{
    "type": "bundle",
    "id": "bundle--ab895787-7032-4498-b983-23daa8dab3d5",
    "objects": [
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "FireIntel Threat Research",
            "identity_class": "organization"
        },
        {
            "type": "malware",
            "spec_version": "2.1",
            "id": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Warlock",
            "description": "Ransomware first seen in June 2025. Not related to the older 'Warlock Dark Army' ransomware.",
            "malware_types": [
                "ransomware"
            ],
            "is_family": true,
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "intrusion-set",
            "spec_version": "2.1",
            "id": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Storm-2603",
            "description": "Microsoft's name for the actor behind Warlock (assessed China-based with moderate confidence). Symantec tracks it as Longlegs, Sophos as GOLD SALEM, Unit 42 as CL-CRI-1040. Names are research labels for overlapping activity.",
            "aliases": [
                "Longlegs",
                "GOLD SALEM",
                "CL-CRI-1040"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--9cbd3d11-fafc-4d38-8719-0c76cfef476d",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "uses",
            "source_ref": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--5141022f-21ab-4ec3-a26d-fb3b4e3afe76",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Warlock payload (SHA-256)",
            "description": "Classified 'Warlock payload' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--bd822f64-3f01-4d8f-bdb2-398f57f75092",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--5141022f-21ab-4ec3-a26d-fb3b4e3afe76",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--b56cfbad-89a0-4d91-9232-20f0d13f44f1",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Warlock payload (SHA-256)",
            "description": "Classified 'Warlock payload' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--55ec9d2d-fef8-401f-b07f-8390d6695d66",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--b56cfbad-89a0-4d91-9232-20f0d13f44f1",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--0ad6ddf5-2a2c-4159-b92d-1fb810cce17e",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Malicious DLL (SHA-256)",
            "description": "Classified 'Malicious DLL' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--410c4396-3055-406f-87da-a30288db6f35",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--0ad6ddf5-2a2c-4159-b92d-1fb810cce17e",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--ac09b977-7944-44de-9285-b37e17231c30",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Malicious DLL (SHA-256)",
            "description": "Classified 'Malicious DLL' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--38be7573-561d-4fb7-ac78-1f166b63416f",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--ac09b977-7944-44de-9285-b37e17231c30",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--bbf54889-ddbc-447a-a317-95f3577eb77b",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Malicious DLL (SHA-256)",
            "description": "Classified 'Malicious DLL' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--feafde29-dbaa-4f4d-b9fb-0fbd2453e7d8",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--bbf54889-ddbc-447a-a317-95f3577eb77b",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--0e262948-d92f-41fc-aaec-e531bfb6934b",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Suspicious file (SHA-256)",
            "description": "Classified 'Suspicious file' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--8a441550-e9d7-43ef-aa6f-3055351445a2",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--0e262948-d92f-41fc-aaec-e531bfb6934b",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--7e35e185-10ff-464e-9562-8157e4a4645f",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Warlock payload (SHA-256)",
            "description": "Classified 'Warlock payload' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d0ffb2f5-ae5b-480e-a0a7-74d4632cead9",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--7e35e185-10ff-464e-9562-8157e4a4645f",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--41aeee88-2f04-481f-918a-c69633a3c89f",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "AV/EDR killer (SHA-256)",
            "description": "Classified 'AV/EDR killer' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--4de40814-de34-478a-8a71-b32a95a210d7",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--41aeee88-2f04-481f-918a-c69633a3c89f",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--1d1904f3-ed5a-4cf4-b4af-cb4d04b9abcd",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Warlock payload (SHA-256)",
            "description": "Classified 'Warlock payload' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--525cd268-3b95-4f36-b6b9-a11c57f88fbe",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--1d1904f3-ed5a-4cf4-b4af-cb4d04b9abcd",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--940da458-ef8e-48df-ab78-8769b23210ef",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Warlock payload (SHA-256)",
