{
    "type": "bundle",
    "id": "bundle--6e9cf8ee-6137-43bd-a10a-297869d484ca",
    "objects": [
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--40cea600-1476-4e6e-9419-6ed052e3ca9d",
            "created": "2023-03-10T05:55:31.704852Z",
            "modified": "2024-10-24T14:21:18.713883Z",
            "name": "ThreatBook",
            "identity_class": "organization"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--43287c6e-0ad6-423c-8f51-b54c24f16b54",
            "value": "145.232.235.222"
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--0065228e-33cb-4f36-939f-0cc5da5b2fdd",
            "hashes": {
                "MD5": "f5b338d6bca36d47ee04d93d08c57861"
            }
        },
        {
            "type": "url",
            "spec_version": "2.1",
            "id": "url--1e31e98e-541a-446c-9c83-43cc92c482d1",
            "value": "http://www.bwaprzemysl.pl/formularz/form_zgloszenie_uk.php"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--5c950e24-9330-4a19-b55b-af8e6892e9f5",
            "value": "36.99.136.129"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--98c73dd6-0e66-4825-8d49-c0f058753b54",
            "value": "46.14.68.202"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--06ead3e3-737b-4f4a-bb42-393b06be0f27",
            "value": "68.183.78.131"
        },
        {
            "type": "ipv4-addr",
            "spec_version": "2.1",
            "id": "ipv4-addr--525f48b2-442c-4f0e-8347-4331f8e8278e",
            "value": "36.99.136.136"
        },
        {
            "type": "threat-actor",
            "spec_version": "2.1",
            "id": "threat-actor--af08d5c9-f507-5ed5-9986-7ffea3df195b",
            "created": "2026-06-25T18:02:16.579559Z",
            "modified": "2026-06-25T18:02:16.579559Z",
            "name": "Lazarus"
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--6d5474c9-6cb0-45db-8a32-ab5a09c028c1",
            "created_by_ref": "identity--40cea600-1476-4e6e-9419-6ed052e3ca9d",
            "created": "2026-06-25T18:02:16.580728Z",
            "modified": "2026-06-25T18:02:16.580728Z",
            "name": "Thief in the Dark: Lazarus Uses Dtrack RAT Tool to Steal Massive Medical Data",
            "published": "2020-12-18T00:00:00Z",
            "object_refs": [
                "identity--40cea600-1476-4e6e-9419-6ed052e3ca9d",
                "ipv4-addr--43287c6e-0ad6-423c-8f51-b54c24f16b54",
                "file--0065228e-33cb-4f36-939f-0cc5da5b2fdd",
                "url--1e31e98e-541a-446c-9c83-43cc92c482d1",
                "ipv4-addr--5c950e24-9330-4a19-b55b-af8e6892e9f5",
                "ipv4-addr--98c73dd6-0e66-4825-8d49-c0f058753b54",
                "ipv4-addr--06ead3e3-737b-4f4a-bb42-393b06be0f27",
                "ipv4-addr--525f48b2-442c-4f0e-8347-4331f8e8278e",
                "threat-actor--af08d5c9-f507-5ed5-9986-7ffea3df195b"
            ],
            "external_references": [
                {
                    "source_name": "source",
                    "url": "https://threatbook.io/blog/Thief-in-the-Dark:-Lazarus-Uses-Dtrack-RAT-Tool-to-Steal-Massive-Medical-Data"
                }
            ]
        }
    ]
}