{
  "intelligence": {
    "actors": [],
    "counts": {
      "actors": 0,
      "associated_entity_contexts": 1,
      "deduplicated_iocs": 17,
      "direct_entities": 40,
      "direct_relationships": 39,
      "invalid_iocs": 0,
      "iocs": 17,
      "mentioned": 5,
      "mitre_associated": 1,
      "mitre_direct": 0,
      "targets": 1,
      "techniques": 0,
      "unsupported_indicators": 0,
      "vulnerabilities": 4
    },
    "coverage": {
      "associated_repertoire_is_incident_evidence": false,
      "attribution_policy": "explicit-public-relationships-only",
      "descriptions_publicly_exported": false,
      "excluded_context_objects": 120,
      "excluded_graph_objects": 437,
      "graph_complete": true,
      "graph_objects": 40,
      "graph_relationships": 39,
      "mitre_context_complete": true,
      "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
      "status_as_of": "2026-10-08T07:51:44+00:00",
      "table_preview_limit": 20
    },
    "direct_entities": [
      {
        "__typename": "Vulnerability",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": 80,
        "created_by": null,
        "dates": {
          "created": "2026-09-27T00:00:00.000Z",
          "created_at": "2026-09-27T20:47:18.041Z",
          "modified": "2026-10-01T08:19:13.936Z",
          "updated_at": "2026-10-01T08:19:13.936Z"
        },
        "description_available": true,
        "entity_type": "Vulnerability",
        "id": "12e11cbb-485a-471d-af92-62c8fa2cc965",
        "is_inferred": false,
        "labels": [],
        "lang": "en",
        "name": "CVE-2026-88772",
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [
          {
            "external_id": "CVE-2026-88772",
            "id": "146b3a40-d58b-4358-9581-bbed781c8d86",
            "source_name": "NIST NVD",
            "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88772"
          }
        ],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "vulnerability--ca814d72-f3cd-539c-a303-ea46caf3b605",
        "type": "Vulnerability"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "IPv4-Addr",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.841Z",
          "created_at": "2026-10-01T08:19:23.530Z",
          "modified": "2026-10-01T08:19:24.005Z",
          "updated_at": "2026-10-01T08:19:24.005Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "24d65cb5-3cd9-462f-9ddf-6770c5f33087",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--f574ccba-1bf0-5d21-8fc5-5ae616fd6457",
        "type": "Indicator"
      },
      {
        "__typename": "Malware",
        "aliases": [
          "win.adaptix_c2"
        ],
        "attributes": {
          "is_family": true,
          "malware_types": [
            "bot"
          ]
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": {
          "authorized_members": [],
          "id": "1b7caa41-88e1-4a38-8cfc-62b85639333a",
          "is_inferred": false,
          "name": "Malpedia",
          "objectMarking": [
            {
              "definition": "TLP:CLEAR",
              "definition_type": "TLP"
            }
          ],
          "objectOrganization": [],
          "restrict_access": false,
          "type": "Organization"
        },
        "dates": {
          "created": "2026-01-18T17:45:17.797Z",
          "created_at": "2026-01-18T17:51:08.477Z",
          "first_seen": "1970-01-01T00:00:00.000Z",
          "last_seen": "5138-11-16T09:46:40.000Z",
          "modified": "2026-10-07T03:14:44.119Z",
          "updated_at": "2026-10-07T03:14:44.119Z"
        },
        "description_available": true,
        "entity_type": "Malware",
        "id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "antbox1-as-ap",
          "as138995",
          "botnet_cc",
          "c2",
          "censys"
        ],
        "lang": "en",
        "name": "AdaptixC2",
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [
          {
            "external_id": null,
            "id": "fc46e012-af40-4581-b3a1-547afa037902",
            "source_name": "malpedia",
            "url": "https://github.com/Adaptix-Framework/AdaptixC2"
          },
          {
            "external_id": null,
            "id": "0bc23b90-6993-4398-8a8a-5541116396cc",
            "source_name": "malpedia",
            "url": "https://hunt.io/blog/adaptixc2-uncovered-capabilities-tactics-hunting"
          },
          {
            "external_id": null,
            "id": "e460f299-f15b-4795-be09-3c736f06f401",
            "source_name": "malpedia",
            "url": "https://malpedia.caad.fkie.fraunhofer.de/details/win.adaptix_c2"
          },
          {
            "external_id": null,
            "id": "8e8d5c64-a4d2-4a0a-b61c-6d2fe807bdc7",
            "source_name": "malpedia",
            "url": "https://thedfirreport.com/2025/08/05/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira/"
          },
          {
            "external_id": null,
            "id": "5d937dab-de1d-4599-a5f2-e46916dbf309",
            "source_name": "malpedia",
            "url": "https://thedfirreport.com/2025/11/04/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-2/"
          },
          {
            "external_id": null,
            "id": "1b9f583c-09bd-4935-9d76-c2fdaffc781c",
            "source_name": "malpedia",
            "url": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/"
          },
          {
            "external_id": null,
            "id": "16d81d1d-b73b-4d18-acd4-2707bbd31267",
            "source_name": "malpedia",
            "url": "https://unit42.paloaltonetworks.com/adaptixc2-post-exploitation-framework/"
          },
          {
            "external_id": null,
            "id": "54772bee-5d14-4f87-8776-0da6ddbdfad0",
            "source_name": "malpedia",
            "url": "https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/"
          },
          {
            "external_id": null,
            "id": "6b335606-ecc2-4251-a003-7ccb021a4993",
            "source_name": "malpedia",
            "url": "https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/"
          }
        ],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "malware--1debe213-0af7-5b63-b7dd-04459e7fceee",
        "type": "Malware"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:23.266Z",
          "updated_at": "2026-10-01T08:19:23.562Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "3937e8aa-f135-47df-a65a-16218446f65a",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--9a339535-d147-593a-bb59-d8c93f8bd5e2",
        "type": "StixFile"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:19.590Z",
          "updated_at": "2026-10-01T08:19:19.988Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "3e5a37d9-ac13-4243-ae3c-180b3a615968",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--70ebfc35-5738-554a-8641-8bebd7626998",
        "type": "StixFile"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.879Z",
          "created_at": "2026-10-01T08:19:30.118Z",
          "modified": "2026-10-01T08:19:30.413Z",
          "updated_at": "2026-10-01T08:19:30.413Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "43850d13-020d-4a5d-87e8-342810a1aee8",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--b963f2d4-25c7-5b05-9fd6-ce3c1edb03b7",
        "type": "Indicator"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.855Z",
          "created_at": "2026-10-01T08:19:26.291Z",
          "modified": "2026-10-01T08:19:26.540Z",
          "updated_at": "2026-10-01T08:19:26.540Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "4586c4d5-7a74-497a-8ecd-cf0eb9e947ec",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--6f4be80a-d48f-58cf-8d50-1a835f210c6a",
        "type": "Indicator"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:20.240Z",
          "updated_at": "2026-10-01T08:19:20.542Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "5c2c4e9b-fec8-45f1-ab56-884d4fcdf75a",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--341d8ebc-0641-5530-80f1-cc63648d24b8",
        "type": "StixFile"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.859Z",
          "created_at": "2026-10-01T08:19:27.237Z",
          "modified": "2026-10-01T08:19:27.531Z",
          "updated_at": "2026-10-01T08:19:27.531Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "608e09f6-1fe3-404a-aab6-25206dab28cb",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--645cd3aa-d47c-5eae-a9d2-0bcd41463791",
        "type": "Indicator"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:16.183Z",
          "updated_at": "2026-10-01T08:19:17.416Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "61aeaefa-dab2-4d2e-8118-214d014b9dee",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--d29cc4e0-79ce-5a53-b442-bde9e1c8493b",
        "type": "StixFile"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.884Z",
          "created_at": "2026-10-01T08:19:32.144Z",