            "description": "Classified 'Warlock payload' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--5123e0c3-b4d0-4422-a9cb-f07843bedb57",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--940da458-ef8e-48df-ab78-8769b23210ef",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--3c5c3c46-6b63-41f3-949f-75f034719106",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Suspicious file (SHA-256)",
            "description": "Classified 'Suspicious file' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = '9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--761b4b2e-b129-4170-a6bc-a349f1030db9",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--3c5c3c46-6b63-41f3-949f-75f034719106",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--b793df86-8df4-41bd-8361-c4ae97594381",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Suspicious file (SHA-256)",
            "description": "Classified 'Suspicious file' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--9a596556-19b0-44c6-a33e-863e5d50fbda",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--b793df86-8df4-41bd-8361-c4ae97594381",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--3c7593c2-fd94-431c-a62d-591afbc881bd",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Vulnerable driver (SHA-256)",
            "description": "Classified 'Vulnerable driver' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--529127a1-a474-4593-a434-a9ac810edb8f",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--3c7593c2-fd94-431c-a62d-591afbc881bd",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--58c26578-9155-4c7b-bb36-6d355b9e4817",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Malicious DLL (SHA-256)",
            "description": "Classified 'Malicious DLL' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--66b08018-81b4-4af2-a7c3-9fe25016b256",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--58c26578-9155-4c7b-bb36-6d355b9e4817",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--0b16ebb4-77dc-4f7e-bff2-59011abd047c",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Malicious DLL (SHA-256)",
            "description": "Classified 'Malicious DLL' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--74279ef0-36d1-4db1-90a6-2476d9b83763",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--0b16ebb4-77dc-4f7e-bff2-59011abd047c",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--cccb5070-bcbe-47f5-9c03-5d5731210777",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Suspicious file (SHA-256)",
            "description": "Classified 'Suspicious file' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--7aec9a2a-2517-42e7-a373-d5e2925c34d1",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--cccb5070-bcbe-47f5-9c03-5d5731210777",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--3603e673-c0ab-4a67-a0d8-7ed0a0c1e7f5",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Suspicious file (SHA-256)",
            "description": "Classified 'Suspicious file' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--3dca6232-e9e3-4edf-9cc0-8bb2d21aec1d",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--3603e673-c0ab-4a67-a0d8-7ed0a0c1e7f5",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--4c0371d5-fdb2-49e6-b8b6-717e5aa70218",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Suspicious file (SHA-256)",
            "description": "Classified 'Suspicious file' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--59fa12cb-b3f0-4ad1-91b6-8d5486860aae",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--4c0371d5-fdb2-49e6-b8b6-717e5aa70218",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--544e72a6-5cad-449f-90d2-c9305eb43639",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Malicious DLL (SHA-256)",
            "description": "Classified 'Malicious DLL' in the Symantec & Carbon Black IOC appendix. Report-wide set; not tied to a specific host in the July 2026 case.",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[file:hashes.'SHA-256' = 'fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--2a45b47b-a7e7-4fdd-84c2-e8129c149e75",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--544e72a6-5cad-449f-90d2-c9305eb43639",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--cfae70bc-a78a-424f-be22-904dfcbb6e85",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Payload host (report appendix): litter.catbox.moe",
            "description": "Shared file-hosting service; match together with msiexec or process context",
            "indicator_types": [
                "anomalous-activity"
            ],
            "pattern": "[domain-name:value = 'litter.catbox.moe']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--5e84850b-ce29-432d-bf7c-53fb573c81e1",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--cfae70bc-a78a-424f-be22-904dfcbb6e85",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--ecab270a-57dd-444a-b52b-69cb3253fc63",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Payload host (report appendix): xn8xyt-drop.s3.wasabisys.com",
