{
    "type": "bundle",
    "id": "bundle--ff74297a-2991-4ea8-aef1-7c73519dd188",
    "objects": [
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--5ace95f0-bd6c-4fee-a494-ca40e791918d",
            "created": "2023-03-08T12:51:44.544245Z",
            "modified": "2024-09-09T23:28:33.92829Z",
            "name": "PaloaltoNetworks",
            "identity_class": "organization"
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--28743bca-0532-407b-af01-8564c85a9595",
            "hashes": {
                "SHA-256": "0641fe04713fbdad272a6f8e9b44631b7554dfd1e1332a8afa767d845a90b3fa"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--a8d0b197-7088-44b2-b5ea-3d18e11e183c",
            "hashes": {
                "SHA-256": "f431e0bed6b4b7ffef5e40b1b4b7078f2538f2b2db2869d831de5d7df26ee6cd"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--2eb683b3-bcb5-4223-b3ec-fe55e44714bc",
            "hashes": {
                "SHA-256": "b1da7e1963dc09c325ba3ea2442a54afea02929ec26477a1b120ae44368082f8"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--e0e6fe9d-0c92-46e6-bf6d-3ca7fc915ac0",
            "hashes": {
                "SHA-256": "359835c4a9dbe2d95e483464659744409e877cb6f5d791daa33fd601a01376fc"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--bad25369-08d8-469c-b282-4732b57787b1",
            "hashes": {
                "SHA-256": "b2b764597d097fcb93c5b11cbd864ab1bcb894a2a1e2d2de1c469880f612431c"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--7ff85fd0-19d6-4149-85c3-d8a149c602f7",
            "hashes": {
                "SHA-256": "dfa1ad6083aa06b82edfa672925bb78c16d4e8cb2510cbe18ea1cf598e7f2722"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--3c4f4f5c-31c9-4686-bdbc-c0e03e73e558",
            "hashes": {
                "SHA-256": "43459f5117bee7b49f2cee7ce934471e01fb2aa2856f230943460e14e19183a6"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--2704ca85-85a5-46fe-aaf7-662bba474687",
            "hashes": {
                "SHA-256": "1128d10347dd602ecd3228faa389add11415bf6936e2328101311264547afa75"
            }
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--4652cc27-a467-4e50-9736-80ff13a2660c",
            "value": "kted56erhg.dynssl.com"
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--47097f11-17cb-40b5-a0d2-ee2d35d2e03f",
            "value": "games.my-homeip.com"
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--220c01b1-7c81-474b-9fae-a5c653570b0a",
            "value": "euiro8966.organiccrap.com"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--6930e34e-7f93-42fd-b33f-34e80aa5a0b3",
            "value": "196.44.49.154"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--ba367f8c-4ebc-40aa-afdc-1c09a5bcb479",
            "value": "116.193.155.38"
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--9a7b0767-20cf-4db8-8da1-03c4e74c4b5f",
            "created_by_ref": "identity--5ace95f0-bd6c-4fee-a494-ca40e791918d",
            "created": "2026-06-24T21:10:20.02018Z",
            "modified": "2026-06-24T21:10:20.02018Z",
            "name": "Bisonal Malware Used in Attacks Against Russia and South Korea",
            "published": "2018-07-31T00:00:00Z",
            "object_refs": [
                "identity--5ace95f0-bd6c-4fee-a494-ca40e791918d",
                "file--28743bca-0532-407b-af01-8564c85a9595",
                "file--a8d0b197-7088-44b2-b5ea-3d18e11e183c",
                "file--2eb683b3-bcb5-4223-b3ec-fe55e44714bc",
                "file--e0e6fe9d-0c92-46e6-bf6d-3ca7fc915ac0",
                "file--bad25369-08d8-469c-b282-4732b57787b1",
                "file--7ff85fd0-19d6-4149-85c3-d8a149c602f7",
                "file--3c4f4f5c-31c9-4686-bdbc-c0e03e73e558",
                "file--2704ca85-85a5-46fe-aaf7-662bba474687",
                "domain-name--4652cc27-a467-4e50-9736-80ff13a2660c",
                "domain-name--47097f11-17cb-40b5-a0d2-ee2d35d2e03f",
                "domain-name--220c01b1-7c81-474b-9fae-a5c653570b0a",
                "ipv4-addr--6930e34e-7f93-42fd-b33f-34e80aa5a0b3",
                "ipv4-addr--ba367f8c-4ebc-40aa-afdc-1c09a5bcb479"
            ],
            "external_references": [
                {
                    "source_name": "source",
                    "url": "https://researchcenter.paloaltonetworks.com/2018/07/unit42-bisonal-malware-used-attacks-russia-south-korea/"
                }
            ]
        }
    ]
}