          "modified": "2026-10-01T08:19:32.367Z",
          "updated_at": "2026-10-01T08:19:32.367Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "61d7524c-81e5-4523-9366-c0ab84ef5213",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--efd5d0a0-c9c7-5c85-a3cb-00cf819c7732",
        "type": "Indicator"
      },
      {
        "__typename": "Vulnerability",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": 80,
        "created_by": null,
        "dates": {
          "created": "2026-08-28T16:18:31.240Z",
          "created_at": "2026-08-28T19:22:58.986Z",
          "modified": "2026-09-26T03:02:05.912Z",
          "updated_at": "2026-09-26T03:02:05.912Z"
        },
        "description_available": true,
        "entity_type": "Vulnerability",
        "id": "7107a9d8-6431-443d-b376-eb66f179f92d",
        "is_inferred": false,
        "labels": [],
        "lang": "en",
        "name": "CVE-2026-82078",
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [
          {
            "external_id": null,
            "id": "ccb6f628-e4cc-424d-a751-493f5c57c6e6",
            "source_name": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "url": "https://github.com/rapid7/metasploit-framework/pull/21842"
          },
          {
            "external_id": "CVE-2026-82078",
            "id": "046bd85c-a72f-4120-9b3c-dd3e09beddef",
            "source_name": "NIST NVD",
            "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82078"
          },
          {
            "external_id": null,
            "id": "077dc703-4138-46fb-a276-83591daaa05e",
            "source_name": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
            "url": "https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"
          }
        ],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "vulnerability--d263de05-fcec-5c0c-91e3-f750608f7cce",
        "type": "Vulnerability"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.882Z",
          "created_at": "2026-10-01T08:19:30.446Z",
          "modified": "2026-10-01T08:19:31.834Z",
          "updated_at": "2026-10-01T08:19:31.834Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "7c8ac814-b7ce-4f19-b511-ae597aca5f5b",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--2078f977-0c50-5af7-b1a8-3e2aa14a6f67",
        "type": "Indicator"
      },
      {
        "__typename": "IPv4Addr",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:14.250Z",
          "updated_at": "2026-10-01T08:19:15.160Z"
        },
        "description_available": false,
        "entity_type": "IPv4-Addr",
        "id": "8a7361f5-a744-4258-9a8d-05105d0b7bcc",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "ipv4-addr--f881524f-e37e-58ce-beaf-3cc6178607ff",
        "type": "IPv4Addr"
      },
      {
        "__typename": "Sector",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": 100,
        "created_by": {
          "authorized_members": [],
          "id": "efbfcf33-f10e-4a90-9ed4-e4de602fb038",
          "is_inferred": false,
          "name": "Filigran",
          "objectMarking": [
            {
              "definition": "TLP:CLEAR",
              "definition_type": "TLP"
            }
          ],
          "objectOrganization": [],
          "restrict_access": false,
          "type": "Organization"
        },
        "dates": {
          "created": "2023-11-19T00:56:33.388Z",
          "created_at": "2026-01-18T14:35:02.955Z",
          "modified": "2026-01-20T20:57:28.767Z",
          "updated_at": "2026-01-20T20:57:28.767Z"
        },
        "description_available": true,
        "entity_type": "Sector",
        "id": "8aadeb6e-a39e-4ee2-8ce1-4725c806eeed",
        "is_inferred": false,
        "labels": [],
        "lang": "en",
        "name": "Education",
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "identity--2b0657c7-cf11-5d30-8867-4c6d9dd99270",
        "type": "Sector"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:21.218Z",
          "updated_at": "2026-10-01T08:19:21.554Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "9977c3ca-d804-4c01-b602-6fdff2937807",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--bd2951aa-38de-55b7-8f93-6efc17ade625",
        "type": "StixFile"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:15.313Z",
          "updated_at": "2026-10-01T08:19:15.662Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "9b04b50d-0a99-4486-a9e9-b02e907abceb",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--98f7d759-212b-5fa7-8749-19a231b24fbe",
        "type": "StixFile"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.844Z",
          "created_at": "2026-10-01T08:19:23.557Z",
          "modified": "2026-10-01T08:19:24.048Z",
          "updated_at": "2026-10-01T08:19:24.048Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "a5f979b2-bee6-4e68-b899-884a5bff7d5d",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--16f0d0ce-d2ec-58e2-956a-44189abc0ad4",
        "type": "Indicator"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.865Z",
          "created_at": "2026-10-01T08:19:27.466Z",
          "modified": "2026-10-01T08:19:27.749Z",
          "updated_at": "2026-10-01T08:19:27.749Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "ac128860-2d4a-484f-bce9-69d21bf750b7",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--6b8b2314-8a3b-5f1b-b67f-1e8aae34b2cd",
        "type": "Indicator"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.868Z",
          "created_at": "2026-10-01T08:19:28.464Z",
          "modified": "2026-10-01T08:19:28.877Z",
          "updated_at": "2026-10-01T08:19:28.877Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "ac45231f-61bf-4f33-8eff-9f79c0c38016",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--adc0cdba-e0b3-5ecc-a27b-f6bf41a7bb57",
        "type": "Indicator"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:19.167Z",
          "updated_at": "2026-10-01T08:19:19.391Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "b2733d58-268b-47b5-b16b-be04d3f7b687",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--c551b890-8dcd-5478-9a76-4e1f7ca45176",
        "type": "StixFile"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:18.872Z",
          "updated_at": "2026-10-01T08:19:19.060Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "b70c15e9-857d-4eae-a619-e30f372aac4a",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--ec4cf22e-f9f4-5363-9a54-b5dd69f2eb77",
        "type": "StixFile"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.874Z",
          "created_at": "2026-10-01T08:19:28.791Z",
          "modified": "2026-10-01T08:19:29.185Z",
          "updated_at": "2026-10-01T08:19:29.185Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "bca38751-5560-4e00-a96e-a1fa3ad7b8de",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--88aa48aa-90ff-54cf-be76-2534402f12b6",
        "type": "Indicator"
      },
      {
        "__typename": "Vulnerability",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": 80,
        "created_by": null,
        "dates": {
          "created": "2026-09-27T00:00:00.000Z",
          "created_at": "2026-09-27T20:47:14.970Z",
          "modified": "2026-10-01T08:06:31.181Z",
          "updated_at": "2026-10-01T08:06:31.181Z"
        },
        "description_available": true,
        "entity_type": "Vulnerability",
        "id": "c0f8d113-129e-4f2c-a0c5-80d76dfc4179",
        "is_inferred": false,
        "labels": [],
        "lang": "en",
        "name": "CVE-2026-88771",
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [
          {
            "external_id": "CVE-2026-88771",
            "id": "06c9dd90-7190-465a-b4e4-1dfde14bd056",
            "source_name": "NIST NVD",
            "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88771"
          }
        ],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "vulnerability--ffd248e0-8f5c-5fa9-8a08-bf788da49f49",
        "type": "Vulnerability"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:19.178Z",
          "updated_at": "2026-10-01T08:19:19.480Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "c1055a72-7220-436b-96c1-af4d2097cf30",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--ab878833-03f6-5709-9d07-ed43ff2c59b5",
        "type": "StixFile"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:21.409Z",
          "updated_at": "2026-10-01T08:19:22.609Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "c3db86a0-26a6-4ab3-9ecb-167012764160",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--872ca414-2dd1-51df-af28-c8e3433c9c0a",
        "type": "StixFile"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.850Z",
          "created_at": "2026-10-01T08:19:25.943Z",
          "modified": "2026-10-01T08:19:26.427Z",
          "updated_at": "2026-10-01T08:19:26.427Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "c58961ad-1747-440f-bc99-59400680c687",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--66d43155-5125-5fea-a656-eb5ca2d34416",