            "description": "Bucket host on a shared storage service",
            "indicator_types": [
                "anomalous-activity"
            ],
            "pattern": "[domain-name:value = 'xn8xyt-drop.s3.wasabisys.com']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--1f656d6c-eb08-4ef1-a2e6-2979932b2da5",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--ecab270a-57dd-444a-b52b-69cb3253fc63",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--1d66d485-67f5-48b6-93f0-2d3a547645df",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "MSI fetched on 28 Jul 2026: https://litter.catbox.moe/6f5tdt.msi",
            "description": "msiexec /q /i on SharePoint server 2",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[url:value = 'https://litter.catbox.moe/6f5tdt.msi']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--6718ae7c-6edd-44f8-80c3-790d6b12b2eb",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--1d66d485-67f5-48b6-93f0-2d3a547645df",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--fc2ffbd6-5a8d-4922-9534-7ea126a962b8",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "MSI fetched on 28 Jul 2026: https://s3.wasabisys.com/fortifs/vamd64.msi",
            "description": "msiexec /q /i on SharePoint server 2",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[url:value = 'https://s3.wasabisys.com/fortifs/vamd64.msi']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--df17f17e-80ec-4921-b3ca-74cf628220ab",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--fc2ffbd6-5a8d-4922-9534-7ea126a962b8",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--03ec87e7-c68a-44b7-ab57-36f2150a6542",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "MSI fetched on 28 Jul 2026: https://xn8xyt-drop.s3.wasabisys.com/xn8xyt.msi",
            "description": "msiexec /q /i on SharePoint server 2",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[url:value = 'https://xn8xyt-drop.s3.wasabisys.com/xn8xyt.msi']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-10-01T00:00:00Z",
            "external_references": [
                {
                    "source_name": "Symantec & Carbon Black",
                    "url": "https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--1083c948-509b-4f96-889b-cd631565546f",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--03ec87e7-c68a-44b7-ab57-36f2150a6542",
            "target_ref": "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--c40639f8-815c-497c-ac57-24535d1be901",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "SmarterMail intrusion infrastructure: auth.qgtxtebl.workers.dev",
            "description": "Storm-2603 SmarterMail activity; may have rotated since February 2026",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[domain-name:value = 'auth.qgtxtebl.workers.dev']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-02-09T00:00:00Z",
            "external_references": [
                {
                    "source_name": "ReliaQuest",
                    "url": "https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware/"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d8c6f36d-bde2-4fe7-b1f9-f6b04380a524",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--c40639f8-815c-497c-ac57-24535d1be901",
            "target_ref": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--6da606ac-8c3a-4974-ad82-3fadb114d511",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "SmarterMail intrusion infrastructure: vdfccjpnedujhrzscjtq.supabase.co",
            "description": "Supabase project used to host v4.msi; may have rotated since February 2026",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[domain-name:value = 'vdfccjpnedujhrzscjtq.supabase.co']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-02-09T00:00:00Z",
            "external_references": [
                {
                    "source_name": "ReliaQuest",
                    "url": "https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware/"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--170779fd-6865-4413-91b5-27d37bcf887a",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--6da606ac-8c3a-4974-ad82-3fadb114d511",
            "target_ref": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--8eda4f5d-2290-4860-b28f-4ea8ae0a5235",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "SmarterMail intrusion infrastructure: 2-api.mooo.com",
            "description": "Storm-2603 SmarterMail activity; may have rotated since February 2026",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[domain-name:value = '2-api.mooo.com']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-02-09T00:00:00Z",
            "external_references": [
                {
                    "source_name": "ReliaQuest",
                    "url": "https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware/"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--1dd9996a-d9f9-48e0-b315-754949680ebb",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--8eda4f5d-2290-4860-b28f-4ea8ae0a5235",
