Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "name": "Multi-domain failover staging",
            "description": "cdn.js loads the arming stage a4045c662b80.js from asseload.com -> cfsubs.com -> helauth.com in order; primary (asseload, burned in v15) degraded, forcing failover.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1008",
                    "url": "https://attack.mitre.org/techniques/T1008/"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--3f9fd1bc-9ffe-54ce-b3af-405e1ff19f5c",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.485193Z",
            "modified": "2026-09-25T02:56:28.485193Z",
            "name": "Screen capture exfiltration",
            "description": "helauth.com snap.js (html2canvas) captures the visitor screen; base64 JPEG POSTed to /cdn/widget/shot.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1113"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--abce81b6-a4ec-52e9-8073-20fce1d60855",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.435139Z",
            "modified": "2026-09-29T01:05:42.435139Z",
            "name": "Self-hosted C2 on operator ASN",
            "description": "api.php C2 on entry-verifed-cdn.codes resolving directly to 178.16.52.101 (AS202412 Omegatech, Spamhaus DROP) — no Cloudflare fronting.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1583.004"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "attack-pattern",
            "spec_version": "2.1",
            "id": "attack-pattern--a4177f74-bc93-5f2d-be81-329ac610a134",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.485527Z",
            "modified": "2026-09-25T02:56:28.485527Z",
            "name": "Victim gating (TDS)",
            "description": "Conditional delivery of the clipboard-arming stage by visitor fingerprint; some sessions receive only the inert DOM shell while recon still fires.",
            "external_references": [
                {
                    "source_name": "mitre-attack",
                    "external_id": "T1497.001"
                }
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "infrastructure",
            "spec_version": "2.1",
            "id": "infrastructure--b91cf883-f030-5ef5-9fc7-dd562d9a4d58",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.436441Z",
            "modified": "2026-09-29T01:05:42.436441Z",
            "name": "AS202412 Omegatech (Spamhaus DROP)",
            "description": "Operator ASN, full Spamhaus DROP listing. Now hosting live campaign C2 directly (178.16.52.0/24), not merely staging.",
            "infrastructure_types": [
                "hosting-malware"
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "infrastructure",
            "spec_version": "2.1",
            "id": "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.485982Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "name": "asseload.com primary stager (burned)",
            "description": "104.21.59.52 (Cloudflare). Serves cdn.js failover loader; burned in v15 advisory/OTX, now degraded. Edge IP is Cloudflare anycast (shared) — block by domain, not IP.",
            "infrastructure_types": [
                "command-and-control"
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "infrastructure",
            "spec_version": "2.1",
            "id": "infrastructure--fc85071c-39b9-5904-acb3-85fe74cc7a18",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.485868Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "name": "cfsubs.com failover stager",
            "description": "172.67.190.184 (Cloudflare). Serves arming stage a4045c662b80.js on failover from asseload. Edge IP is Cloudflare anycast (shared) — block by domain, not IP.",
            "infrastructure_types": [
                "command-and-control"
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "infrastructure",
            "spec_version": "2.1",
            "id": "infrastructure--4fca59be-ee4f-5d00-9b8b-b2be93d2c461",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.43633Z",
            "modified": "2026-09-29T01:05:42.43633Z",
            "name": "entry-verifed-cdn.codes api.php C2 (self-hosted)",
            "description": "178.16.52.101 — Omegatech AS202412 (Spamhaus DROP). /api.php base64-JSON beacon + arming-stage delivery. Deliberate typo domain ('verifed').",
            "infrastructure_types": [
                "command-and-control"
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "infrastructure",
            "spec_version": "2.1",
            "id": "infrastructure--5ca8785a-4b79-5e95-ac01-2833685070f5",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.485634Z",
            "modified": "2026-09-25T02:56:28.485634Z",
            "name": "freightbook365.com (compromised lure)",
            "description": "Compromised WordPress (RevSlider 6.7.16 + js_composer 7.8, transcargo theme; 160.153.0.61 GoDaddy). VICTIM — splitcam: do not blocklist.",
            "infrastructure_types": [
                "hosting-malware"
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "infrastructure",
            "spec_version": "2.1",
            "id": "infrastructure--8afbaf36-1588-5d95-af71-f09b34905d5a",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.436198Z",
            "modified": "2026-09-29T01:05:42.436198Z",
            "name": "gogreenlightloans.com (compromised lure #3)",
            "description": "Compromised GoDaddy WordPress (bankio-core theme + Elementor). Cloudflare-fronted 104.21.1.64 / origin 160.153.0.8. VICTIM — splitcam: do not blocklist.",
            "infrastructure_types": [
                "hosting-malware"
