i'm ingesting IOCs from events in MISP where the events themselves are grouped under the same ID although the types of IOCs are split up into singular events within SecOps. They all failed validiation as the parameters dropped
{
"Event": {
"id": "58446",
"org_id": "1",
"date": "2025-06-12",
"info": "Member Submission: Phishing, VBS, malspam, Credential pharming activity potentially associated with VHD, Vidar, AutoIT, Snake Keylogger, XWorm (Alert ID: 518fcc31)",
"uuid": "8b48b32d-c4bb-48e0-9ebc-8b21f3d0c1d0",
"published": true,
"analysis": "0",
"attribute_count": "62",
"orgc_id": "31",
"timestamp": "1749763867",
"distribution": "0",
"sharing_group_id": "0",
"proposal_email_lock": false,
"locked": true,
"threat_level_id": "4",
"publish_timestamp": "1749772836",
"sighting_timestamp": "0",
"disable_correlation": false,
"extends_uuid": "",
"protected": null,
"Attribute": [
{
"id": "1327102",
"event_id": "58446",
"object_id": "0",
"object_relation": null,
"category": "Network activity",
"type": "url",
"to_ids": true,
"uuid": "2098fe70-1d81-43fc-8bfe-b469fc80533e",
"timestamp": "1749763867",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "https://rvzdm.cn/ketnai",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
],
"Tag": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
}
],
"_AttributeFlattened": [
{
"id": "1327102",
"event_id": "58446",
"object_id": "0",
"object_relation": null,
"category": "Network activity",
"type": "url",
"to_ids": true,
"uuid": "2098fe70-1d81-43fc-8bfe-b469fc80533e",
"timestamp": "1749763867",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "https://rvzdm.cn/ketnai",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
]
}
}
{
"Event": {
"id": "58446",
"org_id": "1",
"date": "2025-06-12",
"info": "Member Submission: Phishing, VBS, malspam, Credential pharming activity potentially associated with VHD, Vidar, AutoIT, Snake Keylogger, XWorm (Alert ID: 518fcc31)",
"uuid": "8b48b32d-c4bb-48e0-9ebc-8b21f3d0c1d0",
"published": true,
"analysis": "0",
"attribute_count": "62",
"orgc_id": "31",
"timestamp": "1749763867",
"distribution": "0",
"sharing_group_id": "0",
"proposal_email_lock": false,
"locked": true,
"threat_level_id": "4",
"publish_timestamp": "1749772836",
"sighting_timestamp": "0",
"disable_correlation": false,
"extends_uuid": "",
"protected": null,
"Attribute": [
{
"id": "1327102",
"event_id": "58446",
"object_id": "0",
"object_relation": null,
"category": "Network activity",
"type": "url",
"to_ids": true,
"uuid": "2098fe70-1d81-43fc-8bfe-b469fc80533e",
"timestamp": "1749763867",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "https://rvzdm.cn/ketnai",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
],
"Tag": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
}
],
"_AttributeFlattened": [
{
"id": "1327102",
"event_id": "58446",
"object_id": "0",
"object_relation": null,
"category": "Network activity",
"type": "url",
"to_ids": true,
"uuid": "2098fe70-1d81-43fc-8bfe-b469fc80533e",
"timestamp": "1749763867",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "https://rvzdm.cn/ketnai",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
]
}
}
{
"Event": {
"id": "58446",
"org_id": "1",
"date": "2025-06-12",
"info": "Member Submission: Phishing, VBS, malspam, Credential pharming activity potentially associated with VHD, Vidar, AutoIT, Snake Keylogger, XWorm (Alert ID: 518fcc31)",
"uuid": "8b48b32d-c4bb-48e0-9ebc-8b21f3d0c1d0",
"published": true,
"analysis": "0",
"attribute_count": "62",
"orgc_id": "31",
"timestamp": "1749763867",
"distribution": "0",
"sharing_group_id": "0",
"proposal_email_lock": false,
"locked": true,
"threat_level_id": "4",
"publish_timestamp": "1749772836",
"sighting_timestamp": "0",
"disable_correlation": false,
"extends_uuid": "",
"protected": null,
"Attribute": [
{
"id": "1327118",
"event_id": "58446",
"object_id": "0",
"object_relation": null,
"category": "Network activity",
"type": "url",
"to_ids": true,
"uuid": "605f7208-2813-4ca6-971b-c849197900dc",
"timestamp": "1749763867",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "https://fxlao.cn/ctaoie",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
],
"Tag": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
}
],
"_AttributeFlattened": [
{
"id": "1327118",
"event_id": "58446",
"object_id": "0",
"object_relation": null,
"category": "Network activity",
"type": "url",
"to_ids": true,
"uuid": "605f7208-2813-4ca6-971b-c849197900dc",
"timestamp": "1749763867",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "https://fxlao.cn/ctaoie",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
]
}
}
{
"Event": {
"id": "58446",
"org_id": "1",
"date": "2025-06-12",
"info": "Member Submission: Phishing, VBS, malspam, Credential pharming activity potentially associated with VHD, Vidar, AutoIT, Snake Keylogger, XWorm (Alert ID: 518fcc31)",
"uuid": "8b48b32d-c4bb-48e0-9ebc-8b21f3d0c1d0",
"published": true,
"analysis": "0",