        "type": "Indicator"
      },
      {
        "__typename": "Vulnerability",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": 80,
        "created_by": null,
        "dates": {
          "created": "2026-08-28T16:18:29.600Z",
          "created_at": "2026-08-28T19:22:55.220Z",
          "modified": "2026-09-26T03:02:05.910Z",
          "updated_at": "2026-09-26T03:02:05.910Z"
        },
        "description_available": true,
        "entity_type": "Vulnerability",
        "id": "c6525476-04d0-4733-80a2-35558d7ac4cb",
        "is_inferred": false,
        "labels": [],
        "lang": "en",
        "name": "CVE-2026-81578",
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [
          {
            "external_id": null,
            "id": "ccb6f628-e4cc-424d-a751-493f5c57c6e6",
            "source_name": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "url": "https://github.com/rapid7/metasploit-framework/pull/21842"
          },
          {
            "external_id": "CVE-2026-81578",
            "id": "51776581-fe42-43a5-90e5-af796e98de9b",
            "source_name": "NIST NVD",
            "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81578"
          },
          {
            "external_id": null,
            "id": "077dc703-4138-46fb-a276-83591daaa05e",
            "source_name": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
            "url": "https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"
          }
        ],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "vulnerability--46bd1df1-d29a-5fde-a495-43cae3ddac82",
        "type": "Vulnerability"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.870Z",
          "created_at": "2026-10-01T08:19:28.732Z",
          "modified": "2026-10-01T08:19:29.055Z",
          "updated_at": "2026-10-01T08:19:29.055Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "c964a463-64ea-46e0-a02b-a8880b52fd0a",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--01755b79-c0ac-5671-9fd8-3d9f25681050",
        "type": "Indicator"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:20.405Z",
          "updated_at": "2026-10-01T08:19:20.784Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "d211d211-3c37-4229-b5a7-de6f6a52d266",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--a1d929df-9041-515b-a132-fa82457a5982",
        "type": "StixFile"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:20.618Z",
          "updated_at": "2026-10-01T08:19:21.012Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "d21330ad-81c2-4537-a36f-e477f5f868d5",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--f1411891-0a14-5daf-8d76-bbf4f43687b6",
        "type": "StixFile"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.847Z",
          "created_at": "2026-10-01T08:19:24.420Z",
          "modified": "2026-10-01T08:19:25.491Z",
          "updated_at": "2026-10-01T08:19:25.491Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "d2b449e9-f457-413b-81ae-f8d8a2572e0a",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--909fb88e-05f6-5999-900a-8e99b7148409",
        "type": "Indicator"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:16.372Z",
          "updated_at": "2026-10-01T08:19:17.528Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "d31fbdc4-f191-4d6d-88b2-85baeda6108b",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--bb90123c-c507-51ef-ad3d-c73ccbd3587a",
        "type": "StixFile"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.862Z",
          "created_at": "2026-10-01T08:19:27.242Z",
          "modified": "2026-10-01T08:19:27.750Z",
          "updated_at": "2026-10-01T08:19:27.750Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "d391b86e-1620-4740-ba59-b16ffc011389",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--da036af2-4adc-5342-9d5e-49f751bd57b8",
        "type": "Indicator"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.876Z",
          "created_at": "2026-10-01T08:19:29.695Z",
          "modified": "2026-10-01T08:19:29.924Z",
          "updated_at": "2026-10-01T08:19:29.924Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "d66af0da-e818-4e99-abe1-66eb3fa87f0b",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--6d787735-5010-586c-991c-929350288cd6",
        "type": "Indicator"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.852Z",
          "created_at": "2026-10-01T08:19:25.938Z",
          "modified": "2026-10-01T08:19:26.245Z",
          "updated_at": "2026-10-01T08:19:26.245Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "e0eb6208-3499-434a-8ea4-56609cb26498",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--b97273ac-c7e7-58e3-9123-15ea5feaa517",
        "type": "Indicator"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.887Z",
          "created_at": "2026-10-01T08:19:32.519Z",
          "modified": "2026-10-01T08:19:33.604Z",
          "updated_at": "2026-10-01T08:19:33.604Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "e2dec70f-60e8-4b64-9a56-52c947605d4b",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "indicator--965feab0-accc-50bf-b63a-7e3fe4c859a4",
        "type": "Indicator"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:16.189Z",
          "updated_at": "2026-10-01T08:19:17.530Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "e9dd1ce5-f9dd-4305-a0dc-fdd82491b62d",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--72367764-eba3-5a4c-a67e-c8790bc0a95e",
        "type": "StixFile"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:21.576Z",
          "updated_at": "2026-10-01T08:19:22.818Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "f767520d-4a53-4a73-901b-175a5c370643",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--195820c0-a79b-5364-980e-28e12a588b2b",
        "type": "StixFile"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:19:14.791Z",
          "updated_at": "2026-10-01T08:19:15.635Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "f77f5d61-bf67-468f-8275-4e32e20afd09",
        "is_inferred": false,
        "labels": [
          "adaptixc2",
          "credential dumping",
          "cve-2026-81578",
          "cve-2026-82078",
          "domain compromise",
          "java loader",
          "lateral movement",
          "papercut mf",
          "web shell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "file--e5e795df-9655-5976-88ff-b9c64a2a67f4",
        "type": "StixFile"
      }
    ],
    "direct_relationships": [
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.910Z",
          "created_at": "2026-10-01T08:20:52.486Z",
          "modified": "2026-10-01T08:20:52.627Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:52.627Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "d2b449e9-f457-413b-81ae-f8d8a2572e0a",
        "from_id": "d2b449e9-f457-413b-81ae-f8d8a2572e0a",
        "from_name": null,
        "from_type": "Indicator",
        "id": "0a6ca413-2a54-4fbd-9390-b21bfffa92f5",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--64f23fb0-4372-5cb7-8dd9-a39c6f9de8a4",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.846Z",
          "created_at": "2026-10-01T08:20:25.168Z",
          "modified": "2026-10-01T08:20:25.479Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:25.479Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "a5f979b2-bee6-4e68-b899-884a5bff7d5d",
        "from_id": "a5f979b2-bee6-4e68-b899-884a5bff7d5d",
        "from_name": null,
        "from_type": "Indicator",
        "id": "0ac8cdbc-ba82-47a7-9125-aaa56c151349",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--aa03b008-dcd6-55fe-afc6-4b0b1a095c2f",
        "toId": "f77f5d61-bf67-468f-8275-4e32e20afd09",
        "to_id": "f77f5d61-bf67-468f-8275-4e32e20afd09",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.796Z",
          "created_at": "2026-10-01T08:19:41.328Z",
          "modified": "2026-10-01T08:19:41.642Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:19:41.642Z"
        },
        "description_available": false,
        "entity_type": "targets",
        "fromId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_name": "AdaptixC2",
        "from_type": "Malware",
        "id": "139578db-ba2d-4db1-b020-a95d399a5387",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "targets",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--16c12aa2-7d8d-5ca1-9986-aa166104b8f4",
        "toId": "c6525476-04d0-4733-80a2-35558d7ac4cb",
        "to_id": "c6525476-04d0-4733-80a2-35558d7ac4cb",
        "to_name": "CVE-2026-81578",
        "to_type": "Vulnerability"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.861Z",
          "created_at": "2026-10-01T08:20:28.230Z",
          "modified": "2026-10-01T08:20:28.990Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:28.990Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "608e09f6-1fe3-404a-aab6-25206dab28cb",
