misp-circl-feed/feeds/circl/stix-2.1/5721bfc3-7090-4109-b492-453b950d210f.json

3913 lines
506 KiB
JSON
Raw Permalink Normal View History

2023-04-21 14:44:17 +00:00
{
"type": "bundle",
"id": "bundle--5721bfc3-7090-4109-b492-453b950d210f",
"objects": [
{
"type": "identity",
"spec_version": "2.1",
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:36.000Z",
"modified": "2016-04-28T09:08:36.000Z",
"name": "CIRCL",
"identity_class": "organization"
},
{
"type": "report",
"spec_version": "2.1",
"id": "report--5721bfc3-7090-4109-b492-453b950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:36.000Z",
"modified": "2016-04-28T09:08:36.000Z",
"name": "Malspam (2016-04-28) - Locky",
"published": "2016-04-28T09:11:32Z",
"object_refs": [
"indicator--5721bfe7-93b4-4b7a-997f-4aab950d210f",
"indicator--5721bfe8-1994-480d-81c7-4af4950d210f",
"indicator--5721bfe8-5d9c-417e-95c3-4867950d210f",
"indicator--5721bfe9-91fc-4710-907b-46a8950d210f",
"indicator--5721bfe9-1ad8-4c31-851f-49f6950d210f",
"indicator--5721bfea-dc9c-44ba-bcdd-4065950d210f",
"indicator--5721bfea-4f14-40a8-b8c8-48f6950d210f",
"indicator--5721bfea-d42c-44b1-b434-49c0950d210f",
"indicator--5721bfeb-ce68-4c9d-b78f-41f1950d210f",
"indicator--5721bfeb-8c8c-4628-a723-40cd950d210f",
"indicator--5721bfec-a2e0-4798-8ce1-4c33950d210f",
"indicator--5721bfec-8a78-45fc-ba9c-45b3950d210f",
"indicator--5721bfec-a3c0-4cd5-8b4e-480d950d210f",
"indicator--5721bfed-fa08-4919-96a4-4cff950d210f",
"indicator--5721bfed-138c-433a-9081-4624950d210f",
"indicator--5721bfee-7d4c-4fa6-bb6a-4d26950d210f",
"indicator--5721bfee-aa10-4ac1-8c6d-4fec950d210f",
"indicator--5721bfee-f614-485e-a634-4745950d210f",
"indicator--5721bfef-112c-41c1-92fc-4637950d210f",
"indicator--5721bfef-7c74-4b55-9dd9-4242950d210f",
"indicator--5721bfef-3ffc-40be-9453-4af6950d210f",
"indicator--5721bff0-bce8-4ab5-8093-4679950d210f",
"indicator--5721bff0-74b4-4dc5-b58e-4c2d950d210f",
"indicator--5721bff1-1534-41c9-8726-4c44950d210f",
"indicator--5721c011-7188-4a90-a683-4f9a950d210f",
"indicator--5721c012-7740-469d-ae53-49dc950d210f",
"indicator--5721c013-6ad0-43f6-b2e4-4aec950d210f",
"indicator--5721c013-a8d4-4a6f-a57c-4fdf950d210f",
"indicator--5721c014-46dc-47ee-956e-4b3f950d210f",
"indicator--5721c015-6b28-4748-8db7-4ae6950d210f",
"indicator--5721c015-6b94-4ec6-a211-422a950d210f",
"indicator--5721c016-a5c8-4888-b999-4ef0950d210f",
"indicator--5721c017-f300-438c-b9a8-46db950d210f",
"indicator--5721c017-f1b4-41f6-891f-4bbb950d210f",
"indicator--5721c018-c9d8-45cd-8fc6-4358950d210f",
"indicator--5721c019-d744-4f3b-b8c2-46dd950d210f",
"indicator--5721c01a-79d0-4e31-aa44-49bb950d210f",
"indicator--5721c01b-d848-43da-a01f-4ec1950d210f",
"indicator--5721c01b-ed14-400b-bb63-47ca950d210f",
"indicator--5721c01c-0cf8-4ea5-ac90-4d22950d210f",
"indicator--5721c01d-22c8-4940-be74-4214950d210f",
"indicator--5721c01e-b2a8-4dbe-b880-49e4950d210f",
"indicator--5721c01f-5188-48d3-9957-4162950d210f",
"indicator--5721c01f-6ae0-4606-bcbd-4195950d210f",
"indicator--5721c020-a958-4061-8f48-4a22950d210f",
"indicator--5721c021-84d0-45d5-bce5-48dd950d210f",
"indicator--5721c022-b680-4661-a7d4-4198950d210f",
"indicator--5721c023-7ab0-4038-b7ed-4cff950d210f",
"indicator--5721c023-6598-4565-a795-48fd950d210f",
"indicator--5721c024-30d4-4ce8-b13e-4f8d950d210f",
"indicator--5721c025-2db4-46de-bcb3-4ec3950d210f",
"indicator--5721c026-bb0c-4ae8-9f97-4ec1950d210f",
"indicator--5721c027-3b1c-44b7-b39b-484a950d210f",
"indicator--5721c027-4478-450b-88b5-41b8950d210f",
"indicator--5721c028-cc1c-4992-89d3-4fd9950d210f",
"indicator--5721c029-ee90-4fb3-a732-49cc950d210f",
"indicator--5721c02a-ea58-4681-adb3-4334950d210f",
"indicator--5721c02b-b37c-478c-b9f1-439f950d210f",
"indicator--5721c02b-a6c8-4985-bcd9-41b1950d210f",
"indicator--5721c02c-4640-4248-b03d-4646950d210f",
"indicator--5721c02d-b810-49eb-a9e2-4273950d210f",
"indicator--5721c02e-5cb8-4441-98e8-40fc950d210f",
"indicator--5721c02e-829c-422e-9292-4fac950d210f",
"indicator--5721c02f-0f34-4522-8c7c-426d950d210f",
"indicator--5721c030-4294-40e4-8e63-45b8950d210f",
"indicator--5721c031-2b60-4adb-8c7f-414f950d210f",
"indicator--5721c032-1674-4429-ba6d-410e950d210f",
"indicator--5721c032-e7c4-448c-9878-4e87950d210f",
"indicator--5721c033-d768-4f83-be8e-4b42950d210f",
"indicator--5721c034-184c-472e-9848-4635950d210f",
"indicator--5721c035-9ec0-4ace-bc45-41e2950d210f",
"indicator--5721c036-eaa8-446c-a746-42ca950d210f",
"indicator--5721c036-4d64-4621-856a-4976950d210f",
"indicator--5721c037-a4c0-41b8-872e-4e8f950d210f",
"indicator--5721c038-bbd0-46de-9501-4112950d210f",
"indicator--5721c1e4-e370-4cce-bc6f-45f9950d210f",
"indicator--5721c1e5-e6a0-46a6-ae64-42d2950d210f",
"indicator--5721c1e5-a128-4bef-ac44-4d28950d210f",
"observed-data--5721c5b8-fb50-436f-ace3-4f2302de0b81",
"url--5721c5b8-fb50-436f-ace3-4f2302de0b81",
"observed-data--5721c5b9-5e94-406d-a228-4c2a02de0b81",
"url--5721c5b9-5e94-406d-a228-4c2a02de0b81",
"observed-data--5721c5b9-aecc-4ff0-b856-4bb802de0b81",
"url--5721c5b9-aecc-4ff0-b856-4bb802de0b81",
"observed-data--5721c5b9-fc48-483c-addc-4f1a02de0b81",
"url--5721c5b9-fc48-483c-addc-4f1a02de0b81",
"observed-data--5721c5ba-b9f0-4c01-8a3a-4f7202de0b81",
"url--5721c5ba-b9f0-4c01-8a3a-4f7202de0b81",
"observed-data--5721c5ba-cac4-4f5e-ad2a-494f02de0b81",
"url--5721c5ba-cac4-4f5e-ad2a-494f02de0b81",
"observed-data--5721c5bb-2b94-43bf-94fa-42de02de0b81",
"url--5721c5bb-2b94-43bf-94fa-42de02de0b81",
"observed-data--5721c5bb-939c-451b-8523-487a02de0b81",
"url--5721c5bb-939c-451b-8523-487a02de0b81",
"observed-data--5721c5bb-53e4-40a1-9cb5-44ad02de0b81",
"url--5721c5bb-53e4-40a1-9cb5-44ad02de0b81",
"observed-data--5721c5bc-3244-4148-b068-40c502de0b81",
"url--5721c5bc-3244-4148-b068-40c502de0b81",
"observed-data--5721c5bc-d028-49a7-a8fc-4ba002de0b81",
"url--5721c5bc-d028-49a7-a8fc-4ba002de0b81",
"observed-data--5721c5bc-40c0-450a-9aa7-414202de0b81",
"url--5721c5bc-40c0-450a-9aa7-414202de0b81",
"observed-data--5721c5bd-7d84-49ee-93f4-4cee02de0b81",
"url--5721c5bd-7d84-49ee-93f4-4cee02de0b81",
"observed-data--5721c5bd-c5f8-4d1d-9d7d-44a502de0b81",
"url--5721c5bd-c5f8-4d1d-9d7d-44a502de0b81",
"observed-data--5721c5bd-20d0-4202-9181-498502de0b81",
"url--5721c5bd-20d0-4202-9181-498502de0b81",
"observed-data--5721c5be-4150-4fdc-a3e7-476702de0b81",
"url--5721c5be-4150-4fdc-a3e7-476702de0b81",
"indicator--5721d30f-556c-4111-b12b-47f2950d210f",
"indicator--5721d30f-e3dc-4cf5-84fd-4a30950d210f",
"indicator--5721d310-48c0-455e-b7fa-4340950d210f",
"indicator--5721d310-d35c-4cb6-8ada-48a8950d210f",
"indicator--5721d311-b5b8-4dc9-ba93-469a950d210f",
"indicator--5721d311-e9b4-4a44-957a-444d950d210f",
"indicator--5721d312-e2a4-485c-926e-451c950d210f",
"indicator--5721d312-07d8-4dd7-b8c2-4306950d210f",
"indicator--5721d312-c560-4486-b37f-47e2950d210f",
"indicator--5721d313-4f3c-454b-9324-4c1d950d210f",
"indicator--5721d313-8810-4156-9487-4293950d210f",
"indicator--5721d313-e618-40f3-bc75-4f00950d210f",
"indicator--5721d369-6320-4e82-a6ba-48a3950d210f",
"indicator--5721d36a-d818-456e-9837-4ba9950d210f",
"indicator--5721d36b-8f38-40f9-afd2-4aae950d210f",
"indicator--5721d36c-935c-49af-9fbd-42b6950d210f",
"indicator--5721d36d-c14c-4e33-8a78-4dba950d210f",
"indicator--5721d36d-1be4-4133-8020-478c950d210f",
"indicator--5721d36e-530c-4e84-bee8-40f5950d210f",
"indicator--5721d36f-932c-4b81-ab27-4359950d210f",
"indicator--5721d36f-6354-44bf-a708-4f12950d210f",
"indicator--5721d370-8a2c-45de-83c1-4868950d210f",
"indicator--5721d371-9a30-4e34-b7cc-4cbf950d210f",
"indicator--5721d372-fdf0-4588-bc94-44a0950d210f",
"indicator--5721d372-08c0-4802-8786-4c67950d210f",
"indicator--5721d373-8d60-48be-8293-4deb950d210f",
"indicator--5721d374-7e90-491d-a4a7-4454950d210f",
"indicator--5721d375-a460-440f-af2d-4624950d210f",
"indicator--5721d376-48b0-4cc7-ae58-4b3e950d210f",
"indicator--5721d377-8914-4b08-93c6-4e74950d210f",
"indicator--5721d377-670c-40a3-a266-4a1d950d210f",
"indicator--5721d378-0c54-4876-9872-44ff950d210f",
"indicator--5721d379-dd14-46eb-aeaf-4e91950d210f",
"indicator--5721d37a-cd00-402f-b0e0-4b84950d210f",
"indicator--5721d37b-2b74-4757-8668-4f1e950d210f",
"indicator--5721d37b-41c8-469b-8b29-4244950d210f",
"indicator--5721d37c-2d34-40a2-81b0-401a950d210f",
"indicator--5721d37d-19d8-4cf4-843d-4117950d210f",
"indicator--5721d37e-04f0-4ef6-93a0-4279950d210f",
"indicator--5721d37f-9ff0-4121-aa6d-48a5950d210f",
"indicator--5721d37f-0cf4-4feb-a615-4e7f950d210f",
"indicator--5721d380-7030-4ded-9dac-4c36950d210f",
"indicator--5721d381-1d44-41c4-a495-4565950d210f",
"indicator--5721d382-0388-4df9-acc6-4d30950d210f",
"indicator--5721d383-d71c-4401-9c8e-4871950d210f",
"indicator--5721d384-6aa4-4b45-b0fb-4a2c950d210f",
"indicator--5721d384-c72c-4e0b-9f93-465f950d210f",
"indicator--5721d385-ced8-4127-8f0c-4c2f950d210f",
"indicator--5721d386-74d8-40b5-b205-46af950d210f",
"indicator--5721d387-034c-42ca-84f1-46b0950d210f",
"indicator--5721d387-21f8-4ace-9340-4d84950d210f",
"indicator--5721d388-dd64-4a9c-9371-44f2950d210f",
"indicator--5721d389-fe24-438a-9c77-4411950d210f",
"indicator--5721d38a-780c-4a40-bc95-47b5950d210f",
"indicator--5721d38b-61c8-4235-8d09-431b950d210f",
"indicator--5721d38c-dd20-4dcf-9930-4c94950d210f",
"indicator--5721d38c-9dfc-4897-bc35-47e6950d210f",
"indicator--5721d38d-045c-4b49-9166-49dc950d210f",
"indicator--5721d38e-dd90-42d0-a988-4b2f950d210f",
"indicator--5721d38f-dad8-4820-919f-4565950d210f"
],
"labels": [
"Threat-Report",
"misp:tool=\"MISP-STIX-Converter\"",
"circl:incident-classification=\"malware\"",
"malware_classification:malware-category=\"Ransomware\""
],
"object_marking_refs": [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfe7-93b4-4b7a-997f-4aab950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:47.000Z",
"modified": "2016-04-28T07:46:47.000Z",
"description": "download location",
"pattern": "[url:value = 'http://amismaglaj.com.ba/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfe8-1994-480d-81c7-4af4950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:48.000Z",
"modified": "2016-04-28T07:46:48.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'amismaglaj.com.ba']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfe8-5d9c-417e-95c3-4867950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:48.000Z",
"modified": "2016-04-28T07:46:48.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '195.222.33.178']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfe9-91fc-4710-907b-46a8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:49.000Z",
"modified": "2016-04-28T07:46:49.000Z",
"description": "download location",
"pattern": "[url:value = 'http://amwal.qa/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfe9-1ad8-4c31-851f-49f6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:49.000Z",
"modified": "2016-04-28T07:46:49.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'amwal.qa']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfea-dc9c-44ba-bcdd-4065950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:50.000Z",
"modified": "2016-04-28T07:46:50.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '74.124.210.121']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfea-4f14-40a8-b8c8-48f6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:50.000Z",
"modified": "2016-04-28T07:46:50.000Z",
"description": "download location",
"pattern": "[url:value = 'http://caegpa.com/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfea-d42c-44b1-b434-49c0950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:50.000Z",
"modified": "2016-04-28T07:46:50.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'caegpa.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfeb-ce68-4c9d-b78f-41f1950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:51.000Z",
"modified": "2016-04-28T07:46:51.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '192.185.160.227']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfeb-8c8c-4628-a723-40cd950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:51.000Z",
"modified": "2016-04-28T07:46:51.000Z",
"description": "download location",
"pattern": "[url:value = 'http://codeaweb.net/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfec-a2e0-4798-8ce1-4c33950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:52.000Z",
"modified": "2016-04-28T07:46:52.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'codeaweb.net']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:52Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfec-8a78-45fc-ba9c-45b3950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:52.000Z",
"modified": "2016-04-28T07:46:52.000Z",
"description": "download location",
"pattern": "[url:value = 'http://gedvendo.com/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:52Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfec-a3c0-4cd5-8b4e-480d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:52.000Z",
"modified": "2016-04-28T07:46:52.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'gedvendo.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:52Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfed-fa08-4919-96a4-4cff950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:53.000Z",
"modified": "2016-04-28T07:46:53.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '66.7.223.218']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:53Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfed-138c-433a-9081-4624950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:53.000Z",
"modified": "2016-04-28T07:46:53.000Z",
"description": "download location",
"pattern": "[url:value = 'http://mebdco.com/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:53Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfee-7d4c-4fa6-bb6a-4d26950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:54.000Z",
"modified": "2016-04-28T07:46:54.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'mebdco.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:54Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfee-aa10-4ac1-8c6d-4fec950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:54.000Z",
"modified": "2016-04-28T07:46:54.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '166.62.10.29']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:54Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfee-f614-485e-a634-4745950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:54.000Z",
"modified": "2016-04-28T07:46:54.000Z",
"description": "download location",
"pattern": "[url:value = 'http://teyseerlab.com/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:54Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfef-112c-41c1-92fc-4637950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:55.000Z",
"modified": "2016-04-28T07:46:55.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'teyseerlab.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:55Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfef-7c74-4b55-9dd9-4242950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:55.000Z",
"modified": "2016-04-28T07:46:55.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '107.180.51.235']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:55Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bfef-3ffc-40be-9453-4af6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:55.000Z",
"modified": "2016-04-28T07:46:55.000Z",
"description": "download location",
"pattern": "[url:value = 'http://www.rumbafalcon.com/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:55Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bff0-bce8-4ab5-8093-4679950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:56.000Z",
"modified": "2016-04-28T07:46:56.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'www.rumbafalcon.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:56Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bff0-74b4-4dc5-b58e-4c2d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:56.000Z",
"modified": "2016-04-28T07:46:56.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'rumbafalcon.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:56Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721bff1-1534-41c9-8726-4c44950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:46:57.000Z",
"modified": "2016-04-28T07:46:57.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '162.252.57.82']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:46:57Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c011-7188-4a90-a683-4f9a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:29.000Z",
