{
    "type": "bundle",
    "id": "bundle--5ab9fbf4-6469-4c61-b75b-a1b0b980adc6",
    "objects": [
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--18a3a1f0-eb3d-4bbc-904e-ee52948913a7",
            "created": "2023-03-08T12:51:43.431426Z",
            "modified": "2023-03-08T12:51:43.431505Z",
            "name": "Malwarebytes",
            "identity_class": "organization"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--af94d6df-772b-4a8e-8690-2a9f5ba023f5",
            "value": "67.43.239.146"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--38220d44-2862-4067-b988-4909dbafb4ee",
            "value": "185.62.58.207"
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--945a4a4c-a69c-455a-aaf0-05a3a2bef802",
            "hashes": {
                "SHA-256": "899e66ede95686a06394f707dd09b7c29af68f95d22136f0a023bfd01390ad53"
            }
        },
        {
            "type": "url",
            "spec_version": "2.1",
            "id": "url--10932074-f09e-4d6a-b437-fa3ad6e66bac",
            "value": "https://loneeaglerecords.com/wp-content/uploads/2020/01/images.tgz.001"
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--336ab584-8a3d-4020-b387-100b94bf5b59",
            "value": "loneeaglerecords.com"
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--ed9fafdb-8dbb-4728-a25f-219ee72beb8f",
            "hashes": {
                "SHA-256": "216a83e54cac48a75b7e071d0262d98739c840fd8cd6d0b48a9c166b69acd57d"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--9bad3bd7-b779-429d-bde6-be9d48363c75",
            "hashes": {
                "SHA-256": "d3235a29d254d0b73ff8b5445c962cd3b841f487469d60a02819c0eb347111dd"
            }
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--37235e49-bed6-4390-968f-63fa16ecd93d",
            "hashes": {
                "SHA-256": "846d8647d27a0d729df40b13a644f3bffdc95f6d0e600f2195c85628d59f1dc6"
            }
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--c458de56-ee3d-4ff2-8358-b5b8eb4ff120",
            "value": "50.87.144.227"
        },
        {
            "type": "threat-actor",
            "spec_version": "2.1",
            "id": "threat-actor--af08d5c9-f507-5ed5-9986-7ffea3df195b",
            "created": "2026-06-24T21:04:33.152246Z",
            "modified": "2026-06-24T21:04:33.152246Z",
            "name": "Lazarus"
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--e5b816be-eb14-4487-a820-172ce4784904",
            "created_by_ref": "identity--18a3a1f0-eb3d-4bbc-904e-ee52948913a7",
            "created": "2026-06-24T21:04:33.153575Z",
            "modified": "2026-06-24T21:04:33.153575Z",
            "name": "New Mac variant of Lazarus Dacls RAT distributed via Trojanized 2FA app",
            "published": "2020-05-06T00:00:00Z",
            "object_refs": [
                "identity--18a3a1f0-eb3d-4bbc-904e-ee52948913a7",
                "ipv4-addr--af94d6df-772b-4a8e-8690-2a9f5ba023f5",
                "ipv4-addr--38220d44-2862-4067-b988-4909dbafb4ee",
                "file--945a4a4c-a69c-455a-aaf0-05a3a2bef802",
                "url--10932074-f09e-4d6a-b437-fa3ad6e66bac",
                "domain-name--336ab584-8a3d-4020-b387-100b94bf5b59",
                "file--ed9fafdb-8dbb-4728-a25f-219ee72beb8f",
                "file--9bad3bd7-b779-429d-bde6-be9d48363c75",
                "file--37235e49-bed6-4390-968f-63fa16ecd93d",
                "ipv4-addr--c458de56-ee3d-4ff2-8358-b5b8eb4ff120",
                "threat-actor--af08d5c9-f507-5ed5-9986-7ffea3df195b"
            ],
            "external_references": [
                {
                    "source_name": "source",
                    "url": "https://blog.malwarebytes.com/threat-analysis/2020/05/new-mac-variant-of-lazarus-dacls-rat-distributed-via-trojanized-2fa-app/"
                }
            ]
        }
    ]
}