{
    "type": "bundle",
    "id": "bundle--26ff9729-d6b1-4fd8-87ff-0d21de4aea36",
    "objects": [
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--c98ec1c0-597d-435e-8d4b-07c44c4c45a5",
            "created": "2025-11-17T00:23:04.296806Z",
            "modified": "2025-11-17T00:23:04.296848Z",
            "name": "Bloo",
            "identity_class": "organization"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--44dd15ba-6ee0-4932-859d-cce03bb77f20",
            "value": "95.164.17.24"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--0f09ca01-e47b-4e71-b6d3-d6876dad9cf7",
            "value": "147.124.214.129"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--54fa35c4-d57e-43a6-8463-28213d33c572",
            "value": "185.235.241.208"
        },
        {
            "type": "url",
            "spec_version": "2.1",
            "id": "url--9a395145-e629-47cc-9236-b4774fbe4bb8",
            "value": "https://www.travismathison.com/posts/Beavertail-and-InvisibleFerret-malware/"
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--06e74583-d9ee-454c-b55c-ba9ba2463fd0",
            "hashes": {
                "SHA-256": "2012f6f7d8add86ebbc6629815832554fca37cc3e1edab68a51f57e345365f85"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--b911f1ef-86d9-46c8-8228-ba7f2f2bb8c7",
            "hashes": {
                "SHA-256": "6a104f07ab6c5711b6bc8bf6ff956ab8cd597a388002a966e980c5ec9678b5b0"
            }
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--54567077-09c8-41fa-b6b7-bbe5e586faa6",
            "value": "95.164.7.171"
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--4a762b1e-f934-4a8c-adff-7a5284b1edea",
            "hashes": {
                "SHA-256": "10f86be3e564f2e463e45420eb5f9fbdb14f7427eac665cd9cc7901efbc4cc59"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--df8d7fd1-9fae-41e4-9f8f-25042dfbe101",
            "hashes": {
                "SHA-256": "07183a60ebcb02546c53e82d92da3ddcf447d7a1438496c4437ec06b4d9eb287"
            }
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--3e82bd70-853c-49b0-902e-bd844d282dd8",
            "value": "173.211.106.101"
        },
        {
            "type": "threat-actor",
            "spec_version": "2.1",
            "id": "threat-actor--517f1d6a-514b-592b-8216-43a310ad6d08",
            "created": "2026-06-24T18:19:48.273738Z",
            "modified": "2026-06-24T18:19:48.273738Z",
            "name": "ContagiousInterview"
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--e305b0c0-53cf-4ef3-8da3-ce57cc72186c",
            "created_by_ref": "identity--c98ec1c0-597d-435e-8d4b-07c44c4c45a5",
            "created": "2026-06-24T18:19:48.305691Z",
            "modified": "2026-06-24T18:19:48.305691Z",
            "name": "InvisibleFerret Threat Intelligence Report",
            "published": "2025-07-26T00:00:00Z",
            "object_refs": [
                "identity--c98ec1c0-597d-435e-8d4b-07c44c4c45a5",
                "ipv4-addr--44dd15ba-6ee0-4932-859d-cce03bb77f20",
                "ipv4-addr--0f09ca01-e47b-4e71-b6d3-d6876dad9cf7",
                "ipv4-addr--54fa35c4-d57e-43a6-8463-28213d33c572",
                "url--9a395145-e629-47cc-9236-b4774fbe4bb8",
                "file--06e74583-d9ee-454c-b55c-ba9ba2463fd0",
                "file--b911f1ef-86d9-46c8-8228-ba7f2f2bb8c7",
                "ipv4-addr--54567077-09c8-41fa-b6b7-bbe5e586faa6",
                "file--4a762b1e-f934-4a8c-adff-7a5284b1edea",
                "file--df8d7fd1-9fae-41e4-9f8f-25042dfbe101",
                "ipv4-addr--3e82bd70-853c-49b0-902e-bd844d282dd8",
                "threat-actor--517f1d6a-514b-592b-8216-43a310ad6d08"
            ],
            "external_references": [
                {
                    "source_name": "source",
                    "url": "https://bloo.io/research/malware/invisibleferret"
                }
            ]
        }
    ]
}