"modified": "2016-04-28T07:47:29.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAO89nEhfjwZEeQsAAOsXAAAgABwANDlkMjU3ZmMwNThlNGUwNmE3OWM5ZmUxNjhiMTM0NDBVVAkAAxHAIVcRwCFXdXgLAAEEIQAAAAQhAAAADYH9m45tDKS6/deuEYqOvloM07bbUy3uM3W0dsU357QmhZygv+iAAV9LG/lHg/540U/iJH/I/RTF2sH2FK835t7aTD97kPDgZE14QdNRj1WwgKB8L08PgQwxcUbQFw7ggXNKSb3QsbjJejn9UprvRyskexfCRVKt2DhJBcI1aWX3lkhlkS4VrEpcJaiM7PKi2aHiMXpFiUvuaRvtk+RWLdUXzCg678PsxGm7/94eI64/eRoF1qm4D26b7CThVUs10XZJtOk2/+oYjW4BUII/WqqCc7jbMnaGlrlwcP8gng6SlTJf0FO0oaeCgy/Fz0oogPRkstsJLnyIXT9/qgCKEMhHVZeyGLhX1zP5+Yl5Slmg4CgKGZ9RiwfSNP5GBuBJ5k2tqCduzQJDhYeZXxM9ybaYFxhqIpfo+hG4lqyYFT0QsITXV6XHPX29ahzxV1eANk0GRHQd7vuiqP8s0VhDPPGddj6pns4/3k9cSB/YFBJSJ4v4cNBCDzwPpU4PXjKZuCUx4xA0Lrz89Lc/izUXPo5qgRY+wykvzwJ8lTXO76tnNBbgvsgq0DZYN/OcVZEvu1zVx9HBqermfJ0liWN35XmZzu4gTAkLmAVUXQ9GJBvdK04ZMEG/qKwyLg1JYlL9xfNDRilrRLHE3PK5g/htpTtekKSwyC0gilO0wDVi1VYN4qY1u8EFCYXx+6UvbbyROjYTJZEz9yb+H+LwF+WtsLG/b2tI4UZsEoRnCQHz5uzxAE6qCnf5BgsAyKnvScSvm3p4OrN9oDei/EK2pDiK4XYid0gfO7iijD8WUF6yI6lAz7Q7f/jdxPGG+g41HR28q2CuwPgNLkjiXoh9khR6bCgsVwXLhiv1S1jSkY8G6gJnpvTL8L/7R3Oo5gIxQOaRao3eGwe/9lkbQ6rY/9L/w9pEiV4H47VRUwk0AMSP8NL4AzT2EQVaprSFyB0pOX4Frwywcd3uOFhXPfLWztYqSwsRb28pleF8VEe2KmQAsQPCoRSuRUPfZV0fEQuFnpVJ81RhQER2GiIVEePqY+H7YfloFWiA+gI/r+a31jIrH8Qwfcbx8+6xzp+b6uqdJbf+qOWj+11htEYMAwwnBHTPvK83BvATNs8Dy6cS4tgSxx83MwGMaKH9rkqgbnSmKHhD1UntSJkC7Vo0n3bjXHPUXeHnmlpddglucrHh9+LGCio4inq/egFoX5lr3xoMDX2DdSnF2zCq6FZVOQSuEqO24ImAbcx92zod1ouITRbBSntXTEwJo6Wc1syZs1UlQkVLL/tvoh4Nm5wU+s7F0w47JdN8nr2I9ciRy6Doa8m4dygX3xEr7pJN/724F6nyA6ttDVBCfHBpN/mY5kvSMYdBGrNqjKdby/R1LbIIueIaO/Z2rTrgwXgrW/vCSs1Q1R9uJ2A1oUeQmX5p1/ozZneeRE0/3QuGzYSrP4dKQW7FX9xwsnt6PV30HmftjZ6dpy3XQ/eBVQSlygRgw+Lmbl82L34EtWMvtCLWX5+8kNSDyJMHBZD4NKQtrpz5xh6pjSV3/8Ns+1xTLkhdf3/OwjUPGjTzBs2MMbs0cIfTjYagIiNJKb3MM+j9GdCql2Ffyv2bR0BPQsjis2nAIGkamZ+OhT3vtMXwLJO5cPP3BxAJMB9Sl2XPDYembMgerbTqgzRh3ONCAt9Mzsk6pFffsp+pEC1P97nlsZ1FDsf4zovu6RU4jGancuISqhdBlnDhliZv0b/XikcYd6nBumv0BO+CBm7dltedUQkAFX36T59WbWANXQo/cagxYi4irYfKmLJH0uQSUwmLUn/7fivTAnJmjze52J0wvROeVA9aozbzKQMADNpyBwMjs3Ds0YVQEZ7g53tIcj9Iqx1BLYg1qSxLYpWP62VhCZmW/EzJyjUWdyytB0gr4DJ53eDTOX1rVLH5rQo0VqEtEXfp49JUJPJaHZHtfLU1odOK7DgGSZscBkCMoLEBQv4rHzzHFZHRjA0ng5uEyBxNsHALz7P/znt+Ub++jSSGfOVcubKFGAwZjQCyI7vOmvmY7ZaKxtdxrtT0iXt2Py4qCIZhetMTvhyrrZH/Zv3ckcCAl7uyguS/Eq67W2DEfn0nZO24tOInJPVTl8Y+s49OEeSDvZtpaaHt0udM4x/H3ynGKEJYQItnD6LQxInhqctfGc0wYc8ndWZ7HjgmpEENFLJRzF8WAW+fM7rlE4aJw2S+iS709AvcSs3ab7W9E0wFSKHt9rMYBThsYA5I5NfdQLJUZMeQ6xmkYqxOPwim2+6C7OHEYg5LT46w/5wNAXuavK7/EaoS69Dw6ND8mSo0ETzDcgcKVA3335y67fNU/8WkHPnn91xcIvnM7iFG3PZnd+AWRTpCq7Ivlfyk+b+QpJvq4iI4qDJgEptmQMP9fOb1vzewr/tr7Cz1MYmJV30suxxx/LjjdXDPb2cjFxIDVX/PWUoIfo15g8G5pecRxIJxPC35m4YTU4TxZ5rg98QnZk+s4EtRoE+TXoZsNHKNS4ff1gPxeVOcMiRmrbRUfQAXCMCWWtBDyuh2JTDec2vSYRLFS68KZneeqVR1/tJVSVDOuvXfWoUeVSzSd6iD8j8xmBzmmGHCbyoeKfGZhTAnOztJVMJ2px/+9QKks/69hD9GYmE2GXZNzDpYwS5sqnY90vxQPUJDuPIBQqU2K7nolUIccB9O69UrxavC8hn7pAuDvcGK3iqUjaV1yh46mIjT6V55obpEnd3bxasLvahaphRzfnr+7mNGWxH5YzB1qI0szvcFkugdwNu5uHrIuoR5yJnxGFBoD5Uqn1abeejfgXb/RK+XvJwrb9V6HdpthHu/EV/kDgG3saVEQ/UiqNs/F48emiI2bNH3B+iyMIpbjPMWtHoARUf+V4hNY00ms7Yf+WsMyd1CGsNuCvaa3DDPQOSDyGwWbXprW+UV6wRG8u3XOMkjSmQTEs6nZMnyMthwdQeDAzcJUM9Qdf94f0PUiFtICej2Q1c8NCoFxDlioEGIawppO/1ZtFnPqu9uT0JIu2MnwqE0KL7lMAtyU5cxhTaWQMjnoOYXAijVL6Yv/9Qxs2DsN/g8hdO3hsv2hybD8RSp8DFLIw8vlpYwEtdb6P7cU1HSNCy+axQw72rP1xYFo69hCz0XUyL9UHN7j+QeTNuRQa2VFOjXpgDu/s02zGlPmJEFeRHL5p8ZQzuDYQY9Im3z/STu8K4XLQDchilUWw8ZjNFNa3Yk2D3ahgHsBMmFhuvpVbg5ctFy+oquvStKJnLYwmPek/VpZ95ELg7T91nTidwImJL6OVoLMl2klyQMmxn5IauJ0ebJVhV7moQxKkU57N7Fvb6uUfuJ+YQbUG/ctVr6hN7nhKHta1P+JBNDV0gbkcV8mIxxIWn6wckM2QCPSMu6I8aQuQp6BzVub/HnTLkLwWtuKGMiyNLSpkwVZvM7Rnfp0OdFBehNNx7yJKmjQacjuF8WkDgyw+EN+VMBpKPim5UpqT0SyX18E/GrbnkMnviIs4G7pM79K8oUNttCeFAVl4YMn0rr89OY4T2RxlEKkg4DRlLZt9Lgr5GaYt8Ojyb1gBqkqu17AwgrzihOeUlYQeM7+Nl3GCom/5NoocHGGgRmNqBj5mlmjY6WNfdRBf/RsOQniRa2K9XGgRBJLJXz5oFlFWC4CKjlxGM6hj9jPh1ENH/bZqCmiDS4EqAnicUSqca/X56ctXPTzo9Hau3vvbBPPtVxUqyUF3zn7yNE9OVEm6oImjT2UurTkPF4Z02sPPS7MCz2uCCMw+VWJuY2sYRK/AfOd/c+WBHGQpIlX/7RiPdFvyym/5PHek/T0zPVjrQ5vh5ONRmBcjtlhj2Ns5PJdMCVxUWt5NT5eVTS1zgxH00CIDwb2gRBuuJHSGmynrrfF07gDC7psLvzFxcc9K5ezYD5ROZTUE
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:29Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c012-7740-469d-ae53-49dc950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:30.000Z",
"modified": "2016-04-28T07:47:30.000Z",
"description": ".js sample",
"pattern": "[file:name = '0011211_00975.js' AND file:hashes.SHA1 = 'b6857c68c083950c44dcb3327243a5ae76dd8857']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:30Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c013-6ad0-43f6-b2e4-4aec950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:31.000Z",
"modified": "2016-04-28T07:47:31.000Z",
"description": ".js sample",
"pattern": "[file:name = '0011211_00975.js' AND file:hashes.SHA256 = '469f963dd30678657f3cdf748495efc52b33ffb2f4b858bf8757b674d1af39cc']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:31Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c013-a8d4-4a6f-a57c-4fdf950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:31.000Z",
"modified": "2016-04-28T07:47:31.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPA9nEgvrPrPlAsAACoYAAAgABwAZDcxNzU3ZmUyZDg3MDY2ZTUwNDYxMzc1ODNlNDM3ZjlVVAkAAxPAIVcTwCFXdXgLAAEEIQAAAAQhAAAADYH9m45tDKS6/cipo6dKcmrDBE/afG/OwzwWnlkjdyEWQa4X8jHN2jyTIgOnIRAg0vm7NqQISJBPC4UvIIBPN/mq9Wgb7gW4LX520Jmvj4/xm4HuKxl/3GYa1Fp2rOtbZnVSezQLlRv7R22TH1GnuugmBsYhqdXfQWt//Lk4dQXfmJFtCPV6qVmHrlNxfw3t3E/5TjApqgROQ1QVip5nyNpL/KoI83YibeDEffHDjLhm/KUuxQWoEz7LMoP4OzvadRQuNj03E+XmpYQGvQuQKRM+Uta3Eo9fSC9tViyh+E6Y6r0XecEzNT9Xw021SiEstdp1MjvHjad3JLZFElr5xQjdIB5zSF8TEwNP3Vjayggr5r34CDFfaDtNux5gsKMaDUpQq7ELmzX7ZiZZDEgA8gzJr2AAVrBLLzib4/3G1G6400l0lqO+m2d7v8jGyeaczgto7yk5MaUr6FoJ4h0zehdV+CJeBJAAOzdcBBVd1ozkWbAZTz6A3u9KRgYRweL5FBkhAtWSdgzxDqFO/XS/f1v98oV+KmJVtfP59lNLh9i9AtOEMuICMvK7qHH1W8IWyN8xZ3roGOCfm0A1wzjqSQHldhl0DWeTLWQP8urZwix80AP5wy0DbF7YxMEXieKFpP8C/1kyV0pUEhj4XJHcB1nrwnxVEiJReZagXBpHiqW4rFHDhT/M3HOOsuIjudPTaZ2muwUaOQeG9ylzarRvlF7Mks+zZewshP3+eGTCbYuNz+yZWJFCve/pYSF+xAKK9NS6ofiV1WB5k+6GdikwZOK23/Lp9DYcWawAqh1Qr3ZwxUo6VtfDk67hpazlu+0Y4MKSrUmGWgkdcY95SYvzrl9k32W81uJylZI5zoijH0b4Pmw/hpWkzEoA6bDBqRF+GXXCdZvhyn+tpwJy6OF8EVR7/xqbR7x1cYthjblSNC+FOCnZtCCmE7VtWOHENx+9Nwe3W7zjVs6u8S8WdNPQuJDJYdkSQkqGS1yXg8CWIeHLt21LW95YVvDTPH97eHvHDb9sZNQ6UVJuA6vbNL9gaFXzqSEboUJ3pSgjLEh1NIEyFwzYUL2HfzZ4hUHzNBAvDohtasb2CMEHFnJnSRzKwaC1YeYsHm+RNK1CdUP7sYSa8O6hbUkx2V4M8caVBOClSuvTiFEBrzKfzNsduREg2Yp73cVYyGArX8+B35GfMDRXMaj77uPprev5MMyovJwVNycewx+NT2gAXqLk5iCaIm8cO1xSD+MPmNu+lkdKSabuvWb6lHfh6S7VtEPBGliqaFSRZHpCF4lXDOjpJWqLD20sJ3Ci0Rghgb9Q4VeS+0iaR1wf2M71dl1lti4GSZn4wpKhJYMgLqYg/LNZb/wb6QnirEVoq7AvY+ho++eGeIZTKbHSKyNTp8kSD2dLDOd+vjfrBJw/l95TrEPGB8FiVueKLzEOfCByps8HFSaLS8acmqpbBV94T9Y40IkoJ92z9Q+UApPKuX4s7t4bCpOXTOH5aT+jepgVVCz9b6bNbN69TYY60Ql+aF8xlErPKHrnLdIFeZ5vE0TfaX5Ybz0h+4LS8c4KlIPkdA14vAnCkaUIWtNVyVnpoWMbZTX+SM8ujUzir65+JAoE7A1dIkxlGBUCgN2RWsGC45VqCL1a/+GCgzgyLjFOn/wNFeQhC8pEym9g6bfORPhEaKK5re4r2n0hXbgE5Ws8iDFe+F1BFplkLMACaPQJQgB3snjWWR4pOjzrIVTTNQNsTJhXHUN34nuxzax4FqA2jS6GPYLQHgaFtw1bsz1vODhyxxx78Nd3FAljddCXK6rgVZicaTyhelm44PI1ajysUgdVJrTSx9rVW/ZdwIxGPRmlh0q1DhseL05VBB5mRk5YFnfGMZ0KqoGiVmGXTrC8X0gJ/O4uil+TvcctnSlpx8vyGllm7XpFxmF3CJBYIdykM1kr9XHJMgnb1bVX/mnxnEm9PWHMco7CjFpNiUJBAMQykJEgUTNZZnztNnAx6v2axz4Z95+r3tjjmSTP5mnz1TfnBte5YREs6+VDpCEVdz3QkIB5jxuyIEZbSFyI4n0+fQeTCTQZYkB6LlkhyTkylbY9piw0EK/Unx8b2oBnVUNDhtZjUHfpINlHDdMbzgCVIc77wlgyFPBSaoRPpke1gD74iRexXQcfHoBKkh1qov2CXr57YwsZSVJJRS0ROogBnj04/RNTKTZM9hmlfZSQxf4RnxoLEYLf2pYgGjExIz/so19/HaxNR/shK/dr2Wg7O/K5YQEOQY21j/BuARhxXoJyJ47W8dfLgjj4roaD/Wl7SnW3z0k2j+4GfuK1LZJ70rYyZos9b0CsU3eFm7A/OcVQJxewWbyEfpia3ROwq2SU2O2p/4WqQNxtEca7pXaAgvcyUdhsXDp8tkRo6aR2AMROwtn7sxUVDuqf0osNQX7Ygja46oMOFoxjiMSOFJWrB4q6uIlZxIhtExSxJjkTB/LJYI0jK1aXvGRZd9ZqgSSvz2CcmbbWFQWolZYNL+Quj7qjPTTQA9MoGSb/dSd6bfOaqVwdP7WKS9tyt3uJ0OGqmsH+Rh2V/DpTERKj+SslouvrwtbD488x5VgcpTRrCnPkvxTwB6R+quxTVfXN89FZxhSxzKneNhgpuVRG1zXKVf8aPt5EoKHpaG8YVDmdQblSWgGBMs08BkfzAPUebFnq8Lfbp5DOIw0pTjELJyxN4Ymdm+MXyoZXVXjAFlDJn4+53c9TQuYqq+H6AJDyxwtOzn7sw4ZuOcstf1fc0D1b3osB1koWHcT/orsyBDqQJgEG23RcTBlgMw2oGb08eADhTLRYYauYr1gSkjrd84/MAVkYtihvrktBRFFOhRGOR2SegwrQf3yN3DQGWs3Dp6DgmiX3ClxT7jlKd1eezQd2572Rrn5k9xypAcs9C7addZ8znPlo1x1NMniTSZw2uFXp3jrVbv4nIyiEc1pi+64cdLo6t1iJlKWlUVWOjWTKdofw/asZVU663Pf4nCZomCUbLPaIdFGr920gtywwiI9+gjFBvwTdB1LUCEwJdEDGk8PxrFZDwI7iZmn0BHJmopk05CfHRIcOfbRSuU9IslASkkEPtMuYfZFTAOxEXG0x2CifQN+r6AZVyQ4T5h9v0gyQ2aDWV/0uCYrfJFBaCLMJlrP43AAXZVaXlmCy+vo/iw7LbiFgrtrHsk5uoLObVwAi3rgCsarS0t4Y/dMjuy7XpNjXDF7DI9QpDa6FmTbvFjmGRZLCn5AuF1YvDmuTfekRCCSsdWN5DAMAKADCaqqGqzAtj72xwR5WDP7xR/to5PvYxBmQNKow/yrlzmJEE8/XOrxaGhH6geUFJOgsM42nbeBTc6y5s+b8EnnB3gvu0ZgVjxfrJV4ddFYz6V2M0WZLYRj8tywIamuMxvlDYdcztBVhysCiQzGNr7qEijSuO6VbY1xcWitm4aXIP1KWGq0ZQRYHQ0XTNJj1Wz4oS4VH+7r3MnNYdTcStSwDpJpvM0kclooF1nDLq2vjXj8VCHisTFTyShgyeihXwxlLlZhXQyMYID67TI3u2RrOAfcqsfh3lM8ZlSQNDDfJ+VaId0fI6j0l9vQuWhRiYTWAQdn0S0sL/70Pp6WpmJyFE/fynnq4r5WNZnUd1NoEHpi5wCxGTZXogoTrTzQQU28Z+BK5MmqinQScIqPYGrJ/RXB3FqeR7Hcl1idGiGFiA8cal6P1mUL2ht2mAzRypQIQpb7EtT0+ES9oTIBmsrKZ+DDAK3mbSaY60mWU0/gYFOM814mu3tbRYUZmN696ge3zlfTcN4GssCDdfaCyXaLeP+xIy9fIwTpyw9wXcMLZxWZ5Pr1qH2DJaUw2Q9rPnEfHwgQsMLLncMI6FxhrJ87nO4P4K9zc+M4mQfM7URH3XVtZCRM9xFOvp8oL8C4/Sj9rZ02GCU
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:31Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c014-46dc-47ee-956e-4b3f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:32.000Z",
"modified": "2016-04-28T07:47:32.000Z",
"description": ".js sample",
"pattern": "[file:name = '0012302_006851.js' AND file:hashes.SHA1 = 'fcc3b24f327807f5271294e7b31ab90587f9409a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:32Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c015-6b28-4748-8db7-4ae6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:33.000Z",
"modified": "2016-04-28T07:47:33.000Z",
"description": ".js sample",
"pattern": "[file:name = '0012302_006851.js' AND file:hashes.SHA256 = '54a82b6f79fcf1f17a6c41cf6a4b1ea2b6ed47305bfea71670599303a5a57f41']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:33Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c015-6b94-4ec6-a211-422a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:33.000Z",
"modified": "2016-04-28T07:47:33.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPE9nEii8kTSlAsAAAkYAAAgABwAZjNiNDkwNGIzMWJhYmVlOWRjYzFmNDkyYjNjMWIzMTNVVAkAAxXAIVcVwCFXdXgLAAEEIQAAAAQhAAAADYH9m45tDKS6/cm2AwgT0ltTgnTohAqqPsc7cYefxoKepqW+FyK0VvV9E19P+LHaXX/lfQMD2mRhl18w+4IpzKWXhLHlurFtzIDpHCQyc1SQU/Ufd7KE0JVmTXTnpDz4G71nemsPgvx75PY4dffeEZJQSsyWYgimVAjGa+cDY+3WFH05Q6XMmJIITCtgRhHh70zHOnYr/TyrDwJ6DuTayE6oQGfvpQwKTXHV3DwXRIME2DRZpeAc13CySzk2djE8CO5C9JIybD4tnaAcZ8drHK7hxObcbJHyPqMVukolhXospGfVYtI+fsTPlkX/MH0HR71iBqjbbpMsLZeduTT2l+qxKRv3GbyVRmq/giD+tw/p9LESQFU8z3iqXdMgJ7FHR7KFkmnqvIfTWcFbLHKJw+ErF6ITkIlXBfRE9vcG7Pf6ystr3tkYxDckbKqI1iBteReV2rlpf8CyZANBlh92hBk/hNw0MsLzLR1KLAzDK1WEKJUw73ZnlTPGTAPk0fDGk4sp77UVs0C0ZRVv4FGVPZ4nSknyWzn8eRvLKHabMV4q9oaeb6dG2d+uInwebs6lV9qswyW2yp5iSK6txoA6YEQJIuySMyDT2nm05PGXRt7LqHES355cw4P0Hrs/pguRyhwCjB0dkFiClvvzlEaOfQhaLC4kSyuTd1n4yS0knVsVE44yVDzyqGXbV9+lGEP4fU8FJhVb8NAeqqlI9Ob4qlhGP9Pfo7hXkUqXldrxHDtho6SfJxWh57MFiXLuzqeg1HJ5JmWqphqOd5Jcw60u0zrJgC+I5x43ZhBM3gLO2MS0c2h2DgdjYmtuRy+Y04VUTfWY3krmCMmaYARNyUAh7h52NZXIw96/yvMhc6PynkiNIzZqYBKQf3G7x1z5UPmsjX52uQDSRIQYN2zbJlJEM/ETtTuIEljCHx1qHs8gpCfKSnHoo8NPcjNGGtfXVYXEA6CEp/mC9eS8EnXlB0tOH2J84/ykuc+fpSeYQzzbxKLmB4LVPREK29CHdMBscOAr6vpHANOfqMovQJO3V3R3SDsh3d+QSbR3+k7p+laJSKZXjKhtoGfmFFNXNtuzpVU//j2i00PRZvkiPQUAFGilwyO+VDxkoLAeuZzms56uZVYSlho3h7gKdTRz178xkMznEgZaXbRm3PrGVkm5I2wB0/1f3gxh1TSLfonnb+Pc+54FtRzzMbJ4Ft5kfi/rahjFIZldQ8pR7kBrdvkVWaGfdM0EBC+K/nIuN5D3fPoDWMBjhNk96wQz6EKNLhb6j2scivK+AGO1zYSOTwnW84hJmVrcO9gveVBUXDykm/ZCySOCJCEHT3UjpjlaKQistkNmWlpJFt9aIzRfe/vElTQL0uEgXgg4oC692YxewiKbnMI4eYy2crciVjaUnj35MUVQpZ4QEXA6crMx5ALm4hqPRZcDbnVrFQymYu/s/2FSvVWNkmE+V/spuKUWT71ChND814gl8knTd3XTRLoy2NZ0f5qc1HOtBPU5pymh/RtgtuRUQWsV0l00lNTAmmdi782dfWznj579nynAakAlD8Nv+SUqGRnzOpvzEP/aPN0dTGr55T9l+/mA3/CVqZJqgU3X/bCxvaDxE9N2lOU1USeMryGhWZT79CPIjo/oDo/s2HauvpXQCBUqPi/qBX+SlZKOMs1gSL6Xd54+m+AN9k+MDr91M6O87Okz4aYdJgSrznYKmg3EuhBMrn3/D8miUfs/1HRasZP4l2AUz8YKEiVFJvZ8LSneMZ50ISW0Q28InUeCJJlyazXRRQou0TSbyKdDhz3l8ETg1qV+ZFneR7YACfLlF2twg3jcWXYIFDzqeMcknFbp1OfkcpzqutUnfzt+WJLGBXI0IXEzbgNf24h1R4oQCTc7gyNBOOb1oJXbbGqwmIpjHoh+i5JmPLBM8EeRzMwCmchH5wklQj9Ncn2rdoThuA2BIvuva/AYDFnsc66M3mtQj4vwIqprxtfyrWj5oh8hGLkjb4uW273UQSb/4rmVCSl3yNNQTXLgBqUpdzaNgNdZpUducgQBUEAG6RJgTuH3UxbuaN0WVy06g5GdHYQ8qvJHHxTTAn7A2tmOMd7exAsGkd3KNEzaJOTagtq1A2XWTeOPzYJ7skIRxsnpLBamyK8RYIlbFhWjv0+Sx0eeHcPWDQ9kxMQnXC9AaWwUiwPPuArRiuiPS0svhv1fc7xClvm49siQxTqa3c4rgnNhmDhDL6cYm6V/SAB21GNb76OqQPMeREO4VwJwkZO+4XE405AxnjVMSITOK532ZZ1kW8Z0gOQDwHsyZZ1m4ffhZN/oDQSiD9zogoYUD6B/XB9lB+UA5iqScKbkSaqLwDQbkCvuLMLYvTXjlIunGhEACFiHAgFVbLmxbPdcVWZhMg9uKf1P1ESp4Od13f+gwbv2fqqFEP2FTl1dSCLm+rs+zxJcNJydQXkrUJZQyALnOmlxGzjRan0W0u9x+HjsPaxEwWqAk6mbTtb6VxMb+c7V1+Z3DdjV0ZBmsMTAb29DBzbMJS5V4KMI88+nl0E1NhX8t7H1qvbMhPrNqjpvsvNAC9ZDO2SS+Q2n3rHJkcALkwd+me1BInetD5MeTfRI6qRAuvaTP8599FLqLJ1040rkhkEAu0xGEME8FDA+gELaxoOpm/zyzcIzv0nLFWV0TkJtU2y8/nLfX+EZc5EVU+LxhfY7W5LKKutMd5h2aHuj2U3Yx9ExOSUQJK2W3AAoCUqOwgqlh0hVlrfcqwZwh5hPWbRwKgPYLSzsx8yr47DEYn+MGP2deyixfVS2kb/pW4dVuxvEqrROmchOai54kpHLS2SDX9Hz5kyWJBZRAfSAMRKEMaVXgpEUmtVR1/vK5v4Z8jbSwGX0YokSXninoUmFScytX4sF0YovPG1vJFGIBzeMNgdLPGhwBTq5YliJdTPydOf9y129OPSNH6uXvnj5efc2VlydQpQGFynoBl+qZJvFIOimd+AVV62pVIDq3VoTwSve55ptj5BdpgIegtuwCjms9gfwpRItiGvUkuRX6mjF/1BH+W4yFycayqT1C4pFJcDYYtaK+CWzDXcgjlguRhC3+f8lfxdaOiihnG95Zwvt2DeC+jFFazcHfS6uEu3VrESLld/+WT+2MHkU4tj8b2QlTPLwqNhB8sdYR/Dkz1YX5SxuQuDGpK+xaDzQ7Wxg1KtGqVSr9e1XFYfCEH0Jo7Npsh53UTWIK+LXwiDvUdgH1P8pV08sGwyBufbGIgu2D8N9UIvjbSS6fGt5rZSbso1UecFv6hC5ij/4VhyLRCCopaJo0fNtIaREnx1QT+CtWvpWzKF+AKsNayedKEJxF1+MHrcLAZML/WpmWJd65iu3VHgQChdMKJLiJhAiCkbOTNdbmu2nSiZMLy6AUSHQ0+j2RSz+JlaBVVpo1h8O5XfQ99j1np3IypmlHw4dl6oslaJdfmm9zWxov468NkTne1XqMoXxC8fhlsHcK7rDze0wOfH/E3qCIOv3WNNSK3ydOwkP9MncwAmC5Tar9R5XaokZ87flHd2EJ3nGbMBdlPX//pL5yhhzM7i3/O99tyMgCJzUGkZfUWbJPxrnRWrJxYJ1+hhosqXmXf/Slg/qLI+Mpy6GZLdIE+hu/i8AyZVli5C//kH5ZvzG/C1434Jn9Cu+OByz9HJBy883VbkOWTXHB94fmr0XK2UlJ47p1JwaBbeR+kJ2eAjjXt7tPjiihGHaRDuhbITtFehtFD6neb9OgBE5RnStTUOCOKAq9Mvn/BbtM4TpTwisiSexRBwZBvrSNnwKfOfIJAPlTQfWnxbvftqRZfsz/m1cSrjotn0KeJwGmdcbPj/loW0jIjCsEJImCoyR6m9T/YY+NAtpPbICdC3R4NW6vEf/dT8jb8QNl/WA0SkKecFvBCssM80pPqcFt3PLzB9pDr
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:33Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c016-a5c8-4888-b999-4ef0950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:34.000Z",
"modified": "2016-04-28T07:47:34.000Z",
"description": ".js sample",
"pattern": "[file:name = '0013409_006382.js' AND file:hashes.SHA1 = '2b184654ae31004040cccddf171fcb66fdab6907']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:34Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c017-f300-438c-b9a8-46db950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:35.000Z",
"modified": "2016-04-28T07:47:35.000Z",
"description": ".js sample",
"pattern": "[file:name = '0013409_006382.js' AND file:hashes.SHA256 = 'f92fd3ad5f4476bb9aa01228d08324a78fcd83fa767358a6fb16070f1233fc42']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:35Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c017-f1b4-41f6-891f-4bbb950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:35.000Z",
"modified": "2016-04-28T07:47:35.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPI9nEiS7wwyegsAAOUXAAAgABwAMmY1MTM4ZGFlNDU3YTBhZDQ1ZjViOWU0ZDY0ZGFiZDBVVAkAAxfAIVcXwCFXdXgLAAEEIQAAAAQhAAAADYH9m45tDKS6/crKwAeuwR0LzSvDdJT8GWp63anz36E03C/wbjaRIwH8HYJ+uIa+th6cur8ya0aJGUEDSztEZ5YbO28PlnYroLcFLh2wl34vXGI9qiQJ1vU0B355c6/LvFq3WhTO78i7OobwMQEzmtAvngM2RHwFP8Gh0Get898FYFqu0n3BO6LToqpXAsG+GC/VOA+OXqUamMFwVRZYSgW4wGPquOqThUSnGj2lif3mBd+RJI8zOeptHmAPi+JPSMRgj8NcVhHB62KlSfz7Q7rLM80QVlQbuMJMzCsyy2yppDWbqD0reHtEI0LSYgPRbzzCJsIqlu9Pv7rxa+uyNpHN394X2Bpe+MBF2h+VZTa00buV+H4fMn0QnWqMFdH1Rpqe9FvXUABXmD3QOMjMAcWZN4ias7O/2Se3HmAw7jc3yVsg14QD23GukVRq1BN/E3ky2Z/V21SmVthSo/N2ZW6pBgCnEbVDyUntHI27zBLO92wV0IQr0Sg7LQl7lYjkkbx/WdDgru2ggbNhQXp8wg1j3hxM2VOEN59tsmmADydnuV6dT0BwI+yJo/wvm4bHMxx35Gj1XDK1cvEm9R37w5n/wt+cxdTouf9ebOOAo3ds+tQSS6vECE0Zy+GWzwNHLLCTToXlNdOGbZK4APAyuSCHLf5nUHoowkrAv150wrQtv9/xv2y0FP+a6IYQl5A2BfC9hm8O7RxKDKulmGbL4KqVjbBY+gpZiP0n4hxJUz73M5UFbdZgtjDX/ntxo+JgKmmlcVXvegLE9uYWGMtin8aY8hS2Ks2C416ouIZ3UtK7JaJoowV1ZiN0fkfkcJVxFQWP/TC2Lw+HiDNocvtGYKtP5KMxw+40D7d2RQpzijdbdJS8w6svc0h3xFRk9P2TpeQHGdL9e6P01AWeDw1e9rCEQoitQZSuF2hGxJd6pKOtdk27w31J8n7P+77NYCCnOOhMRD1OQUe8plk9C3CJZrI7VtqdO8xV9rXg07cA3Hur74Ebxn7aFDUcRg+4x46dNtav1LtFEvS4JURHLKdXjlIkmC35o0SD9mRKsoQCLACVAhOSvb/qLzwAoH7+QbvjpPTY+1vzvMYYEKfPMBpvWvIyBx/nQSaRAEMo7vSa858qKUAb/jR+2NR4q7SShrTM8FNQMCC3mn4j+/oNe2KFpGYkq4jfJ+9jtIKt5M3NHymuAqeFid1QEf3tU5l23onaP/k1dSIkbmDqDCA0KetfCXlItRE8biGe1qosi5poFAvDuu50MyTtFMs5vemezXWMvAz0hGmuxU7GE1WRBta/JV8i7lGt8BxKByLBr0O4nFkGixOBD0cMt72P9/7dHaHSA1R0VrZ3OkAnUo/KR0+71zsRRBlBeHOo0LzGf+zBu1O1bht2fX+VoRDc6vX/nTb5grL36FjMj6MqxfH7HKvbKq3s2KMG9tsUzIZxFfsEav897dOS42KyXIhPrrG3Dw71geRseax+ka1Sm/NLIpp9nYwcmKy/YJimY4msiuE0TuvBNkR44HScq8d9C0Lom+BBKt+zwNx3BWPN+IeltfmkPsCmJ9JgXqAe7k5P93G15FMfC7RrwFMqdB5BROWzf1tRZ1ge8KezuKaOlOrDgQtENiA2X1X2gfN+Y+4UduxOFyvT2lyq0edv+YF7mL4TXCWmRih7kaURDHndsB7fQEb+/VMv+ZgEO5q68/MUE4BSCmsxj5Vf3nGNMx3fdXmGHXjLKcxWceoltEoRl/3Q5O/cj4mJfoJDfFgu0eTidkmvOjI4uZt+2qMfo4iZzom7jNktkX0E+vUNF9SBiFYRpDuu+XEkBbYDyB2KzuEuZXVK+J3WcUARKw0jGorolmShZnp8XTc5A9XGbWBscs2EVoZYW1k9lBfAOfzE6D3tJK+BCVSJZWw7bxnl0S/ur2WQUxqg98fcKT1fQ3t3EKMV2yEkYui5ir+3OCd9oG/c5MDb8O3Svk0ANCqf1usrmTurY4XpkOPS2UySAppsUPw5x2JCz2LxsafXdMWxxg60xNctA2kRZ/SvE5ajq5z635ICBl4b/kUdJN2XPO/SZ2oxCQUu9U3a+NslKpK0gi2U0FVnQzgDsDzMxjawFGKvlHC/dOKM+CoTbXcut1wF9Zpflaowtab+FPTO+egAag+DYKM9blT2EaAighibIWz4E8qc1r+F0Xl31W6HGGGXJobc1EiZveDs6spi9CkxVFpu8MMQcXsKE2yBMvJf5v6ffSfhVzPwqt/dgabyOj2f5SnJ/VLFoD6Vn7OuP7JB1NytbZSIsXWjg1wUMrL39BWMBdftun6S3EwJTnIBY0nZ3Y1otx5GBCmFqmU6fZalR2caP+oL+2k3TrRPrAXtRwwi4Es9zrf+5k1nKwuoP4CAvWmfRUX51n0t/Et+wdt5t2ndyNx1QiTp0dk+8Gp6e5ZJ4bEN3Wit6HmmmKUe/T6tceuoJwwilWMd2HK5He7+heI+pE9gxM1e+7pUSeeQDcznkWLO1A88gC8dmeQWLSLEmVs6SiYl+rNIYG8vJc6RgUku3cgh4l5SnACEEMSzcG5xZOcUYYjtCSR6Wq4kxtXrOK+6XB0P8EkSt7B/QkLdLWl98BRcf8YnEtOGZcBg+yFisfns+hXjL5PM3QI/VBrUQeqY6kAoTLgsxlcd8MJdsz/eksBVEvsDH/Ph0350eE6C2W6oqzdL3enxuHpAUTcX6xOD/e8y195imsIcQ2Px08mVrS/DqxucZSpnyoBASM7wYWtnSzRZatQ+xCd5MXLDqdWXPAFNPVKzfdcD5GCRUcB1r5ZUdmEo9mfTzWecwz+d71kjWuiq4X4mKnYRPED2xG8SrYaa7FI2/BZg8oYYMmXRs3xJO8dTy3TPWJwxiF9zrVl4EkGEcYOc0FuEZ1FeiFDFe691h65lziMf4yOr2SCMjSgP7kUEca6p+4jvEPFnvJ7FD8WU5GHSnvoqkZd40ja5vLEHoUW43JJUQ2mQHuLt8Ar1+T3BWDznOChLzbUqJTfLOaTq22mogncLE7Et1v+4qzyfpMm/4C/2lVyVr984K6jgvTv3BX70ceoSiVwZ2x+T/GvyHZvx18VlDTGErM8xyHcbbRi5ht1tcuQQT+VHmWBPXjqepTc/pJ3Pq82JJqJCXYmyD3NTINXsxceHRiTD42aSoDMHs5kSdT+qQ3jiIwsbQNwTSDx+FH/x7q45Cu2w9GOQfv70UViyJL4g37Qzm+vAUXSPDnXm/HcCTJGUEv25b9O0UbHnpL+Snv0FVqzt6bHk5T5oEH1CZKK6yk2vgZX7X/oLJkZFnFiSXjrDFC/SXNMDzLNgm36JH14i+TEVhZBOGvUiTmoNLKWZfAsmj4w/UQ4zs/nlNHILt3k9awS/Spv5zw1mgRNS/kBqkk78mhcm401Ly4BPTz3B7HSGBevL9vUy956p6PiDzABFNKWpw34XtP/vaePeGI1tuk7D5pvgpukEvGft6d8QuHiCIcx1mfy0/4QizS6qupIOIYt7asjgJIvYzE/fcRLVh6O6sA8+NNTqUfvnVXt7omGhCx63lUA3HPqLHp8lOO77d6J49a1A6alW1dIR70AmFwK13uvCeQ5SH68Gia01hAXNSaq3mMfAp6gy3DGkilbRN3X8S+IPPJShXDBHu4JBj5LCtvBuggZfiXrlMvezYMffGsIjR/akmjAtbL6XSeAeEBpPITJl+DNiJ3dCcOJcUBR04J4+8yVYXLKDdKJ/fjno9JFLgUQjDOoxYAjEjgldP1K/odETScF766EyFwBzvZ4lBZXZa1V+hhT3yT+8QXbSNb/U3cWFKRuN00WVmEiicfHLw1qnhckXvtI7eW0smZH/KS6IuFkYJSeKB+mdCSIuIgQOijU1y9FR+mIno2FstpWP7eSGG/FJ+ffCHdJ6in4EJE9JRibA9xBT/AjaWF
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:35Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c018-c9d8-45cd-8fc6-4358950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:36.000Z",
"modified": "2016-04-28T07:47:36.000Z",
"description": ".js sample",