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "infrastructure",
            "spec_version": "2.1",
            "id": "infrastructure--01154441-797d-50aa-a4e1-b4e787c0fa17",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.485753Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "name": "helauth.com recon/exfil C2",
            "description": "104.21.29.209 (Cloudflare). snap.js html2canvas screenshotter; /hit beacon; /shot base64-JPEG screenshot exfil; /a/done poll. Edge IP is Cloudflare anycast (shared) — block by domain, not IP.",
            "infrastructure_types": [
                "command-and-control"
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--5ac177b6-128a-5bb1-ab64-389ee25aa4c9",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.444229Z",
            "modified": "2026-09-29T01:05:42.444229Z",
            "name": "AS202412 prefix 178.16.52.0/24",
            "description": "Omegatech block now serving live C2",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[ipv4-addr:value ISSUBSET '178.16.52.0/24']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-29T01:05:42.444229Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--8d1552ea-5e2f-5525-9244-9ab29b405c38",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.448471Z",
            "modified": "2026-09-29T01:05:42.448471Z",
            "name": "Arming stage JS",
            "description": "obfuscator.io arming stage (658KB)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '51d4def852645a4f7a436abe7aa4498d08f57395e2f40e3c17cdb3f95d03f2d2']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-29T01:05:42.448471Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--2a25f3e3-c3bf-5362-a6ef-e5b6ff1b92cd",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.495546Z",
            "modified": "2026-09-25T02:56:28.495546Z",
            "name": "Arming stage a4045c662b80.js",
            "description": "Clipboard-arming XOR/b64 stage (key qEXvNnc5bx0U)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'c5ef6b9f44e97d55d6a0deac0ef22118410c3114e7b5b97f4fc1b5b0c5b4a1e9']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-25T02:56:28.495546Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--be3758b2-7209-5273-bf1c-15c5e9d182bd",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.44297Z",
            "modified": "2026-09-29T01:05:42.44297Z",
            "name": "C2 IP 178.16.52.101 (AS202412)",
            "description": "Omegatech-hosted C2 (Spamhaus DROP)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[ipv4-addr:value = '178.16.52.101']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-29T01:05:42.44297Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--d61e033f-9a5f-5451-bab4-91c2e77bb803",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.436607Z",
            "modified": "2026-09-29T01:05:42.436607Z",
            "name": "C2 entry-verifed-cdn.codes",
            "description": "Self-hosted api.php C2",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[domain-name:value = 'entry-verifed-cdn.codes']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-29T01:05:42.436607Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--4ba6eb97-5d89-5486-b80a-791394dc7173",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.486097Z",
            "modified": "2026-09-25T02:56:28.486097Z",
            "name": "C2 helauth.com",
            "description": "Recon/exfil C2",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[domain-name:value = 'helauth.com']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-25T02:56:28.486097Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--3453ebee-9dae-5dd0-8ec9-44550901d19f",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.445577Z",
            "modified": "2026-09-29T01:05:42.445577Z",
            "name": "Campaign key",
            "description": "api.php campaign/victim key",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[url:value LIKE '%a3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402%']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-29T01:05:42.445577Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--0106d241-9285-559b-b8e8-62bee8eaec4b",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.490386Z",
            "modified": "2026-09-25T02:56:28.490386Z",
            "name": "Failover stager cfsubs.com",
            "description": "Arming-stage failover host",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[domain-name:value = 'cfsubs.com']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-25T02:56:28.490386Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--86dd4e0c-897a-53b1-8aba-f1d76ea60abd",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.493018Z",
            "modified": "2026-09-25T02:56:28.493018Z",
            "name": "Lure freightbook365.com",
            "description": "Compromised lure — victim; do not block Splitcam rule: victim host — notify owner; do NOT blocklist.",
            "indicator_types": [
                "compromised"
            ],
            "pattern": "[domain-name:value = 'freightbook365.com']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-25T02:56:28.493018Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--c1084f59-0447-5285-8535-89ae770f2abd",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.446859Z",
            "modified": "2026-09-29T01:05:42.446859Z",
            "name": "Lure gogreenlightloans.com",
            "description": "Compromised lure #3 — victim; do not block Splitcam rule: victim host — notify owner; do NOT blocklist.",
            "indicator_types": [
                "compromised"
            ],