            "target_ref": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--b92d01fb-a8a3-4403-9987-63075cab4d17",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "SmarterMail intrusion infrastructure: 162.252.198.197",
            "description": "Storm-2603 SmarterMail activity; may have rotated since February 2026",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[ipv4-addr:value = '162.252.198.197']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-02-09T00:00:00Z",
            "external_references": [
                {
                    "source_name": "ReliaQuest",
                    "url": "https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware/"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--d5c6ee09-7f3c-4a13-9927-baddbf43a96e",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--b92d01fb-a8a3-4403-9987-63075cab4d17",
            "target_ref": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--a7788e1b-6aa3-4920-b603-825884456fb9",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "SmarterMail intrusion infrastructure: 199.217.99.93",
            "description": "Storm-2603 SmarterMail activity; may have rotated since February 2026",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[ipv4-addr:value = '199.217.99.93']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-02-09T00:00:00Z",
            "external_references": [
                {
                    "source_name": "ReliaQuest",
                    "url": "https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware/"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--a6e05e0e-a297-402c-80d5-0370188585d2",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--a7788e1b-6aa3-4920-b603-825884456fb9",
            "target_ref": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--f303f6d6-7cdb-4377-93bc-d625fc84ad5c",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "SmarterMail intrusion infrastructure: 157.245.156.118",
            "description": "Storm-2603 SmarterMail activity; may have rotated since February 2026",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[ipv4-addr:value = '157.245.156.118']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-02-09T00:00:00Z",
            "external_references": [
                {
                    "source_name": "ReliaQuest",
                    "url": "https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware/"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--2baf3560-e81c-4a5b-8d45-a0c1775b1d9f",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--f303f6d6-7cdb-4377-93bc-d625fc84ad5c",
            "target_ref": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--f3e30804-4859-49f4-b03f-823607c978c1",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "SmarterMail intrusion infrastructure: 45.127.35.186",
            "description": "Storm-2603 SmarterMail activity; may have rotated since February 2026",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[ipv4-addr:value = '45.127.35.186']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-02-09T00:00:00Z",
            "external_references": [
                {
                    "source_name": "ReliaQuest",
                    "url": "https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware/"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--27b1ede7-0fb8-4ab0-8aea-b602841b535d",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--f3e30804-4859-49f4-b03f-823607c978c1",
            "target_ref": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--01602b3a-f6b6-45db-9add-9adc9a1e73d8",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "SmarterMail intrusion infrastructure: 178.128.103.218",
            "description": "Storm-2603 SmarterMail activity; may have rotated since February 2026",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "[ipv4-addr:value = '178.128.103.218']",
            "pattern_type": "stix",
            "pattern_version": "2.1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "valid_from": "2026-02-09T00:00:00Z",
            "external_references": [
                {
                    "source_name": "ReliaQuest",
                    "url": "https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware/"
                }
            ]
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--bb18918f-76ac-42b6-9351-ad35c1f58599",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "relationship_type": "indicates",
            "source_ref": "indicator--01602b3a-f6b6-45db-9add-9adc9a1e73d8",
            "target_ref": "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--139e94a6-8662-4e71-980a-62132cf92939",
            "created_by_ref": "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
            "created": "2026-10-03T00:00:00.000Z",
            "modified": "2026-10-03T00:00:00.000Z",
            "name": "Warlock's nine-day SharePoint intrusion, and the dark-web trail behind it",
            "description": "Indicators collected for FireIntel's Warlock investigation. Values are transcribed from the cited public reports.",
            "report_types": [