"pattern": "[file:name = '0024112_003320.js' AND file:hashes.SHA1 = '6175615d815253440173b0bcdca046ce7e4d17a9']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:36Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c019-d744-4f3b-b8c2-46dd950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:37.000Z",
"modified": "2016-04-28T07:47:37.000Z",
"description": ".js sample",
"pattern": "[file:name = '0024112_003320.js' AND file:hashes.SHA256 = '28888f3676af42b3773e2f363c71c8ed46f5ec9fdc7e28dd159fe2d0b0c22c58']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:37Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c01a-79d0-4e31-aa44-49bb950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:38.000Z",
"modified": "2016-04-28T07:47:38.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPM9nEjb9o1fjAsAAAQYAAAgABwANjc4ZWQ1ZjFhZWQyMTc3ZDliZmZkZjkzNDIzZmJmYjRVVAkAAxrAIVcawCFXdXgLAAEEIQAAAAQhAAAA7XoiPGr236pwkQDzZd/lovU4Em6I+1bDSUiAhvcd/IOS3xagPkwYt1sgXFx0yHGmBHcpLLci17iY8eRjBJ+6z5FQ6HPCgBzXqpt+/1Yz4DRaFz/4Snot6mlXqGSWRRxt7KBsXA/qDzYtG2QLzrdG3OPb/GeCOgNnnz1+0pvGzrGZqiWq6ovBGQHmnULhREUKNqLQeYMjd9nrAU3wDbdmOr/ZkfAu9jImzvsgkUuBq1o2OVNyZAcNDvGNUIDQV2mEGWoonS8trpUdTD5wvSPRJAk6oLcmUMa82DJPVA3ofR3moWigSjURJ3ZevSDF8znj+S8diMs6YEL9ZairNEQOkMfVzp1Ufl/F67KdNXUkMsXH9wPIBw5/f5kP1zf6Ae8xrAL504Vs2GZ8Wi66eIsNGW6Ooj4h6uhbKT94MZ3+4yBu/1b7xV3bufOMgtNt6RS5mnFL9WIXOUkYAsUhdd27m6mEiIaroGM4aTbRtCjFTTu3bgtoHzCBNB1ldp4gO9j1Z1yagdhkXVhc6t/sDpNmiAsej/KKJtLhuXR31QUjNkMAsDhmhmSg+beyuL4Ge6/jesFg+F9eA7I0unIjwOjgzphGWoCMLcx8dUv8o37JQug57LmwEKj8MDhmhXH5XLkY3pob+s4PNCU0QnEaF+VJhwz/lpCI/5XB9Jnzq3nHOuO2wtxE+xmjucDaHf3SrlTYxhMdi/O+A+DrcPnqrk7R2FGUJfK0SxtLmheQanwJtOCu0xS7MYAk1AzwhK/QGdk0ucxns2tzWH+t3KfWvhrmvh8r6/hZTncf1G0/5W1qFk0HGjULmchS6AGEgh2rl4wtSDvSsMSrpB7t617XaHgAR1yt9+ZuieMLfKqThZbsKrbbWjpbSui0ndJpvaILKCjAPvLR2vXgahnPfKZXbueqTWoWapBlA8QzRhrlsfiTR7oWEv1e389Uz0050b2B8SlHxugUzueNoNBlOtVe7L/PcY94Ht6mH0dtDHxsYurowxBGGWrHFx7xwB7SIfFVlzqXEf6xcc90jq8KGeA6RvlS/nzeAsR0hADhZbkaSiFaujm13xOrObPYgAfFTKmeAzLEe6DaGKS1s5e79Le4bN/JaiolTYipXgOpc2Xmzssa0gPJuQV9qb/BGggqL4iW4veEwwn0kHj6uYrEwntNMkdws0Si5+n+1CRMzNDDwv1PWRVbXN6HwZ0xGKJQ4jgskiUuZpSeLpzuDFIy7ttHS6IWgDCyvrf9uVGtWogKT8TFkLx6LxuNejw3FDL0u1+vMcObVn0nqZHAeqPzLTJB1pgUksqY6iuN717gFRxSr8Sv8ceOmUF9CGbUjGGo+u20ysAyGLC+4N0g4QeG7wlBQdQh2jz3NYckTpcJ/yLl+SMdhoAqLaA/fLhVZIaeegw0df4XdUVhfUUlOub1p1aNedVc4N3CgWDGIR7x2XFXAML9M1X7pSBwSWkw2M3LYqduKb2YRP5ih/CQdvMFo+6V8Gfkhkm+2SaOkUCqlC2fCqFrk9eex4tUbSyk1AjcdU6oV5eyiUj5rnGA3Uuzr+wzf+qyFNw5bDqXe2gsEDh54uY4zPWr6dHB8wpIvIpBUeH1eo/is3FqYmavqs3axQXTMgF+f0XneP3Oi/R/DQQI2Wm0jT12ZTV7bau/LHZvgcfraIRjyCM0ztKagZrdkUussxz14j9NtzZpkjoi3eInwyuyfHBZQ3WZ6YFUU+TPDG5epHYzb14paLLaU/mQjyiQZrLRsy00YnfvWWhBoIHOM0VITxGgOR5EoYbfp4WRux9BPtubO0sh9rByhKBYiVDgzzoilrJCq2ORBo7DOfazmSshd3kqZubn/G+4qeNaKPnKr83orPpJ2k2JL7i7rGnvrIYavmdDxw3LDRA29jtAA/p82ISrCeKqH6BbdbP3LnubcQZw2Gf2CpcZmRCyKq8Wtz9PWCBeEmGC1pNUkNvxoOoxXBh0dfQEmpIVjqQAhCjIPVpxaFqHSTI3HSkJ/rhs/WvOF8uuI6ad4PEQerinKmg/WeQsknESbVYith5jmXS7T+qI65lBsNlQNoiNq2QMXJvcRIozG55zygzZgPfyKO2ItHUtqHeWqqF+y4VpU9kBlKkqT3iZ1WNsYjMRmpUqUghfATl/iuzUza97kbb2dgV+7NDT3BNzGHhAMEb6HPE7EHpGwjdJu3GbaUjp6H17XsNd8gxj6GC1N4WDh6i/UWDh8NQFE/18q/wvNxtYTQoZ+BElQTJLh5LEMD9GP4t8gw+PX7uG2649uF3iR/3Cq6eI7q7cdWYCPxjgmNomTq3bXtLi+PCWgMxB6BZInLEl4DUEWH58oz+eyNddXNULUm3i6rmhsUs9GtXd8DKbFB1b+ox7OQc5MfXM+vY7qNHUM6CLP6Ypr/tpjjI+xts3wLN2qVx9zGMV7uZPFVaTFyOq1GxRMagaQyKGQRzpJJ5Szh8lklpPuxr0O7/E2Rju5etuN61jFy8aC3HBLaOm4Pephi0wFL/KBmXlUvdTF1Lj6lsdS0VWeLvhsbqrMBPRz+9E1girCTGxrL70QLvTx0mttJsRjeERpax+AGn4VSIDsnyYBHhsbQeAvdPirerstzMODH7oB9KcjQMyZN+7flpCdOWEjxN86L+Jvdgxvx4fbvPgyMvoEaqAhdlgaiYwdJmiAQP2Nb8tMuA/VJfy/jNiMduMZ5/8BMKZxNGSs8IrZXvS9K6DFOvd449msGcdLnVnP2YAEgb4KNRBiVXRH8w2SUNpjIY0hWYzO7QbVs03dZrjpb9fAYYJcQh8WL+3MQd2KF3Hv1RJcT9kUudDr6k4L+VafTpLOfF39U6l7s+n+RFgftrWlcvFbSdQvuen3BrSqEUDtBFsm6PVe3ZnHhKh7zBNyo0gQd/aa3poP84F32hLTlnHSDQDeiiJe+eMgruCJsXREyjgkeL0LVaA6nqf3Sd7LRflbPSr0HN6wNM0zFjcxtcAhz9LWfa3k364j7ErqzwAN7Kuq2usOp3RUgMQhqsJufgosyTlzjCfHlUNX+/ZArF7TrH6L1721LqhxMNIVZBJ55K5bHVhvFfLKXyKhByo1hEA1AmohIBR8YxAW9optmV6CQGEhBrdlPSPHxTEm/1YKPagxTgosRwD6DA/ycgLWQB+NnE9/b+HO7qdSvx3N6QieuQIhAmFgRcNKrOdEhqFsO0K/j1sIzfUL2G/sJvIZ/qkPMDwy6trBI4nAq/Dkjz/aOkuTejZ8aKNXNCASaTIEweFBiABcHwqwwHa+5qXShADTiHBprdQmbRW/WBCMeZGHh7ChPdxEfwazSsJtN01VDhIKOiCpCY/3B8bYuy48d8MSTU96pYVRUfEUbK6x1EdCMyBYS8k70H5cW5IM/V3hafEiDWrCGcS0iFBwrxCpx3MrTsH2XJiibM3brKTqHrtzcNccm+PJNQ/7kRiEG/kWHMueGWx5wVuq2PBcplYj1y+GWOOhKmujryX4Lqni1dLCx1Yj5fGxqJwRB4XEg7C4ILIgV0aBOGA5W1CWvACiX4+gdN2nVPNnqpXVaLJ1JB/VJc6Y4EP4RD+vqfouaHjj11jF8XZtvMK31aN3vtqT68wcMOlKulB7aJlh+yFE3FyNdnC9GYTtschOxCaxKFdlopNdGc9XgnOyWbugbEpdNxRnOND8W49b3oF3SUZZTtozHSmCfDLJExmP3kI8x7NH9DNYBU4dZRWn992yL9cg63Q3uCGmDZPWOm07uvAcsunMAbzjdhJb27/g1/VFarze/7AU8LX3l1A4vNNh5W9KzJlryBH2k/jR+oVhn0Wfv041JaDHKbl58DOVc1Ye3and3m4Q72TmOvJHEnTHXSgctztwvalFYk1UNoqd4TibH//U6Wc6x1RIaBmRsujmYyqBRdMctdQrbzJQrRo68sD9qg/Yoch+QD/4o
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:38Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c01b-d848-43da-a01f-4ec1950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:39.000Z",
"modified": "2016-04-28T07:47:39.000Z",
"description": ".js sample",
"pattern": "[file:name = '0032210_003977.js' AND file:hashes.SHA1 = 'af7374850936b6d24dc9d05d247194a5075669d8']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:39Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c01b-ed14-400b-bb63-47ca950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:39.000Z",
"modified": "2016-04-28T07:47:39.000Z",
"description": ".js sample",
"pattern": "[file:name = '0032210_003977.js' AND file:hashes.SHA256 = '76586b2f828295b0f1aaceed963a817d550cba2d624adb03fe37bc6bb1258ae8']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:39Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c01c-0cf8-4ea5-ac90-4d22950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:40.000Z",
"modified": "2016-04-28T07:47:40.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPQ9nEji0kQIgQsAAMsXAAAgABwAMzhlOTM4OTA1Zjk2NzM2MzkxNGJkODFhMzZkNWMzNWFVVAkAAxzAIVccwCFXdXgLAAEEIQAAAAQhAAAAuu1gBAeLIBOTPrYtjgMmoSVfheXJs5BdWRzgb/7DcyzVSFg4bsnSAHHoO5ulv8DebU0CsAN64ENjOayvH6rfKUSvP4CbGIhcFzFBfiCa6rfoKDjGaWwhdfZL7LxUMNV6l2qMXO0ITSB+FlipnPn1TEyksiPzbbIisILIJkl6jgICK/u1F12s77dSu396SPNRp2zTkjB436Zxl7KeRN6jnuGE7Eld7bxpSwcaY+GVGAG9CiOd9SYV3jP+m99DdL6X+GDaYexW9Do2aWLeiYZF1F/PsaGq/5cCXy3FNkpNbzWmPXFGpbr1qp2rRc04N5leWnxwL++tRixD60QKDXLFBX6vNkSTsjtVoOPmbhQecfGjt3oFkf79JHrFtdYI3KeXCDVDRmKgpbADHcmVXU4Jx1r6YNZwRkUlrHNaOTRiORy4pZJy3B/p8KgA+Q/IP+pIllFlzAMtMMkbhYjQBG7/T7jBZ8vl0RESDEiskAdVWHarnp2RpqUj0GOuPYauuDl6sDfZQ+mtTir4mQ0YnNjlyQJblhY1XNnwyKnYkLqyviFzVDUY0i6GNA9pmrnMH0548/4PINyyp8ARc+McZ6XJN17Wkf4QDzjJ5lMPbFmPU3k+jR2QMnd1hJwqhfrSsGBy17AjlcZdg9SyDGwVp1hbde68K6Uzew8ZA0ym7O7K2C9scpUEM4/H7syKbXO+5zdsrX3JJ+4yCMKedy0CavYYYMAP0JlbYejD3kvvBzdRvA92EXTR4YZvCR2kU7HG3NZbyzBtS0Ti8xArNYmyT7dKRt6LV+QA3eZvOBtvHGNd5mUgSjtRskU2p3MFIGnp8Fynw48aB0wzvpTT3J8PDOREgp6B2WItU+iZ9Go7R0j+seLc/SVoSqWqhffSVttWsSi1RJnRhsSQchI3BOR6uWwi3Cu6TePgwTTI7HyIziUDnvUxHa6JxzULOKsqK01jd+D94+2g5nspHp22uB59c4GhKk8UvjCoqWNX8avgfYIvNtvhbDwgCCh0R0BIegoTFUF+h4zv8qv9Meqj/2EbeXzfaM6SYw4dg230a/BZn7iBh9bZ0DbKMngKUCR1wANsVpPut3rXLg7wOVoibRUifritJGsNzbeWLhy0wSpfBPGqupBVips0pAaXF715JQmZECX1SY07hRNIDgYL8nf10n9j7AtfeaeJAEPkHqjtvkjwfEVhbrog0SuR3jkmdQINPLE2LMu2O+Fcll9k2MOQ3DfX/bXRaTs8DkkNFh5g1sC0fNt1xtVxSKzGZl4EsXMyX9plToHfgH96tWea7mpvtVX4I7BlZnNZ23Ygce1Hn2CJ/t8IRlI2EkuldSc9vownlT2KTDyXCtOjJ6eY17luw7PEg96QfuYe/3zvT+PEXnKQlHsn8EdstIhV2i7Lm1Gtu8Z3seqSFYigobTKa8YzzSBXvQHpH5QYmpeTlDIRQuq6LE4n9VH0hZforeTsTvIvkQKPqtm7Bo9nbZ1gVXA2wd2jpHBZNRv4zJcVz+lVmrRrlklGt7AjMkLAnfVrCvJxsJzgHaryuDZksF4Yn9P4iDbtsCFayJ9hufsEMipPbPOqrr47I1ZwBBehTZCqWz7in0g5NImQGpVIpo7Ew5NDgLmIlOG3v61+auTe7A4dLMjOooVS/lrrWvxLxjjM6xUzq+AIiGllNApX9zWEwsYZ/ImmzIUtECTuwZsG/iRD3v0BLj4AaRPn7ebV9ppx3Y7fUZNTXx389q48CDMZr9F4WCd2LuwwjzDkHDNlvMh71uf0yLrRMQl81I/bZQkcTURqv3AztGhdxOTbDR6tBMHCpz/CRl9372onkuGYC2BlvURvhemmocNFJOZd81yez0e73a6+lTPjHOz8INcIJaD5vPdo+6ePZbcy4/e3Z3x1if27PS0PD6mGXctF3xw/YsVo9eudh3H0Wd7J7YCy55Nk5urWJbIDKt84OEvRKUl0t8UQWYmQYaVuwoSYFDcG3TOSnNdDCUP7GpuQP+HbdQA7V2V6CyJfUqRN9AaUYYCgdqEPsXhpmOYCxRifVjzeZ1Z0674dKJJ4TA6G47YK7O0zheQ53IenvEjGwRfztn/xaTjcH83HaXKtnGKS/H3CsctKkUsoAwkVD/Km821/5Ft7ZVULTD58N46JtTfeFEFdHSZM16ESEEDqm1vMI995FXobNZf1+RYJ9V6ZPi45k51zvd7I/QHFbci+fhXP7pvBQBMBLeco+LqCCCZjV8sGsfeIEkpFoHOvlkepH5Z7ckxtEPj7Cy2WqosCEeEf9v44rRTZuKXPyAB44a9uD9ppwq0DIm7hS/NfvFiCid6pa0ILwTp2CZyDxmh9iq3pZcD4TY4nZiUAWoqxXq8n/iSEEcKuX1xUerU8AJ/8FmeX+afMH5gJSqlkqGfGi6n9VRA6TrckCqxgRdCL93F28plcPyr/vdoq+qc1qNhEdFOBRORA37LTDHUutkbb/Mxk+Ii0yPHlQdItRDr8ogfa2TPhJJsVgCd1IZIpwgEatIAZRG89SqGod6oV2OzpPKbZ+ujW+iGd5MSTpHkj/5MufZbntMF6dmV1Vc4z9pf55FIQkRbyZqdbf7EcBwOR+hV6Uiy99C/I+1jbsoXEExMPpWqXGSUX60i7A4vVSwx9iBbYDUr+S2JsCINiZfIsdjXkycXJO25eHecy7/Zo/QY1aTSgDv7sopuT0ls6pg2qGhEjTpbIWkJb8LDp0/ZVXbcLCb+Yz/wV5i4XiiSbYZkE1TPn/2ITiMKjO8ZqNIqcsVXRPUQ68ihxfJiUDAkly9x3AJthK2BGczsXeNElvzQEbLGtnOgpKwnbriDBNr74jVBeGfvor/5S9wT7Sgs+a364MWJXy6rBWssWdpIqgjYDwnG+UgQ+cdb72CS53eXJ2l+bx78CJuDIaP6NlRo1SmaNblwNAbptCqgCpnyyPP5wIVlzeiqH4Wavye1I2OfWToz0EbMtQG4LIAdd2RFO9lwItKIjKtBiLbdMaQ3gyYOgCRdtQxh8CLaURD8SfMaCajgko5qIpyObyHRlve7HcTwmuuThvVtlIjweLKPdFcinXEgW62KDu6zH74jcfvIS2SklrI3ljwX1WJiZPau321ErwmKuPTNLh6lu0gyuiKEdNvTHKpgmxfjLIelk+nrEqgpzQLMs1LAgXNzGHn5Brpt8TlChmc1itBOjtp/dMt3eBnGt6FnLdqL1VcqLtsoNwfgxdnz/wEBDoaB2hD46t/euGM6vbRezzahLZcjrQ3/0tr4QqX7Jf6CLJ1o0JFON0CPNDo7b8ZZrbm7W6A8QK1ATwHVCz4KJcfAPiGVKxw2Z153lNs9VO1QQU3nBmbDh2lTAoU+lT6Tg1TArtOLEPWBZWfSHQvJWObaofBWe5GKPQ8zt40Y/ter6kjkHtnI0e6T8rjhA+a5Hh3cPMEDillyQukERn0nRAQcb/+WcCIpgLjgvqhjx4lUP2qHoLlgVFI7R4EmQpbVZ1WR/UiNd+X5YzSpjUNYpUIGwXK76PDJZGmehclaVkRl9+ZYIrpnk3sxZFKFvH9w9ZG6pUBCk8IkXCXFz/YHYvq1+qb/JPbjVPuk1ntHzW9+4yIzYcv/RKa6UxZiTSKqYy/4FT0+zTY9OYKXU3/0EDo0DevnuyTUCjkq19/d/l6dZA1jnrNPOlGJrtIY3MeJBXLHdbUatYQ/CVVjXCDUqLrknYhmZ2s37R/6WJVuVKrbxS8ySNsgkAIB5TUYOSggTOIjjzf9wTH4PLnUzWLZdHbgKV9K1mAgkWrPJMNqci4XDdJK1YkbPE4R+hE9/HCr/1q1++qq/cnPEGOmzz7NKvZsPofX8ny7Vx6XtV0xoZIniynrSkK9TEZHQXx38IPlFUiBBZ3Ww41Ah37Z8PRjoXMDmg5PpsPsAdIuklQSrAydmMw08gZmcbuBcuz
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c01d-22c8-4940-be74-4214950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:41.000Z",
"modified": "2016-04-28T07:47:41.000Z",
"description": ".js sample",
"pattern": "[file:name = '0041312_001095.js' AND file:hashes.SHA1 = '1b426c091599f20c25dfc7e2fcc778ca316754be']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:41Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c01e-b2a8-4dbe-b880-49e4950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:42.000Z",
"modified": "2016-04-28T07:47:42.000Z",
"description": ".js sample",
"pattern": "[file:name = '0041312_001095.js' AND file:hashes.SHA256 = '63812bb81454ca52fe1c3f76c329af54a373378d7d0d309b5ed7caf0c1984caa']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:42Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c01f-5188-48d3-9957-4162950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:43.000Z",
"modified": "2016-04-28T07:47:43.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPY9nEhuoKB8dgsAAB0YAAAgABwAOTMwMjA1Mjk1ZTAyOTk0Nzg5ZWZiOTJhMmQ2OTRkMDZVVAkAAx/AIVcfwCFXdXgLAAEEIQAAAAQhAAAAiP/IDUiKYPJ6ecGoOxMunV3VARXWxoEgsCMWaokAZm+Rt/9dC63GMVZkDyVliBPKwbyTRyl99Q3/0uN5jzePSfXhGgdUebMWLDRcMGFVeaF6IqI7BaKnMPJQaB91g+2Db+FHXxxH2NvViZJyi4PJhqNnmEvx7fYSP1cnN5EdGUjyCDnNJb8OOxYwUM9rT9phcRz8qWRSKrsBnWbCdrwjfbw6Mhul6pHAlLWg0fTlSNFaZfLaj1pa4erLQUn0ttXkHjqY0NeS1OJvkp5UxXI6qlZcUF72KU3Id+SUU/HSvvlBkts7RSeYJPYwKHXc5TPMLypommWh9BWGH9uYzI9eA7IDOR+QIyA5p51/Yed6zt/+MY3hcFieaEBv6gAyiI0/0RhEuYe3Nsg22FPn8nPeIJsiwbJpatvCM/fctQU4//8zB7IaES1UYeVzbZYOCu4OzN+IONjW6sLRXj+3wDZjRrV0puYbgVbBAI0DUxGhLqf2IsQCJXwVRbcuGu7Zn96il+0RfHllsr3xmgwqC7FcQGRecKht6nmv/3cSV/EBeQXlb3amn/NhdbhNCRSy91I7pmAFHcQBJHY31BG9t1TKYDVyS/ong0/LR7vniN0Bduh2tPL6XP9gPuu3LTz60IW+ksjGWk1prqfcFX/CcOL1b3OdHzczdIuQ5U6/hzIKqc90Q9JfQUwShh0LnT4pL/VGOi9Hb4W8a9G6LFhtGVRpRvSjQJc88YVzSHiQD0fea20P7VeCcWz//S3g5lUdq2OH0PeawwKQKIgn9Pi3j3zBk8Pr4iAqxKBNhhoAH9WNgbRvomChFb42g5l/gLefaeHYYWD0p2jdKVZICkZ7/hSiaE5wtekoYMhSgK22ckDytJUBaXtY/RWMHUietRd//LIshaowK6ygn0/CTX8G6/88N2lttU7V2o/yqJmGS230wooLqwK5WVD8ezho5Mx/dg2unFCi23ys12/X7bTW2M3L+tVOrz5NKxOEn4NFzuJrG6OJRHBILwJ5L4Xte6cFEcFz70UsbAF3lpyGxXHiNSvdJ8+0A/isZOswco7yk4Wpki9F2KE5SZN14tqn7yfcSalzxpbkEbVI2H1Vqc9mp+/PszvgeQsvLcSZGgFLxqZdQL+ItgPhELJaDDjh3iYCROShc0UsvNC4HBdoLE3DNOdkgb3no1BwwFmttSRwEuu2vDw2xT8zGlnZQiahxo/ybtu/zn+ARXhTclOI6zKtYx0HcV52VPO251Y5ymC17AheT9iQwqy3VQu8STXQLSwvSdl47EQGN5mNa+cb9jFleaaBHlikheKchJt4mXVUi4vbPilrz7XS6NUpCw8NR/dXWwS5uqTTNAbsIOzElxX8CidnwZHlJfVhJkpPmPG5mkrisJHN1UUP+dyJ9QvjEiSll7WHCZmFpZdcIisEVhis2Cs8+6Aaa62lMrfFf1FgLcI0QZilschFsiPucVEhQ5C5ZjfbaHOGmBTNqKYahzuqaeXeMVU6AJqAjUabWOmBpMNDFH1h+t7oYS6cb2zeQAKgEmN5A7M2gwlGKZ2mOj1yN6xxuF0wtscIn10hat0n5UP3B6VgbNKDwGrxP8T9hxLhVI7aHU83l8NNa8KE6Y45UiqkzbeSeVRWUsaGT17ny35EGiE41g3NfG2MbqIU5ESlIemfLwg8t84zpnR6bJ82Bc/9pxPdRmR5IRN5mzsc5Po6+mhpcrqc+zMGJwDEi7Gt93vjLDe1/rq8v0PaktDqSLSUNWMfEQScEYV8CqUc3RfFjJuMAmMu9Uqp3zKWo2X+fKEEWw9z5a19/rifTiGIlDnlg44NXgDXi3GS+IGuiBuNfL3nvgUBwcI0nnZv400hqBnem8Iq1WPndg3dVRwyP7SqyIPDVY6V+glKi0AeP8aa9XNUCzzE3mvYwA8IHQ+pDwoGjIhj0wXQO2I6hsmr/grii1HEac2zTsGBK4eWxB/dvRrhi3w2b4YQc9yDUCkZVjdzluo21vWl3fOA+k/RMsMKENicPWbpvJrmymecxzuQHr7YrSh2c4Z9AQHED1FPLLxhHWzy03hjaLK8A/AXK15A9SKsdhTz1xTEoGD+ciSUZR8FuPyapiI9raAWkxaSL2yLjcYfZ4UAg06BZEOwlYaY9o2boNZIVneC3N2+9fuZ0YYzgDvPT0nLVNxnPQdTqXTrbUKJJ6cZP5Dia2gnspqqvtsTQOa77E5HW7ivrOs93CEjI96OBCyUZ5F+G2NWRarUxdX8D3PSxFJEmbFDnZl3Pc4KBpzNG4eR68WzzD5o0uMxVhfWC+9y6zNB3TG9JhXlDvMDY7OejSzJovzCeA4kuS3mqthnD/bo/IDjJI+Nu+pgXwJ41Q5CSk/9cJ2Br5C0bhVCejAoGfBeIkEBewU66L+DEZg4accVQPvl8cU7w33kCmg+ZA0HtniVYyiBkj8yW5xsTtAFVMiXW2Gr1FlJwleFVmLvelfWWaJ72b3yb9Xq0ZBX6VWrCzjt7PDG9QdnUrHKH6KaGyccWCANwErdLMRTCkKNXxk1dT3qFbyUNjDePwMGlHOMKIFaDQwZHr9AYBWGhGE/PacyTA9BqeIdynZd7GKeG6uNKyTrp/824U/7vmA1d9X9s0H6rjB7iFhX8e9NItRnNCJmGu0syEza0iOEva5el1PPyHc6KplfhhD13r8aE87C+8+2HyHlRN5NVZ8omcIg6k3UkAOu4PYkFwc9DjKLaZS9yHCBEm/3dMqhSCEk78VtE/tOoTmlTmb+IR1dxs/zyrdIvvvv/p/7EhRO/JYOgW8xgnxRxlFChJOTbIIQE+y+znMXlceJbeeVysTTElDr8whcvW4xeOsl8lFuwY2+2i239s/uyUAQCdFWP1GTDWCV3G+7xeIbcsmWeCUZ20fSQxmUSFasqC7jW1OUEUjGs0ejoCV3UPyuJjPfM0njEtp6nMjmBRxhJ88mtXNA/L2hLZyG8FWq4DYfruDd1hSk58hR+mnh8cm1IYXuA1rtzD7i/kp/JaaNiyDw/h9diSFTu5787Hz9z58i+rJ7GQZb3XCu0QSjy7x0H/l9cmZ7XavjDoKepqQkB685uanB58Dg8TPVyjxkI6CHcBkNOdjfjxz8dov33zmIEQ5VAKOn+lTOUA3vMrfgkdUOi63Ycl48DvXcjbYD+i/4eTER5XY6KIu3HPLmkd0a9yL6eV9IjpcZIbGdthFxqcpDqgFP1tu1GXsxriWBN3/jVYzXslcmksJjO5ztMCbdLko6+ivF8PnjzERZ3XunFzVikY08eECbqy70TBBKPWYWmwV84tImOn7y1mDle4Q9e1KMAcAubuYhNByiUL09l7KTZC6n2IcRIDuD3PVyMhnF0EZFYXctDSh+vrhaeQJ0wskkntk7Z91Uuqt5mhidPoCdrnKcr0I2cGuvhAsdKdLB1f+HY+r16irtKtJicW1151+sBSdRHTq6mz3VDhdQXZ/CEVdW6fv0lOtblUT9VkQWoigERF0a8qWhkHz9fELOkiRjvalsPl4VWUDs2ZIIGDqkDwIyJu2noJWrqqQttUPvUabmTELNhKXbzmGplsMVEEorT6BAStcMfyfaBPU6sn4XivTrKu9Pd2xcHC9oeNBCacjPcWUpu6FvboyrcnD5LcCKTkSVox2YpwsD1EgBzoqrh2JlrDOs+rLC5jHKArW+sTlsHuaVBdnRAO242/ZVUW2x/zSaPSnYaW5owLbfm0JYdrl1Sq/7+oTYboIFXoMfnh70nepCxLmXHUr4olki/HLx4cvl0fIEc7/vZcgS0hM9qWEaDPd70e0rqzR3F8V+HMce+Nd4RyXq99FLRnqKadTSTAnU0grr2zCODzp56MSGa041oR7aFqP/jh3ntPU6Nr1nyulpOZbU734WoCRqIKbB8QaRcjAkWhADhSJa15gBaRbqWu3OUEsHCG
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:43Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c01f-6ae0-4606-bcbd-4195950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:43.000Z",
"modified": "2016-04-28T07:47:43.000Z",
"description": ".js sample",
"pattern": "[file:name = '0042005_006033.js' AND file:hashes.SHA1 = '592842e6fa89922e913963c2d0165ff25a73a2a7']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:43Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c020-a958-4061-8f48-4a22950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:44.000Z",
"modified": "2016-04-28T07:47:44.000Z",
"description": ".js sample",
"pattern": "[file:name = '0042005_006033.js' AND file:hashes.SHA256 = 'ac60c0878cee1c57008ff6d6d9348b64024c7deadf4701bd08017f70ff7e65f8']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:44Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c021-84d0-45d5-bce5-48dd950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:45.000Z",
"modified": "2016-04-28T07:47:45.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPc9nEjVqVh/hgsAABUYAAAgABwANDJiNDE5ZGY0MWQ4ODc5NGJkZjY3ODI0ZTI4YWMyNjdVVAkAAyHAIVchwCFXdXgLAAEEIQAAAAQhAAAAO2cXBsK7/ntcs3bCAbNaUVjR74uvCgch/VOZo0CX+FBMh63RZpkj5EyNhiqOImtT1ieInQwBbI17CbJukiorxuowPbmq1jKzttQMGPq+xMzlrwMdZrKrDBBg2f/LEKYTo56KYTbz3JS2xXriGEPI2NZHV9MsetXSaxL3Sgr4yy1L6/bHrKq8cAXZzFCzoS7IBAODuPPhUvF+06uYAAb7wTqnp7UExCWLvLNo0ItSJOziy90ezysLDNrUwdOp5VvTU4OuoBfse+2uTbPN+vxj/d4PLBwwQ8e8MmZpnLQYLlWjCxcOapoaalniEaJ+L7e2va1ktwgnHfkQdnwYf/ZqNzL8M+CLWmqHu+dNom13mQQEjicP+pYJcSwxozPwg0WnRk0hkkfSO5TyhI+vRp26NtXi0VtQ5pgNbQoLcgeeO30W7x+Qfpuig+iCuNQYxxyMUGu2jY2Me1QS/zz7Ayas4joLkYjDPE43dDA8mfH90HkgUNMC5oviZUqIN6524wEOEx0oizA7YrOpfd6DzGXWNUx4SCgKFR/cfi4T7au4SKhfuImA4iGcso9ox38cdwdUL5UMiSoYiDlFSKLAe9lB+qB7Aoh1PI79oScWozubICKdBd0m1R6r+cBjPtF1C8Y6R6lTLCo3KW5JGLnlXj9Qq2tXUfrs7tCO7hj0PonPdGLx/Mnv3/c+E7ZKOgND6jpWfWQ0GdKM6TGomHzkKXkFAxVeVvM8GULQqLS+2etnb9a4yJsMfU+dfE/iH1ul2AXpkUpYHa9g7cxEYNkjFC5vGLEQVXkS1yle/FL30a22BdCAAMKnAlXjWOcWlxVQTrYugcnyEmC0L6bLjQoswkq66SH26RxPiSVSyGRdW1pw3wxrkXYFYK/GGnSKEaDXJBY8Rs5W9KOcvQa4s297UnlrYZLcvgjWcIuyQMv1mQN6IA/N9K6DsxedzrSHtjvrUnxy5sMfmIM1Dg85kmwyNamZ0yc2WiTRkpaKG31RZbZUQWnvs6cmNyHMn7+McWFdnzf3LAUXPUF4LTDlFOsWBRt+I2AX6wn5hpkweRpIafeAiwJOn/WT9ObIaZ1hYybTbB3r0D6FkIbE7ZdXKRfb2ri68IjSRAZJJHc+9uFsvBNMp12IFf1IhFaiDF+MMGncfpX7jUb2fn8Lc4bS8/FxusEKVYgFgitO3KdB1X00N7R8p5z/GIQT46siB1f0k1FdB+TYTYMA07hrKeYyRk8vihwrLu86LAxkUVkQLGBLammggE3HZ05ssyrU4QLYcuQi1ZB+yCs2uraWu0oc6Qjksxs230C41MgTzwVcH3rRLBWX/dAqWVwU0dmtLdhm1cGiiZuBHcmkHRdwWdLNl34eUgbZPIlW1Wm7LAg74lYTNVZHukROH/wXHqyv0JFX/4D87a+Q6DnCGAMh5jsiXu0RtzYTJovfSdqXjMBA2TUEZPC2g5WByuH2OvKh1/ssJQJIogOK12n0y8uEDCe5OUaK0c3wvElm0E8ZJOZKYO8Oy7ZvDNugk+TEs71CUHuTs4CvKxicHWlqd2zkcSsh7vLzUaG2w2rGyv4nlWx6mZzNWOGAOA5j5tVMyw/W192aR45LOoITXt8/Dhzx9SkrGTQKlv4TByMGxFX18WTyc+6TgFNq3N39SdbTJewsXqnNh8HTkNEEB028aitM/eu6ud5fbW9oa/V6g34HdE7tZ5ja+Bn8g/gcQVQmHawNDrqg9WoMzlpyAzABUGTeQ6GoR1fVnJwd6hCCVJ35MXAm2smpd/6in32s/GpG1c4rgBEVAdoh64vjXOAqlGOnmttyAjEbuX6z78IhVZTQ7rbpo+74/9gEwusVwbMOkJIvvkPl3oNdybrfaGpVo48blKQj82PmA8zoihcpDD1awAs4RaYw0VrHDK5oJsSXIXgaQzZaqdkW+DODSofUB0l+1nq/GQUAKSwL/clWCAATEc+pBsSIrGpHR3JdnEKAiI6jk/gLVhdPiQa9lasi7YhxMC5q36WUNRqLsCepRz341oRwHMrwh2xOp5DmcSEx2Sd0G9SwPjB0gTZ8B3pezAZWja5sBY+qsnZyugCy247BRRlZJ8da+Px5MPoyp7K2E+Uo+RAIDlcOKW5/2cvf5iLH4XzJZw1sDqXGcR+T7tago0HXmAoulf2vn60rKWKG5lii677jNfnUKPCFGg0mTa414UX6eMblKTkKxjhc6Aj1r0kTiRHeguZwWlXa0h47yiPcusSl9NZbXEV8WOLT+9Lll26jAS44zM9NsuxPSL1Q53U6qc/7uy9Uar3Y6y9h7wNrO39/gCaeBXYm9IAT+LrFRiorV3KoBOYCAE+yTXHGcntWIC2iew3jzX2HQEYsEMcZMfXdQJfpJNBKjhwEWPYRIspHXCwPTb/+mRCjvN5lRT6c9i/UpVfOe/Vrx7dlCunHgDFqRCLJibTgnmfBeFi2W5y2EYtjKtmCQGDlG941bey2ajNb8dzwCNoxL71zKPawg5fkF+DVt/wAoFztfzgS0LajRWBApltbNSJBVLggcl8cNOZEX8momRVafXHy55YihXTBVK+s+dXsgNGNq7GXcsBXUiLRwEpKIRKwYASQEC877LXeOFwhtIWYpCWJITsuO5pxUamxgf6tIuIoSr9LRua996RGiyVUs64fyeq9KY8NcZBAHm+KLhQ65yykRYpR1PAcSszLY10D2Uz0cYbyjrtRYHzwZw5Waw0Fl5gHQcCf0RtYb60wQQ1IcVTn3HrgbNKRU11yV0y8+pF6NUjwcs3sK4MxN8mRPmiuVs+DsZJFXXuj/Xd7QWDAk4CaW5JIUup7yrJXaRaI86InKU4uQEtlDkMV9T6TgapojUYLVtApZb8Q1x+EnQXjl/nZh9yes91j/RbuYJ9bVt7JbWRambaUl0l3KQ/6givkCygA1BKOIh9n5jslkPZgRhiNCPLY/4/H4aA5T6vqb1I58VeHOJp4xVu+Fl72+eLYoTieNDr4h4ROptRy9qKN7C86uWSmtr/qShpqubbrfv0x0ECT4QQ7NQltVRtijhFDW2r7Axg84wg09f4I8Mo2EC1o0x8AtLB81wOWBMLzyBkeGGgLCGfR/BscuLc5x9VLqTpdA8E9Hohddn5dw8furInkr3XPKdsnLWAiOsHqsY2Kb2frrRU/iBwnXWeyNg4auB9P/Os2mRklxlJ9cd3Q4tsAf8zaUNm+D+O7F8wyD15H9RA03nlbFbKy6veWJsKPHaO8wlzCEk2w8C/edeZ+rdsTk46a56+jH2Ge5iiTalkktH2yqTie0692SPDRcpWuQsWSoLCLfxnmRXAVQVGJfrTny97jdBH43afMBYLvcGyqBo99Eke25FG/Aou8/Gl+0H1pQZLrlgZ/roCy5SbyiOMk3wfSbGAPdwEcyEsvrugTR2ZTnA6N4N4lgUhrbLajswBd0uqzB7YwurAZwudWeE2AnMbp8AbL1LB8SnroJz95UuYqPl9ZwghXckXWgfgxtHbR6Rv2J/wjgV88Kuji9k5ZIntVaJppHHNWbQ8JWgOjZ0RTIzJtYVLl9pFTOIOuFV3aEGR1R+aE4JTOy2yST2l+fKY42KBT17wl9xXcCsuBJ8uS0SDP4Ca7yDOlSNKf8CjbtHZaQIvyYvLldQ0jlIq4nB41RIAFB005FjHje9IMAEfNio1ihHkGNVlM7g1nxYnsdBXIvPtdAwZPAZpN2Gd/hOiu31IXPFeY9OzbZXRbG3sKdAtZfxI4bdmS4OIY6EkYELF48aC4BR5KZa42O9WiY55c5X4YCL31ZALtzGSTUIzhB4OF7iqTnXMzLjhPVVCGvbW449gtIkEWlX6UL3mO3qrRQHJq3jryQ/DpKq+MF+PYwhJyVt3zdbUB3qy3Gn4+8PgYQj4QD5QMQqUi4UEVay6je9xa60gBS9gd75+dzfL/MyMDDe