            "pattern": "[domain-name:value = 'gogreenlightloans.com']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-29T01:05:42.446859Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--147a483c-1178-5c18-945d-0bc4badb8e85",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.447688Z",
            "modified": "2026-09-29T01:05:42.447688Z",
            "name": "Polygon EtherHiding RPC",
            "description": "On-chain command retrieval (abused-legit)",
            "indicator_types": [
                "anomalous-activity"
            ],
            "pattern": "[domain-name:value = 'polygon-bor-rpc.publicnode.com']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-29T01:05:42.447688Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--62d91160-ec25-5e3f-a392-fdb9437fa8f9",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.496681Z",
            "modified": "2026-09-25T02:56:28.496681Z",
            "name": "Screenshot exfil endpoint",
            "description": "base64 JPEG screen capture exfil",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[url:value = 'https://helauth.com/cdn/widget/shot']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-25T02:56:28.496681Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--a13e7921-ce01-5158-b904-15ff5d917a47",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.49107Z",
            "modified": "2026-09-25T02:56:28.49107Z",
            "name": "Stager asseload.com",
            "description": "cdn.js loader host (burned)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[domain-name:value = 'asseload.com']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-25T02:56:28.49107Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--482a6f0a-45c0-57a8-ac77-f8b0beab378a",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.493654Z",
            "modified": "2026-09-25T02:56:28.493654Z",
            "name": "cdn.js failover loader",
            "description": "3-domain failover loader",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'ba70a75c4b0d81e083fff510d0d6cc0c622cca3660cfa576e34ee899be7f72bc']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-25T02:56:28.493654Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--5f9f0940-506d-5fdc-9517-c82ecd48a003",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.496119Z",
            "modified": "2026-09-25T02:56:28.496119Z",
            "name": "snap.js screenshotter",
            "description": "html2canvas screenshot recon",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'e87e550794322e574a1fda0c1549a3c70dae5a93d9113417a429016838eab8cb']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "external_references": [
                {
                    "source_name": "SecureLeaf",
                    "external_id": "SL-ADV-2026-WP-001",
                    "description": "Unified v16+v17 — WP-002 ClickFix Variants B and C",
                    "url": "https://secureleaf.dispensight.com"
                }
            ],
            "valid_from": "2026-09-25T02:56:28.496119Z",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "note",
            "spec_version": "2.1",
            "id": "note--304aca18-340d-52fb-984e-a8b3ce2c53e7",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.436031Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "abstract": "Degraded delivery under pressure (v16 -> v17)",
            "content": "v16: primary stager asseload.com (burned in v15/OTX) degraded, forcing failover; manual sessions got an inert DOM shell while screenshot recon still fired. v17: Polygon eth_call returned a maintenance page and only a non-command numeric string reached the clipboard; C2 fell back to self-hosting on DROP-listed AS202412. Assessed as correlation with sustained blocklist pressure, not proven causation.",
            "authors": [
                "Dispensight / SecureLeaf"
            ],
            "object_refs": [
                "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
                "campaign--361195d6-0849-5dbb-935b-ad07043339d6"
            ],
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--01d60f0c-5499-51a1-9cff-6a5d076cce3d",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.454672Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "related-to",
            "description": "C2 domain resolves into AS202412",
            "source_ref": "infrastructure--4fca59be-ee4f-5d00-9b8b-b2be93d2c461",
            "target_ref": "infrastructure--b91cf883-f030-5ef5-9fc7-dd562d9a4d58",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--02fe195a-f677-5e9d-b4a2-58aba156cbed",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.498155Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--482a6f0a-45c0-57a8-ac77-f8b0beab378a",
            "target_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--0a7f25a5-2e7b-5cdd-abe9-12e0ad9a2287",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.499571Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "related-to",
            "description": "EtherHiding on lure loads asseload cdn.js",
            "source_ref": "infrastructure--5ca8785a-4b79-5e95-ac01-2833685070f5",
            "target_ref": "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--1c7ee531-9555-5a10-818b-ba0de913cc9b",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.450585Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--d61e033f-9a5f-5451-bab4-91c2e77bb803",
            "target_ref": "infrastructure--4fca59be-ee4f-5d00-9b8b-b2be93d2c461",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--1eae7216-da6b-5f3d-8573-b7feff95564f",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.498036Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--86dd4e0c-897a-53b1-8aba-f1d76ea60abd",