        "from_id": "608e09f6-1fe3-404a-aab6-25206dab28cb",
        "from_name": null,
        "from_type": "Indicator",
        "id": "29f6d56c-6ceb-4340-87e7-2b79fea5425e",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--8b5c9b07-e1e7-58c7-a767-feaa3c67b3ad",
        "toId": "b70c15e9-857d-4eae-a619-e30f372aac4a",
        "to_id": "b70c15e9-857d-4eae-a619-e30f372aac4a",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.934Z",
          "created_at": "2026-10-01T08:21:19.193Z",
          "modified": "2026-10-01T08:21:19.612Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:21:19.612Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "e0eb6208-3499-434a-8ea4-56609cb26498",
        "from_id": "e0eb6208-3499-434a-8ea4-56609cb26498",
        "from_name": null,
        "from_type": "Indicator",
        "id": "2e09ce57-56db-49be-8b7e-e6851ab067e7",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--be648040-e894-5951-841c-ac8401bdd982",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.900Z",
          "created_at": "2026-10-01T08:20:43.987Z",
          "modified": "2026-10-01T08:20:44.135Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:44.135Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "a5f979b2-bee6-4e68-b899-884a5bff7d5d",
        "from_id": "a5f979b2-bee6-4e68-b899-884a5bff7d5d",
        "from_name": null,
        "from_type": "Indicator",
        "id": "2ed88706-3840-4638-8305-d76b54428d12",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--931f02c8-3d5d-56b0-a116-fed82084bb57",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.864Z",
          "created_at": "2026-10-01T08:20:28.231Z",
          "modified": "2026-10-01T08:20:28.608Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:28.608Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "d391b86e-1620-4740-ba59-b16ffc011389",
        "from_id": "d391b86e-1620-4740-ba59-b16ffc011389",
        "from_name": null,
        "from_type": "Indicator",
        "id": "36611b1d-89b6-4019-9f7f-79d0153a0af1",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--39c31420-33c7-52a8-8826-ca4d9dcf2d34",
        "toId": "c1055a72-7220-436b-96c1-af4d2097cf30",
        "to_id": "c1055a72-7220-436b-96c1-af4d2097cf30",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:32.085Z",
          "created_at": "2026-10-03T01:01:42.739Z",
          "modified": "2026-10-03T01:01:46.731Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-03T01:01:46.731Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "61d7524c-81e5-4523-9366-c0ab84ef5213",
        "from_id": "61d7524c-81e5-4523-9366-c0ab84ef5213",
        "from_name": null,
        "from_type": "Indicator",
        "id": "3c00bac6-8095-48f5-a2c0-909ee4732a9e",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--53ef317d-abc3-5905-8b35-266c8ef5f5ca",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.797Z",
          "created_at": "2026-10-01T08:19:44.144Z",
          "modified": "2026-10-01T08:19:45.721Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:19:45.721Z"
        },
        "description_available": false,
        "entity_type": "targets",
        "fromId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_name": "AdaptixC2",
        "from_type": "Malware",
        "id": "415a4dd5-afe9-43ca-ad6a-1be48d4bc25c",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "targets",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--53793a4d-84bb-50f5-ba42-31a635d07d3e",
        "toId": "12e11cbb-485a-471d-af92-62c8fa2cc965",
        "to_id": "12e11cbb-485a-471d-af92-62c8fa2cc965",
        "to_name": "CVE-2026-88772",
        "to_type": "Vulnerability"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:32.074Z",
          "created_at": "2026-10-03T00:58:05.228Z",
          "modified": "2026-10-03T00:58:11.956Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-03T00:58:11.956Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "7c8ac814-b7ce-4f19-b511-ae597aca5f5b",
        "from_id": "7c8ac814-b7ce-4f19-b511-ae597aca5f5b",
        "from_name": null,
        "from_type": "Indicator",
        "id": "42894b4d-c0c6-4b7f-83d8-87cc47014da4",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--368a4b00-3a99-5c7c-803c-6ab8b34d213e",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.869Z",
          "created_at": "2026-10-01T08:20:29.320Z",
          "modified": "2026-10-01T08:20:29.709Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:29.709Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "ac45231f-61bf-4f33-8eff-9f79c0c38016",
        "from_id": "ac45231f-61bf-4f33-8eff-9f79c0c38016",
        "from_name": null,
        "from_type": "Indicator",
        "id": "4d63b920-54b0-43e6-866c-9338430398ce",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--fe3da8ac-2018-59c4-8dac-aab801a401c8",
        "toId": "3e5a37d9-ac13-4243-ae3c-180b3a615968",
        "to_id": "3e5a37d9-ac13-4243-ae3c-180b3a615968",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.867Z",
          "created_at": "2026-10-01T08:20:28.450Z",
          "modified": "2026-10-01T08:20:29.013Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:29.013Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "ac128860-2d4a-484f-bce9-69d21bf750b7",
        "from_id": "ac128860-2d4a-484f-bce9-69d21bf750b7",
        "from_name": null,
        "from_type": "Indicator",
        "id": "5268cd85-99b6-42c3-a7d3-4bc87ac3558f",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--766af6b3-38b3-584a-bf53-a43e74013126",
        "toId": "b2733d58-268b-47b5-b16b-be04d3f7b687",
        "to_id": "b2733d58-268b-47b5-b16b-be04d3f7b687",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.886Z",
          "created_at": "2026-10-01T08:20:31.311Z",
          "modified": "2026-10-01T08:20:31.842Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:31.842Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "61d7524c-81e5-4523-9366-c0ab84ef5213",
        "from_id": "61d7524c-81e5-4523-9366-c0ab84ef5213",
        "from_name": null,
        "from_type": "Indicator",
        "id": "53464573-efb6-4a48-8985-70d3410f65f2",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--640aa796-7f58-52a3-a4d8-7065aaf76716",
        "toId": "f767520d-4a53-4a73-901b-175a5c370643",
        "to_id": "f767520d-4a53-4a73-901b-175a5c370643",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:32.063Z",
          "created_at": "2026-10-03T00:54:00.096Z",
          "modified": "2026-10-03T00:54:06.029Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-03T00:54:06.029Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "43850d13-020d-4a5d-87e8-342810a1aee8",
        "from_id": "43850d13-020d-4a5d-87e8-342810a1aee8",
        "from_name": null,
        "from_type": "Indicator",
        "id": "5c778efa-adb2-4cc7-81f4-ef8aaa5778a8",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--2855472a-d24c-570b-a4e2-3e3c5064d802",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.974Z",
          "created_at": "2026-10-01T08:21:53.067Z",
          "modified": "2026-10-01T08:21:53.240Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:21:53.240Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "d391b86e-1620-4740-ba59-b16ffc011389",
        "from_id": "d391b86e-1620-4740-ba59-b16ffc011389",
        "from_name": null,
        "from_type": "Indicator",
        "id": "5d1e887e-be3b-4070-ac55-594467c989f6",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--37e9e1f4-1844-5cf2-a6ba-bf84b041dffd",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.797Z",
          "created_at": "2026-10-01T08:19:43.440Z",
          "modified": "2026-10-01T08:19:43.810Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:19:43.810Z"
        },
        "description_available": false,
        "entity_type": "targets",
        "fromId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_name": "AdaptixC2",
        "from_type": "Malware",
        "id": "67eb7acc-69c4-433a-a160-f03e957ad56f",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "targets",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--f5676370-97b6-576e-a38b-5deff2a85002",
        "toId": "c0f8d113-129e-4f2c-a0c5-80d76dfc4179",
        "to_id": "c0f8d113-129e-4f2c-a0c5-80d76dfc4179",
        "to_name": "CVE-2026-88771",
        "to_type": "Vulnerability"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.857Z",
          "created_at": "2026-10-01T08:20:27.203Z",
          "modified": "2026-10-01T08:20:27.787Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:27.787Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "4586c4d5-7a74-497a-8ecd-cf0eb9e947ec",
        "from_id": "4586c4d5-7a74-497a-8ecd-cf0eb9e947ec",
        "from_name": null,
        "from_type": "Indicator",
        "id": "7163df39-d52b-409f-986c-7737418c97e8",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--1f84ef4e-48d8-58ba-812e-33babb8b84c6",