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c022-b680-4661-a7d4-4198950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:46.000Z",
"modified": "2016-04-28T07:47:46.000Z",
"description": ".js sample",
"pattern": "[file:name = '0051911_001267.js' AND file:hashes.SHA1 = '3652cb54780c794e36f823e48446f6991acae73e']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c023-7ab0-4038-b7ed-4cff950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:47.000Z",
"modified": "2016-04-28T07:47:47.000Z",
"description": ".js sample",
"pattern": "[file:name = '0051911_001267.js' AND file:hashes.SHA256 = 'c91b5108a06ed1fcaa3f16807713240bc91c5bad39b2b3a79e4b5000abe9bfdb']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c023-6598-4565-a795-48fd950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:47.000Z",
"modified": "2016-04-28T07:47:47.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPg9nEgbnBKGkwsAABMYAAAgABwAOGQ3MGQzZTljYzUwNTU4ODc3Y2VlZWU2MWQzZDFhOTFVVAkAAyPAIVcjwCFXdXgLAAEEIQAAAAQhAAAA9TYsPqpf7VPsKZFpmr6JrSnRg6JdAtRC5SZ/a5CIXCLpt4Dt7kgpj8PQgXxkEk7xMg7fwvJ04qhPJqdhQZDBZY/3NcR9+9iN3AeQtUnukVBnqlvScupTM6GD+CA+CkK+qvm+zAXZV8exPYz8GCORmjxbBREZhv0YgC5RQNHaqTna4iuP3Emu6Nn3W5Lbbpg88qsfyJn4D+KK8lpeMxSOMpEwQj0QyC0gE18ZqrTkc2rMYsIQPfrLBGNGVNd9kuA8qW8HTmfH5DKq/2ZT/5BDou186Gy+qbBt8KYHuatGhbVDrWOkWEWUQRYlmQRRhPoHMzwjdNVrkUFXtdcaeTUIS2uIWicZDbefxonR19Os9zDOxgSlgC9W23LNpIjxrthSy+qBjs4pb/j6IY8inGEnxBYt+Fi9nwuvSdNATpFM3A6LquGVIxpkD2Bju9MyQYQCH8Bi3JNIPK8m2CsAYsaeSvZimgFVE1GwUupT7KARaVSw2ZZBnL++C4a8kEH3SbfUmAd5jpJYkhykJiGK2Cjj2sa/4ukop/U4XM+gyVVZJXJTNgxIzTuKDrKHn54yyUO41WD4E8tyVSXF14BjIC+Ad5jEYuQ5WN7qPHJDODqo3CXwDlBgjMFg0rLE3pvK2+rQCOllTlRyU5wc0ZPS3f72Y1xlhsSTzHdWaF6wvE2FzGDdbJnXpUCPSNb/epSB0sbahd4TaXJvWPLsD//KhO7WTaAn6BG9+xLOlIuwsecGK1ZONcFPc2XH9xFjDF45gm+VhPvE2rIkiuv/SlqiKiX+LRlzsWlEWgbBNhVPp9AIYQNRMTszyjrOVi2fG1SJNR0jIU56YEnivBbX6/U6Vc5qQS6jCE9c66rsGCNV+ZkGPjxTkYKmWhuR3EX8uTEtbV1wJbx7vqeZEqC9H7iQLNcRzK3ZVNrg41B+Pqy0dahpwh32h03rEd/FLjR1dVcKsLpYxeitRCExWLk1mEAam3Pb0ZuMOo7xBeFXYcQGm5iawFi0PoESG/OE7KczfPZ7rg3jp3CLeYKIsDy289Wd30eGmWuiv59rr0cmrWGHMPDJrKwdIr0E5GJu5cO/3yA0z9CZ6oAVhk1QXmyQVRcfr1MKB6XNYaatYQ1aKHHgXIvVNfe7ciSC348ysAehOyLkt8X8LJn6j7XOiXgrtLDj3r/QFGnis9eq61AbJm1jwopNMmkvtGiQl1EHBZdnK9IiK4/qKtOMF7xdQkwr7M84yeCkCn3ZQH+xEIbPnFas7Hyqhmg4P2MPD8mENbuopFnlxVg3je2DAiycEHe8Dlq1UL1csWm8PVlA/hs2Cb5r1t1SYKGpcQHFS7J1B6CF4Ps83zZjtzdvyHTIQBEMSzn3/WPgoDVVGt4XVxrJM5iTDE6MANxXqSegj2WtQ6NqhFWUziKLUb95DgFAIUpAKv+Y7y0LkbzU8ib8CLfFQm0qKsg5yLmrEAlj7iBPAEvBC+p5k/Nstk9WTQbpJEnRxKTDFvxMWQhO2W0TChHG61LVtOYIIzXF8xDpVUgwU9ApAEwO6c9ibUOMGxPEpk8sFpBbPwCipvuU5iHSow6XJt1jFl/MrRlhHZZCmPuXEM7Sk8i75n+XkQ1q+SUovebRVnXAsMovvyApWSLa8Iu4+EyzWwUwOgj/cbVag4vVHpOJ9e4FFv8jC+VtgTDeRSYjkyYkLdrTw6ngumcnlpa7ReC++iV5g3uVOoE1ric/pr2IE2XORhohldj1zCEi7lI5LOy7mFbPL/c69amIsXaWbDZn7tEIuO2frKhagqzApf7lPijrxvtKwQsERPSaLZVV2QKkwzgz/8l1okublmYm+wR/Ohf9T1PVlYQ0LGhXzHjPWWtMRITwKPUYUDVWaCGHugIjugkP/GmP7yXCjnDpiSTeFx86cmz0+vVx/tCj795jgajowgwzZ3oZYsyfQmVV6zW8KGABIQRs/oBNHE1+U6hX8L1mx96E0W75Zx6zTNMSpNBZlt9FcuhXNWZ87GvI2z5TJiAAAjy580Xv8PXQZvhSNFDuo+UxtLzaFakVzaeNtu9MbwXIJ4SiXPHgFRHBBZRyupPg3xCjI9c8XgSMjUWp2OAEjdefDeOvboGr84hO4hCOIQvifkh5vnX6Yh6uvTSacN57V+LSOXYSQqh9sP2XT3GwQq1z/eSjc/BxpXLhYn64kcW+RHxufYVTPdZCE1EV6/bO0BvuyXKafXQz7SqfY+LDHjBVNKI4Q0RGbwV6mvxXVb+BW+dlYtVgu4T3A3IH2Qvc2IXm0BGtymsWeHSP43Sy+errwAw+kUhtoalgjVAtqQBvs3DxJRI+ERXKxzpw+6fXBsH25rz5vJC+y8uYOXCdy4G4bSKyteDlkiogEtzMQIWxmyRG+RV5IeXLa1f+oKtW4XMLHQJDzovBNBoKAvj8dmCdefOftRonDgBH5+6JZ9VKPznLBiUIPTYZKY8sueJqkcEUOPqkDfOcLFmmH24/vhskkIpKWG/S0mPuiiMVq0DIiRMNSaVSKP5mjUcZtVHkMiHhWUCxHdLwW+3peGlZyxwEEuMkvLTzfvK8RL9KUhD/DEBMxz8lyee3DNst1TNmoWM9xMqpvyKJHAmOmMYkXUXGFH5NpIkGFf4bMcXfhiFiBhI9wzVmcr+3n6o87keZsNpvrTrirwv1uN/9ghA7B5UrtwBuB1TfixzvV5pLrOVRgz0uDGxfEVScfd0Qvjm7qHvkCHDUL9BjWXnL3+qUAt5t6dvxwk3kaNtyx33x3FMnlE7BKHX2mXI68/ijehuDZ66fjznt7NX5v8Peg8xlGbxYHfKLwJ+dctiwP1zdkxxNqHAzbVpZXj4nRuatcN9xJ83mZEQyRkc0skEddMFzXwvA4zgO7iM/9FKPJv3qBdLMIYviScmmOQK7Hcsy5I8Ym3RCiFrRDYPOMTDaiNITXvV29vExT5mySlNt3N3INo0CKUjx1TEuhlkrb/7sdGOvt2y/By3jacryXblsHN18ppVmQ/yPYA4j9DK09dZOt38u7kkcdW5IE+km1fKdB3NbIUowpePI0xjP9hMKCg2jIRuCWllsiP7E3ZL0kIyEycslM+8WKl/KWN02hT2WN8qmRl4QJsqqGRTCDeuSjl+2h+C4dHAMCjL3rMmHZCDnSrbzI2u9Yh2PKkfoSRwpeTXxVisj95IK3HjEQbVB565wJMpKW5aRSTRgsLNQcJXrfNP2BJJ5jw3ajkgulTgLEYhDayfQZysMDZvDdo0ZiuaY2okXs+moJ69ZhCZPeknS96yKyPmSGFsJj/YHold5VYvS3Lhb3lwMWhXVHse/oN3zCkwXywVaucWVwSfdjw3bhumddn7Ac5szqo9I4w4cWWH6jVguEugoo/ilF354x+A140c2n/2OjIoxek0N3qqpJ/t7rytUOuvtfF2MKXdIhTGa/DD2DXoZdAYfQlmhuKTUlvpb6J/DbrME2/sqgfQuHq6gvIlOtHA+fmBWIaTGZ9TPBNPvKUmVMpw/vyD+kUFs98kuSZtzKSfgZQwt51wbHdGB6QIp0BCaTZMNYbXY/fYhh1OkwMyZPOVEGkSRA/EnDIdjZgCR6DfSbyioEQvdGQUsZgaweBmWeDLyE24kggJ4eNVRiashJx4Q7b3vuUwI/wL4qAuQ5qJcHbm8Kn/HbzVbzyrofLrdAlUjyRExKDz4e8Se2tCbHdkFUchVyo5rFfWpmLYs+W+tQM91IBOvGCeXCX5a2y7MhPXUqbXhp5FEUqS7XRCPyFrdO6q2W9S+ava0l76ewfcyzVakiLc6ntirxwhNebKI22H1yF7VWZ/qSeAkSQfcF5HrsvWtam9l55Jvt1e1sbaAFmAOqSWnoE0nCIvzCVzQ8mQnxS0eF9by0xFk6hWjS63XSZ+sFUZ2U+zjhwsaZhilFw3bPwoy5jg9c9CrGLEji+v1DC
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c024-30d4-4ce8-b13e-4f8d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:48.000Z",
"modified": "2016-04-28T07:47:48.000Z",
"description": ".js sample",
"pattern": "[file:name = '0052014_003645.js' AND file:hashes.SHA1 = 'bdfe54e6a53c47539a74c083b193cd99de58691c']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c025-2db4-46de-bcb3-4ec3950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:49.000Z",
"modified": "2016-04-28T07:47:49.000Z",
"description": ".js sample",
"pattern": "[file:name = '0052014_003645.js' AND file:hashes.SHA256 = '9783caeeb220a7e5b16dd16045205584e8ec3490649c78c4d869594e6df034ce']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c026-bb0c-4ae8-9f97-4ec1950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:50.000Z",
"modified": "2016-04-28T07:47:50.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPk9nEhGEND0jAsAAOsXAAAgABwAZmIxYTg1NmJhNzhhZDM5MTNiZjQwZjk3NzJhN2FlNjdVVAkAAybAIVcmwCFXdXgLAAEEIQAAAAQhAAAASL2d6Pb0mDs3tV6JnckwdSUfIbRLe42D09pXDnWkLC+B/IXqZp8vAUwwBJYT3gWKh2Xs4uyd7cBZNaO0Ba7E5805tziPnMKLL9Iz9OufX+KDiBvospUnacBbhfrAW+T4Ut67gFFsJPyoXNcuart52LRqgZlMSJMF5YOblyeN+kOnurV41o/q/N3ZLlefMq5iysS2lM1uuZT5RAWXfLRFtkFcAddjwm1SxzN4754UP6ub66S2qGJK+VxLyTebihGbe+WhdWXLjg8QBGVSKxNSTY1sJNLIJHs+KsCJfi/wunjVUWMZw7WgSjlCdaNSj5dQ8KrizRQXY9HOlVY26L3QqDBgPAxW38R+Br5SQndIfLpiXVKDm3Oec2tbdUxPsAIiqrAUJ//icnpHvP1aWnneGAY7Fj/H3iZ3W8BtWG5sL964hOIOQXOcx/FgkxMmupMVAOughXbbPtk/BVwhZr88hHVAGbQZDQdyOj6NLQ7/gdW9Dguk2iu3dpoS3eKp7EMpAnK+l1GUZ8amdROCYZy5D0XN8zaXsf2waEZGUQCRobVj8YmSGq4uEyzcRf3ZNZ0OpFV1xb9nvKk0BI7EiYelBT59gNpWnm/ZKYFTw/omQlQdxpxYqRdvRx7A9KG5pBY/QYWCEx1gCDb3mSAnPdM7m22YxoAS+EMETD41LCnErOI8txD21M9pmCJzE51VxDVivo+bc+E8mT2T90GmsPux0vHYKdaMS+5+scxYqGSJV9XOnWUDnoNmXF7LeGvA/K0wufM2zacrG6Dnkq9gxpNB6fkbFG3m2hFvf9Oeovr+x6wz/Ivf7K0lHM06QhzccF5mtgPux+fuCLalwDYn4Tp/O8/6SK3GqnPri0vFQd2MFwGH4sEfzcCSv5LBcIPdWL+H7Egcmf+T+wiR0qXmpx7s2CDHNyUYwXPZf/XEjIK55NCCqHKTzmmZXAJVGva0xcWS2XzORq0PZ2GLZXyjvufYxXtAuIXaiqA3j/KP1ybI2EJ1BfJap6yKNy5a7T6HoOu6FBDHFLcvWvTajf5j6A3srwgYJ4PugvOIPQb69QmQm01D53xiwT8yJGWyddzlvE0C0rAv1fjxFYzxjoo6kDAQE0i+GXb4MMQmCooMMruW8e2Rb8bUxMwJccgG30fi6hEUjYBlJzWxX6ZOQOE+nncX5/uovEBx22Sf4S1etKasiCqXw55Vv4VEZTP/MefFyY65rnSjrJzJbN68PL+qBqINGCTEAZPHs8oSVxH6o/s3J+nI7AGjxEG9372R9BDbbvnCVjJR+4L3qk1buNecysE6y+kgLIs2cpLtup66tvSQizc5LfnBVa9RYHZHNrg4axI9Pdc+5lorHg4PW7XVYH+JtOQB58Y1E/x3IEC82Ih0efjttUJcM9KMNoaLzk/XM9mqQqORh34UcfYn4gjIFuQwmCVgxsyf06TEM1PAWlazWPo0V8oBBFF+A+z2L3ZAzLUMx0t4zKDf6fJ2CZaKD+1flMHKPNuXNy6vVIbC+VG0lrJIWj4zj31y/Ljyvw7K0JTM5VV05vuY1wGzG7L9NvnxZUR7mZC1Pusyz0G4qtiULrW0IYbdb0fOBmqW1PEspwYMMNJ4TSGYWiB5AkuMKiErYSoM12totlFQSotcojopvHC4wb1Oc7WStmVAMA41J47tN6LFu1QgR4WZoy3B3gohHR0dCCFOTZ/VzrsWVSI6K42GGb4UcM+r7svTXRhfL1OOaSTMjhYU5upex8dK9iW/SpM7KRoLBM1/CmX3z/cfNDD2c5Hop4EN6p5bp8dE9i0LSwnN/IPzHOOw5i3LYiWjbwycGb7XmUX/gtjoipoaNE6qpYzL258XxDiHA8q7bS0ZALVs9baJRblvMTo9hbZuOG1BswT8Ts8fWEp2DwlozPtBcx+jlenkXl2qOcjT8WkJOaPkzhdTcQ+ToskkPQtPuaO6njhDSuKw+GuVP8TYZqj4KG6A+jApV49QzthFC1FYYo8/o8gbqRVjSZK7gnIJ5eySov1WKyDzihr4tIB7herWokNM3UmPswxJRcJIa4KfFDl3Fgkb+GDAqNXgFcdxC7WeaNASJB/6Se0FuVCmPbfk3WERi9etYBgc1LOOzWJ8oII2Ly97Bfo4RonGrCGMAeRb3Rg4ZBqHauqDCUkEv4vDBK/9b+VLISALE+e4cr1fVxOn0C9+zjErZty2ym7X5TVzP1U8f0nUb7IXl+ybBEfJGUB9+lWW6ORabx2y82MAnCkSPNlnJ9cbpPtS2hVnroMwhk/7xKCVqcTtREABUVeNkC8dy6K3zOGtKxiYlG4d/f1AKC6QOkasyedTvKm9qo6C6qkuQbFWYsGIRJ1PkEBPs7XiK5PshccyO17+C/OV1Kiz1Q88rb/4WMdhvIujDWcvlnsTBKHmXQyNu/3of5d2B4Zf/Z73LoDiW5zqL9IAIvb1SXYDokwY8DhaXf/v7AvsNfcHyirCTDhBfJeNnjOLYl5y4KVIegBpyiYHljhCHnwWch1TTm0D9lXWvBa/9N8pgLoecM+7+00EohCVES+GRkBfP7o2fW4WDHZICsuuFx48/V47H7xKBUCkwGKGhuhSnziEWUKDrWcUSERyWouQDrUoAvNNTqrzpiibKOk++s4jEIgbZFOw/Z9uEZs5CI+HzmKi0ReBNpZE2Cq3snJTBaVOejN0FKKKvm3gL9BpE/SB94uK9k/q+9oQ1cE6OZoe/fpRLLxe6OM4j73PVZGIzwaAyuDtmbGOs1V429+/zDnrNJ/SePndaPXzAVJQd/wd0df6AUwrp07w+PZ7PJZt9FZaYa+UrbCVFODbmPxcE9lQJ9nVk+yOcXLAvwW009/pCb4X0I520oR6I3V0PLveGgamGM5ziIwA+qgBX2vzb9zlL3sPBfKigpW6v6Z4LHuM8xHOHLasEcsqpOA+kPcPKm9bFH/ohd7qbWUJUQJKqe4b1KUPmKa86bfGgwvlcnDIXnjv8BoRqmTQGsmS5FTV2FEYTf+VlrZ16kKtkxLd6GWINT4PzbLx/aIrodX059q9LmKR/IbAIn3YkYonXpJdDBa3fZQpp313IdbHXYbMag/4XXDFjiVu7PT5nzCmCSVlu/LRoD4CkcD+b89SOnmBuPkl9YLBkuV/VKSTFR8KOtU+PlfaOseviVCzC/v2yIT1xc+6Sv5n5gWpmGBPtg7/aTczdINWkf+/9UbJSgaQQOJu0r/1twrvSJctMYIrETo0EqtYXGcSxNgvPhTV//5P4GNFbwNepfAR9G1MdeWKTRkZctiJAOSR6u6EgvHmhcOdChkskZ64IXEpB2t0KmkyuJnDjpGrXuk+/X+WLkDht5qscugQuv5JO0md292hozEenrRUW0IS7NHUhCqEUmlAPp83iKjpdPTfLByfRZfbb/Fcqrf6L8JlXsbYadsfTm7BlUxraMBVo6yL7wUf4wl6VlfU1C0s/tak+qgp1dv0LKsNa9HQtthgxfnrmY+JLxrtwBDcKI6/Oo7XChRsVPSuEqg/DaxZfQnbkwsT0wQ2/aZTyv+tXyRJ2Xc7Y3TCD+R7x6KYIbsrAjyV7XxL+PcPJkaUlevwVhNCnUMTesfk6UFkNAO2BTNoi4hDwrQQP0Ac5TcRXF9d+wlT/b7eCkH3ZiANU5b9CEl2YJWvkMJOdzCh8SDKnkxldkxjw3FAmfwSqPX3aDPqDZnAz3lG1ryxKyZaAyEzmIFNkoSnRPUYqHS4a6cqXR2OjzD8hmmhcEAgJFRJt+3VZKC9Md23vmNhQ8ea7+EZ4liKhYmaToxXc1ZeiMoJkt5H0hY46X3XVdIGywyafpd/y8vVrqeJXdDtcMrZtNRl59lppO02OyEpB1nM8+X6m1F3nAcU0yOayAV8rq2Oy7/SaRctizYzJWErzShOoSEQLfIskk0124+rluEkCCThTq/WTu
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c027-3b1c-44b7-b39b-484a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:51.000Z",
"modified": "2016-04-28T07:47:51.000Z",
"description": ".js sample",
"pattern": "[file:name = '0052511_0013.js' AND file:hashes.SHA1 = '96dbdf24c2d4feaa7063ed728f928cc1ac08d055']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c027-4478-450b-88b5-41b8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:51.000Z",
"modified": "2016-04-28T07:47:51.000Z",
"description": ".js sample",
"pattern": "[file:name = '0052511_0013.js' AND file:hashes.SHA256 = 'a952ee278df4a965b8f0958be62f70d5fe21e22de042be38b371c8b71618f545']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c028-cc1c-4992-89d3-4fd9950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:52.000Z",
"modified": "2016-04-28T07:47:52.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPo9nEj/OQsaaQsAAOcXAAAgABwAOTBiOWE0NGRiOGVlZmQ5Y2Y0NjJlNmU3OWEzMmI1ZjlVVAkAAyjAIVcowCFXdXgLAAEEIQAAAAQhAAAAGfQ4Y8mEta0SYFlUFduQtpWWyqV6g3y7r/ICQQmSgMrJ8PtelKZ8TBMjhXQkwmaaIMQU5fI8UvEXjMKkNzO9YBnOZkcTLbQwKuz1MxKE24eaVsx+tldZkGCIz80Pm7LBf5ux63NE8YaI3/fDuhxCH5+09DbIRZUT9NaWsJtANRNcbATO+W5d0o0rCVUWgKAq0U0qxeOigWWb/mka9TXhnAe0jKhp4F3YU8UvfQQdH2ZmoA99t/JiunzPgVTlMCUhF6QHhGzTtcYmYLQgwfg13qss3WNP656kEMDGpGZwlt18zMZTA5YAtW6dQXki87dkl2G1Uq+STTain3q/tnegle1FslqPKKYaTKJaGUnkpJvMaGq8MMRHeK8IIvYLtbecdd1Ku50a0+yRLXTWLyn8UQjUPg9zewLEuy5zD5RRkiz0gwp869QATLQ2qcqGez1lE9xlV8FrhFk9nzNBKMn6llUuBEakiD8PrPLGcacC0ZcQRAGL8xJAQwnXQi1udaWiaRZ1T1BCZ/IOiEOSHi6KqVyN5oLJd20Mx9iNAH0A9eYedPK1IVX9bFV+PymHgNPDAW8gT2rSAajxzB0HnDxiseX0ulKp2k78RrWXc/zK79Zwt0wuf0kqHZ9R8BvnlYbfJdcG1XnfGp6qFfNd1HPo4G9Z2fiwi83YDr5kouLjH10Alel9hRpwCjObtxaXcOeOkeJfh8zM8sp4F2yNzcKkC3HejGg9mn0ao8V1EtrMOOJtNBMxp3jTHsJhZtRjN8qvNf7wL0oiASoIWBrq/7gBFt+8cTB0J/z2bwcB2mJtv2oJm5nd/+ySB+ndXOuvE+N6RHvN1QvDn7kuaznwu0wDWd6shLiO14Nm7CiHqjudjD3JcY9ltc4y/Zn3aIR+jRQtNPsdAOJmrVfoIQQJGkJ/MhfLHd3GqE+ycc/tTyOKCSa1QRK5AZ6qtRPrbNjDdc9AqkMrU+ThnjBXSa+Jiw52kwQW5FPGBf+wJymL29fZ/izuvbZitlQgwJoNzsL9ooJfl/1inWB8H+IAKtaviq+wPul7+tkwjZ5NaYSk2E9T9hVpmzkb6nynLgLnX+WLtCkQtKvrvbW3e3e41jJ2ZqRBxtY53eagYIdb1hve2X5FVTH2WUD3zC+YPobIyIYa9aosrSaB2cc4isM2ugwiL4uGyeXgWZ3SuIpCX5MJQeWqf3S46+hlSYRVphob0ReLPLD/HgFXo7xIXUBTPN6mBjHs2cSCdkqPWsqv4kb9f4R8cjN0obYLnJAAW3AQZKd3sQWiT2kn5KvnoACkjnxj0CBQO5dL3gWQo9L/0zMKzO8+wLqKwmjdMmmblWcTTqh8pg6tnzZ7DzaiRLe/vodB1IcjWeYcD7koYzqv4dkkPEWGJAazeoTs0WkckI2dmDIf41kTg9R+kHQRMDjbBRXBlooIQPXIdtEB34bX70Q/SY3G+IxaGUx/6ajfp2+/pcKcqXHXarJtQO5rLP4oePigC1YrMzxE0CUnTNYDx77TSiWOzF84SpYs8gjTrPxvLLxJVhFISB9VfVSnebYw2oqpKGGph9wUZfn7L9sVWQiV1mh16Oe/CjkFXa4XJjPVy/WsrduVuBdARH2d1kooKHUxEyyT+yOHkSWr2RhFJPrsM7Phi2nsPZAB51oWUMgYJJQtH4U1W/42qqiRpyv2kvteFkKHBRQNWEVsw64ZZt8Mi4Jiu03+6nyDjtwNn7XS0F0aLdNBo4N4z1dBnPPoiJqiN/LoViwYBedFZIQ2HUsrAYZ2jgQEr+1yKF+6DpJVRXEPqNFApCAEM7nPhHsf6QwTfJoR5qNng1wEX+kf6TWHUYXhUOTNCM2shno4aJxZPTUbVcdfpSDIxcSVdxUk9R9UTv6VcQuokw/i/C0ls1w3Gg0y2DZbG37Hh3D+JyHx1qp6sg/zVHAI9H2j+W/7x+U3kHqlfWL7Q8Wz39o5H2uuiwliWJBH9Jofs9mntRc3k9zfn+bvMu61/CmhXFOUY3SzS9wANX5/KZpY8ho3jLhhyv0qCBziwFg3bE/sQLVyZaJ7hMLxhEsPAPt6Ejm/wV30f9NU//bj6MyL887Tn6rgaf19Y+AcQBv6tt657Q8f8a7/rxWs+FhxHloB+l+ewWuYSNXaa1N2t2Tx3m3I+VcKc03uW3IUaYrvP/qHWfj0VW/6knFbscMXWkYzLiVLXP9Q2G01CZptEMuPA5NC7QREjD3sOUZDaym2O9vCYEg8ctq2A0B2TPN5PmXXuln7EEW/FzP2vBXTK1FPAX/jEz/oxn3tyuB6vTTywYzwz4TCLGnmCibUf4tKoMh6/85zzLnOPSWvAfrtvzSDj2zysrlZccVkbbHBLW+5W3t8R8BEDK5YELulBdyGkhMpLFgREi5gEUfWm4/PSRIcJ7cfLjy5OOyvGSNXJeVEafYYy87myCBPg8ESyMfOqfjONjJH5arOImo7TDA6KnBslMGQhv8Qws6vBALRLrG+9MMsPe/rBnolp+0C3J+It+usZpjAnzbRHj67A9ANTkDXbLDDx3LzEqHFevktQn9M0fkAZztFeKQGeEwPR9eumRM9L8cxV/PX8m2DFkAtcNdI9n4PhdpBEoJ9OkbymdVSmiVo19ToVVC2D2zONT17tmTJTBe89g9ieeIWzQn/nIv6VWwuSqU79Ofe1eU0NFz2R5GngcdtDG1XeE0aQr4QtAS+JyGxQiKnfhH1Eq4bqhbehDhi1hBPaTgb10z7iBWe00kRvTLRVfXXk6Zgcd1IQSTuLERf92p5eQW002vYR2JPL7l5gaeoO2SfdXz8ymvn5F6i3jYfpeBoCh462pH3zUbvsRj2Qg7k7kfMbPahiZH0VDCWb3HEJBGCCjl+WbNDRr4RCV+OLn9OTN4WJ3DzEFEDMEkVbppr3GRuCHKGl/CfVXV1WL0G2HvwmETT2zEJZUPDXJnBH/89kgQ3GxsMfrzMfjqHzMqECZIwm+04qlUGBkq+xsKH4N3KxxvcbHNW2MNEAE5kooSreTpcg+AYUQyMN+ZfzRuTvd8MQtSnlzjICA6X40FVFGECySH5TAYVM1vszOfFWerSw4WRfZSmFDDANsvm5Yn9JMkgFQIEcG8dXa3k/KQkim25m4P4xxlux0LdOpO9S2lgtis43hx2w+G6h6AUO+DEcLKkav5lLMEeoPsYGeC90HAI6zyIz5BYwD7XVTMq5s1LTXZ28HeuXvbR4AKUKZqLFIF56FTERxnZPgp3NGS57yXeQ2Nk5PxUtJwtE0kpgVYC3cWdaOSLJqOE0k4KkKG+1Q6HG/OqzVHY4s5ZTveDlgmxwopuN4Gn0UFyLibP12cQ0d0CdB7EkzHbVINYnK5Jd11lxiZSZ9o8jW2zy2q3LbR6eYaFz70IWzHf74ksrB8M1l+j2SkqHtUe1D2B9xHrE8idm5OSrafRYNMpJHnPTAUnPS268/nmTGU0Q2M3JdCPuDNsdZ8kptf3Oq+pg9sskDomiUExceRtUE60kP5Sqen5WkgwoyjluGPGqUCJWTMcmk8EFzxURWMI4ZaJ6qRCeBeWgnZsbFVX0v/ffG5A9e6Zy8ILp8OHTsBCRbgy9NUwcdqw4BbI3c0qOijgrrq+KwYo46OYg8Cf6LClvVgK8XXlgM7rix2U3D9vVd1Ly5WzdrBEbR4QLMz3HCd2i5SRCeCX8ZvG/x8vMcpJ3ttHz43LU29U9wxfoTHYFY0G9pdk/eei2LqYyVMLM1g8X4JxXo4FWsa/C1zLtI3b4QgV/Hi+N2cLin6UZ7Mf7Huq4ZxRimUnC+8dVXG6y9WUWN6+qjA3xMO7618+JW/boDRi7K34+iwP8Llve+uIN/0pwi8eaIVqcolUZ7jdjiVyTWfh1I7qv9Tgt3jJnasR3tL3UXffEMzEYoUUiXI3KStQSwcI/zkLGmkLAADnFwAAUE
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:52Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c029-ee90-4fb3-a732-49cc950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:53.000Z",
"modified": "2016-04-28T07:47:53.000Z",
"description": ".js sample",
"pattern": "[file:name = '0054812_002055.js' AND file:hashes.SHA1 = '36f063622a48593621cdda7acaf741ef4e5ba627']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:53Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c02a-ea58-4681-adb3-4334950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:54.000Z",
"modified": "2016-04-28T07:47:54.000Z",
"description": ".js sample",
"pattern": "[file:name = '0054812_002055.js' AND file:hashes.SHA256 = '85df7b46a53342a304499734166b8aaea975f578e521f92c54cf562d95ebec08']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:54Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c02b-b37c-478c-b9f1-439f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:55.000Z",