                "threat-actor",
                "malware",
                "indicator"
            ],
            "published": "2026-10-03T00:00:00Z",
            "object_refs": [
                "identity--180cf3ba-ce3d-49f7-8745-b65e59aee1a2",
                "malware--8cea1851-5f50-4fcc-bd06-419bc3dbcc51",
                "intrusion-set--b815d2f9-24e7-4d10-8ddd-4e7ca73f61d1",
                "relationship--9cbd3d11-fafc-4d38-8719-0c76cfef476d",
                "indicator--5141022f-21ab-4ec3-a26d-fb3b4e3afe76",
                "relationship--bd822f64-3f01-4d8f-bdb2-398f57f75092",
                "indicator--b56cfbad-89a0-4d91-9232-20f0d13f44f1",
                "relationship--55ec9d2d-fef8-401f-b07f-8390d6695d66",
                "indicator--0ad6ddf5-2a2c-4159-b92d-1fb810cce17e",
                "relationship--410c4396-3055-406f-87da-a30288db6f35",
                "indicator--ac09b977-7944-44de-9285-b37e17231c30",
                "relationship--38be7573-561d-4fb7-ac78-1f166b63416f",
                "indicator--bbf54889-ddbc-447a-a317-95f3577eb77b",
                "relationship--feafde29-dbaa-4f4d-b9fb-0fbd2453e7d8",
                "indicator--0e262948-d92f-41fc-aaec-e531bfb6934b",
                "relationship--8a441550-e9d7-43ef-aa6f-3055351445a2",
                "indicator--7e35e185-10ff-464e-9562-8157e4a4645f",
                "relationship--d0ffb2f5-ae5b-480e-a0a7-74d4632cead9",
                "indicator--41aeee88-2f04-481f-918a-c69633a3c89f",
                "relationship--4de40814-de34-478a-8a71-b32a95a210d7",
                "indicator--1d1904f3-ed5a-4cf4-b4af-cb4d04b9abcd",
                "relationship--525cd268-3b95-4f36-b6b9-a11c57f88fbe",
                "indicator--940da458-ef8e-48df-ab78-8769b23210ef",
                "relationship--5123e0c3-b4d0-4422-a9cb-f07843bedb57",
                "indicator--3c5c3c46-6b63-41f3-949f-75f034719106",
                "relationship--761b4b2e-b129-4170-a6bc-a349f1030db9",
                "indicator--b793df86-8df4-41bd-8361-c4ae97594381",
                "relationship--9a596556-19b0-44c6-a33e-863e5d50fbda",
                "indicator--3c7593c2-fd94-431c-a62d-591afbc881bd",
                "relationship--529127a1-a474-4593-a434-a9ac810edb8f",
                "indicator--58c26578-9155-4c7b-bb36-6d355b9e4817",
                "relationship--66b08018-81b4-4af2-a7c3-9fe25016b256",
                "indicator--0b16ebb4-77dc-4f7e-bff2-59011abd047c",
                "relationship--74279ef0-36d1-4db1-90a6-2476d9b83763",
                "indicator--cccb5070-bcbe-47f5-9c03-5d5731210777",
                "relationship--7aec9a2a-2517-42e7-a373-d5e2925c34d1",
                "indicator--3603e673-c0ab-4a67-a0d8-7ed0a0c1e7f5",
                "relationship--3dca6232-e9e3-4edf-9cc0-8bb2d21aec1d",
                "indicator--4c0371d5-fdb2-49e6-b8b6-717e5aa70218",
                "relationship--59fa12cb-b3f0-4ad1-91b6-8d5486860aae",
                "indicator--544e72a6-5cad-449f-90d2-c9305eb43639",
                "relationship--2a45b47b-a7e7-4fdd-84c2-e8129c149e75",
                "indicator--cfae70bc-a78a-424f-be22-904dfcbb6e85",
                "relationship--5e84850b-ce29-432d-bf7c-53fb573c81e1",
                "indicator--ecab270a-57dd-444a-b52b-69cb3253fc63",
                "relationship--1f656d6c-eb08-4ef1-a2e6-2979932b2da5",
                "indicator--1d66d485-67f5-48b6-93f0-2d3a547645df",
                "relationship--6718ae7c-6edd-44f8-80c3-790d6b12b2eb",
                "indicator--fc2ffbd6-5a8d-4922-9534-7ea126a962b8",
                "relationship--df17f17e-80ec-4921-b3ca-74cf628220ab",
                "indicator--03ec87e7-c68a-44b7-ab57-36f2150a6542",
                "relationship--1083c948-509b-4f96-889b-cd631565546f",
                "indicator--c40639f8-815c-497c-ac57-24535d1be901",
                "relationship--d8c6f36d-bde2-4fe7-b1f9-f6b04380a524",
                "indicator--6da606ac-8c3a-4974-ad82-3fadb114d511",
                "relationship--170779fd-6865-4413-91b5-27d37bcf887a",
                "indicator--8eda4f5d-2290-4860-b28f-4ea8ae0a5235",
                "relationship--1dd9996a-d9f9-48e0-b315-754949680ebb",
                "indicator--b92d01fb-a8a3-4403-9987-63075cab4d17",
                "relationship--d5c6ee09-7f3c-4a13-9927-baddbf43a96e",
                "indicator--a7788e1b-6aa3-4920-b603-825884456fb9",
                "relationship--a6e05e0e-a297-402c-80d5-0370188585d2",
                "indicator--f303f6d6-7cdb-4377-93bc-d625fc84ad5c",
                "relationship--2baf3560-e81c-4a5b-8d45-a0c1775b1d9f",
                "indicator--f3e30804-4859-49f4-b03f-823607c978c1",
                "relationship--27b1ede7-0fb8-4ab0-8aea-b602841b535d",
                "indicator--01602b3a-f6b6-45db-9add-9adc9a1e73d8",
                "relationship--bb18918f-76ac-42b6-9351-ad35c1f58599"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "external_references": [
                {
                    "source_name": "FireIntel",
                    "url": "https://fireintel.net/blog/warlock-ransomware-sharepoint-water-telecom"
                }
            ]
        }
    ]
}