        "toId": "d31fbdc4-f191-4d6d-88b2-85baeda6108b",
        "to_id": "d31fbdc4-f191-4d6d-88b2-85baeda6108b",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.923Z",
          "created_at": "2026-10-01T08:21:03.741Z",
          "modified": "2026-10-01T08:21:03.905Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:21:03.905Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "c58961ad-1747-440f-bc99-59400680c687",
        "from_id": "c58961ad-1747-440f-bc99-59400680c687",
        "from_name": null,
        "from_type": "Indicator",
        "id": "7bd27b93-6f06-46be-91fb-92631d5608ad",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--d9af2109-0ff0-5a28-9351-8c2fd2e8457c",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.889Z",
          "created_at": "2026-10-01T08:20:31.910Z",
          "modified": "2026-10-01T08:20:33.187Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:33.187Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "24d65cb5-3cd9-462f-9ddf-6770c5f33087",
        "from_id": "24d65cb5-3cd9-462f-9ddf-6770c5f33087",
        "from_name": null,
        "from_type": "Indicator",
        "id": "7f6a14b7-7d73-4a71-88cb-43dd98b5d15c",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--c3517032-741f-507e-976f-7868e549ba37",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.949Z",
          "created_at": "2026-10-01T08:21:29.951Z",
          "modified": "2026-10-01T08:21:30.138Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:21:30.138Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "4586c4d5-7a74-497a-8ecd-cf0eb9e947ec",
        "from_id": "4586c4d5-7a74-497a-8ecd-cf0eb9e947ec",
        "from_name": null,
        "from_type": "Indicator",
        "id": "84ac4990-c3a5-478c-ad5e-e58f294cdabb",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--3769cd5a-2c0f-5805-b31e-03010817829a",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.854Z",
          "created_at": "2026-10-01T08:20:26.934Z",
          "modified": "2026-10-01T08:20:27.482Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:27.482Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "e0eb6208-3499-434a-8ea4-56609cb26498",
        "from_id": "e0eb6208-3499-434a-8ea4-56609cb26498",
        "from_name": null,
        "from_type": "Indicator",
        "id": "8694771f-6575-4c75-b872-4e3780957fb3",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--8e6058a9-a855-58d6-b437-d45b0a33a05c",
        "toId": "e9dd1ce5-f9dd-4305-a0dc-fdd82491b62d",
        "to_id": "e9dd1ce5-f9dd-4305-a0dc-fdd82491b62d",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.878Z",
          "created_at": "2026-10-01T08:20:30.421Z",
          "modified": "2026-10-01T08:20:30.882Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:30.882Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "d66af0da-e818-4e99-abe1-66eb3fa87f0b",
        "from_id": "d66af0da-e818-4e99-abe1-66eb3fa87f0b",
        "from_name": null,
        "from_type": "Indicator",
        "id": "9255c4d1-f314-415a-a40c-29df8ddc64bb",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--ec109d31-5b34-583b-9fce-56fc8b27fad8",
        "toId": "d21330ad-81c2-4537-a36f-e477f5f868d5",
        "to_id": "d21330ad-81c2-4537-a36f-e477f5f868d5",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:32.037Z",
          "created_at": "2026-10-03T00:46:06.034Z",
          "modified": "2026-10-03T00:46:12.241Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-03T00:46:12.241Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "bca38751-5560-4e00-a96e-a1fa3ad7b8de",
        "from_id": "bca38751-5560-4e00-a96e-a1fa3ad7b8de",
        "from_name": null,
        "from_type": "Indicator",
        "id": "973a3439-d871-4fa1-88e0-35045cd3c3ea",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--63916a4d-b977-5472-b355-710462a94d78",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.851Z",
          "created_at": "2026-10-01T08:20:26.937Z",
          "modified": "2026-10-01T08:20:27.660Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:27.660Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "c58961ad-1747-440f-bc99-59400680c687",
        "from_id": "c58961ad-1747-440f-bc99-59400680c687",
        "from_name": null,
        "from_type": "Indicator",
        "id": "983c82c3-1fb4-496e-bf16-4c4a82543fe0",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--b5bef87d-5b94-589f-9b1f-727707e4b912",
        "toId": "61aeaefa-dab2-4d2e-8118-214d014b9dee",
        "to_id": "61aeaefa-dab2-4d2e-8118-214d014b9dee",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:32.048Z",
          "created_at": "2026-10-03T00:50:03.843Z",
          "modified": "2026-10-03T00:50:06.437Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-03T00:50:06.437Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "d66af0da-e818-4e99-abe1-66eb3fa87f0b",
        "from_id": "d66af0da-e818-4e99-abe1-66eb3fa87f0b",
        "from_name": null,
        "from_type": "Indicator",
        "id": "9d8118cf-1d66-4377-bbe6-45caf04897fa",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--7c48c35a-d55b-5869-ad70-28bce63eb618",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.873Z",
          "created_at": "2026-10-01T08:20:29.631Z",
          "modified": "2026-10-01T08:20:30.252Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:30.252Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "c964a463-64ea-46e0-a02b-a8880b52fd0a",
        "from_id": "c964a463-64ea-46e0-a02b-a8880b52fd0a",
        "from_name": null,
        "from_type": "Indicator",
        "id": "a0f709b5-04a8-483b-88c2-97fb5e8bf334",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--8ab52584-da62-5031-b768-da4fa16cbf31",
        "toId": "5c2c4e9b-fec8-45f1-ab56-884d4fcdf75a",
        "to_id": "5c2c4e9b-fec8-45f1-ab56-884d4fcdf75a",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.961Z",
          "created_at": "2026-10-01T08:21:40.711Z",
          "modified": "2026-10-01T08:21:40.902Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:21:40.902Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "608e09f6-1fe3-404a-aab6-25206dab28cb",
        "from_id": "608e09f6-1fe3-404a-aab6-25206dab28cb",
        "from_name": null,
        "from_type": "Indicator",
        "id": "aae0d49d-29d1-445b-b641-afb38e72566a",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--ce484696-a356-5282-9baa-65b96d5ba607",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.994Z",
          "created_at": "2026-10-01T08:22:04.914Z",
          "modified": "2026-10-01T08:22:05.102Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:22:05.102Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "ac128860-2d4a-484f-bce9-69d21bf750b7",
        "from_id": "ac128860-2d4a-484f-bce9-69d21bf750b7",
        "from_name": null,
        "from_type": "Indicator",
        "id": "afffad77-fe80-40f2-8502-1edf7d6e99c0",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--dbc1ea00-69e5-5679-b55e-6ac469959dcf",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.888Z",
          "created_at": "2026-10-01T08:20:31.719Z",
          "modified": "2026-10-01T08:20:32.953Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:32.953Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "e2dec70f-60e8-4b64-9a56-52c947605d4b",
        "from_id": "e2dec70f-60e8-4b64-9a56-52c947605d4b",
        "from_name": null,
        "from_type": "Indicator",
        "id": "b29c493f-36c9-400f-977c-df0deeef1e11",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--da0d71bd-fe2d-578a-a4d8-dc3cb06cd2ab",
        "toId": "3937e8aa-f135-47df-a65a-16218446f65a",
        "to_id": "3937e8aa-f135-47df-a65a-16218446f65a",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:32.095Z",
          "created_at": "2026-10-03T01:04:51.374Z",
          "modified": "2026-10-03T01:04:56.943Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-03T01:04:56.943Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "e2dec70f-60e8-4b64-9a56-52c947605d4b",
        "from_id": "e2dec70f-60e8-4b64-9a56-52c947605d4b",
        "from_name": null,
        "from_type": "Indicator",
        "id": "b56f36d2-9637-4446-bf9f-e252d1364453",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--3e591e3f-16f4-5450-9b02-499d1c93f5e3",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-08-08T12:29:26.426Z",
          "created_at": "2026-08-10T08:01:15.752Z",
          "modified": "2026-08-10T08:01:17.620Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-08-10T08:01:17.620Z"
        },
        "description_available": false,
        "entity_type": "targets",
        "fromId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_name": "AdaptixC2",
        "from_type": "Malware",
        "id": "ca114af3-b409-4865-ab6d-9e6168c14ff8",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "targets",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--ce60b269-db72-5a85-8ff8-d6715506524c",
        "toId": "8aadeb6e-a39e-4ee2-8ce1-4725c806eeed",