"modified": "2016-04-28T07:47:55.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPw9nEi1Tu85eQsAAN4XAAAgABwANTc0NzhiMjRjNWFhN2E0MzM5NWY5Nzc2Njk0M2Y1MTVVVAkAAyvAIVcrwCFXdXgLAAEEIQAAAAQhAAAAs8ddcKMghWhvGmMkpNhXkiIMfscKJEUg6SHs1k3ngTzd8JzruhtJEN1mPm71BUcwtEY4UnHL7cXo8sc3b8Di89ITzOVLzOgrQWc1BprgXIAsc6UGHRj6Eb9bbFt1ukIKGWzJ6g4ueP5iI6cAWCMsNt/g154iqY8GrRzfJAGZESaaUKA+Q1ovb/Cy6o6gGfCK/bLsqFMzGgvrK8EXzsrw4eu2xkz6q7vq5LrSAXY8mNuPxh5B6CGDXuNy1LygVgDDn2YBdi+89d4WW6i6OyT7Y4G5xx46AfBnKWMyw5nk3V21KKZtnhcuT5GTARrC5IZqeKax/M8MaCU+hOzPxahkinEgmWhSa+Mn+sJDXH7J4pDGPlSG/NNmrX4+thrmEBXiT2t2oHt17BrdE+0FqLSbeAhnHFKU74QhlDdZDe0U8+GYwqfL7+wVLeSHMriTIiBPjAuVl41zpEuYQH7IAaWDP6svqsaKW62em9m9+AkNMUwIJ7afkSIz5/lN+ptq7DiwlouJS6f4oGBqdOInwEz/Jz4fK9fOiiTxPP76Ld97Gu3qyMrwmSqu0bKFIuWuS1r7Z0cuXLsPt026kZvhvT8x5ytFcuzgs8BZCohIS8zKaOoKAXMZB782b2mhUjWYRsLubgfyS6+AoBOQSrkxNWA29a6B5cJzAOIt5vqyPqLbP2Z3a2I9fc9uFhddqxKAp9nnJilqszW9fjRztdeLdzPfWTzz+Y4iI8BKmI3xmFWoGOtP+QEKJLLjqHihakG5wDn2L4nATT4ikO7FGmpN5nRKVEw0uLXRnklcYLSv4GGdTmOYxwcSPYM2rS2tzIkCa5mGshJSY43cyx8DS5CVMMxjmjV31YFRvPMhMvL0yKZY4srAvNjEXJi+SbF7W3+QBO0RgwFm7qgfjr+I73Y7d2F1JM0hubRoV53iHNtvj8M/N2AbpBfZfw6cTn9J44fuSRJDfWIO4z1fJz5/ADM0lryJmNOnI6uRY+U1GGjdFsaVSdpOVOebh0hSoo7C0lQZKYkuy1/P8qIXvqekEa2x1O2aJp8sb4JeVkkjnwfSB4rNrrZ3IzldYO+uPQNDvMCAfpcYbnMhoYQAc7Rd581UnKHFFF620XQToF9+4WSl+UFaTqTvzl8cpnFMVrWVygaSNE3wEuMHZ0Jwwdr51Q+YxRV8Z1Rr/T6NHBR2a5fba7TIC6oUD3wCKaBbevq3WW23MCreu9AEZU+9MUwquHJw1eO25kmpUhM6yA9i8h9DqN09ZI0VJCeAtnpAFjH9e8HejG/04LnZzzWj3JcfPE0jfbSJRKUABYpm9KUmHcfaPGOHagWVnGmR22b346NobYWzuLw4UKndS/HOkXsXtUahrDbD/tKc/1pl6CCrr/WOXt1JZzO4oCYZzjXo5Xj9Y4xrbGsnf0q+tUc8brRi2phnRUa7+zum33jo1aI7Zwf/yKtNz6H6N8aH1eDOo7E5o4Y/ivhdKufU8kY+kMIy+u1BBNwtCFQ3FCjBaaIAA2xP7hV6vPWEMzJuYtDZPOUzAC5NdkfTW70Xfs0mk137K5caHxicfST4IGOCtjuJruhZ/nCAOND6jbcAk8YR5OgB+5Mymd9pwlVF8f+xSgaxZt6k0akg218FMpiDAlPjNr9PhJ0ieFIv8wSW2Q9cyO0gc0wq7cKNdK/j61WIkJyIRmm9j0nvGXtnZlbmsEaouJeVVnKd4+xW5bnkLmuuFa6rOnFbAJcQI6I5BkVcD7uP7/c2MkBBmTzI4P81dZXRiWVDxiQyUPt9Ng+rWbk2RRK4nXT8A2g/ap97XcuIDYW48y02QmJ4698q7UVu574NS2llSQ3JjFoCh/TulcmJcMoS8PmeNKmuxCRCHNy/92oPm8z6bnfUYCnnVcfVAiUNWI+IkZxdJiLHkaGvANfxaerYCF+7EyK0phwkT+OxsL0YkZCe6hFs8MrUJCHW6VtptND6Whg8Vs8zC5KUCeycSc+iZddx0TW6FTRq7b44RAbn5U8VodIbCxhJv+iY0mqGKO5UpEFGOrjDFM8ern8HeUiDT0njDFuXUkkaJcse+BSyUANzW19fZ0vL3LN2/cwXrlwmlsF2AG+ltrsVBHnmB3DGeQhaiBPKmyOl4akPTt/T0dY8oEz2aeX9ZQoDQrF5czPv8pdECKL2ywC1iFIz/V13vCbO7O1jxcpZl/9wFbDC94M1ICTpdFcQ2XaiW89S9jpJV81aOBKncgeaXQ/y94BYE1YZTOus8I9s1PpvF4L+4jSLUwsn9oM/N+oH5gnQexZJqCdoTJmYZAKQKbT2tecmWS77wi2ni+owSyvrXPW0uxURKVYpKp406wMbh+CmhClUDLP9DStKlBbjvG8nFion+zAm/eB4J4oTws3bhvZh+/QPKgiKOKJpXcuOJTSMclulVQlzYd98fZrlryV4gT7Ayg2uxtkcg7z4LeIbAHobWSGpHxLoRa0NRZxYx35SptfYY7bjmTgXh5I0OVTAuEc1LpQfq/zKwXHRsHQiWjERJO3nA2Sv/2q8gNGyjt3VL6Omkl+YgKfAq37tovk8q1M3mmLSner73PzLoVyxBvkNvRFEETzuZsXMglQpQ3SD1yyEmnFVgB6VK4eWTk4PmGW6G9t7twzF7F9D7ojGTLvPgSFkBWTGKfy0U7iDywcY7DMt5BGDtiNNo+y8EjF8yllhp4y4MrP+zujnCLHr+idrU7hATL+iFTMrKTcNgWDvhY0QeZSd1N/5nwavdUmiZTuDZxtl/veFZxyWrS/0e8MdJUeJGOp25x3mptQkzQPREcVhMn+f8LpbTaGVwyya0LOr4uCusGi8XkWutP/hOkr7/IfHEq4WpkTXt8WH0UqFtdoDBZLiHvvT0dLUTSEgYQd9dOV8lRAl74sYl9pFQD1BUy1Y/bFOz6mG6zEu1ZLCg5EcE6bDhCkWj7wjCZnoey/Kjt500lMv/7GukrtVn2xJwTbymkiIIOxVwdQe5eoy3APsu9MVm4b8hn2nIWJs6zVVfPX17W9i2+8pDaP+a3zPeEFO8MLwgxzT66XVnd9SViz6yr0LGzlggCZKPdMW1Q8Zmtg1+8LDaI4Lso3q6uULaRXUFpgf8W5fQIfB10wwn8nwnSFTLP2w1XYh3nycZw9TXgoyVXu8VIq67bVzqu/alFSnIiH9eNXF6MQnVP7uzeEHqOQFcfO5SLAJBUAwiPNTMf+KfYZ0RT6Fo/avIVj5eDsWk2lUK31lXY3UtMpWcyZcveHNRarSBwWnwv2R9iA6I3prKhmAC3pJBnO7WRyJusf2Ft1Rh+mJtwjk8f3sgG3s0hAniyA+cXDgnyb4cGaiDwlzXytaBlRi2mZEObCM520L21DmvwJdoi4FI+W8HV0xKU+4DfccMsQyNyscmbZdzXBMwMUlBJzO0C4suVUSjE+qzB0BF3D43c1/JngyjKOXRl02xVsfTVkUxMdj/wNTEVFf2HyXgFLbGc+002QlY6F/PfzWeFwp9jpHek+/eS1ebJmqRkzFt4+RkBzg7dVKmcL5EO+vfbGZ0HfPUL5lHYtHe/gLlyT912/mvlYaLk0MkAQYSimTkdjnu66ELs7nTXeVgjoT2mT2WN4I/JAiOD2r7FQZOuj1pLeIX3qpvu1y8JN7VCwtRgvv1Fac4ddtOyE85x0YsVn/pDeK2H/2RDnNzrYeX0vvuiOAtUJ+UwG9RzQEGZXD93dF5FpGESVdyXO0ZD0wT+j0bqVp4GnbEZ6pipJxBoncgMpzbmirPr2UpId4M0ihSkuk8B9l5xpwIlnjUsGBdxVxOTNh5Oyyws2K/yZ2cXJB32LywmPlqECxQNCtTTDLAycikdxz/2wTerZhlw6tcD/++fL2am8kILOqXucN54tvUXBFDURAKIeaQJLdo+UNyIHhFEUu1mZN5P1dj0TxMVg3rRd9JjujUE
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:55Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c02b-a6c8-4985-bcd9-41b1950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:55.000Z",
"modified": "2016-04-28T07:47:55.000Z",
"description": ".js sample",
"pattern": "[file:name = '0061609_005549.js' AND file:hashes.SHA1 = 'a375ee49de4b66df29e1ba594fee3630e73d621c']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:55Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c02c-4640-4248-b03d-4646950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:56.000Z",
"modified": "2016-04-28T07:47:56.000Z",
"description": ".js sample",
"pattern": "[file:name = '0061609_005549.js' AND file:hashes.SHA256 = '3ce1af4092be0d2d3502533bfc268c49d432e6c6c95711e41530c5a9e6aeb69d']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:56Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c02d-b810-49eb-a9e2-4273950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:57.000Z",
"modified": "2016-04-28T07:47:57.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAP09nEhhCOSChgsAAA0YAAAgABwANjlhZjkxYmEwYjIxNmQ4ZTkyZjhlYzY3Zjg0YmU0NDhVVAkAAy3AIVctwCFXdXgLAAEEIQAAAAQhAAAAZKNz6CkIbBGXGERzIKFByVejDRtCRgkoF2NNFsUp8tQoc6jXpsdg0qwr0ppSWSd7EEjK+04ZEitUB/rtGlJRMOhS74X/2HBe3MoCM/80H1WIYY8qKDfZU/52x7++hYbzaei96ZWDj7gQhSQJUwa9w6edgTy++mfNMltROMv+kMi/KzebM2nIAxAgWaqerXcSi1BZPjKXdXai2gGWc2YTYHZe7/3xQ9eWclkF/uTpmFnpVMA8hG4BV7mqWC69zxtMY/BBuH3T/goelbtbpRmRsTuEp3anpWP2/KrvD3E0bo4+SBoRFloIWwcFbUov99cIvFHzUw5QZNwpflenSDeJJRVGhYcfoftgNoRnf/vvZtLGNlVS8MJ0Q1qaV+8YJvOcET37Yb9fe0xMw/RoJl/1iEYR//7/zrHrlhrE3vBX+N9fjMt3ZydANqwNtkLwPVY4RBebYXdRvJwN5TARpkn/8KN/DjmHmfuyQl1uX08FOSOri3r/XaR7S/+ItdzIDtkxw1KRB2d53E4VuYd1EcoJHdzRShpjwPGd+6Tp1hWiTAR1xhZQ0ey5BmVmpq0zX+Gppy5V5pEI4sOyDC2406g2wyMzTsBgBIt+gniCZYCvoUjrydB/Dq3chVcW4HbHV/kwjymLfm2Qdou1yYTLudynPjhpanTqcn3H6lQ4icNEUplkTqRCNMtcdmXr7ua6eNBhKbp1oAui2djXDjuKD1jq2zFk6e/xpE5btc0Ct9qhnQHF93ClLbw66/vItz4sjmX5m2o+LqhlSoh+ExMV4mH53labdQ2bVD/FJhwWgthrKhHC+oGCl6excDmpLt2QAIxJraugIKRw/LwiBiv2aZFPNCyD9jHqhmxxjVacUyf+vNHikOlD4to2h5PX12e1k4B/iUC4esXyoNavcF+hCwDwYOZ6OqweAGwfvVz8o6Bu5BNlgC/dMtavui7E1WBt0+RgF8hLscJyRygg40ybITqrVI7d7ch/jYYKU/iG+J07hRMqxuNlaGoc+XxXW/W8rRXKZ+3NeK4jzS9zzDBJtE6Q9KBgGpVwhLkN6CpQnWbdd4xRlhTFii1qZHdh1M/iwwGMeQ5DrL9N4mKrSvI3yOb3TKioHETqyFfjPi+hVkYZA3Kpicxquw0Y4nI5m8QqMkArUGtRx5jGXbZGg0K9PHBxr+9ikeauWE8OHKp0YT+yLI8RMluZWr9ZGphzR7OlpngOhYjqvNxTG4hGjLpeU2SYALmwbHNZ9A9Ta8S8lD69inLlIzG3Dpj0vZ/7hrOW9PowV8bY40LojlSubH7WCmqp9xVGEiBwTXHXVgKvcAM6Bb+tkCaHfSIJk/CHAuX7iTn99JrjuGwEIVKB8Oq2Gwb8xAewoT1T6t7VEWDA+FYttFu9yA7MZiyKcPghVN7kGH+6UJyM4t8b5TT8Pcg9IjyyJdomieBPes4SVtF3W/HPvZU+usURv8cOa5g6//LrTAzdZQqVPio4kK7q2v9jpHvqosMN1G+0u/klxNL2T9qPEtFYXFglR5uaPaArL5ZoZjW8iJDQA+ZOnceTyXoMIqRnE+/EESu3qqyNxm+MyLsnpfHcebJEY5eQKdkDRWIzej7+d1Q9Ef5uWCqI2c3KGbxN8af1tohglrfW4ByipQEPYfcs+afQ4YBK8BNzuzdRqC56h4QuioIMgiDWOiIIF+D0R14wuhsovxfhdnID+tJwv4Rsp6yeAGp/ukT1n/yaGb4IMECAHDQXJIuYygd8hAcg53r7mTyhloWFGHiOXFuQZovdkExu/w8kJh58zsgQwcrUCwmhxqgRe1tHbS6Vd9VZvKpz/JAixSrGfIAnoChVxiBeKPJyRfopnCL/smxK0aONjGvzeSFIJA9K8VAo97P32t3VQqSkXFDeW6JEJlcAV9eJD+USonQR2YbWeks1WKerNxSI9mVX3ZICnyS0QbGqRYOKGfQUHqRMBRKVhMYFFtmkzCUi0H8fKoVS/Xvm1BdNls7T5rzhgQ5XwuHpxnySnrTNdIPQATWjjE3W/gicQXj28CxN7ShO8NmQwRa6zlzPHzCopclo32AepBzEJwLipsVKpz33o07N1ckNMT2AYmEFnfqNXTRI+QNyFKh38IFE1DF9KNb6Bqq53TbORiOabTuz1S7IoNjEPdUXKOjn4ijFs6GwgLu6zEcXpY6yEA9/fR3c3HxiT4/JVPJI/gx3KhCO5lQ5tKYrGnXS5EVEokt5BDAdDk1pRSnhP1BiXnkWntJGDC+j+uaxLhMQ8phSZ2aw6OWnuZtnZSdfadzjvT28RK3yKa0lJ8RWAVNawjXKT8CiY8ljUL7FoGUWNB2ItVCFAt3FsJ5xdNxW3sox5N1uITHz+P6lhfLi8ek0Pl3jmJH2oAOFeQCORJYXqUiIEIvXIVU4p43wjzmtW6sijB/po0n6PQSoJ+v2Xhm/lYmVOql3X9V85oPjyg4KYl2jY8H/+8Ui1+rze6cSx1uJMfMKz/lrBgbZ/fFVi++osWtLKicv1iEVeN5sBAoknxEBfWnyfjkUpWD3X5dHUG0A8f/tmtdw2Cwc9nWEegCYhSfDQ8kry4IhX2qNu7k/c7l8qJksWn3RVBPUQrP/0KOaqGEBuPZQmy/mmYYo8Jm3a7HH/gJm9nBK4/GXc2IXQDBrEmJcSW0rJ1iZw+7sOgcjD352QEUVTKAPuNkHdGl52LjzXnjpOGZCbD3QHf3P0Yus4GPZw4qLhKmOVvUDVZbUK/R3NQBDl1FgIx89iPiInyLWFyG4pCbqB55ktcWi+cNRIXGS3z+tmhiVrTuZnORHa/a4b7dszdhUzSz8Arh3aDjJBE6RDJoRj+2hrENlGsuTluUvVaO7t9cHT0SOIlVI28Ex4qBdZjb1uj/7U9+OezK968IxZs1zSv8bly1JND86UNUbaFeozFsxSnSeUvU2YfTc3uy1dcq0A4668lZfv2n73k4MM289z+3rAeOfUczR18WIpfNI4YI5zJLCAjdDTsRehfxhplWAZNKLxz3HqypQsrtrFtGTHDGEIihnBLZN7m+BVn8vhLoG+12ymlAs2RcKcZm/StPFDRBCLLB8vtfupZl7TJ3RcHtSqx/mckg9FF7yJOjCIH535NMGJKAGjU6WcxxHUisHVs/xAWkfz6WVOprEbASCEIV/BsfSq622i8f8I5n4U6KlFfSYjXJD4Ci1NB8USSRKWY0eQVxqGNTJemgjAXDHG1QIVzSc2EcR+egtxfmHfPvND6avoxZA6JR/78Enl0vXg18hZtNezexu2GcLrPFHMlZ260zmsA0rP6GXR7XLK4vXOdPLd4IqA57UxfJQf8TLIZ1Th0PyTyJ2EKZaZHPJo4FFOC1AJT2dSrfJAndPy7gYKO05+IB74dq21KyK80rnm9FOpS9r3pgRiWj7SOkX3Mp1ZPztowC+Zm2ODA9DgyhSoxiRVau3whVmyvmJl3qL+5DbDcaTuXPJ3kMO8/lPybGgI9VkPp2vHmh41L7ew/Q7vk07PKC2T9neWTyXfsP3WHdbXvD6gvLQW+q3s9FzXqm8yMcoAUOlf1tV528F6cCilJ82Ye7CRonYZN8lzy6uthpgyLHtqL4Ps3Z/84DI0CJFGw3l0TR5I7FuK9nsdem1jEtvr4101HGXK5LaAeZgIGRI7jzaVTSEdNeAnaxfgEgNttgvUgN4QwB9QajgxRUOdbnQXOVB1jE4M5TUKESceNKjqCKTvC16sCqMukQua1uyAowfnS8tfK7h2YaRq5QBNYPbAHxDab9vRTm0y/Dj2to9+jNtCM4oNVE6a7gtaSDdvjESOPiNwx+II9fA87Rom9S6GCk9r8eVUDE7wRxb0R7HAcIQYRXErBCoZmz3qjNADdiflumInFzfDCBeQmRyfZProaGpra8oKrgkGtv/t0xu40uZK5mg6a4w9RUDzQzscD
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:57Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c02e-5cb8-4441-98e8-40fc950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:58.000Z",
"modified": "2016-04-28T07:47:58.000Z",
"description": ".js sample",
"pattern": "[file:name = '0061913_008459.js' AND file:hashes.SHA1 = 'aac930f7418b4a5e1d078ce59eb98a881b4d5d8f']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:58Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c02e-829c-422e-9292-4fac950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:58.000Z",
"modified": "2016-04-28T07:47:58.000Z",
"description": ".js sample",
"pattern": "[file:name = '0061913_008459.js' AND file:hashes.SHA256 = '12035e330130f557b6ee29f870e0de2d92beac1122e504945a65521b86a568c1']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:58Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c02f-0f34-4522-8c7c-426d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:47:59.000Z",
"modified": "2016-04-28T07:47:59.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAAA+nEg5aU2YiQsAAEAYAAAgABwAY2E2NmFjNDEzYjk3MzE0ZWRjNzMwNWZjMTI1ZjdiMDBVVAkAAy/AIVcvwCFXdXgLAAEEIQAAAAQhAAAAZKNz6CkIbBGXGLlD66unmLPq2PyhGJ2TxWqbmTxeaY3zGkOaSb2w66H6NCO6TT24Yg2AxZx2jkuKY4+JW+Rdwi5yud138PkNZHmotnAfdnYI42BHv1/zjp0aMKo9OUL9a3oPp6JNk0STaM/iuo2Nt3sC8Ub5jdcgLH7Ooce+1bU8ZIPo/dAnRAYvu05//+nayFr7G+lzjmdmoHuzhftB8DpYyxORA+EMBPl3B+2WybaXXIDbpMLiQIVqgplR19xBgixImWy+9V2fKR4AyFErGkW7FP9DFJe1CKaKMWqGBvS0beEYcEECsOK99d/X58CuteZuSDy3S5eL9SqGE9GUmcSjgqXTdyAAUjst6Kcpqs3sL7r78H8YBsc6yKdQ8NHs5jxa1mVj3GhIC0E+CBZrJGRJwsc2+1Jk8irT3AZlGsTGsBYCxynYyj6uOqkMnHm8dnvJHleaFab84Tu2SZxkTl2zDjP2/7/3wHbDXtNbFUA4ll6yqXCDiV9MCE//nhsa0QS0XhrVENGGVr1Cmoy6hAIIa9demDD9IswcXr7gI2hlecJuksQ4jYJa5DOduISJnzLxtoPtjpcpa82pd9rDkrUVZp1pUoT25GpeUxRrRIAI5IrvvEpQ8tbIdg48oFdXBIo5kJZkZFXbkynNATPFh5WDT79Nu/XCQ+KrHrMOHNhoExR/bUa3NKrWLna0956E8lWG1dWFEfB5SjZ7+op5wY6XfUR3AHvaNpXTawv+tqzSsUwN25jD+LnUQQ394UPsaUeIAa9n0uDp588tZifp42njz90ppkkZ6QIhcNozH1FUIoaTB/wdVGBttbnPrh0wM0JiMUc6G7vu4Zc+29K66qW2h1AS5nUaldpjC4TEVIbk2yV0ffJE4mHT1uUq51uSs4AmdcZ62VfNDwcnPE3d26Az9XScOV7pWPi/NUIjQQZhiNoaRDiy/F3hlGXVfGQTDt80boIiXwg0KIrYj8YsWGWcoJLNr4V5oPBx/D3zFjeVpUvww2sXMg/0d1Ku5AIZzKNQeAHQt85BO4xIbnxIgwsaP5xjWvvprUStZlf6OV2VQAZF5apQ1t8RTzmuf8sATvnMmMMWEKi30Lj3XwPrOsF5spySUfqVyOwCi9A27z8HiYEV9v0b9jHX9U5KjSDxo6O2PYvIRZGW6iCrmNusweRO4lmYV17TmFx+GUmk3jlYSlDMuRAsNzGxql4TZitlWer5e9NOY28yHwvwxXZvzIcpWbMGY06bfQw2jcejGBvPOEZyGS+9O7dDkXN6r3/DOykc7P1TeKIssIZ5MIPiL620H5mk7D49+OWLtvD2Ifrmza57oUAiedzQoSL94Tv6kLBUPROH0LkLg1JYZeToeldo44+SMoBPdp7z1R6vTT1X9i36GgxRwPTLArvRuBiEGkU6R0VNUQvwltyAMIA+jHbdYc1HiRe+HmSlnbwbNoPhj7gWo/mZml64k01Pf798KrdX38/OhKiSq8oENG9/IV6lG1rED3Ed9/QlqYtyhDt30VY01BjC1X0qEbrrFUGpyMRDfaT+0tQbB1ncDWEg0u7dux1bXhTxNEstl6IpYFVh4twCP9Gopms+amD445A1qFe3BlZt3pabm4PDOHLFVyXPXLpTfTZjMKaH3FI5Vt/1PAqukJy9TMYeQqbI0nUo6F6Pk745AW9iLGcbjNLeVVn4njXdTBebhXpFLqKemYKJh96oX/7bApEOWQue5oSFX3N0OapNb0UqyZxaGXVgnbeFiiBklZtuJB11qLGYsIqOK0E1I9Q8eo0Vw/K1imM1uYwPTrjO8J3IokFfKFuAgzXAhZP9u40ycF2TEixEh9SFMa0s38qd3HODJHfVdBT7jZCVmDJkhk9JHOhaPHhjBEPdeOJiIwhC9V2aikW0l+SCvx1gej8lf8nPdWYprKh8D8t4ejIqxQwJWvG+ztfbqHEQbr3TEWRXSxnXzKFIx7nsMCTQHGqN89Ni+7kIOm25u/E7+TjNr9o6gQ43QAO97PEwLuXS8sUXY2wVnCImfTv2l8yZSInHlt5Wyz9FXuHXy8c207NsKAwMrtbOI2gb5/DS/ffJmQEByht5jgGtB/SOacAvPaBUt8MLHp5DUu1YYhnqd8GpJ10AF2CgM6P214NggiY4z8AI1rGAKcEmca5FKTHXGlYc69h6wqsgkW5Zp1YtoI5w9jhdG+3oDFroCel/FPGl4G36iMEiiN9aItfTcPAd3smWMy0GPYc6YmwvGaHHvKjFInSW89bCRxIrl2N5nEjentsmvBALIQIt2ymjfV9qTganOA0tqaepgGry2ls6MDd8O1E6BKwyZyiIwhYn9YZ0JjOFLzYA3RmqTjI95O3JVxS4W/iJWzv9tW9MQpCMiJihdaEp+nuO7tadTs2ANJNhZvhJsom404z1hWyPZmxsPTtzQYvrp7xbetIIjJRNlpOTsFFWgQcpXMY2Ri5lNin8vTIDc/MvoqZdwAAcfhuDMk/JCcm0sLqQcFkU7VySEWpKhD69kqiIcHt8hX4uqbmlWkoEdYdij4R4Qk9636rlaZbzyNOXNF/JoQ9pQhfORitY14z1aSD3MZ+zegRKlBTVw3Lw77vUPx1ZdwoJeME2yBHg/leKg7v7vxNSlKN3GyWB2vK59HO+wJMekxnVmaXUDcAQFXimjKC0NNI4pM5uUgbJRzvnLBmybxQnijUn1u96cMVz/9Q/iPbLVwYJyz6L8S7Ip0+gf6MSIIIsJ+D0r9c648EgqoukEDjuw1sDl7xl8FTLZGUlPlTA34QEubvmpgSfat8DpZDCcmYDP2anOGTPB/d52vAniON23zLnsirS7CWTFrIUH4G09v6VG0KOLj5wltDG92Ie0WuHDF2AKc0L6LO4HoIbnmUjckXfP+m9kfQc6Sp72X6YYa8EK0CZrjRV51mFb2VXDWIV3feFItwJxunbeFgrRcp90dxbWmH07/Vg9Ogzh92FSSAq+FTTes084yh2ZiBN9GQl4Gz84PtPWwnwAS13zsPPHz8RFUexu38AYN/gu4eXhGmcWh5sEcYoVU65m1AY5XTtQPzqCbeVvTOFnBTZapd/APhNg1B4F0bKrSN3Ru2EFzOLwec0MDyW0YBFszoj8FoJIjCQJGx8qdkTawdXF+9JItb7V4BGhsMHrHkXxo1ThpXUovJ3K9ghYj2P+m94TJA/gAKQ+hOkQRkRHklQbnMk6tick84CwSRaJOwiNF2yiNUJq/oMdA+aGXZQym1ODUIdK7x1GoKSQxZlrruQ1TnIUIda6SvQMCLz+lJIqEr+glXvmfMN5PM2Q+eYcPdt4lJVbGdIEnlXr2i4U5c+DpQzTh4ptvdrDPF6LfhRSFHAbYW+vRW9zhsL+d+j9lCpr11J+zkbMBBziI9MnhVsS8hVUUKQLk8PzPQCcAop81ofAdHo9vVo+ye9qfL83owTXmvQKA9M9ilzZbM2EnES/suheiZ4v7c8Nacn+odqpaPUM2ntyTT+pzXKrjFmVfi6aelXkA+Eq/MxqhlK8/YzXXql4+m8XgqsdjslM3BqDXt4Trzsx/gOFvoy5BcNITE/kvsPzKxzgdl0mNg0RiUC1RVMusTIdJek4RKRdacd2bsRZvCt9AFm0myWdmGTYsAgx1EhjR+fdR3ZFMARIzaviIuVS8Ao+8uBZ4G9m5Aomhrz5AztQUHfDGnLyEyQOSt36roOsGbYO9ux28tFaPRU21s/zsUNAvTPGTegXWR5GRwO4LrSxpjj/YzxtIp2fKMswbEQMkP8DT+tjoe4YfNrDUE0LE+ck/HJNUXdbHxKkma5VODQEtSX7PZs/2kkDrhLVFPRMiR7Cmv9mKjoNw7/pTvWXHVuS3uERHEvftq87toLdSVaARyKlupThEwMVm4rMx/KpIYWGB8t1ruLezvTEZ//QvQcdfOc8mFpMM
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:47:59Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c030-4294-40e4-8e63-45b8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:00.000Z",
"modified": "2016-04-28T07:48:00.000Z",
"description": ".js sample",
"pattern": "[file:name = '0071109_008310_1.js' AND file:hashes.SHA1 = '52ec171c9ba56cb5156aebb74c4e9b0a57094698']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:00Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c031-2b60-4adb-8c7f-414f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:01.000Z",
"modified": "2016-04-28T07:48:01.000Z",
"description": ".js sample",
"pattern": "[file:name = '0071109_008310_1.js' AND file:hashes.SHA256 = 'ed6e4a8a97e223fb4c33db66d9eb5b13bec86b4d2db25b1a6b257aa0705dd529']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:01Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c032-1674-4429-ba6d-410e950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:02.000Z",
"modified": "2016-04-28T07:48:02.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAAE+nEg5aU2YiQsAAEAYAAAgABwAY2E2NmFjNDEzYjk3MzE0ZWRjNzMwNWZjMTI1ZjdiMDBVVAkAAzLAIVcywCFXdXgLAAEEIQAAAAQhAAAAqNvJ+OSAFOZkQMWFqK/JHA04F3KJDpqq/OrHGhZ277MRROR750yDTqBrgLZQNNbGUljXqVp++Hns/EiBGA6ltUrRnaIonOnJabSRNAY1nycUuNlp+Inb8UV+1xG0y0SK6ALwdWA9qMVz8Z/vQ57kl4oQwPusJ/cvsHqbzu+dG/q+dj5YB/Kl9NkcwP3wPilD3sW/9/FCGuh09kUHjdRO01/UoXTVwcQOXICABZyA8T8dYsYXrx1eT58zOu65wyGEx7UxSZyKXx97QZcn77op4y/A6FwfzNLjVYFPELnorAMPECTbzmmvlQRPQAtAMC+Wdrg9BJ4N0Fa/rxjAk3ZlI8D9Ch/Rk0oJCXAWr348qynw50g5jHU6CE7hHNEtzPhO8Xc12Osyw07NZTyUhcbCnFT7FqXSKCb8PwTfZOGa8NpTJolc9gIWbj6xVZrOimAUMv3D58CEMHguaSBlWyoA59gLdMIowobkI1dYdroYMGWZxKAM0a+GXgunXHfjn0wpEJXfqeuqxeE05ldqtasYkYkjPmNQJ58NhHJJhQ3zS3aVo5RbMpHEuxg4Ip9Hdgc7JO2LcU1+jJyh73DNwFXMLWZpFW8+M/xp0CEYWE1DN1T6P4l7TIH5V0ZuG6WYilm8TlW7IshYs9idSlI0qfqphxTbtxp/vYMiq9oQkgB3f9K+aQU7XubSLNmSh+10r8CLyif1Vekj1ZLShXnbGlotBUPc1bo17rGLwHdDQaIYFU3SHrsunXqPjdwqiXyo99vZnl2KWrAUC0PnRguw/RWPdCiwu3dIfEQI/0fPQDEZZWe6iayS0JXSOjiJVzluX3RStf72I/RkdzGSL7LZDeTIY8DtZCuUWOHnuCyCJqaSnN6hZcGJSr8FyGOXEVOyTeC+0Dlk0PZieioPFFgVV82RBAbWMPcBwV4Xx2fAqrhUuD8x49j1l1aRE9d/5V3hYWyyqal3jkbGqxorxe/nUc8XzcHmmV34rebibdB8EGXjCEwBs9JPbfvSqATDJ+FgxtnXLZ5+RspDW1qZIdv5TupMQCok1Gv+Qi3JEftYMqjvsVE/pyIkyGKVwR/DAhJxCwCmVQThij1uUynQWZsAcPbPV2QjuhlbTZcxz98o47GBp5GhCKfYMPc3w4vIuKQLLY8Iwhe+uVjh0M1LqkiuY++xJ8HHisFgBtKzEiBveGPGb9kgGX4/4za1uoXpRsXyE/QbzTGodVSIAiTCfmkUS/bFzGyUKREi8CFkzUa+NJHXfXmXpbkLWFmvijgevts9JCFOvKyRFHZmkD3qbTIsIJIhgZQDb8zv/G7GZfysx0j7xnWMvZz/I9+YX2gIfPJ4rWXxtE+2MdeBuV+TRYKzDyaF2an7UOI7UOmFOOQ9F83jzI6fhvAAwR5X7scvDPCs79P+PBvmtTDfDGEYcKFHM/ovhsntZlybUJ7UFntXtKq7NeNhku7wbygxYBlaHGXzm1CQaUBKlc3zoon9XPM3pXry60bWEJtjR1jMIwZkW+jdSczpm3vm4m33743K5p+sQtPl6QQSebKPz8BvGykcF1sBFU/8yCcZNIX2XMkhUCLQyinA+0ZyyK/5FHz4J6gFm+uGAulb7jWULfVkcDiPe/GrGhY3qZVQd4VriwjmHNBzKwTrNVthenL7bnWm6Xl8LUycG9D+TN8IXn3TE0kHrzQ36qB4/WzTgQXPSJujqG2ciSCFr+hJI5H/f99FfGKMZmwZC+l3E7ojBrbSrmwSpK+5B9ofD9MPtfEnxq+81LZ8xmy46mXpz5LewupxGFiS+TVHodatA9aoGzluPAAz2x96JGL5o9p6kReZzYDsZD2wc3ROqYTdCWVgy7wWQ9pfYhxY3jM/ErCJ16A3HiQSE0lKi9y+FcjpIqVKjxDQzFFGTkYCKN1sC5Q12UcIS7xByUceF/SIXfxAaOmcspA8J5EWaPTOTdSUKjgNBZGz3aUwamODctNU0Yrptj1111QOBV1jjoVIfcQYXw+YTkJlOu6II92zLyVmOcuELTa6t649WODznWNLIXHY6Dp112AdE/Mc7ly47kWRUVS/tX27/XUhPSANPfOn2V5YNNZnMT2rfPReEOUYJUZ2DU/vrpyn5lvh9nZt4Etwq3/goDn8MJJahsjRTS0uZr8IXUVNjCxUluE43GbNSkz0CWubWeKvM/NqyO5syW8TqXYUugIa+gvenSOyyqSJsPtRvyasw6OtL8LK2mjGgoHBDP/QD6PkMnZ7l1qc1vkrPVjAax/Hp/mZfzY+YXxifmJV+ZhD7ulJiXydhctiz82JEcY4PPJZJi5nM3kB8usGovVkO3oZFo1Cd+l3tefhlzviIJ2k0YY/eDjUIBdAB2uQHh4F+0Woh1qt6HqfWyrvIIHgM8Q0wlQejgFz5h1v1rJr2IXvkJlA2FGCfeSW4yKLOXDDPB//zEX5vjlezt1yOVSzVbLHtP6O3MC0s+GvvhV5839UcK8WpvBo/M6iEV/p/dgtw44pVAmBBU5m6nUN3uy53UXNcDfNi/5TW7yRSEKl0K3NKzUmL7P+qhCvcw13fC/Mu5sTx1dGmexs86bO6lDQvUSJYNShPwmROpg2KdeF7YOhRUFLKmNwDD7fzeJMpg0e/qtk8efRiBItLpsjmSUHKUz0/TMazRpBbEFYnC0lBINf8kRMZYlVRZIB5NTzkEMUtgItCmuIwxiKqgbe39tGLCgK1xFssPyrfzLq7LWfyoeHW99+qADwJCU+P2hJK83uJ9Wq/cfyvCBiPl0VzsAWSmg7020MY0A5PisFcH4ahI1X+N9Xt+z7DGZZTjsl4TSP9VyTy+Hs3tmM+pMT5Hu/u+wiaNX+sB4Ehz8XU+CRYOw/BF7C9y6S4tII21wTsU/slLZLsP3HmjWdoHUPkSOL2MQu5Q61XiwF+AnwFVDBDFPssirV2ToiQ74pWSY/eiZg9a7ivjE/Oubq84hrFyeIck2G2pYfONIOD3FtSPb6GUetlRSh4t7IYaYAdgV41CNBSMitUcz1CC4slxKp7GVg7Eiju7jXITS47+Z/qjb6mQeHGjhsFBeS4jhQsSFv+1wgTslAQ/N9uP+5s6Cw/r6Hj11qSn1qspBfhqBSd7WMbm2dO2nz81i+EA35rSJ5O//zuPQl8/aEqmu9JpTEqYI/3d8p0u9KG5022C453hVQktS6zb6JfsC8z4+I/TQgKSe2cOB/qKTme3SyYsnapj9+blDzxKwrd3bJHOyAPnfyw6JbOvQsRIHur01YCoRIZI8OSdC0ZEtMdgfTQmefGyQ8IvShmsU6iDMXmoLcBsBRqjvOHG5ZbG9zxHB1ircRpzo2XX4s/2XiTYFtSSQ/t8vwLwQ8SNaLj+LjiNi9MH8uPbRCyQW8FC7a2aoZn9/NRGprHeG2BG5RE9yrVKt40sWUXwri05cUwaM2aJC8wg43nG9JBSh9ocZATPl2KiUtXTh3Ctf+jIh4Fi0JoqOX99oAKXXAhNOaWrlf6kSw6wS9ogZ/UYEzJlgGi5Kso8bHR0c0z7iWQ1tlLxOmEpcO7WvNfvY0fFwUaPVsSiEbaqkPUDUCeUA8hWnr03IIJbFMN3BefKxfe/bvbuwejlwM+F+E+SphAzLZyW5FE+I0VJAUst52UYSacFcvgI97T2ECrphGqIbhevjxyhNBRt+m3fngj9Bq0tZpnl0GhBRQQG5/99aR8dyiJGlqxOjRPTA9xFJfiJxgywYmFD68/xLgEsBOUfqNsf+t7NtPkZrJkNZH9AaYXRjNaaF69bWV0wkqewT/+LRSrIA8MdfGbD6RFUwMqblH30CYwu9N547vmDshjktjL5YB6ALvGbg0kUMjM/Rc21okwUzKoxKHLbMMvGdGp0X6DqwJcN6zFRZC/jdASnN0vxCFeUvIofQhBCl5Kee5eRwIdwdyXS6Th8/QszeoQj