            "target_ref": "infrastructure--5ca8785a-4b79-5e95-ac01-2833685070f5",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--27604c2c-fc45-5b8a-9131-00951ed1eb94",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.499452Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--a4177f74-bc93-5f2d-be81-329ac610a134",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--2add4c19-c1d4-5caf-8833-a0fdde032cbc",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.498683Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--f853a6c0-c528-5885-92bb-3c3b65c6b671",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--43c65d85-0614-5513-bd6a-2cf44f9134ad",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.498315Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--2a25f3e3-c3bf-5362-a6ef-e5b6ff1b92cd",
            "target_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--47a2bbea-483b-5309-9171-e55a01cbddfb",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.499327Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--197213ad-deb5-514c-af1b-45044c5fd786",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--4a6952b5-9550-5d67-a338-28672f31a3b2",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.45503Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "delivers",
            "description": "Compromised lure (victim) delivers the chain via injected EtherHiding script",
            "source_ref": "infrastructure--8afbaf36-1588-5d95-af71-f09b34905d5a",
            "target_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6a8a84cc-f96f-5f2a-ac85-2d2a8efb8558",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.499154Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--3f9fd1bc-9ffe-54ce-b3af-405e1ff19f5c",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6bc27d6a-4f35-5040-8120-1b0a50a94687",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.499917Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "delivers",
            "description": "Compromised lure (victim) delivers the chain via injected EtherHiding script",
            "source_ref": "infrastructure--5ca8785a-4b79-5e95-ac01-2833685070f5",
            "target_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6fe67ccc-f741-56f1-bf7d-9b3f071a91d5",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.450976Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--5ac177b6-128a-5bb1-ab64-389ee25aa4c9",
            "target_ref": "infrastructure--b91cf883-f030-5ef5-9fc7-dd562d9a4d58",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--71782451-984d-55fa-97b4-1dafc44ba2ad",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-10-04T18:00:00.000Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "campaign--361195d6-0849-5dbb-935b-ad07043339d6",
            "target_ref": "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--7620889d-4a49-52f7-becb-4c4229b70b32",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.497677Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--a13e7921-ce01-5158-b904-15ff5d917a47",
            "target_ref": "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--77b33e31-477f-529f-bfa9-865137c8dfb2",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-10-04T18:00:00.000Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "campaign--361195d6-0849-5dbb-935b-ad07043339d6",
            "target_ref": "infrastructure--b91cf883-f030-5ef5-9fc7-dd562d9a4d58",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--78b8e147-9a46-524c-8666-9b0e3569dbc8",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.454884Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "controls",
            "description": "api.php beacon + arming delivery",
            "source_ref": "infrastructure--4fca59be-ee4f-5d00-9b8b-b2be93d2c461",
            "target_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8188422e-2f38-5eb1-b6a8-bf99047a5fef",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-10-04T18:00:00.000Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "campaign--361195d6-0849-5dbb-935b-ad07043339d6",
            "target_ref": "infrastructure--fc85071c-39b9-5904-acb3-85fe74cc7a18",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--83d13507-2db9-58c3-a8b4-fd62b5bdac9a",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.451177Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--3453ebee-9dae-5dd0-8ec9-44550901d19f",
            "target_ref": "infrastructure--4fca59be-ee4f-5d00-9b8b-b2be93d2c461",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8cab6a16-a790-560f-8f64-7e44cf4eb5b8",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.497543Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--0106d241-9285-559b-b8e8-62bee8eaec4b",
            "target_ref": "infrastructure--fc85071c-39b9-5904-acb3-85fe74cc7a18",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--926010c2-9534-5fcc-b250-0eca979e0e74",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-10-04T18:00:00.000Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "campaign--361195d6-0849-5dbb-935b-ad07043339d6",
            "target_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a08e8a48-6421-53f3-91a1-705c7f4ff106",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-10-04T18:00:00.000Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "campaign--361195d6-0849-5dbb-935b-ad07043339d6",