        "to_id": "8aadeb6e-a39e-4ee2-8ce1-4725c806eeed",
        "to_name": "Education",
        "to_type": "Sector"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.796Z",
          "created_at": "2026-10-01T08:19:47.843Z",
          "modified": "2026-10-01T08:19:48.101Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:19:48.101Z"
        },
        "description_available": false,
        "entity_type": "targets",
        "fromId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "from_name": "AdaptixC2",
        "from_type": "Malware",
        "id": "d16f4963-347f-40e5-a063-1c287cc68c8c",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "targets",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--8a880b18-2f9a-5550-bb36-7da06b7637c4",
        "toId": "7107a9d8-6431-443d-b376-eb66f179f92d",
        "to_id": "7107a9d8-6431-443d-b376-eb66f179f92d",
        "to_name": "CVE-2026-82078",
        "to_type": "Vulnerability"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:32.006Z",
          "created_at": "2026-10-01T08:22:16.260Z",
          "modified": "2026-10-01T08:22:16.481Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:22:16.481Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "ac45231f-61bf-4f33-8eff-9f79c0c38016",
        "from_id": "ac45231f-61bf-4f33-8eff-9f79c0c38016",
        "from_name": null,
        "from_type": "Indicator",
        "id": "d224d150-d269-4d33-8d59-a96a6e093c1a",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--eefd07f7-f9a0-560c-9830-da471d46a6e6",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.883Z",
          "created_at": "2026-10-01T08:20:30.783Z",
          "modified": "2026-10-01T08:20:31.208Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:31.208Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "7c8ac814-b7ce-4f19-b511-ae597aca5f5b",
        "from_id": "7c8ac814-b7ce-4f19-b511-ae597aca5f5b",
        "from_name": null,
        "from_type": "Indicator",
        "id": "d8c4e5fa-b3ff-4ad2-abad-484fb3533b05",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--9dd7e367-fcca-5426-a959-253f6c10a680",
        "toId": "c3db86a0-26a6-4ab3-9ecb-167012764160",
        "to_id": "c3db86a0-26a6-4ab3-9ecb-167012764160",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.843Z",
          "created_at": "2026-10-01T08:20:22.751Z",
          "modified": "2026-10-01T08:20:22.946Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:22.946Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "24d65cb5-3cd9-462f-9ddf-6770c5f33087",
        "from_id": "24d65cb5-3cd9-462f-9ddf-6770c5f33087",
        "from_name": null,
        "from_type": "Indicator",
        "id": "dcca91f6-fc89-4f3f-b0bc-5522228a137d",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--e795b098-481a-548b-9684-11be4c3b482b",
        "toId": "8a7361f5-a744-4258-9a8d-05105d0b7bcc",
        "to_id": "8a7361f5-a744-4258-9a8d-05105d0b7bcc",
        "to_name": null,
        "to_type": "IPv4Addr"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.875Z",
          "created_at": "2026-10-01T08:20:29.630Z",
          "modified": "2026-10-01T08:20:30.078Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:30.078Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "bca38751-5560-4e00-a96e-a1fa3ad7b8de",
        "from_id": "bca38751-5560-4e00-a96e-a1fa3ad7b8de",
        "from_name": null,
        "from_type": "Indicator",
        "id": "e4ce455b-2366-45ae-9912-d14f8cb9f04c",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--2005e895-29eb-534b-84b1-5a6657ed14e3",
        "toId": "d211d211-3c37-4229-b5a7-de6f6a52d266",
        "to_id": "d211d211-3c37-4229-b5a7-de6f6a52d266",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:32.023Z",
          "created_at": "2026-10-01T08:22:29.837Z",
          "modified": "2026-10-01T08:22:30.071Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:22:30.071Z"
        },
        "description_available": false,
        "entity_type": "indicates",
        "fromId": "c964a463-64ea-46e0-a02b-a8880b52fd0a",
        "from_id": "c964a463-64ea-46e0-a02b-a8880b52fd0a",
        "from_name": null,
        "from_type": "Indicator",
        "id": "e92a8b04-7cb2-4fbe-af31-1d64fbd92932",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "indicates",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--8fc4d42d-62bf-5cf1-a618-b38fb2904bb9",
        "toId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "to_name": "AdaptixC2",
        "to_type": "Malware"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.880Z",
          "created_at": "2026-10-01T08:20:30.786Z",
          "modified": "2026-10-01T08:20:31.233Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:31.233Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "43850d13-020d-4a5d-87e8-342810a1aee8",
        "from_id": "43850d13-020d-4a5d-87e8-342810a1aee8",
        "from_name": null,
        "from_type": "Indicator",
        "id": "f75cc01b-68a2-4d61-a77f-c1f58bdcaea5",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--a8f4f204-4343-5b1e-8666-46d062e8a915",
        "toId": "9977c3ca-d804-4c01-b602-6fdff2937807",
        "to_id": "9977c3ca-d804-4c01-b602-6fdff2937807",
        "to_name": null,
        "to_type": "StixFile"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.848Z",
          "created_at": "2026-10-01T08:20:25.423Z",
          "modified": "2026-10-01T08:20:25.615Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:20:25.615Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "d2b449e9-f457-413b-81ae-f8d8a2572e0a",
        "from_id": "d2b449e9-f457-413b-81ae-f8d8a2572e0a",
        "from_name": null,
        "from_type": "Indicator",
        "id": "fe9db8ba-b426-493e-aa4b-b0941ef0915e",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "standard_id": "relationship--5d03cc49-8e16-5d11-adef-fa37dd744dc8",
        "toId": "9b04b50d-0a99-4486-a9e9-b02e907abceb",
        "to_id": "9b04b50d-0a99-4486-a9e9-b02e907abceb",
        "to_name": null,
        "to_type": "StixFile"
      }
    ],
    "iocs": [
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "156[.]227[.]0[.]13",
        "description_available": false,
        "object_id": "24d65cb5-3cd9-462f-9ddf-6770c5f33087",
        "object_ids": [
          "24d65cb5-3cd9-462f-9ddf-6770c5f33087",
          "8a7361f5-a744-4258-9a8d-05105d0b7bcc"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "24d65cb5-3cd9-462f-9ddf-6770c5f33087",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2026-10-21T10:12:28.434Z",
            "validity_status": "active",
            "value": "156.227.0.13"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet IPv4Addr explicitement associé au rapport source.",
            "object_id": "8a7361f5-a744-4258-9a8d-05105d0b7bcc",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "156.227.0.13"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "ipv4",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2026-10-21T10:12:28.434Z",
        "validity_status": "active",
        "value": "156.227.0.13"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "67a5fe0dd43cb25c539341c0bf31d2b0",
        "description_available": false,
        "object_id": "bca38751-5560-4e00-a96e-a1fa3ad7b8de",
        "object_ids": [
          "bca38751-5560-4e00-a96e-a1fa3ad7b8de",
          "d211d211-3c37-4229-b5a7-de6f6a52d266"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "bca38751-5560-4e00-a96e-a1fa3ad7b8de",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "67a5fe0dd43cb25c539341c0bf31d2b0"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "d211d211-3c37-4229-b5a7-de6f6a52d266",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "67a5fe0dd43cb25c539341c0bf31d2b0"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "md5",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "67a5fe0dd43cb25c539341c0bf31d2b0"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "acc6aad93d92b4eca8b0fec938ac38cf",
        "description_available": false,
        "object_id": "d66af0da-e818-4e99-abe1-66eb3fa87f0b",
        "object_ids": [
          "d21330ad-81c2-4537-a36f-e477f5f868d5",
          "d66af0da-e818-4e99-abe1-66eb3fa87f0b"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "d66af0da-e818-4e99-abe1-66eb3fa87f0b",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "acc6aad93d92b4eca8b0fec938ac38cf"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "d21330ad-81c2-4537-a36f-e477f5f868d5",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "acc6aad93d92b4eca8b0fec938ac38cf"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "md5",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "acc6aad93d92b4eca8b0fec938ac38cf"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "3406e4d5b6cc917080c531fae37decc9073e7617",
        "description_available": false,
        "object_id": "43850d13-020d-4a5d-87e8-342810a1aee8",
        "object_ids": [
          "43850d13-020d-4a5d-87e8-342810a1aee8",