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:02Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c032-e7c4-448c-9878-4e87950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:02.000Z",
"modified": "2016-04-28T07:48:02.000Z",
"description": ".js sample",
"pattern": "[file:name = '0071109_008310.js' AND file:hashes.SHA1 = '52ec171c9ba56cb5156aebb74c4e9b0a57094698']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:02Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c033-d768-4f83-be8e-4b42950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:03.000Z",
"modified": "2016-04-28T07:48:03.000Z",
"description": ".js sample",
"pattern": "[file:name = '0071109_008310.js' AND file:hashes.SHA256 = 'ed6e4a8a97e223fb4c33db66d9eb5b13bec86b4d2db25b1a6b257aa0705dd529']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:03Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c034-184c-472e-9848-4635950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:04.000Z",
"modified": "2016-04-28T07:48:04.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAAI+nEg4gbNqcwsAAOAXAAAgABwAMzcwZTQwMGI2MDhkYjNiNzAzY2RiZThlYzBiYjhiMzJVVAkAAzTAIVc0wCFXdXgLAAEEIQAAAAQhAAAA8M+R2MQjLORxxRtyQbZDi/+RWbg579CucgpK2LzjPfTjKoclRn6w7b8Are6/Ve7/2PfUwVadEzMm10xwouMlVDcP1a2voj+TbMUkYFkadZ3E4Xg7xgVjBAh60DY8Ne+jUTnXdaC7gIkocWsU9W2l40zuuCLxYouC8U1aZbDa4aEvsVnDorhshKfPAlvSO4jcvFDAPWZdJg2sK+mwA/BdYbEJA1JHDD8Xu4qbHR/tFKfdhkYyN+oz5m5BBSWfXklAgNRzCOBtzeqUp4Rp5QfF5t/YjVrWkxKOTHk3Ck41lX09mf/ui3KisuHS0yHXNSQ2sx5N1xfbUl4f7e6qj7zDLMpotdwrpiOGA50OTdbEkj6R1Tb+Oua4WyMJW6+7YlzprtmTFHl1/EEus00Pu/+ghwGogNVsSAN1t1T2lzIJK0sXNfParftKiNF1yYtQS478ic/I9+jZQLJr0QN36UDrmsyhbaLbjaqQdMzFEHsbXGnT03R2Ovol1E7tePe2lfJXD1iGq0mQG0xBQR4VMGGED0/NXlTp7K6YpOTxV8l9EXOBw7HdE1oPIgE+9NdTRXW7AnCAhtofrgppwOsfGLML/wIlhEpOq5Jo8qEUmcefCy6aHIBfGJhhcNCKhZFPQVsWg8pWfzs0qu0x4+5JPYUWtrG3P6w29pfukemxA2kvrJLpzkRMITOSVgMJSI30IZaKcABuaS0KlreUqmyZrxeqBDgzqxVJ6mKwavhEk0IY3dY0ATh+Ix5JTFevbTpPMq0a7j90Mn7KvvuzgrXeMP6ulz/Ocp7yMJrJ/PP/USmOadYoh3l084VacpUiSWzjJZOS3oYfHBaZwzIt+nirdq14ZhTZ8fLhJgVR+FLufFt+8BFtQKH17wGqwNHZJ4hIfYD2M913+ZG0aZpm8iU+YF2Ue/b7KoVgWR6AQ2ztgKloFQOgIo/SSK7HXtESmZ0B4wvjpSbQQTiN23LPTtWb1H6dj+AYnq6rgFQhTPXtBud2USQlZ8qAXH8u1+HgTA1hzraW7GlrkDcwvyPRvZ2ge912tpXqGAewouD+yn0KszCLSWP0fHmL/u76w8/nlsyZ6IDrBiMTJoLLbYU5vJ+Tjpn8mMFsVD43cClx2tO1Jvg/b7etxD0TB3CCjfuweLv2x8+PVRgD45TKiq9swZDdsu/+hphv/GUgNSqOyzO8YBNaRcGKBdmC7tB3nuJpzglJ+4UAu8uCq07DyJLb9vDoMuzBmJgah0OGbS4HjoJEsHroc8qkqJEE2cL3KPDIA5EDQxzMm6OYJO4wSWYph4uuSmkPaCVIH/grXaM79qmPkqYJl6K4uNydmaGneIz3u3te85WxQ49qOLJn87D6Q+JI5WMhAsTCIrET1Pzi86ST72maeVLkM4y96zpOMzrvUH0bYD2GUB2iJWBzwguZDk5FvxuUQlgZsPVcWmrKD9IL+TXXkWlQdfgU66tnvpnzH2juBHGOHO8lP17MPJJ4lx/5Ckm50DscpLdyd+SFTqwkasTQeLBuHa/UpTRa3vZwNZ8xcwDAsWc6/3E08Ezf69rM8VBtsEgJlLueVwEUCop0YmFmL/ghXlw5LKP49QnZqOPPc7NxQ+kwq90T3RbJ9LKOU0t9s80QfUjeIhgaJGzV2vkk9eQ9e7VRrFw1nUWi9js4GILzYqvbI/mgk/nDQ7ddShzUK6lWX/KgP9E08b2GroLLam8HyGCb+ZQ0GeiV2nFSeWlLlek5LAWrci15A4tJV3TAdwQP/mI0AF8VmPHalWLj2s2gqHJEFHmZ324Ogf75RNsw1X+G7jva8OLGvpn/6QyHigTCOyljHkgCOE57V2Pe+z+2Wl/LTdpdNjbcIs7Wv4wNuqp+8HYcZRJBWxpuiuGYwdTrDYXACU1Qk2VwQ/leoTxMPpgfUCp/RMFZpB52xXRS8mDfaefA7QodFuyMgXrDoKvSdGy8jXvM9TZvJQbflBzEx+tmcFGHHG/Gv9JfOPjieDjYYyPjiV9KxeX+x1xg3JmI6ExGZejI0lp1/JRLP9hmj3QSw08HDwo9nFXy+Gmk/H1R8jjiXaudYWNyxBNQZ+QVVlZEYD7aV/XqaWOVe9/xb4C0BjECDB+4ycpkpnhDmp53Yfam/ybvvUYb3HcVFsrzoKfXk2Rm4RKdTzblmdi+XNvtVPiJ4qy/kuEFgxdyxqqZkhHlOThSPBvXqK74EahOV2OeJSL3zS36fzmBMYS14P3XCCeAlEIq62SQZB50XrpI8P+i2kuM1cgd0nEIQAU+1D0tpKdLMBIbh6JUl0ZHiHX8D7/LgdH0ZYPjLvQpe9tNyo3yKZ+dFZzjZZ4XQdRRPZ8nLySnU70NU/lvc/yK2uoEYiZIRAxiB+IKUR8E/wRcmH+WSZ6ZQm7PgqbA9OYIznTSA9A0gCL3q6Ba+jH2bp+d10U68S8eMUl6Xg/mRgHrbAt2Aq3MNYzaNkC57XiPZvN1kG3ryf1wBn1CnkY7MzaTjJgjpsdd5AcmlRObOs4qkR37VmC/oWTqznY3jMreyTMBPjYxlgptssm5oBDChjBvG53qvRRagefvm0/I8OP3WwVXUpB03Cn0IvCJ9+cbF9HKYbau/up30qlc4ZEraRty08wTzFSIAWMoO0oks7IHDSF5FqJWlZC4AXjfBxkReb+ngWkXZHNywdxXgW0d3kBHsJcIRJzNIBEUbzVlqYFWcjeiOeaz8hxD1o48BNAN3j9EZZ3kuaySttQcIF4y7HIp2jezJSs56d5t1QlKrKEEdLQC7D/DyC2JB/9ZcM8f7XFT0IY8/ZAZKZXLi6avV0kwqCOq81pyuHrSBI/S4AXZp8AAVGu9CQ/pBR97mooTVvLXrneTK0CfAYccqVFvQqhQcH8lo6kOR84pMJ+lD5akUetqs52ELQVtRi+aC+++kQJ0vEyUoFUQs/d2E2YAAwH6iz24HjYtUcoMSLlFLbbmXFlfqFzikoyS9cdo9gi8TSev7z1iLZFSIVVqESRHBSt2OgVs+fYKXBpcSbHdb5OQ/0xiGySRR424gRJxoixqSqcD7/3ELl0tR5gHApFqBypxIuRiui/GtD3t03hSHu855Fh+KqMj/3ql8VFe53pyvAND0TIW8AVFgonmcQdT5oQa4F4Z8bxlEigpB1HKKVdb/JAISKdSc3nIv+Co2y7ZiSHsop8pHJdZoe0WO3WvJw9rpK1vZiC2qVhGajfg1rE7lAxftTl757pBHTXZL9xFYgQ0bDSYYpQUFEzgqCDi8Vu4ed905JCzGtGEKysoBx2qSoF7VpkNJgD9EqrWh/ksYiS4vV7Vw/6KyFNzDZs0hmgdkAmiwtCwI5eM61KNeGU2drxn3i7m480HX6WTXwrsAcEKa1GuJfdsPXu1mo7afVtANqedwUZe+3rTLVDpDSKTusPWvTVOFfOVusCfhw3RJx5b9zrRlcrZh1npPtvTIILPcI33HiO9C4qVscAyB4+/Zf3GpP9Ub4+xKKCL7Ihl6sHkb/GoQtNQEPMwPnD+62dwO4CXEc24Mbr+sGAzeuPAjMDz3prjVW5Hyv8mKpcdepSdMBF5o1vbShBal+VixI4KzJPqUHs6W5QdIGnKyFSb4xQgZ/vC+ixCrU4IGlQX/u3bEBJaANpO4+BxsSwLv0+AOrviJ8WQxZZevze/uL1d+mvvsyXFHwpyBFPEGvNfRE6n7577Q1dIe4rtJeh7E5ryzpene6ZL8dvXAN8uiNQyAlpfEetnF3D0vt/CX2Y5TuHnlYY98q8Gc3XCykWAMBosAN3zyAS6R/aolw01ktBTFi3YD2UX/5H6STaVK5kGbiTqkXEXB/rMrSN6l35bNauFLTNWEkQEvjcLQQWTT7PQXlmwDZ+Y4MKYcrzRzmPMIJ9qn+LVO2p2IJ62V6Gr7Swvx73qMIrPyyvVPM3t7ETcUEsHCDiBs2
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:04Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c035-9ec0-4ace-bc45-41e2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:05.000Z",
"modified": "2016-04-28T07:48:05.000Z",
"description": ".js sample",
"pattern": "[file:name = '0080304_00660_1.js' AND file:hashes.SHA1 = '02c27767d35d1d9dbc6d6a4c3b47f6afd657136e']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:05Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c036-eaa8-446c-a746-42ca950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:06.000Z",
"modified": "2016-04-28T07:48:06.000Z",
"description": ".js sample",
"pattern": "[file:name = '0080304_00660_1.js' AND file:hashes.SHA256 = '233e127b56facbc31d8f71e7e34f643ffb50ae3902608c804d4cebf9c7ca4fbd']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:06Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c036-4d64-4621-856a-4976950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:06.000Z",
"modified": "2016-04-28T07:48:06.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAAM+nEg4gbNqcwsAAOAXAAAgABwAMzcwZTQwMGI2MDhkYjNiNzAzY2RiZThlYzBiYjhiMzJVVAkAAzbAIVc2wCFXdXgLAAEEIQAAAAQhAAAA7UIDfh3Pmqt4MLgfdzCcHUVEQXeGdi9WlmmPOGSiqlWoVLMVwovWJ7v5oTKGa2m0rF2khYAbJdNg63dGYCSqRG+EAME5iRj0OFbieegAu2wTG1nlGuo2AuFreoRb3p/y0uJgMrSM46reHqwiuxzVdGFbMjKj3AfE8FA4FuR2P7TfjTFgK6eXFGl7d8FCOcE+k8shvJbdb8jcwbWyDz1ldObYZM/25It/nN8AzP8K0VjWjRas5MgKHwTfpSGdt6CXY7QgTc6YmmXat51BLfqpynUPMkmp6dp4S/JpGzOoE5Ydm2LkZz4F4A76gu8LArw/eMrAcSYllEoSetqR4VJL4ZvERuO74aajq6aAadfsYpZk1O0PdmiNW2jDjsF7mQCWRJ7In3qRhSR6BjL0/zyLvQpsE53BVuHyk4oKVmzkEkC2tenBzGxms4i9P2t3b+7aJXc1DAcYx3WSRpQTpFRnANL7oTkTiMSgH/+PkXqnI1KBcAPw+yGTFxeHpG2tkJQ7Q7LN6AlLxsxtU+BN8F1PPfaYfyrYUYMWzUUbqo6CzdOcqZIgGVHH0w6F4Og761VXUKCBO2GYQP62xcNJy3WN9yVu64DJyn4h3QauaYvelyQJEnnIf2d2KixrKoBRTDSH3NUk7Rer5uTbIRiNq2WtMfKpzV2zL1w91efD57P/qYQlKzM1RDXQbRe60t8ntyREkpbv8kI4FqMpx8gLFOhiGb1PImjZcEZEU7bKn+4ee086YfzFg6O4Da95queq8b5LmnzvBiMiCOQfZ1mpj59otRqtR7qPaWxZ3pOzwXt6YFwvDY35XgDNLCXuDqEqyEwPRYgL1TuFYaSur6z68Nr5xqRxSTao0VLJLbFoWtUloRyFQh75zAG/BpBivF8AkLlvC8Ae3TyejUcIqvOLvR9ZSuHXiG+x4aTlefxE95eDJr9vOfpSEin4SDJnfgvmlPyxpbIYMKBCNX9HnBoq6LLa056/PB4b6Xog7mjRJl3RBkhAeQq2bhwtS2rGdHjZnbJ3ijO/dULsDivHxh98JUlURoFNBl7eKGvzOK4pXWu0r/J6t19LXSmL6BiK3WJSzZu4L9e8897RGah59RGiYQGBa065g/eTuhDku7AbRcQX5xpk7uvrh6Q8aZ18Zg45hxJa+f+BmU1I4VE7Ki7+PfumdyY9RpuX43191f9IA+BRq8tSEfv2caSWENx8nQV8a5V2rbjQzWLKiodswAi8jMGnoJNIyZn2e499UdGy5b73xlxTBMaewhHZR56KXsTEFVLnHl84EhYRLQhkgx+jYpo/dahZVgSS55WEu+J/QSnknoQwev8qshJ3CGb48kj5Cz0AP8DtxnU4/jhka6spFk0ZhKWH5eFFxST1JUagwCf2g9G+iSlRVguTinOgg+F8+Ds8at0KPG09XrmYKgSbZf1CQQEf1DEmH+c8uDdtYWnsM6wTn7NgfHkkDV7mXefF3n69DyuEYo/lRbLRXlKIIJGLvPkLdPaykYrSbeiY8HuWrNEVVWG8YTowyzfuEflXCycRB3oBoEqeOIUAx4SPczmyNhFNFe4TMxcvMQ0WQ3dG4TlW6Yx4OCZ76EYFiZa98o8+mKPxAfJP1r2K1LWes+SfAztmf2f6OjoaO56fOj1EKB5kvLWEqWNBHVpeP/swqkPfm7dIF20mUHk+d1hZKojH+srW/mH+ddkfgMhS66T0xUKtJBLdasEDCcApPXcvKiAoipL3PtVB3ixUbXPS1OZSZmMoxEEEPNM9MBElTq+cxDAtVp4Zfixud8yD4eeilr0yABq8CwovRTq1Oi9mChEzcOGBHTj6m+fXJLMVZnXHIr62vIVVlNMh9R4s9fVnUPteYwZ6SZoX4I8PmvtSNBVnJBTeMs/P2EKqMgWFZEkojl081TuNvJqRu1Eqc7tawbNz1+G/wLULqU4tWBDbvCWfx6wy0a+ULfcnA5yTKHRAPIL0gtBrSO8yh1j/v9DV9cacOMumH2pKa7FL6ZzLVuJQqekFC92yzRdN4d/McqlHNkKI0AzUsRt7XG+Fyq4a594KKY65+cVhCdEyLK6qj2E2tCI1s3/QI0ZG2rs+7NtX3Lv1E4usFvyNq4yM/hAoJuemOtciTACeoObv8W+2HsYlEDk5m/0x8oI3zD7ANYfPkw+2jo5HD17bKJkKxBr344QWthp96+rvNvvKqubPEHACAtnp5hhD/escxYTT25evQqK0e7VJKgp9omLJnRWyTKeEeZrrUEb71eCNatwQVdCJHWWd/FFxhFOW5DsVh5jrnHFD6gbGd+HDutUUOpfNfPNWlXRZNY3HcdaT7aOipqu52JAcfrRsR6dSiQAjULeeCmV4yZDkM/ozG8FgXsh9AMRAZIR5Y7jyCtkJE9yWa43/LAGpO46Hym6EYtc84wiVCrSxcuNCyDxj6afqESQbNH+5GCd2CoJFaBWEsmyzjp+sJOQTlj70CoEQREt+YGGsrGHUWaxR72bPSA4BhVRIna+6K4/gokZhNaXt2lKy0PktFFZwpLipYNYver2c5539ETKVEfSilucYGEY7WK0OJ7/lUGE+QTg3qBMo7yTCiO2137y+C9qXKxbmQmRwa0N8G3/zyrQWacPVAUy4xOR10jsuedVbiIVLdOVwiqxPeHfIpFH+Uk6nT/0tE/npPDPOojS7ORjj/YScumxF/qEklgTy7hqoRq0Ayu6xeWpSMStAA9P8anboy1+sgVAC01dgxEwylXuWOk4MfIxft4W1poTSj4/tilgdfQ2rP2zhC2zpFXyVPDoxUyRB+9A+Mg6o7+5ERDKZtWQ3JTk0K6+nd9ndeYExZ3S7CKhTfts4A/3Z2EvHzSbrqqLyjN3T7AeOoJups59r9H5T2x/89rKZ4rE//w+VLLIL0zVBztWwpv5kDlhYDfKGjhG9RNiDJnG2pdPqei915tISraL8Giwmh5mlOlWP//UOgkLvYCSIF2Xpy/foGCKxJL1p47KGn+GMMFky9dqLKNp2apC96G0wGc2h1/Ir6qr8dqGqAGUawMR8AAsT2zH2kYxzzardjpjJyOiU7swjVp7lMmgm1FxxRK/8uuFJAmKZnc635wyiSGBxbuTodYXqW/Drz7OMETvnzeKWw3jd/xlVZnwtdPtiPiap5fNFoWY41irxJ7JTE/7zpTNaUTHmov+Raj27HxKDhm3nMByK0CHwf8QX2lEkZj7vAAxTULrt4BsO09RJwSD5IwhVFhqvtRV5qzy6efDF3I7l6RJOVC6WjEwTQmIcVq1xZ265bNrMcA7h14aI/JjOLEr87jW8l9+aTjTTHviRMKjKvLa+OebfLRWQNGC1enQimU+lMFwftR8HQoz8Tdt7oTjW47Y9EkAXp1iYhB5pGQqmaqqgUHqvHileh8uELDphZj1Pre405+Jdm2EyiFVB1sOUMfJMGqK2XTXodfzbI15ibdxrzq6dIqEr/nrfW+wRNgtXFRRT10InUx8k+vZ8SCGBmE28NS6OQLGi+3ayuXrKbYeIiC6M3A87wcKyAdpORzgLJdDLWDf9Oeo0Ywi9bsq+8jCnTRnzUAjkcKwKcOTZz3IUwrVWj/afaIbg+Uscp34W8q376esG99HX8rTvQjQBdwdv1yof9Ruop5Jtmx9XI4hw1C91hf/kSbYd2Ajlt5b4c4iHPrtAk7evoQ3VaU94OaIYAehh1ke8NW33LAZweP+p56pfywqAwGX2O7XvId8rPrVXubHaXhrcC87Skcp7aNrxCEfqN8nHWo5vlAspFvysysT5yCflDdr8iHrrdWWWRd1iddfPAYG/rj7hwhWbx+LopB0FqOLfqPY5rb31Vlon0euUyR7fEtE440283w9qbyHoRq9sDPFCEhEYglw+iA6zjcxgUgWpVApKfEWGOumsegXCSfcYTP1dz9T1CvAeUEsHCDiBs2
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:06Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c037-a4c0-41b8-872e-4e8f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:07.000Z",
"modified": "2016-04-28T07:48:07.000Z",
"description": ".js sample",
"pattern": "[file:name = '0080304_00660.js' AND file:hashes.SHA1 = '02c27767d35d1d9dbc6d6a4c3b47f6afd657136e']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:07Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c038-bbd0-46de-9501-4112950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:48:08.000Z",
"modified": "2016-04-28T07:48:08.000Z",
"description": ".js sample",
"pattern": "[file:name = '0080304_00660.js' AND file:hashes.SHA256 = '233e127b56facbc31d8f71e7e34f643ffb50ae3902608c804d4cebf9c7ca4fbd']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:48:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c1e4-e370-4cce-bc6f-45f9950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:55:16.000Z",
"modified": "2016-04-28T07:55:16.000Z",
"description": "Locky",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOg+nEhZ1m1NGzECAAAiBAAgABwAM2M4OTQ1NmJhNWFiNTQwZTQ0NWE2MzJjY2ZiYmI5NThVVAkAA+TBIVfkwSFXdXgLAAEEIQAAAAQhAAAA17Z6tafUkNjSbSZ9HxLvN/brk1yXyXsnZEOs7I1Ar/mhwX1nYV1W5tgdhqM1lJxC+pF2yhnEAjJ2nv9N0UsoBhPS09YQQi42uHMV/h2Nx/MXXGBWi+Tla/jRjaed9+yf+7WiXlBLa8G84SyBEb8uinm18m78oNeyf47Z3p8toRrBcri4HAxvLWNKXiMy4wZmdxqy3VOhT9M0lNqA33arnvB58l67S9zSdQz0kcviiwW+eCKcEKtXLLV4ipaSJy6IGqhSUX5gMlJGJ2UrMsfKM4bv85kMOd+r9r0f1b+zFKFVMt9F5wUC1U/a9V3no8OOAUoEjKpNP5mgMVnJxwj7HTcYtzIDaJVH8rQhJTllKuIsOdFpuyWiWnIocJulml3YEk+/o+BSbyIITWphU6d3JozlW3w6ijrgC/p81vrxvsYBVLtZY6Mw/fEGSC6BK/0CAuU6DsTLOYwlYxMWeZgTXXb4a6Tlqc2lW0x4cMDeqIlVj1QXXeMpZuTKsl/9+yRMxjJNmGs6xd5zIUaJlV9/TVQSfP6BtDiTQ6n6A3ylNC5VVi+0DYtSvcEOM2vWDFO7BxCLlB+8L88ZpXsgri2RYeHd8s/COUu3YPjsonaMaiwyuOGvwlmcPdF/3+wHGg7u/nmC7x2ETzEUS2sPtd0PEh+bQhq6oupyzA4SAunI4LM+tWPS8FZRiSFBXO6zkzM8p0krBgbpRpOkI5eDDe+BgV0GdvSjHdlpkpdhNHIKYeq3k4Fed2cRLl1kelxrQ/I+OljUvR3ugM0PPijNWrJisrglPN7Sld0pvCmjsFoFeEPxl3fGx2byiduJHbCIdu8KVx1KCEav0lEFh60h+orjJP4eO4mfosmw/t+SSoqTMW4mvqn8/3c4nuhLcMMAtHqXGhWypYgggseKvbFh83L15WQ1z+r9/DSrDjzfQF07TAGEs2Dm9jZXyFxCk0kY5ZpeQ54oEaf19K397vpA/evlW+vQJ724tZSyVCHXjNCjwHYH5GQO4d92GMBpUEhL8LFt8o3fXPiELy2TNp652OAd6mrhm+Dr86scbXMDD28AO6cuNV6b5VYYSUF/pK/kMnHxENtFU/yuLRGLg35fQq3MEFmzEF2WoI4nFn388faWdjt7kIrVeKKo4AjRZhnor/hvWkb11zDyVwby9BDfTMWskH2yJNo5qjlTYhKiaxI99My+FCgKkMPaJ6Cim9xgxErxDvPSwC8PRL+faJdcoaDIoi9zsJa2cdActNHd63fRd+MRvX93gRuUZJDJq4SnsPw72kgGtW1JaBbgA4zGSFaEf3iOvfv3AzrLMAd4JyAy7jp3CeXLEiDJzC0rx6YzJ5TcnnwOnmXnnaKmV4fX2LafhkIgCcmz02q52QJj+XuKtMazbCYhd8wxUv50mWAKc9fqjFuWPqnJjtQ503Sun9hqz+bk0cGfGZKjtyAeALXHFz/i+Lg+6VG1ZESPqhY0h/Q4QgEtDJWHUvI6ZnhoUXBj5zDDu5uy2itsMBU4+9Yrdc5JZlMQDBiL9nr5KttKduoW6UphNgYDBOtyy2llUvpd9Ri4dn1BiKrJ9RustlsbbWG6HG6ymZ1ZKUq5XAatwEkDhdAYKTZGNUN6S82SSV9IvHfKHJ+x2scvog1SU0CKvteEDBF/Zg8fyvIcB0hQTToePEXIPBtEdVSFVJtqhPhOx1EWPjwexig1R6qMzyd1Ihd5hXpxBVARnG3VaQ1JEQNe2uLJ1C+0ZUJgp7PJfZuoWr5SMjrCASNEmL8sprldQPgxzWpKF1TqOZooF7uFTMQaN9HhbRX/0uj4FnHoqbu1sBsSDKKKgvQZ1LCUd2uel5tAOqig3N6WHvY+BoAji/pU8yhowAom0w5lHbAxgLVKhHlOBa4Zu35ws5oGbbgLPj3EVpFZJOHoLctNMjSrQJ8vF8rZr6ayYmevYVyaHEtJUYEQ/5CgUJVfcOyOUY5SCzPnp52mmw3HagUPFKP2qSUsfh0Cnw1GcDtRBMSwFVoM78O2hBjvEC5dSOTM3zFX9CNP5RsnhIktVM6bSDIBEY27lH1ar9Dt7tipfoxmGN/mh+u1cgnsfclQ0Jem0Ut+w7/uLXytgr73PCOWpvyYq/POjGCf6YB45Afwkt5sZ0wgF8nQ3R9JNYdNv129hHibaTLtuKIMzJEuSZS+BuqOFUxz4xxXTGXvYwB8e7A387wKy4n1KaWaRijf5vVyDm2/C6oaHFUuU3njeKinjugBnZg2DEE5JDbAo0urTnAHZYetm+NZlvjUAvZX/KX4nmR7tb5nCZWZo/R7WYk+v0TbtQqJ2Q/woAICRORgFrNvu25LgAmgDM3GcXF3RYQdemMDXsaPHXj6CKhq0c2kXf4OK0y0+yZCTK7bcTdIZgbumHVTlHOEq/4jScx2cCxmzBB0yk5eVFPmEL73RtiIj+4LujkidOqtmpVuj8kiz+qgVTfxaccEAvRetlH9ppdqMgI25lIQqF/zUB3sZGIv60HWEedusblI34+fCenHXTLalCZrg/p2qaGW7OysM/UrdmRhBGGJ8tnKejxPkPugGA37P15+DJk7oTMBziF6pu9ROWNDJlYDw5EUD1XyHVfY5N2cu0d0b7VMDsDRH5zA2zLuxdVQWzTkrlqT2LJ28fCkcHVcGYFORSRRq96DT2ZSC71aqnOuOitCKP9LMRwnNqSvtj+9oCfs6hbmtiWGwJlBs5Dfr2AmQywihDAKTsmWyaqbeKmfdwqDfxoxLAISU8ONLFWnFcIFM7wp3ImijRfaSmPDCiwuNx8eiOcPPdfVEflLDhEQYbxVFDBTKD+khn/ilKXeG+Nk5YnzVln5lQLWBurHHdfCnYRTNqvPKvbjN1xC+rYVsTzMH4Lk1BRWKAqzyVyrWTkwkVj4Q1ZRgyvXehBEQHpF+2FcDj+gBa4v0U/4RdnvPq+LtzWNhQzL/JxNfiLgkCi1eLIutmH53S0Ql+eibE+3X+5fz0K+dozw3pGgAozyDK7YSsEuwkYQdSkjoNI17uC3dMF5AgYxDMFKBc31BH1D/IScvbGWL3GsDjbBylN7kzek2Vc+n2CPNtKiPtLZXHCUZSwK6SgYcJqnQEVse0gADbeYrwZ+FsdMEgK1FWDsncWhbdhQWAy1cN94L623M58O/exsn9rio2jJbwRocZ85e5icsXo6YiHbM9pNp63rkirFElbqiA7vzgd+PJzEkfUFlrtu87GSw7Dp6ewRH0XLBv4UpCZqYjDv759xQ8e2FSH3jh0bPM3t5B1D92mAhQwlnB5WVeywFuFllDgDP09lpz/2GdpccFTNNwQDdTleqKhBrfxKDSDf9Czt+WsoeMS3NCYQVKPR7AODZB1iunHar2K0SsPJkI+KHXyUXuMKYCnPBz0ES6F3E2sVmGWBQKdIZF90WPkcsHTZiZOlW1SJAf3tnCKnXSQFiZnz5Uw2447Mwm+x65stV7IgwSzJzv/rc6figQbNib7pdievIRZ/hA7kiROmVeD53Ih6hTXPpoWdvlQq/NWosi8O/QFZLkdn/BUZ3Ah2KTaBP3Zsxdwf5szXV3NoUlDTx/PjZZliqIYQnoCoPAa+EH+IQG7FQuNtzlMFcRhsw82BKRVK6O9X/36msPvbh7V+dKQOtPqd+0u+jeMyDioo9DZl6sdh9Eoakdy6yEqSWJCldjOlV/quQNFQKktQ52ablfT1PRYKVFeXNdLGrUslDc0yC9+E+TIPdghG6ufZjOnQwwva/XdUdLdTO1PfGTy4ROZ9J4lJ8T9B/upLhdEHk+4UcEomioS/FppzjG+tRQkD4a5fr4rtOPRqakZqv9uhOsC/nmVLsknPB/krs2EsqDhdXQHKY6Z520D4sWCzwcpCakCjnYt6y6/+vzo7EeJNR4wBZt2OcnXFI5d/LURqO9tGipIYj/Wzo11XF9+MwP
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:55:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c1e5-e6a0-46a6-ae64-42d2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:55:17.000Z",
"modified": "2016-04-28T07:55:17.000Z",
"description": "Locky",
"pattern": "[file:name = '8759j3f434' AND file:hashes.SHA1 = 'c0d239bb3761a9b4e6024f6d970f3a495fe6a04b']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:55:17Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721c1e5-a128-4bef-ac44-4d28950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T07:55:17.000Z",
"modified": "2016-04-28T07:55:17.000Z",
"description": "Locky",
"pattern": "[file:name = '8759j3f434' AND file:hashes.SHA256 = 'd2954337252fb727b01a7e2a8e4c4b451cb00c9abe6dec34b8b143d845a00111']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T07:55:17Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5b8-fb50-436f-ace3-4f2302de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:36.000Z",
"modified": "2016-04-28T08:11:36.000Z",
"first_observed": "2016-04-28T08:11:36Z",
"last_observed": "2016-04-28T08:11:36Z",
"number_observed": 1,
"object_refs": [
"url--5721c5b8-fb50-436f-ace3-4f2302de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5b8-fb50-436f-ace3-4f2302de0b81",
"value": "https://www.virustotal.com/file/d2954337252fb727b01a7e2a8e4c4b451cb00c9abe6dec34b8b143d845a00111/analysis/1461831042/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5b9-5e94-406d-a228-4c2a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:37.000Z",
"modified": "2016-04-28T08:11:37.000Z",
"first_observed": "2016-04-28T08:11:37Z",
"last_observed": "2016-04-28T08:11:37Z",
"number_observed": 1,
"object_refs": [
"url--5721c5b9-5e94-406d-a228-4c2a02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5b9-5e94-406d-a228-4c2a02de0b81",