"attribute_count": "62",
"orgc_id": "31",
"timestamp": "1749763867",
"distribution": "0",
"sharing_group_id": "0",
"proposal_email_lock": false,
"locked": true,
"threat_level_id": "4",
"publish_timestamp": "1749772836",
"sighting_timestamp": "0",
"disable_correlation": false,
"extends_uuid": "",
"protected": null,
"Attribute": [
{
"id": "1327118",
"event_id": "58446",
"object_id": "0",
"object_relation": null,
"category": "Network activity",
"type": "url",
"to_ids": true,
"uuid": "605f7208-2813-4ca6-971b-c849197900dc",
"timestamp": "1749763867",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "https://fxlao.cn/ctaoie",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
],
"Tag": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
}
],
"_AttributeFlattened": [
{
"id": "1327118",
"event_id": "58446",
"object_id": "0",
"object_relation": null,
"category": "Network activity",
"type": "url",
"to_ids": true,
"uuid": "605f7208-2813-4ca6-971b-c849197900dc",
"timestamp": "1749763867",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "https://fxlao.cn/ctaoie",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2218",
"name": "malware:Vidar",
"colour": "#3d5116",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2082",
"name": "audience-industry:Retail Banking",
"colour": "#185dda",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2207",
"name": "malware:VHD",
"colour": "#b1f090",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2088",
"name": "attack-pattern:malspam",
"colour": "#8d99c8",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2256",
"name": "malware:AutoIT",
"colour": "#c4cb5f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2077",
"name": "attack-pattern:Phishing",
"colour": "#2976dc",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2095",
"name": "malware:Lumma Stealer",
"colour": "#897c44",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2160",
"name": "malware:XWorm",
"colour": "#43e90c",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2175",
"name": "malware:HijackLoader",
"colour": "#25c516",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2133",
"name": "malware:Snake Keylogger",
"colour": "#13739f",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2102",
"name": "tactic:Impact",
"colour": "#ea268e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2150",
"name": "attack-pattern:VBS",
"colour": "#6f2df7",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2702",
"name": "malware:DarkCloud",
"colour": "#7b4f6d",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2084",
"name": "attack-pattern:Credential pharming",
"colour": "#25961b",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
]
}
}
{
"Event": {
"id": "58436",
"org_id": "1",
"date": "2025-06-11",
"info": "Member Submission: Unidentified activity (Alert ID: 456dd77f)",
"uuid": "bb44d78e-edb1-4220-99e3-b980c1103876",
"published": true,
"analysis": "0",
"attribute_count": "36",
"orgc_id": "31",
"timestamp": "1749657767",
"distribution": "0",
"sharing_group_id": "0",
"proposal_email_lock": false,
"locked": true,
"threat_level_id": "4",
"publish_timestamp": "1749686436",
"sighting_timestamp": "0",
"disable_correlation": false,
"extends_uuid": "",
"protected": null,
"Attribute": [
{
"id": "1326789",
"event_id": "58436",
"object_id": "0",
"object_relation": null,
"category": "Payload delivery",
"type": "sha256",
"to_ids": true,
"uuid": "4db3818a-245a-4dad-bf87-a065591a203c",
"timestamp": "1749657768",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "267009d555f59e9bf5d82be8a046427f04a16d15c63d9c7ecca749b11d8c8fc3",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2097",
"name": "audience-industry:Payments",
"colour": "#3eb067",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
],
"Tag": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
},
{
"id": "2097",
"name": "audience-industry:Payments",
"colour": "#3eb067",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false
}
],
"_AttributeFlattened": [
{
"id": "1326789",
"event_id": "58436",
"object_id": "0",
"object_relation": null,
"category": "Payload delivery",
"type": "sha256",
"to_ids": true,
"uuid": "4db3818a-245a-4dad-bf87-a065591a203c",
"timestamp": "1749657768",
"distribution": "5",
"sharing_group_id": "0",
"comment": "",
"deleted": false,
"disable_correlation": false,
"first_seen": null,
"last_seen": null,
"value": "267009d555f59e9bf5d82be8a046427f04a16d15c63d9c7ecca749b11d8c8fc3",
"Sighting": [],
"_allTags": [
{
"id": "10",
"name": "tlp:green",
"colour": "#33FF00",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2083",
"name": "audience-region:Americas",
"colour": "#d0832e",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
},
{
"id": "2097",
"name": "audience-industry:Payments",
"colour": "#3eb067",
"exportable": true,
"user_id": "0",
"hide_tag": false,
"numerical_value": null,
"is_galaxy": false,
"is_custom_galaxy": false,
"local_only": false,
"inherited": true
}
]
}
]
}
}