          "9977c3ca-d804-4c01-b602-6fdff2937807"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "43850d13-020d-4a5d-87e8-342810a1aee8",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "3406e4d5b6cc917080c531fae37decc9073e7617"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "9977c3ca-d804-4c01-b602-6fdff2937807",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "3406e4d5b6cc917080c531fae37decc9073e7617"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha1",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "3406e4d5b6cc917080c531fae37decc9073e7617"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "561485ba4f3954414b7ad1c4d58a6a9748116d30",
        "description_available": false,
        "object_id": "7c8ac814-b7ce-4f19-b511-ae597aca5f5b",
        "object_ids": [
          "7c8ac814-b7ce-4f19-b511-ae597aca5f5b",
          "c3db86a0-26a6-4ab3-9ecb-167012764160"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "7c8ac814-b7ce-4f19-b511-ae597aca5f5b",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "561485ba4f3954414b7ad1c4d58a6a9748116d30"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "c3db86a0-26a6-4ab3-9ecb-167012764160",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "561485ba4f3954414b7ad1c4d58a6a9748116d30"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha1",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "561485ba4f3954414b7ad1c4d58a6a9748116d30"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180",
        "description_available": false,
        "object_id": "c964a463-64ea-46e0-a02b-a8880b52fd0a",
        "object_ids": [
          "5c2c4e9b-fec8-45f1-ab56-884d4fcdf75a",
          "c964a463-64ea-46e0-a02b-a8880b52fd0a"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "c964a463-64ea-46e0-a02b-a8880b52fd0a",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "5c2c4e9b-fec8-45f1-ab56-884d4fcdf75a",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a",
        "description_available": false,
        "object_id": "e0eb6208-3499-434a-8ea4-56609cb26498",
        "object_ids": [
          "e0eb6208-3499-434a-8ea4-56609cb26498",
          "e9dd1ce5-f9dd-4305-a0dc-fdd82491b62d"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "e0eb6208-3499-434a-8ea4-56609cb26498",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "e9dd1ce5-f9dd-4305-a0dc-fdd82491b62d",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "861207a8973ab353910d746853b232429fbaaa621ff0ab2df182ffb7af75d6ec",
        "description_available": false,
        "object_id": "61d7524c-81e5-4523-9366-c0ab84ef5213",
        "object_ids": [
          "61d7524c-81e5-4523-9366-c0ab84ef5213",
          "f767520d-4a53-4a73-901b-175a5c370643"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "61d7524c-81e5-4523-9366-c0ab84ef5213",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "861207a8973ab353910d746853b232429fbaaa621ff0ab2df182ffb7af75d6ec"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "f767520d-4a53-4a73-901b-175a5c370643",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "861207a8973ab353910d746853b232429fbaaa621ff0ab2df182ffb7af75d6ec"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "861207a8973ab353910d746853b232429fbaaa621ff0ab2df182ffb7af75d6ec"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e",
        "description_available": false,
        "object_id": "ac45231f-61bf-4f33-8eff-9f79c0c38016",
        "object_ids": [
          "3e5a37d9-ac13-4243-ae3c-180b3a615968",
          "ac45231f-61bf-4f33-8eff-9f79c0c38016"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "ac45231f-61bf-4f33-8eff-9f79c0c38016",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "3e5a37d9-ac13-4243-ae3c-180b3a615968",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2",
        "description_available": false,
        "object_id": "d391b86e-1620-4740-ba59-b16ffc011389",
        "object_ids": [
          "c1055a72-7220-436b-96c1-af4d2097cf30",
          "d391b86e-1620-4740-ba59-b16ffc011389"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "d391b86e-1620-4740-ba59-b16ffc011389",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "c1055a72-7220-436b-96c1-af4d2097cf30",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca",
        "description_available": false,
        "object_id": "4586c4d5-7a74-497a-8ecd-cf0eb9e947ec",
        "object_ids": [
          "4586c4d5-7a74-497a-8ecd-cf0eb9e947ec",
          "d31fbdc4-f191-4d6d-88b2-85baeda6108b"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "4586c4d5-7a74-497a-8ecd-cf0eb9e947ec",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "d31fbdc4-f191-4d6d-88b2-85baeda6108b",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58",
        "description_available": false,
        "object_id": "c58961ad-1747-440f-bc99-59400680c687",
        "object_ids": [
          "61aeaefa-dab2-4d2e-8118-214d014b9dee",
          "c58961ad-1747-440f-bc99-59400680c687"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "c58961ad-1747-440f-bc99-59400680c687",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "61aeaefa-dab2-4d2e-8118-214d014b9dee",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "c59edcfa37db923d3a6a4739d073aee9f54383505d196d36de2e8834aa3c2378",
        "description_available": false,
        "object_id": "e2dec70f-60e8-4b64-9a56-52c947605d4b",
        "object_ids": [
          "3937e8aa-f135-47df-a65a-16218446f65a",
          "e2dec70f-60e8-4b64-9a56-52c947605d4b"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "e2dec70f-60e8-4b64-9a56-52c947605d4b",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "c59edcfa37db923d3a6a4739d073aee9f54383505d196d36de2e8834aa3c2378"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "3937e8aa-f135-47df-a65a-16218446f65a",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "c59edcfa37db923d3a6a4739d073aee9f54383505d196d36de2e8834aa3c2378"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "c59edcfa37db923d3a6a4739d073aee9f54383505d196d36de2e8834aa3c2378"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c",
        "description_available": false,
        "object_id": "d2b449e9-f457-413b-81ae-f8d8a2572e0a",
        "object_ids": [
          "9b04b50d-0a99-4486-a9e9-b02e907abceb",
          "d2b449e9-f457-413b-81ae-f8d8a2572e0a"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "d2b449e9-f457-413b-81ae-f8d8a2572e0a",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "9b04b50d-0a99-4486-a9e9-b02e907abceb",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222",
        "description_available": false,
        "object_id": "a5f979b2-bee6-4e68-b899-884a5bff7d5d",
        "object_ids": [
          "a5f979b2-bee6-4e68-b899-884a5bff7d5d",
          "f77f5d61-bf67-468f-8275-4e32e20afd09"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "a5f979b2-bee6-4e68-b899-884a5bff7d5d",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "f77f5d61-bf67-468f-8275-4e32e20afd09",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4",
        "description_available": false,
        "object_id": "ac128860-2d4a-484f-bce9-69d21bf750b7",
        "object_ids": [
          "ac128860-2d4a-484f-bce9-69d21bf750b7",
          "b2733d58-268b-47b5-b16b-be04d3f7b687"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "ac128860-2d4a-484f-bce9-69d21bf750b7",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "b2733d58-268b-47b5-b16b-be04d3f7b687",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044",
        "description_available": false,
        "object_id": "608e09f6-1fe3-404a-aab6-25206dab28cb",
        "object_ids": [
          "608e09f6-1fe3-404a-aab6-25206dab28cb",
          "b70c15e9-857d-4eae-a619-e30f372aac4a"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "608e09f6-1fe3-404a-aab6-25206dab28cb",
            "valid_from": "2026-10-01T04:37:49.000Z",
            "valid_until": "2027-07-18T15:47:33.557Z",
            "validity_status": "active",
            "value": "f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "b70c15e9-857d-4eae-a619-e30f372aac4a",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044"
          }
        ],
        "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:49.000Z",
        "valid_until": "2027-07-18T15:47:33.557Z",
        "validity_status": "active",
        "value": "f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044"
      }
    ],
    "mentioned": [
      {
        "confidence": 50,
        "evidence_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
        "name": "AdaptixC2",
        "role": "mentionné",
        "type": "Malware"
      },
      {
        "confidence": 80,
        "evidence_id": "c6525476-04d0-4733-80a2-35558d7ac4cb",
        "name": "CVE-2026-81578",
        "role": "mentionné",
        "type": "Vulnerability"
      },
      {
        "confidence": 80,
        "evidence_id": "7107a9d8-6431-443d-b376-eb66f179f92d",
        "name": "CVE-2026-82078",
        "role": "mentionné",