"value": "https://www.virustotal.com/file/233e127b56facbc31d8f71e7e34f643ffb50ae3902608c804d4cebf9c7ca4fbd/analysis/1461829116/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5b9-aecc-4ff0-b856-4bb802de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:37.000Z",
"modified": "2016-04-28T08:11:37.000Z",
"first_observed": "2016-04-28T08:11:37Z",
"last_observed": "2016-04-28T08:11:37Z",
"number_observed": 1,
"object_refs": [
"url--5721c5b9-aecc-4ff0-b856-4bb802de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5b9-aecc-4ff0-b856-4bb802de0b81",
"value": "https://www.virustotal.com/file/ed6e4a8a97e223fb4c33db66d9eb5b13bec86b4d2db25b1a6b257aa0705dd529/analysis/1461810851/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5b9-fc48-483c-addc-4f1a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:37.000Z",
"modified": "2016-04-28T08:11:37.000Z",
"first_observed": "2016-04-28T08:11:37Z",
"last_observed": "2016-04-28T08:11:37Z",
"number_observed": 1,
"object_refs": [
"url--5721c5b9-fc48-483c-addc-4f1a02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5b9-fc48-483c-addc-4f1a02de0b81",
"value": "https://www.virustotal.com/file/12035e330130f557b6ee29f870e0de2d92beac1122e504945a65521b86a568c1/analysis/1461829192/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5ba-b9f0-4c01-8a3a-4f7202de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:38.000Z",
"modified": "2016-04-28T08:11:38.000Z",
"first_observed": "2016-04-28T08:11:38Z",
"last_observed": "2016-04-28T08:11:38Z",
"number_observed": 1,
"object_refs": [
"url--5721c5ba-b9f0-4c01-8a3a-4f7202de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5ba-b9f0-4c01-8a3a-4f7202de0b81",
"value": "https://www.virustotal.com/file/3ce1af4092be0d2d3502533bfc268c49d432e6c6c95711e41530c5a9e6aeb69d/analysis/1461829414/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5ba-cac4-4f5e-ad2a-494f02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:38.000Z",
"modified": "2016-04-28T08:11:38.000Z",
"first_observed": "2016-04-28T08:11:38Z",
"last_observed": "2016-04-28T08:11:38Z",
"number_observed": 1,
"object_refs": [
"url--5721c5ba-cac4-4f5e-ad2a-494f02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5ba-cac4-4f5e-ad2a-494f02de0b81",
"value": "https://www.virustotal.com/file/85df7b46a53342a304499734166b8aaea975f578e521f92c54cf562d95ebec08/analysis/1461829139/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5bb-2b94-43bf-94fa-42de02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:39.000Z",
"modified": "2016-04-28T08:11:39.000Z",
"first_observed": "2016-04-28T08:11:39Z",
"last_observed": "2016-04-28T08:11:39Z",
"number_observed": 1,
"object_refs": [
"url--5721c5bb-2b94-43bf-94fa-42de02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5bb-2b94-43bf-94fa-42de02de0b81",
"value": "https://www.virustotal.com/file/a952ee278df4a965b8f0958be62f70d5fe21e22de042be38b371c8b71618f545/analysis/1461829143/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5bb-939c-451b-8523-487a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:39.000Z",
"modified": "2016-04-28T08:11:39.000Z",
"first_observed": "2016-04-28T08:11:39Z",
"last_observed": "2016-04-28T08:11:39Z",
"number_observed": 1,
"object_refs": [
"url--5721c5bb-939c-451b-8523-487a02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5bb-939c-451b-8523-487a02de0b81",
"value": "https://www.virustotal.com/file/9783caeeb220a7e5b16dd16045205584e8ec3490649c78c4d869594e6df034ce/analysis/1461829240/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5bb-53e4-40a1-9cb5-44ad02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:39.000Z",
"modified": "2016-04-28T08:11:39.000Z",
"first_observed": "2016-04-28T08:11:39Z",
"last_observed": "2016-04-28T08:11:39Z",
"number_observed": 1,
"object_refs": [
"url--5721c5bb-53e4-40a1-9cb5-44ad02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5bb-53e4-40a1-9cb5-44ad02de0b81",
"value": "https://www.virustotal.com/file/c91b5108a06ed1fcaa3f16807713240bc91c5bad39b2b3a79e4b5000abe9bfdb/analysis/1461829241/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5bc-3244-4148-b068-40c502de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:40.000Z",
"modified": "2016-04-28T08:11:40.000Z",
"first_observed": "2016-04-28T08:11:40Z",
"last_observed": "2016-04-28T08:11:40Z",
"number_observed": 1,
"object_refs": [
"url--5721c5bc-3244-4148-b068-40c502de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5bc-3244-4148-b068-40c502de0b81",
"value": "https://www.virustotal.com/file/ac60c0878cee1c57008ff6d6d9348b64024c7deadf4701bd08017f70ff7e65f8/analysis/1461829428/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5bc-d028-49a7-a8fc-4ba002de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:40.000Z",
"modified": "2016-04-28T08:11:40.000Z",
"first_observed": "2016-04-28T08:11:40Z",
"last_observed": "2016-04-28T08:11:40Z",
"number_observed": 1,
"object_refs": [
"url--5721c5bc-d028-49a7-a8fc-4ba002de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5bc-d028-49a7-a8fc-4ba002de0b81",
"value": "https://www.virustotal.com/file/63812bb81454ca52fe1c3f76c329af54a373378d7d0d309b5ed7caf0c1984caa/analysis/1461829111/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5bc-40c0-450a-9aa7-414202de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:40.000Z",
"modified": "2016-04-28T08:11:40.000Z",
"first_observed": "2016-04-28T08:11:40Z",
"last_observed": "2016-04-28T08:11:40Z",
"number_observed": 1,
"object_refs": [
"url--5721c5bc-40c0-450a-9aa7-414202de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5bc-40c0-450a-9aa7-414202de0b81",
"value": "https://www.virustotal.com/file/76586b2f828295b0f1aaceed963a817d550cba2d624adb03fe37bc6bb1258ae8/analysis/1461829181/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5bd-7d84-49ee-93f4-4cee02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:41.000Z",
"modified": "2016-04-28T08:11:41.000Z",
"first_observed": "2016-04-28T08:11:41Z",
"last_observed": "2016-04-28T08:11:41Z",
"number_observed": 1,
"object_refs": [
"url--5721c5bd-7d84-49ee-93f4-4cee02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5bd-7d84-49ee-93f4-4cee02de0b81",
"value": "https://www.virustotal.com/file/28888f3676af42b3773e2f363c71c8ed46f5ec9fdc7e28dd159fe2d0b0c22c58/analysis/1461829417/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5bd-c5f8-4d1d-9d7d-44a502de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:41.000Z",
"modified": "2016-04-28T08:11:41.000Z",
"first_observed": "2016-04-28T08:11:41Z",
"last_observed": "2016-04-28T08:11:41Z",
"number_observed": 1,
"object_refs": [
"url--5721c5bd-c5f8-4d1d-9d7d-44a502de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5bd-c5f8-4d1d-9d7d-44a502de0b81",
"value": "https://www.virustotal.com/file/f92fd3ad5f4476bb9aa01228d08324a78fcd83fa767358a6fb16070f1233fc42/analysis/1461810889/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5bd-20d0-4202-9181-498502de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:41.000Z",
"modified": "2016-04-28T08:11:41.000Z",
"first_observed": "2016-04-28T08:11:41Z",
"last_observed": "2016-04-28T08:11:41Z",
"number_observed": 1,
"object_refs": [
"url--5721c5bd-20d0-4202-9181-498502de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5bd-20d0-4202-9181-498502de0b81",
"value": "https://www.virustotal.com/file/54a82b6f79fcf1f17a6c41cf6a4b1ea2b6ed47305bfea71670599303a5a57f41/analysis/1461829431/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5721c5be-4150-4fdc-a3e7-476702de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T08:11:42.000Z",
"modified": "2016-04-28T08:11:42.000Z",
"first_observed": "2016-04-28T08:11:42Z",
"last_observed": "2016-04-28T08:11:42Z",
"number_observed": 1,
"object_refs": [
"url--5721c5be-4150-4fdc-a3e7-476702de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5721c5be-4150-4fdc-a3e7-476702de0b81",
"value": "https://www.virustotal.com/file/469f963dd30678657f3cdf748495efc52b33ffb2f4b858bf8757b674d1af39cc/analysis/1461829140/"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d30f-556c-4111-b12b-47f2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:31.000Z",
"modified": "2016-04-28T09:08:31.000Z",
"description": "download location",
"pattern": "[url:value = 'http://gedvendo.com.pe/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:31Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d30f-e3dc-4cf5-84fd-4a30950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:31.000Z",
"modified": "2016-04-28T09:08:31.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'gedvendo.com.pe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:31Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d310-48c0-455e-b7fa-4340950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:32.000Z",
"modified": "2016-04-28T09:08:32.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '104.255.193.164']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:32Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d310-d35c-4cb6-8ada-48a8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:32.000Z",
"modified": "2016-04-28T09:08:32.000Z",
"description": "download location",
"pattern": "[url:value = 'http://lifeiscalling-sports.com/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:32Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d311-b5b8-4dc9-ba93-469a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:33.000Z",
"modified": "2016-04-28T09:08:33.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'lifeiscalling-sports.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:33Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d311-e9b4-4a44-957a-444d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:33.000Z",
"modified": "2016-04-28T09:08:33.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '23.229.237.128']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:33Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d312-e2a4-485c-926e-451c950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:34.000Z",
"modified": "2016-04-28T09:08:34.000Z",
"description": "download location",
"pattern": "[url:value = 'http://mc2academy.com/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:34Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d312-07d8-4dd7-b8c2-4306950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:34.000Z",
"modified": "2016-04-28T09:08:34.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'mc2academy.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:34Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d312-c560-4486-b37f-47e2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:34.000Z",
"modified": "2016-04-28T09:08:34.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '118.139.176.209']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:34Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d313-4f3c-454b-9324-4c1d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:35.000Z",
"modified": "2016-04-28T09:08:35.000Z",
"description": "download location",
"pattern": "[url:value = 'http://www.adgroup.ae/8759j3f434']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:35Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d313-8810-4156-9487-4293950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:35.000Z",
"modified": "2016-04-28T09:08:35.000Z",
"description": "download location",
"pattern": "[domain-name:value = 'www.adgroup.ae']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:35Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d313-e618-40f3-bc75-4f00950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:08:35.000Z",
"modified": "2016-04-28T09:08:35.000Z",
"description": "download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '194.170.187.46']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:08:35Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d369-6320-4e82-a6ba-48a3950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:01.000Z",
"modified": "2016-04-28T09:10:01.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAEFJnEj5UbHRmAsAAA4YAAAgABwAMGFmMDU4NTllZTNmZmFjZDI2Yzg0Mjg2YmVlNzZiNWRVVAkAA2nTIVdp0yFXdXgLAAEEIQAAAAQhAAAAsI3SdPR7CVPjR/ivpyEVOc2P0joL7Lx76vlEhM7PaLtFbEZ1Lw161Pmjw/+b3unnxgnQgfiAL0pwvDktTgFzOKvy7sEekHaRI8+j7rcR+pXU7mRugiV5ssv3jVEqlb3n/zlJ1adt3E5tABf7QrB6D40vs5L0rkFo5ljgCTVqpc/5bTyk5wXbinu6fy7e4/+4dTst34pZC5+7q3Ew/gqdERJPIVr/k+mDDqOJ1Big2EpsknWwK7KsutmIIuo/O127iROAjsVApzwQHRJYNGX2T3BjLgq60ic+HVmqnN5zYQXutEQMrAc5EcL7Ui8LtK7Nwdd4Bq+6LtNqrkVdScBkhiUv3zSpPAvQDuqzYmO7aBuvVMUM/E1x3Ga5zOrroSRFu6T91zLcoNKHCL1UrvhFvkxr+jyfE2Tq1IlWsJBVtrIND34WrmGdQj9tf+02Da7lBum8POXPuKk44+p0c+Z+BXZurrNAxJU37QwjpY9Ci1S9ipgRucH8ZUW3JDQM8jcv03BfObd7PYqtfAjs1k56JanNiObLF7ipKtc6kL9yiTVqD56eNxllBeahn8se5BS1Ej9Nhi3VvcDCMvRzg4vVH/+bB3LGFqfRabhNoNo/fSo0YLr1UvGN/f1m2e1GsDCOdkE7rl/xOtZv29AbsHqlg2uqbyYOZ+c9VvuIAvfrq+wbvSPL5YT7KIDwBZlMowHevVAChqluJ8oBbU1N3vV6ARKJim48qj2h5cXCeUKpPPelTRdqcIWNW4kQzwAYZhFw+roPpbTfcbGhXpKcXGJDcsd7FMMe/xxsyly6Rj4uXVdOdA0e75oTjYPvxiDVMjO+J5fCnBwD3jBVQc64ZOpaZW0pdOMEUeb02TfdQrQegBrJ1BLqBP+l3YEYr3USYb/SJ3Hump7I9MPZc7hdJz3gA9bem188hYlGI/UhkE/WfuoEQYugHoK46diDJdggChQwZkt+VLADZs97WiQsMq/Np+4npZmAzplX1cpiytL6EWt4N6CV/hvLvc2F7lmsRAtEP9tzQR++3+PdCIgI2y1BDFaSAC2J1FigentrIrSboIED1cjBOpeQnxGkVOUxOEVl92LT5Z2SGN1dQaUc96/HsZ70GH3jN6Rgf/lpU/5FQuGzkBbbWm56f8RXYVmHUzvQRpSZcvWqwR1P2orDs2fou7pH+/dgLdUfh3PXNLk3v9QiKUreX37NH54lBz1bdTWA3xTo8MQXi3uUJvyJOYgT6y7VUyz5wzcBcxD2HtyU/RwdmH807dCsJ5aQMpWbk83WHwncE8WEuAPHetWr8gzBYc+IansGsekHFr5j/3ADi458zz0PIzhVlE8Hg4syazvi5XGiyU6ngc8M2CJuerjr+Ebg0qHj/7gxh7w9zqFl+cTx2XJ23dBNa4t5ZH8yi20ytTMCeoOIljDIjS4ZY9xeLSb0sd15Fw1YGYyA5DVJPSHCZL1Ro6qAsm0FMOd1782YxDuwL7cVm+6V/QhLg7+8LsdYeFbln88rB/2KCbwmeEYQVIvT2MzOHvXp4AF68Aa2Fl8Z3E7fNc2ru74A1FyZKaTz7cjehJqrIsqRQ6k+OkjQmsq/IdwZHJnzGbi3D7Ou+s3TxRi0mksQqMU8sTGPTieO0tq7y9suTnzzFKrMLcTMCnCu8m9ixPPlS0dHy11j+0um9DnyOU5ZBDI665hN1Q/UwdS0GFNGmcvgAbZ5WdeddgreG1dvToTwzdMydy4UQMoQ+p0d4NgxHYDLznDvVn8ww+4npmhVyzPaLn/Uju60YD7gCtYCSp1AXb2+K5UKdvVTV32WwYorxamMJdPnkxoDCOJGh581LS8+GtVYQpmiMDbZWlZ9dnM3kWL3ZT2vRkCQi/72t+NW0DQC3aAdyloLkcO5opY9ncWtGe5hvUH0ocE3S3MG3Q6FprgSk9knBPVc/aH2OtVC4fSa0L1EVTBpYYZ1XCTuvX4LSgkMDEz43Vso97acdD2/5KjAicfQlZ00sA2yjTiRTPC9rWBqC4EskzxlebRxn/VJbo+Rj6GujsZI4RXa3h/g2B/zXVJax3Dd519BJlyyMf29NP4PKEBR5gCvzOUIoQH7xaDu8Xo04SZrDkGIaNFOA68M5QKVBt89b2Tt0N2jA44bfy80rRi67A5OUCgbiCtvBuwUPho302tFhmkU0iXgImCuTPzrFyRnCd8k7dh+0GfAmC/b/JXij/AdthIWb4j4N86bbtJgUOSLjkIfpBryTioqylDf8sUeM1ii96DHx0D1c/9/FnMgFFqf3zY5M66en82G+LTu1ydPVD0Aa4snygDg2EODn0rmU0bn3EGDywq1iZE2LFsgDs6RZXS6/BSLCE9E7rQqdMDxosY/u7+Hhp1s9a1QQi+W5c5+N5jhuXA5Cx5wybgaALI/gUSJPNNFMg5gIMyHGvsmKoyOtidx+ymPqU6PbwJovZ6ZsfYuVckN7LwM4B33aZcuoKViStAKzGVK2Ljh7MwZ0+mivsL4RlgCn1vjAb2pUWewjlzHS/fXdBYwowV7e6VUdTX8s9N7/T8a3fE6OLWCW4zZfthsyxskL+SSfQ0r9DN4tof5f5E5ODj8d4RnyRaVByeGTh74OissIED0BOP+6Sm6QsVOJAr0LmTKhFVvKRw74YpIK2ylvVqokMEjQNvqhuqJWj5Sd2hTPiekZwRgSwwRp0rVDEIPuHlmRcQZxsqDF3EYVN9l16lEREmK//Sd3+PWaaA+ejvKfFV7ozKGMyeBr+g/MramhOYjgJZNyrAEdinHzR2QUNBSRKCQJ5SoFWJTS/AIwbhq7gfSwfjjSOGS7tLzhc4afkUGsYm2vUGu4DCez/41Pp9dJxfWZ8P9LLF2wFQz33GlhV31uuaGi5Zk7rMadPd5eUIKKld0eYZ8E0XnfBFNfGtgejZkrNZkSJimnG8uTDBTiDXl7dfzydQmjQUXagUigv63I4iWqWYEfUIfZ5cBw8tznqvS1G3oALHYzF+0RyTXg5KDOEo6V///+KwTsoHJWlwbhrwCBTiRvSVLXVD01j175xWk93kKouLO59SB9/YE26Wbg/A3cLrvDRA/B00e/RpvuN9fZv1soeaBGNFnW64X/xE0Ocd6HRDsqYewrfojMdM7WuLUM3YWIYJK4unt9P4Q8sknEl5lzq4szS0Sh9UlaomEAAf1HMuCYBSLlWDtTb48BifQ4O5eXjhewK3ivHhEegDOp9E9u6iRDJiHQWsy3y38XqIjuv33NRgTTTYPOeckrVT936zFT4IV1IYi5cYogWVuhStJ2js431XqIC93GX/3G5gsoOOJW3OwS1sWtWnMpbD0L31W0C1/Nk9zbodhwOTCL6B6g42vvyXW+EGzgy1pBGv7R/pFDnBPKMUkrvsLFGVhSSS4B57LCNYbVcO+cqzg5RHc/qEmoMU1laoE3M8oJ2p4eb03glhVtxIkzY37VbLqRX+EO24LqeqAMLMxVW5uAMHI3J0HuxrSUG60CRZn5bw2N3uOmrVQWf8p+vIhcG9vUcMkYoLdOdnTsUmVlz6C7D5LDbcDuCWwBJXIERHo7XtDy2RZFo07A3K032J+x5+8dhyl/mpQsE2c2xDaCGDPrZTUEgXh0mpjSP6+c77avNCNqsHqVA4g09aSMR88hIhg8fo1alX4EPnwf8agX3sD68g5wFDXklSkxOetcPA+LfHvWH5vRnoOQlC64keEK/qVsf9WgIj9rqe33T45C+duISGhmgNeA8UHe7Kf+TLM/dakuHZMuuXj07iNg1mQ8jylfa60YipuQmOAGNyl9IZB0cEpvctsml/T0UDGM2/RQHQvCL7bR3d7j579fTDEDHWbkbf7wntmvEwadJBXe6iu9IKJXpAR9DzJOKOxQeH05lemj3bf2UOlpkVh/DgnqPGdUUWNuV9nNRLlSaz9B2q9NZUV8OUuJY
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:01Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d36a-d818-456e-9837-4ba9950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:02.000Z",
"modified": "2016-04-28T09:10:02.000Z",
"description": ".js sample",
"pattern": "[file:name = '0020101_004495.js' AND file:hashes.SHA1 = 'e03d92dd5b24ccf032f66b156313ebe445cbfdf5']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:02Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d36b-8f38-40f9-afd2-4aae950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:03.000Z",
"modified": "2016-04-28T09:10:03.000Z",
"description": ".js sample",
"pattern": "[file:name = '0020101_004495.js' AND file:hashes.SHA256 = '6290da3c5b80a86630d755bbd9e371e0ba1daea58ed91bf8092ac15448f65319']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:03Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d36c-935c-49af-9fbd-42b6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:04.000Z",