            "target_ref": "infrastructure--4fca59be-ee4f-5d00-9b8b-b2be93d2c461",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a37ef585-0d75-5c2e-af83-dbffce539063",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.450784Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--be3758b2-7209-5273-bf1c-15c5e9d182bd",
            "target_ref": "infrastructure--4fca59be-ee4f-5d00-9b8b-b2be93d2c461",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a3a5e4ec-f861-5ba5-a0f4-836887f5a70a",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.451541Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--8d1552ea-5e2f-5525-9244-9ab29b405c38",
            "target_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a551badb-c9cc-549f-b1f6-f5de14686381",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.499689Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "related-to",
            "description": "cdn.js fails over asseload->cfsubs->helauth",
            "source_ref": "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
            "target_ref": "infrastructure--fc85071c-39b9-5904-acb3-85fe74cc7a18",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--b354d4cd-b82b-5c6c-9311-c446a22db477",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.451307Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--c1084f59-0447-5285-8535-89ae770f2abd",
            "target_ref": "infrastructure--8afbaf36-1588-5d95-af71-f09b34905d5a",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--c4ae40fc-912d-586c-ac67-9fd9c56a3e9d",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.498802Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--8aa7ed1b-a02f-5a78-9ff5-9aeac9cf53e8",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--c72cd30e-9903-5952-82ff-b0db9f9d97f9",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.498441Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--5f9f0940-506d-5fdc-9517-c82ecd48a003",
            "target_ref": "infrastructure--01154441-797d-50aa-a4e1-b4e787c0fa17",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d004dbb0-91e2-5870-8684-84c9a832821b",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.499801Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "controls",
            "description": "Recon/screenshot exfil to helauth",
            "source_ref": "infrastructure--01154441-797d-50aa-a4e1-b4e787c0fa17",
            "target_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d2d3e537-5e31-5437-b07d-fa2793d797b8",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.454301Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--def9347e-4e89-530d-b16e-90db04b57351",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d69f8fc2-5af2-52a6-b0a7-deccb5491861",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-10-04T18:00:00.000Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "campaign--361195d6-0849-5dbb-935b-ad07043339d6",
            "target_ref": "infrastructure--01154441-797d-50aa-a4e1-b4e787c0fa17",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d6e3640f-eeaa-5fd1-83c0-2066b1dd57aa",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.498919Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--322ed22d-d83c-5de5-a18b-206907dcd1aa",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d78fc41a-c6f0-5fd7-8b31-80930c1a2928",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.451708Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--3ed57db8-5aff-5570-994e-e8119412e6e0",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--ded5ebb2-0d5b-5d17-b4e1-3d7177e75714",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.454019Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--abce81b6-a4ec-52e9-8073-20fce1d60855",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--e30877c0-4e27-58b0-ae04-615b4875f785",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.498561Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--62d91160-ec25-5e3f-a392-fdb9437fa8f9",
            "target_ref": "infrastructure--01154441-797d-50aa-a4e1-b4e787c0fa17",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--e40c0cc5-feaa-5d7f-99c6-748f291157c8",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-10-04T18:00:00.000Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "related-to",
            "source_ref": "infrastructure--fc85071c-39b9-5904-acb3-85fe74cc7a18",
            "target_ref": "infrastructure--01154441-797d-50aa-a4e1-b4e787c0fa17",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ],
            "description": "cdn.js failover: cfsubs -> helauth (third choice)"
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--e9ec6008-42f4-53c3-95b8-0bd2a35a1ab7",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.451425Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--147a483c-1178-5c18-945d-0bc4badb8e85",
            "target_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f43aa04c-0aad-5e65-bc06-fc2ae6c99953",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-29T01:05:42.454186Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "malware--a0aa8c7e-cd46-5331-9dbe-f9ad312dc823",
            "target_ref": "attack-pattern--8e795a7b-a0cf-5629-9e29-df20c14751d9",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--f9b59a59-4534-5ce5-8948-6295437a0e97",
            "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
            "created": "2026-09-25T02:56:28.497378Z",
            "modified": "2026-10-04T18:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--4ba6eb97-5d89-5486-b80a-791394dc7173",
            "target_ref": "infrastructure--01154441-797d-50aa-a4e1-b4e787c0fa17",
            "object_marking_refs": [
                "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
            ]
        }
    ]
}