        "type": "Vulnerability"
      },
      {
        "confidence": 80,
        "evidence_id": "c0f8d113-129e-4f2c-a0c5-80d76dfc4179",
        "name": "CVE-2026-88771",
        "role": "mentionné",
        "type": "Vulnerability"
      },
      {
        "confidence": 80,
        "evidence_id": "12e11cbb-485a-471d-af92-62c8fa2cc965",
        "name": "CVE-2026-88772",
        "role": "mentionné",
        "type": "Vulnerability"
      }
    ],
    "mitre": {
      "associated_repertoire": [
        {
          "complete": true,
          "relationships": [
            {
              "__typename": "StixCoreRelationship",
              "authorized_members": [],
              "confidence": 50,
              "created_by": null,
              "dates": {
                "created": "2026-05-08T09:02:49.438Z",
                "created_at": "2026-05-08T10:16:41.005Z",
                "modified": "2026-05-08T10:16:41.176Z",
                "start_time": "1970-01-01T00:00:00.000Z",
                "stop_time": "5138-11-16T09:46:40.000Z",
                "updated_at": "2026-05-08T10:16:41.176Z"
              },
              "description_available": false,
              "entity_type": "uses",
              "fromId": "31f9590f-40bd-4175-92ed-39ca49a33a08",
              "from_id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
              "from_name": "AdaptixC2",
              "from_type": "Malware",
              "id": "2ef5d43e-629e-4e03-b696-31a7356712ee",
              "is_inferred": false,
              "objectMarking": [
                {
                  "definition": "TLP:CLEAR",
                  "definition_type": "TLP"
                }
              ],
              "objectOrganization": [],
              "references": [],
              "relationship_type": "uses",
              "restrict_access": false,
              "revoked": false,
              "scope": "entity-context",
              "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
              "standard_id": "relationship--a42f9fd8-dffc-56a4-b32b-f88aa1be719a",
              "toId": "ea4de683-0cad-4497-a044-65b61045d534",
              "to_id": "ea4de683-0cad-4497-a044-65b61045d534",
              "to_name": "T1574.002",
              "to_type": "AttackPattern"
            }
          ],
          "scope": "entity-context",
          "techniques": [
            {
              "aliases": [],
              "attributes": {
                "x_mitre_id": "T1574.002"
              },
              "authorized_members": [],
              "confidence": 50,
              "created": "2026-01-18T18:28:11.149Z",
              "created_by": null,
              "dates": {
                "created": "2026-01-18T18:28:11.149Z",
                "created_at": "2026-01-21T11:31:18.951Z",
                "modified": "2026-01-21T11:31:19.843Z",
                "updated_at": "2026-01-21T11:31:19.843Z"
              },
              "description_available": false,
              "evidence_ids": [
                "2ef5d43e-629e-4e03-b696-31a7356712ee",
                "ea4de683-0cad-4497-a044-65b61045d534"
              ],
              "external_id": "T1574.002",
              "id": "ea4de683-0cad-4497-a044-65b61045d534",
              "is_inferred": false,
              "kill_chain_phases": [],
              "labels": [],
              "lang": "en",
              "mitre_id": "T1574.002",
              "modified": "2026-01-21T11:31:19.843Z",
              "name": "T1574.002",
              "objectMarking": [
                {
                  "definition": "TLP:CLEAR",
                  "definition_type": "TLP"
                }
              ],
              "objectOrganization": [],
              "references": [
                {
                  "external_id": "T1574.002",
                  "id": "7a1e1096-14a3-4673-8aa4-da93b15cb955",
                  "source_name": "mitre-attack",
                  "url": "https://attack.mitre.org/techniques/T1574/002"
                }
              ],
              "relationship_ids": [
                "2ef5d43e-629e-4e03-b696-31a7356712ee"
              ],
              "restrict_access": false,
              "revoked": false,
              "scope": "entity-context",
              "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578",
              "tactics": [],
              "url": "https://attack.mitre.org/techniques/T1574/002/",
              "via_entities": [
                {
                  "id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
                  "name": "AdaptixC2",
                  "type": "Malware"
                }
              ]
            }
          ],
          "via_entity": {
            "id": "31f9590f-40bd-4175-92ed-39ca49a33a08",
            "name": "AdaptixC2",
            "type": "Malware"
          }
        }
      ],
      "direct_techniques": [],
      "official_catalog": {
        "complete": true,
        "fetched_at": "2026-10-08T07:58:58Z",
        "schema_version": 1,
        "source_sha256": "6227cd8ff0e21fc6355dc871dcad6a354b0d36570d2c3b783667577320378730",
        "source_url": "https://raw.githubusercontent.com/mitre-attack/attack-stix-data/master/enterprise-attack/enterprise-attack.json",
        "techniques": [
          {
            "attack_version": "2.1",
            "canonical_url": "https://attack.mitre.org/techniques/T1574/002/",
            "created": "2020-03-13T19:41:37.908Z",
            "deprecated": false,
            "matched": true,
            "mitre_id": "T1574.002",
            "modified": "2026-04-15T22:56:43.434Z",
            "official_name": "DLL Side-Loading",
            "official_status": "revoked",
            "official_tactics": [
              {
                "mitre_id": "TA0002",
                "name": "Execution",
                "shortname": "execution"
              },
              {
                "mitre_id": "TA0005",
                "name": "Stealth",
                "shortname": "stealth"
              }
            ],
            "replacements": [
              {
                "canonical_url": "https://attack.mitre.org/techniques/T1574/001/",
                "mitre_id": "T1574.001",
                "official_name": "DLL",
                "official_status": "active",
                "relationship_id": "relationship--7bb3a367-c3fd-4981-8d95-8ba142f92cf2",
                "stix_id": "attack-pattern--2fee9321-3e71-4cf4-af24-d4d40d355b34"
              }
            ],
            "revoked": true,
            "stix_id": "attack-pattern--e64c62cf-9cd7-4a14-94ec-cdaac43ab44b"
          }
        ]
      }
    },
    "report_metadata": {
      "authorized_members": [],
      "confidence": 50,
      "created_by": null,
      "dates": {
        "created": "2026-10-01T04:37:48.005Z",
        "created_at": "2026-10-03T01:08:02.950Z",
        "modified": "2026-10-03T01:08:09.232Z",
        "published": "2026-10-01T04:37:48.005Z",
        "updated_at": "2026-10-03T01:08:09.232Z"
      },
      "description_available": true,
      "id": "f26f9774-5ae6-4cea-b398-388898722074",
      "is_inferred": false,
      "labels": [
        "adaptixc2",
        "credential dumping",
        "cve-2026-81578",
        "cve-2026-82078",
        "domain compromise",
        "java loader",
        "lateral movement",
        "papercut mf",
        "web shell",
        "zero-day exploitation"
      ],
      "lang": "en",
      "name": "PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578",
      "objectMarking": [
        {
          "definition": "TLP:CLEAR",
          "definition_type": "TLP"
        }
      ],
      "objectOrganization": [],
      "published": "2026-10-01T04:37:48.005Z",
      "references": [
        {
          "external_id": null,
          "id": "487fc939-2be4-4855-947d-b7404d0184fd",
          "source_name": "alien-vault",
          "url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578"
        },
        {
          "external_id": "6abde39c863acdfda74e5d84",
          "id": "fe9fc709-295a-4e1e-95ef-b8649766b206",
          "source_name": "alien-vault",
          "url": "https://otx.alienvault.com/pulse/6abde39c863acdfda74e5d84"
        }
      ],
      "report_types": [
        "threat-report"
      ],
      "restrict_access": false,
      "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578"
    },
    "targets": [
      {
        "confidence": 50,
        "evidence_id": "ca114af3-b409-4865-ab6d-9e6168c14ff8",
        "name": "Education",
        "role": "cible déclarée (relation targets)",
        "type": "Sector"
      }
    ],
    "techniques": [],
    "vulnerabilities": [
      "CVE-2026-81578",
      "CVE-2026-82078",
      "CVE-2026-88771",
      "CVE-2026-88772"
    ]
  },
  "report_id": "f26f9774-5ae6-4cea-b398-388898722074",
  "schema_version": 1,
  "selected_date": "2026-10-01",
  "source_url": "https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578"
}