"modified": "2016-04-28T09:10:04.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAEJJnEg5n8UWnAsAAD4YAAAgABwAZGE4ODRiODE1ZGMyNzdiZTUzMmM0MWNkNDI5OTdhZjhVVAkAA2zTIVds0yFXdXgLAAEEIQAAAAQhAAAA4QKEP2IQ25hY8aS0TCltb8GX7WgbH6G1cxsFEqRGfEujQdWNvlKRdc3pBZeBUHwlSXTMKy0k/OPa3QR2ZRNgu3zAKe49V4ypGdgyw3MgNUcWh+b1IsCkfT+Hz9y0LN0/quEVGnjpFEy1po4qsn2ehng/uldFAnwevga5FBP2e6ryHW1myfb6R0sDWj7uRakT6JwUscUBmlbJjxt07NpjGBn2wBEhOgX5hLgj/vowCRVxPWtEWgaLxq78wZFtPsQAIpqprCfi7SsiDmlagrFznz/IzBZSAYU3Zzq6m16Ft9r5YVj2KVqF86xUMaPuASeoW1uF1Y83X8yEPQSEiPHT5JVqWbxaYRYjNA7/j2avRYmIEhyHTIkQ65TeAJLixDm5d9dg/723nNxvwTy8Ediva5SUonTnBMcE7qszBE+Vh6WHwEbwq08Nlu7VXU25WPWCmmQcmWKPyJh18TwSfV+mmiicdVTC6Klr2rE+P6CCjZz5O1nbxGw+/tbu76wiBTtunrzMNp6ejRHPAtvSWQMUHcl9fR0uVnfWZjgc1P3wGuVzDYxzJhbhsdhG2Oh9Kqj8N2CCzRTsNd7fAiecKelJo/fRTg7w3O8a3EqXFA+bxXe1mP35x1CiGZQkb+xsOpxmqtaGHFvoLTLN5mX7IsNq6NbOUXCqp0jCxU9s+9yzMs65N/QYB5IGcunjU0fc/mSVu9BrQQqcnxVxL/UDbRuPpfKZKViKt6Shg9+BgntPC7xdVTMmGpOHPAnCjDfmqt1KtTpqWE7mZpw7O/qiTpwqMOjy8xrJklMd0+x6mYeXb8vrqrC5lVdw5PJ9LfMqxhFu8vSdEcifzdeWmJA1SXyWY2502MbI+AXcxJgiTar8Amm6g/A0IN6s+lVaaibuaETGpjS47WBa9CWO3+11qpp77Ecley/vRpJzsBnE4sUsjaoZxv30bIgTseBn615BUtJ+1FfwakHmHZmAXoNEvLnVlYTfj/Gf6T2jS7Hzh31mLdeRd1cbx0Z+niICB12TxfjDluin4whGGRh04TtmBkJHZA21vZBYxYXbNGD8L46fVuvDWDas0ij8pe9XGbD7X7/7/47TTQHQ/hEBsJr4iAMdkpgAljs/eefoMBsZwng+phV8DqwkDVma/wcBD44k9up9ixVvfRJBWrfAy5XF9idxugzE4ZF14gNHEEwXw7m3wQwKWRY5ZC1ufScCxJOtLLQNlOY1YY+B5pCLWJApJ0c2YuZWEVwXKo8gRZSlpYgEIEf6KIINvOMj88QzUe7aRD/3oXerQ9Srm6xSOl180Qm9va13CORETcW9rAvEbcSX6Zh6reD0sIzWa9D3IyjzI03grgpb0qhq8+DwrJORgBaOePdebR2IMo//hZQdgfbYdym2owOgtNO/CoRa0buW+Z1CI1ZF37Y4l78TLvLHwznZjG/+3IuihNmJxRFiu16H0tYc0x2Jfn57C98bT7YFY0SXA1oQayycNvDvudZ28POv67MNU+qvz2dy5O+tU3Ev4UuWqeNziJTGgPXYQZ4/uH0fU75oy6fOL6ceFeRwhUR97y9OI8RzQRod9/rb2o2B0in2/jmIhSkMDjBh37gbQ5llEpRws8VQ0s0JFUzVzu8iP4CFBcpw9tyrKIFCKWQ3K+/K9hSPa2BryrPR8WWpoi+y5Sf58+u6d81OgFtmVmh/ifs1kIgdxtQOZAewx+IIDcwU2CIaY4nXHpegIMZwTq3n6hcY+xiiHfWlr2D/VoVLyGBsJaTYJLVcYj5ED8BWGpaZc+0nqecnZR5Dpifrf3CEwyPDmMX4V/t9G+LPrbRPoJ8Zu+7cGTXPQu0jUrPruUQ6TkeNGdvmhagnr/uUcRKhVb3KZIkVEIcdVcuQ7L/yRuqawNdcnw0lGKcQju0xAJBpbYLOhIDCEBBC6OZ9ErVd1tKybkYr73H43GPEi/zyoj6jxJk8KB3stNjIien24bu6dm1qhAoprjeZosuCdekudwe85ade8honIitJj8dIGzRKgxu4zi/4TLWh192K5/1B2v7UOI8CGcLUGamPJubgwj4ywxxCAY/ejMCjXMVPsaTZQBDBVoJOSlELMHeEYYuJcPBy+1ZxTs/lthH6IJ4il883w0bEwcG2WXI2HRZKr87a08ayZjCFshbcODhJ6vtoQQB+c3OF7768uS11kG2iDOheg8ss3zgRxzWCsKD3uCDnxYgwhS+U+OSMHovENP5bGjbd7JVtZpSyRq2PqqzykxvgGrWJSeKt5J41gUnBLjikaiIisPIPyoem90ZMQJmWG0Z7YNO920Ila18pSJEKCKX9h+clDKdouDc67L/vKtaEUK8fUQDaLgAIb6G0Bk2D6TcTQ3MZFiIE8ji17xVu0TEbpf/wkWMV7s9UOIP7QZ7pg0f1+hbJfH+vxLkXW0ZtkBKhR3GmVe+r1ngVYbZW+XxSRMkS2h+NAwY3EQ6kPPuxe4Yyscg8Faa8va591YPfsno0gcgKWVwa+nUr1K2mit1VtSog3bd9J+pQH/Rkc4GXpfganOw2M9oWJgqz/8IgfWDh3l/pdBagxjsXM2BSBvJEtvm0Cf0eMZjjyBykzoT0ODxcJP+aJTzyhRSXgouTS1ya89b3oPabn7S7r/kRGxsmAoGytu0XpBYHlUXLrR/DJnl3cxtOhydc7Gnr2kC+6iDUbpwkMjObpLP3IZUW4awWRYwokHVkzq9jkaTq9Gdh925VA1VMIWxNOnlW5tJZvVwKVxOfteXXndAn9jZlx99b1B5xK7nhXtQ+jeiOqOhDsKAwTfzYsop4Hqmmanm2d3uLY8peU2JBg8bH3Jd5Sk3TlUV5BvcQsiMFknsO2xwoD2JSQxOc14maKOeMTQds8qMHhP+s2DxxtTXdcXU7sNKkEJglyjklbi+6qZTelaBx9krYYHhPJPAPq4N5prMacj28Ro/vQN4rA2iiFpAkhE7hrPQGp5gjR8TyZA29BAB2Yax1mL4MxRjvkA0axHDIxQ90ql6pcfoWr3vLgk5QncMpqx/BYlrimK3qEiDY4IdJPYurFXrPGRS04fkgj+Xc/WxdaLFt+XB2M/S1cQNHjwqyrWi8r3FLpT8JGY3I9HIrrPboGZ3ckmfLJ+m2VBA4vznqdrNCjsoF45/CCgG1FPgR8rXC4NgCwi1gUC0JkbcOpslPPLodApTaA8PwWywbcT0GXXEJ0OllOQa3WyAkK6p6t/V2xYzTtzn3JzUyh4jwprD6OHG07UXaeXjkVTgDBCcx6CQuPhqUx6TbwMGzHzQ/mL0ioIYGIciAu0MwfPhqPUe2coRo0y64gIsXxIfBCH76bXgOpZcDMI3Gqyn1puhi7z7RQwmsXWIALCOC9hdVkgk1HWt5fAEP6G+QU0REMvF5QVviZA9ITuT5acEwTKkzEKO8QC84sim8BdQNYIEd/8tMpsBHg/Fng11uxx3DYr48sjNryTeZNufo6y95Fl1/g9wkIeNTIlcbC1HE+9BmOROyTZ3KGnk8C2bgK8n25lj+TvvbVpbC15rpSmXVikOj2BIEBUSL61H3ct8gcl0dPs5BmiS9R71K2u13AL+rLTw15ZF01YdUSap9lg9PDl57Fpk7RYYphk8JDb7vX/AWoyeUoYEYd2a/RO3PigAlVLFATQVYSvB8wRNyJ8vz2MbJHHFYniyxQMpsK+0n2fNAFfj7wS3IM/Pox2o2np4cCzszhXpLxd8sNJWBLAc0RaxASW3MH0Rxy9j/54F9SMSV5PxCJ5OlX2SEfLnH1ApFujjfrMMpOXmEo8+r01aCatoDfBR8hRXeXPPobkYitwSyArdhAOxIPPAadqrLLHBzBsDpleop5Mcq6KSswxBiji21jNnzpZBrn0QRRNtf34mHzh+ERYSnONvk0+2r4emQKHzCAzSi/KVKdQ0Lmw5xZJYmjQyXaxsW8i
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:04Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d36d-c14c-4e33-8a78-4dba950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:05.000Z",
"modified": "2016-04-28T09:10:05.000Z",
"description": ".js sample",
"pattern": "[file:name = '0021103_002453.js' AND file:hashes.SHA1 = 'd66230f5339aa86cc16ecd046af8d208571812c3']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:05Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d36d-1be4-4133-8020-478c950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:05.000Z",
"modified": "2016-04-28T09:10:05.000Z",
"description": ".js sample",
"pattern": "[file:name = '0021103_002453.js' AND file:hashes.SHA256 = '02389f9c8e45bf046044974fb34a14a8b34b239f219dee732c8bde5652d3b067']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:05Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d36e-530c-4e84-bee8-40f5950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:06.000Z",
"modified": "2016-04-28T09:10:06.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAENJnEimLx3oiQsAABEYAAAgABwAODMzNDRlOTQyMDU4Y2U3ODM3YjRmYmVhYjM1MmRhZDhVVAkAA27TIVdu0yFXdXgLAAEEIQAAAAQhAAAAvaP34mJ86ZlwSVWLkPYvl2xwoyEyv79eKiScunPuVgaP23dOOnHwQkxivlI+B52dgC+zWfBKrLZm33LO3z+e9pLpPJgq4jr0BudJlOp1UMSac0QKIS2RupacQ2XzrbSdfADsD2qWvEDbFv4VB18kNWcLA01QWt6I9WDBaI1z7L2fYdHVUh7xPfgtFk+vkh1MeC9QK0lIa9tZS7/0G5M7R6lulmggcT0HELujbEg49oePXm6XR1rlV/R865KfUFQNKOWn0J2STLhhQlXLy9F0B9vgPrtJs06+qBvi/crhJQUF6yFlJpOKgZTUALhiQel64m6HxhJSCpkVy71wYgJppf2AL+4FTaKiRU7e8wbAYKe0aCAqFsGw3bwT4cc6Ebd/4FDCVyz6S2xTf1txaL50Rxv6nbQAPQya46NZfHDFAlIlHkFwTqwA2bb5Q2xL65vlYVL2aGRrmP02Yj8WiCkkbxyocph7dfaWBDocE/3bV/5O2kchVtIHg/kfS/QpBfTQkTzdWGtdQoiqhsmf/eeKMRx6HnSyaObu7bhDHSwNlltNnKcOd+oydRdC1/WCUNKLQ/BT4X5AV9r9wwr6h+FRU0FwYzAqqCTqFpVwmntaWjuy6HKlfqvSywXyU594zYXB+UNAon5EMoNyTf4PGqIBF4ahc5aJFtgUBWLwPqHe2mtcVv9NX3DonAHn4L/o5dXhsBcF7YyZAgM6bxDKFV9O45NWl5xNTYV6vKPbRFY1VfH1NL206JALsbukvNy/TBX6emkzGWH/mEoi1rdvWvi8KHPeodC/ZJRsahFuZj4Un0czmyssIjtcEI+siE1LF/nrVBktDLmMnYSb15A8E2CGreUwlqZ//h3JUecejLVthwLCFS0twvwscs0VuPCDE7uAaksvW3dNazcmwh4oi0pwNUSyWg2PRjh8CVwGlw+8hIovG+TzpCeVJ8iaPVJnNn5DoVDfmpEPlf2j4PoCH4m4GXbV0q9PpJF3bONyEHn54EnrXaU48/xvhHXC8PN+F5v0Dt/uZ9UIUmEX6bogxp50uQEly75jSf86LWkB6famQoxZi0Kh5GoXq6vCWIPK1Cc917zAfzTACdCHLN6RpKi7abW6x+uRPU9RDAAiFtkJHbvpPCG8hzjdHCJ1sXpPYr1B4qZRvlHAq8HKW3wbTGnEHdmb+gZYCxRa+tgtIzLKQWusOgJl65EYPEvRWYkbFMYUQxsoFW06gaW3gEa0nWbQFpb012vqem7SP1onF4P3GwNnzhZ6QDuDjqwEvS4L7Ur2AoP8DJqOiRsH9JZMJcNaDuhivBWyqtDfJKQX+NPeRoKKgDjK2e/6j0d8Mf61PGhkgRorP9OeWYnKynmY2Nw3esWPtpczlYfoSj81qYdfMKP8mG53ePol+JTqMzx12kXPKYeOirzAqp5zhW/IPOViLqidtZIW1daCnaMvrKkpAJC2R3jucMKmOqgpaH7926qVIK0XXaLq0T40tLOu/q417vRejIbPMncie405IWigGxze/2Psb4oIuUgTPnt9N7ToZOd3uzleAvRY0NMAch5PNOY6dRxqyNnLVZJqvgf8AW4atVUAPznRUe6T0GntcdYqD5IC9Hbtu+eR0EKd5zBpivaozCTD7ac21ozU6RRNRTYvFl/tdeaC1C7sHxZFthWeAtSbFJSE0fthoxPtHb3N5ohoAf4PeOjxjKeoiejEac7HJAynJeA2p/kN0K9CT1rvY6FLQ/gU9om8ind7IaeuWYGOHUz4BvAYaJVwL47N3Wc8DZSXOQDM3IjSmntxD/+fM7Mt5qOMOVcuPNvkDkgatM0TrE8QvAQeFlERs+56k58HC5QeV6TkfWIfGE7R3XNPdDTVhGtdUMKAEay4GqGyqY1MG/QZ7OetqlUEAEHMmZEpPaiY417tlC1oyFhEYfwvpBL83sgjMM3Vnesid0NYFwZC+vltPqmfZsDoL0Sbm9Mg6kzkNOophWNT/LKUJ/rAJPvMHIcJNe6s6D7PtfNBVSLzDMj2+b3dpwpKjVEGDtgOEDN+bcsccWE80/TOE2tyHljnswfBXF4i1pFavL2UNmpUZbV1v0aLxqBFQinI568aV6kjN68lh6qjQIl8zQ48uGmKMZBgjyWTTJKWYAyr5eAxJKdADrvU3mD+ZhePTMA6XicFbsY9Dt9wHOGp1CJMW5VuO2bcaoiJhfE26rnGCHWR3pzQTERsMxTGcbKD8+rpSUeZeamMQnf+wYM2czKmOyi8lAujot5MHcAaArxbChwJX3VeYexZd82IjlMD/iKLu/NH8ZceL/e6pQCTBVG+x7DWFnnG5Ol5ilKxw4UBE9DBcbX2xM+aabB7jEqDZitL81jsqpMoK/vqgtoKgbEMGY9e71WBco86UVGIjSYG+PKKWQscnBY028IalZ5UxfjANYPAM3R51Gf+BYrZ7vlxeKK2t30ZgtHE7WnQb+FHAtrnltt+SZRv/gE4AHKK8TeST8wAOkxSLRstqex2yt2MKv4TEsP1ufDnc1AXuBLBRbNAW14nCzp7sd0AnkaHRnB+z8xycvKjZaDA5BMDhau0s7jvAA8czYXKhzbJ4ujyoHXDmUqBdvjCBB38lOKvj47EvnoqSjn+/hORqlIZB9U9XG6lU0Hv1xl82PKViULGqHvmtgY1FkS/12JKSWlbnFHeytFeNFgNpRIbiO1FU2j9IbuNO6jj5hrpL9LoQGT/zsPTxkPmH3Kv7Z3MoWopQLvHK6r4LJuArToGbAXqtX4oshh+UDN0VRvqxx8TxjX/jLbR+B9Y9SVP9nCiHCvq94RRvv14RLoP0vIjj1Oo3SyKq0mliDTMv4uYxP0QJ+GxtAaoJV2rWThGM43OVCR26M1PPsm0By/NIaaTfjIUYX/Ga2qypLBQSiX2r52jjMFIFfVTqaa8G8Npxi6Z8EEBv1PO77R+Mf1CxOi5Q6ExKNBzZzXSWCrcI5yoP/9fxeTxrG8osje/INOCx7RHcN53RrRZkpiJg45gWLB8T00NsVdxuV1IP3Kueyp6g2O1ZZC9gxSspk//zvY1SNmU7EtSXP58eGlSpFFFJjG9wkq/mgaMwv3jgttz7GFsmz+mJW/7r4qdfRgZr2e0MvDXjSNOsp49Qn3M7GoImWyB5sWvN0aan3YLcn0nBNm9BdLRVY3KoyXVZVRlHabrwn70HOR00dgkxxOO3bbVtUNOrL+TngBaUzanIji0g+Cp62dt/ESoy0PYUiD4uXXQMHwXVEvN+5ERfgtTFW2qtmoAs6lj/eyI9EDI+XfnnkOvZPAODySrMcwk9zyCDi9NCzzfzC8NWPi2lnHC1e8tqQTbozzelBk0allLas+IWiumudbLcIqgNuSvW80r63M/FynyccxtqH5zaITcFrNnxdYdpcaW47Ofy/Q9BQ2wGO3AogdmvmlCiTcBuIXmITDGqsEpJOL+VXIy5S8KuLxpH0M6obf+1V4WZrcpx59GgUvDW7wiJkO+myI24KmgFsrWIY//yiTDEqbyHuhQZdOJmrjFjU4JzjmDTYVDxmdvCy8f9UiXp4ZkMOVXDW9fFyfyzR1ypvzu79BYBbE8gMkm2FrWk+izziphFFQ1R7IOD+yxN5XU1mv149JPxiMnmKsA1fv5nR1C2KfF0aV9NkyEhUrbi3PLRVAOm0CHQrT6zG3G9JtIT+PvRdKY65yW1wFEr7p47wAtSevHFQ1ctxe9KQXxubgl5A6+L4d0ekoWOB7bHfyrQ4jk5zOasMBJIKdq0lM0wO/maHaw1X/QaOHNsDF9M4Av45nU3noR/LF5NgCgZz8ZK9krBCHpvuqY/maQsuU6zKSINjz0IoG96nOV9kdAYZJFZ3aTPebLnnhmkUrlOMtpaApS72Pe2ChpIgftEqdkL05tf515gJJfOsxnQXZ96AOQV7koZBpAodkuhkBjBn
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:06Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d36f-932c-4b81-ab27-4359950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:07.000Z",
"modified": "2016-04-28T09:10:07.000Z",
"description": ".js sample",
"pattern": "[file:name = '0021803_009241.js' AND file:hashes.SHA1 = '231f0952539bb8d949678eefd7df270ebf328a21']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:07Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d36f-6354-44bf-a708-4f12950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:07.000Z",
"modified": "2016-04-28T09:10:07.000Z",
"description": ".js sample",
"pattern": "[file:name = '0021803_009241.js' AND file:hashes.SHA256 = '588377320fce56cdbfb3527937b9db2780d22192813d0de8375c8eab3595cc33']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:07Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d370-8a2c-45de-83c1-4868950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:08.000Z",
"modified": "2016-04-28T09:10:08.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAERJnEj3vWArmQsAAA4YAAAgABwAMjhjMGE4ZWYwOTNlZjNjOTc2MGJjYzNlOGIxZmY5NTlVVAkAA3DTIVdw0yFXdXgLAAEEIQAAAAQhAAAAVmyeHOVsHoJi6REAJajCr/P4Rqyg8rzpggxJ1JfnYx+DHXlraAEXVvShf3hSfoSQOZEc3nGrYNxHBggh3p+sBXChWBT3zTilh5/B3VF+NaNxbAZAaVz4MSRdisn7fTXBODKAlQ9nCNVetreUJ2/MYt1C/iD66WIXfku5Rj624RW41VwdBjEIzAQBpWLIhxPIbcpU+G3zoo9vaGdIIaN+VOLKI5IuDXpEuj2v+gE/9qXvSnysrDEfDeY+Qh6VmGa/Ol7iq0W6WTTM1ls83NxJp3PxzmgbbHgTCpWMWXGnxA6EJGMflbRYOH8k27/0XmfPOCq26e8JHhNzdtWZnVh4uBCaNq8wHJQg8ErMi9GymlIvanuyi4DHyP4WUgEGjaYg3QVtT4z2hpgSJwlC8z5/HUwjYpatBZ0FaqzKhTNf5p0htiudZ7n/UCDatm+sJSJWSbvQWfIZobJjfmcta9fJYIztMk1tURJf/dpcZAaMD/jtd6hdaqaWG6FaC6Yl9rEPUwKlTPcg5AHuiyyPAPUAmvBNW9up17WfXbG/ZW/dgTCpadhvuz6FRNwPMoumC4y287IyOr/D3DysTbD9LkyZw33SGW2YusZQsC0R+kiWs7nXmQp7I6r89plXqhuKpDOaqcD3rtNzRzlCIljHhEJh3CNiaTHu+TQZj26kc7m9Q8fkGunTKibr/pRF6qOwFd8qxnbd/aqR5TesMNbxVqXaQDsS+FKoK2Rywkac6CBh65QcKahkIcn9at6Egl7Ix/I/s3krCBC/eSpbSVx5NKMW9fE+CLrZb7Jn2P3oRndnAtU8b3jviNCEdv3wD9fbulp6BdMVp0wHi+am5GIysR4dBjFLAcI7pgrS5WyyHoVcKzId9IiqoCDPlIOJY9IxrID8+XcnNRDRi4jahxG2981+oCSTN2A+eRra30iylTsl90jct9+bfvjAbGmm2qKmHBxtKgRQnJgml6F8aPC95dxZ+PLkEECZMU03/j9H2+SK8TZ2TE6V9bRdSS5K2MFhwq7j3Vblo+whgPkVHTNJ+2PUjKYoJr2948oxsKDX2YPKccSRj3uoLnPpAUXGAGny6d+4YyXsyBawl6lyituNazBbKHCq+/Vg+rSJSM+3MiQsPej0NLFDxI/scIOiVnrDRmMzv+CRH+P7ssAzs3Axz8K5Z2vWitzzXqiJW35mCLZ49x+TCuWkOVWNPz5DQS8ffX61KVySElxc0WopPmnlY25gvTt5X0Sqlh9sA1PwyVQc1jF9szjAq4vGUASQqO7Bn0Bjooc/rMlxNj1MB08U7kL29uhl/Og6+29AVyTzLURWmWEAsVyQDiOJc583OqD8Pr1sfVPkpaQFwq3mcHpF+5+I+p5RfKFwd6wM9fi6ZO+QgEOFMInrGWp7dHeQwmVIvsvwyMkqViL6aicGhmewj7jz2apjEqjde5pq76/D5DCAr3fJ/BtGESxo2IQqUOJjQ3htR9ILkqBPEDGRN/9R/4CYHNUhGKTk8FSFCNkwD4qOUAsLZJi9pNu0DuN8XXOUODDgc2YLNFBv/v5xY6KquYZfKsfB4N1jj6gdjWD28n6VP7NuFmTZ7vEmewc+2yqGw4mKh8kKRLCYzTFNWV4weksLFo67aGSpbujj8RNqvxh1cuhikqpYpt3QBq3U2cQwkwIN78uY/QlzAEau4TonLkEM3UKUmsIASayvcP77WMCnOL/3TvpCDFNGejn+WyOs62YTPSYwybNT+fze0d93ydDajE6a/19D4vEglZjF/QpLvfLliKYvjKtwq0b852Xhc1BlLTd0HOMpeSqe7k8RLFhyFgd/y7vpX6lIdbAHhB87ftLl+rQZlFXMbwg0mZMuT+MgkgGY6VtUWAZkHj2oALLnC8wqBUXE4+JdO04PH4cXFhv++dU1Qm7Zjn2RLPM4oy9JpHBsoo5eNE5d6NPFa99HxUn2D8ENTayN9Lo+ASyfGDMASRcgkkQatwpMmx2ArB0Y/GcICwPU6V5ympHJg25A4UtERkm15Z1lR2MWu5Wj8CCWpcNveKfFz/xU+8sfbpcv5THwXdiMyEvofQneb0UAzj0U0P+mB8xlUacSbTigo4A5sFiY7reG5CzbZpwcC3DhCB+afsaCo7vlmMoCoHTykKpoyJxr1GmdR0/zfKPFuEnaqfNV5ECBOBwzEx3wb1xrs9csQrUzCjQ4URvGw6SscTWqnsJDAxzgMQuoND74YYPHfZY9H2K0NadUdI3JnN/WMsaWqz8askBUoSdwhPDbNZSCcLdbjVM25cyFZLwtZOECZFCbwoS3X1xK1yEEF7r3klttHR5yWp8rAzUnGtx7VrJbPxQWqi9cTDV9UjLVTNEoPXncBLtkeCzKjU8TJG5ijnjgLWlIzhsqshuFLVpWGoKzjNq5kH9CnwePizOL/c8fprbD3ABEnMWAfR2KmHSsbCgkDDszGruwOM0JsIxinWyqracGPNjkVdR1AvhbLCzYuntWKoft5ftfhHBaE0cP10Cs7AVM/Z0kqmSW5XIZ5F7pz9ppMM+tM3SCxdBLHnPwgj4xdwBu/EcvgYp6UMEdI/NBVCkedciv10VsY8rA72P/3riKXRMw0jSeiqmou87ZKefJGb4Ww34DY1SDUPu/Z44Si3IT8gGcWI82G2Us5PyFKugcVjBbqJWeOIJkGhBzH3wxNvlPOdXWWp6HVpzFHAkuSFtgfaJkN2YyirT12BZCnSJLv7x/zo42lIgh8OnGb9UuYRj30AN1t13hv4OQ1woNd7yiw2E+ssfcPH+jEMe7TtZhjlgNgEnvpmirSdz9lznY+Hnde5o/SUfXD9AME08LAT1SwlT0cRKor5ywKkzAOtv+KnXot9QQ0EJgLBUqDzkFKK6NBgevW/Cmwo9Sh+58PrN6Ax+KhS4fk1e1+QrmIjgqfnZm9aSpkTmN0tklNhjPmSbivMneiMnKt0l8uVVs/HOcXWfCWyE2kCkomZSffv9aDfCJZEO/F4pHNRL+C+yRkz27MtfecT1p2ujcHvjai9rJkmQh/+OhnHHEta6uANAaZQ7Lworo7ksgOGqYzVI/C+JD8sQgPiaWn4Jihb5ZBrUzkLPj106V5wXR4cIphoxgfip8BkmGodoO4tlOmZLuU+bfP5Byp+zhNYxbuvFpKUSV5J5qGiyIYuQtxQhy2a8eJFwPaF+xemC0VX4uN6KlqlMLtAz27IfJbMJKaZbFCnteNiShjd4zIJld8oaWbEMC4czIY05efpLh1YdK8QeAjLv16tiGwHM/9lWzkB854/I1LnSD9C5d55uSI6FMwP9f8UP92cM/iawgJa5slBNPVlRgUz+BoujyGvhxcuZrkYpkRc4GwogOZmzjUp1aEufcV1F/4dg7ixAIs9BomJi/4o00KRwzGvBP0v/Y+uVQN36Blbeg/6Z8obt++3qp3feYW2uwL2XL4uoyVLOQoUhTv5UyjPLu3wlrz/dJRWLax+fWOgOQsplPsZxA9Ajt5EJRRphkeGgmJdXeWoAyHrI03NEaqv+E8DsKCUAyC7XVFdgPMjFFADP006AG2Pt2MUetwr8d4XW7/b9F26nUo12UQ9jcZ6i+xOpOEused/LV+00dDYN6gkgzhtZR/5//zdZjjkhyeHu1Jf8JIB8n7BGOWDpS6Cz7Q9SwKa1oo+Nc/am3A0+S/nu8/KQp5cfd1ozKiFMJY2/r/6SdgueBMxN+5+WCRfv/x6Iaazx4SmCRb94TxNy9LVIJgVgjCR27JvcbZAyF4kN2acWM7OEHEsNM9B1OWP8LlQOFyEouJsDzc86rvf3rhYyHJ3A6joH7g5OrxwkU042inbAt5hWZIZzByCcBkLMLHs2FvvLaATMmAvVYH58JIeRKB/QT6CGV5x9S1lLYyC8LpK3abGfEamTCTWiuZ+PPUeBrxlYgb+ibqJrHCVSf9p
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d371-9a30-4e34-b7cc-4cbf950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:09.000Z",
"modified": "2016-04-28T09:10:09.000Z",
"description": ".js sample",
"pattern": "[file:name = '0024508_008066.js' AND file:hashes.SHA1 = '99ea601ccd4a3bab53cd16c9b41c15fb30b2cae2']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:09Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d372-fdf0-4588-bc94-44a0950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:10.000Z",
"modified": "2016-04-28T09:10:10.000Z",
"description": ".js sample",
"pattern": "[file:name = '0024508_008066.js' AND file:hashes.SHA256 = '301d07fc7df5477d819ddde25d5b283ec0279b8ff8573b983f42da846e971822']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:10Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d372-08c0-4802-8786-4c67950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:10.000Z",
"modified": "2016-04-28T09:10:10.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAEVJnEjV+R5BcAsAAB4YAAAgABwAZmJhYjAyN2RiNjQ0N2FkOWExMDM3YmVhZmQxM2MyOGZVVAkAA3LTIVdy0yFXdXgLAAEEIQAAAAQhAAAAmoCiswzxcQqp3fZMRbZu8bk7xuRZ8+xrsJtyRcdwM6aiCttFNC8rZE2BzL1uzsVEfZ+e1oBmVR8GZ3cmF4x7q6qQiu890M2C/Gn5NLNTdaMvlmdUd+3xosBcu+SCujZnCJy3vnK+O+CDOpfOuUyMwg+AxIGfzjFwLn+FaF8yL2hRIBSym7oOMBjHuFHNv8wgcTbzTLHDXjImj8syssYXS1YaElzIc8s6YcFbN6VwNLbm/oc6IEwVbk9qDvsMbvtf4/++aQBY2x7bZ1ZY41WbchVMeF5JRPaDxb7JaC0Xmk0kOhF9vJK7ynotLTh6JuBHh9/g8SwGnULDnJJKv2pYh5UKiRPp7CAzZsnLerNzL+3tlUTZn2Geij4wSLhmtUQ4B/oqywUdx2M49HaISubaoi+ACVZ/6ioCYGfPiQsCaGF0xtmATJsPzEXWHTmqA5Q/1/O75DpyZPAZHL+zYa+8Bn/TdgP1dyKukCG45yvQEKSDMYwVwEXfsvZUvLYIoes/n/Xv7eMLsn5f+ODKtztsH+W3O2sh5qKxyzfsjJtzdpS5YrUebIdq60t2ilOOzhnPoIsIWJJdlqwYzUUYy70XGyPqUG2OBZMcdkHqeKAPCh/mA8RDKcwmLro6qS6FBE1fQ9q6yOwH7XhDHUEkmveiO80M8bIDQ+WB+OLSMbnKOgKQ0MGcJiCUELvTmPsIdnCQUyDmmVJz719iYK41A/CWCuFEPJExt5bTjOCuXaKGSVIxWP2zUSYDP/FZYdnzW9CZXluTvcsfNFf9JLnpxVqMFzeaSzhnLKdKt31vEXio6geu5thEo0MjItPrAkjJv1FozLCUdlN5Kcibuc/Obv22DIR1kF4XvsquQ1Pm5oYaSKP+sJLVLlKoGx7YmduS++0QIYUv4dXiGTmmfsu/soTflOqqozCwAUApmfww2xdsBFGCbHuCUqNKzmb8X2DCtA0NO6oa0wmAMnYH00LEmGj46H9mcYi440sp43OG2yrJ6BxqnAUxbiskmXihmO3y3q8Rlzg1qLH291HZybDKx7bxYXCWLf/RLPOKrorMWmFYEd18GIMbMDwQbTUCUYaS9rNjHAf0Myz/trbA4HAC+NWvJ3F33Im+TfdMLi+zvm4BW7/6XIDNCXnFMY88X9mtle96FZ8oEqjoYG83gsjp9pBIYEI4LfI2d00bOzaCyDCWm+b8P887z+bYMigPBCBjHKld06suc8TQGd4Q2+NdO9WOQd8UJGCggwgy3dHlH+JEOBzEWdNgRz0mH6LNJa0DCR+twWWMeN8iAKpLnOPI+6TkFwCFJtq8apA5Ja9K7DDfw7p1WxBkgRJWfDl1ovMq6qo9QWNB4WzKcWrPnriGmAIvZfL7/YGU9W0o2MZRWesl2J6o3oFqOp3lLHNdqpiByN1Wi6PLc//1JVmeI69lIq6jEyRaerl1Uz9FA2QzY+IrR9rZYzQIILmAEVIrKsaAbTmkXXrkwZkS3c/p7Pi3+RXQUVI9qU5W78eFtqiGeQiTHhd0l6XSGsIkyKqoxuEMdJddES/UMECaF0fbaWj9O7bE2/2wySTsh2lmmxukDgX6a3VLVAeFHX5zW5WGecB+WGd/GKkCmxPgBurnljMN7f+JPuCX6wl0U5u32gJrYF7YRJYJp9K4GzKdCcrsT17NA0CEBIQji+3HLGAj7LGXNebKokmCREny3Iea0b6zIrVkCObEZ7HwtopVlgnBT4AIhdkA0bGYW32tcfF5lw/i8+NV0bTUCuSmdvNBH3Lb2rwozBrIXW0xi6tvN9ufrwtluVXauAfzPef6RSl7sUcpQ1+LKIuztV9ONqZMOSj4yxuPUegIHlEhs2hwG4u4hF+kWrqfIaXX3fPMuagvtsXMApl4SaW5vZcpkho85m/4f4nRY7skjXGfWow386zvrdKgSWm7Knz5MiQIn7KDyr4OpTLamRLD3toEpsm41CJ8JTm1mxVWMWFqmptKoqPc79/HMzkmKaNV+jh0AjFD6guPmyuocqVm9kfkNydalxQjuz6430ATXOZxDv15v/4TTsBFdfO7ndhNC9ZTsriX+w6goJGuEbSfTKOkNJ7LCvUQjJghZU+LcLjKOCaJa42+m985ugXiY1C1p043h0enwIhGD9+erRgOxY1JWR6FnHdqqOiwVU8uQjbKhtusSfrziZ1BlBPE9Rjix84T9fISN0sX9alHEixAH/JWmt/EZ474fp+rVdSmRYsQfUT6onCoWizyWnLWqZzDZyTS0wsin4Qhwb2q+jPZ0kEO8Qt8u92H+80nMhhGlHMaPSjIRu6z/5wCQlGIsOpxPlRMaNpDGKyBUh26cYx2N79qZ52qxQ9jMnEbB7rX6IIcuBBfWzWah9WqLvnst9rvHPfS61p1LfvkPu/ZtYIfSGmeMUfJc+INncaKk5kfFYdjr9c7+okLx+9QVg0SVasi4ME1EjWlNAl8cqC5puckt9Jmho5tSqMabqCLQqhwpND6RYVrDKuwMGP0CU4R3YVn4ph6TxyQV2jJy6LvqieXcp7Is8fLw7yVcl4PJNMxIFQ3kHZPNIqeIpFlleBXGqyrv5dwzfJsoBTZu9WQAqLQffgVuVbywVLc3TLyjPU1lCQE4YnTWc0uiGnin1cX5QyWtdAzGrB3gr0KqGzW1/6+mMt02WzZVf1JGgTWm+LhBZE/I4cEJimkXxVqO0vGqC4c+rMWf9lTin9zKsQm6uRik/r5fMf/zBZvSMYTlnm1vD8xvjNySf8SHhxlb3BvmF/ER9u9tzcR1KDheKsrvK2FL85pUHowCob95uKn0wBomOXIRqXl/wod7jE31RMPwDY21vIHtj81zz2smrCoHptmgDdsZ0RqMss+z1RXBZzURusMP2OkNWqNSQAfhKO43cMeFPKIFVeEttL9HGV+RX0jtO4SDavhY4mgUaEX3QdYy3xvPDHbkzkgNiE8bUVQs5IzL6O1e9MoSKpJRDhmm8EQXx6W/FKTaE/eTA3DfNKorNUmzlwHRLYWJYxCd5LPNJ/tI1+ANZuBm7Lr7kX39JyHmMoX6336Z1EeSkLeBvo9aMX8i6naX1pygkCnwTo6pVp4qf35EQ0KE3SyKjLZWymTRjAVq66WI3j8GwSSe5iqPuWSVoC08Yrr+apTzR9HpforVU4bja7WUSIiwhuvGpP5BeyDvXhciG/XUOtoq34o/HnNM/K2z1PSv7rN0uknCJrOwzV1HhrS0E1pSCqlz1Zzn6AQum/25nuFC+KCue/t8HG5XdSmIv26NOmNE01rBXYfIqeAwf8FGakgdRzXfSXVjXVM8SbWp/zVhfXKs7f9TJzca3CGs24SkTnCXksDrwWWZHmAek3g6wArzWyUSeVEVTq3A5wXpy09ghFxnyydInJV9oz29aeO8fPUj4gSST0XslcND6CMTBMDEicXudcw2QaXGvv5Bxl4uPVlRzjCdheh4snYjoYvSLXeVQWxeu2td4wziEqMSYoBUz4y0NlIp1JK8YRZEjSfglFx5ovv8tdxyWCdKhnc6o8JvhyExRW2W1qe7p3XNxi/VVGx00HDuSl0R4gIT5IDeR0F4DuEFIhLRFRK68beGgup6aE5r8uI9nsuUeDrHCcrS6I2+xfseBxip0Hufyp2KN75ql6Q0hbLyrCHxq1HaFPbPUbzokX639xAv5lKBjWREXu/tjTf3SyCdexbUs8KR20Kk0JrCZ+AN5KHoLe0jjHq+pUiEx11xL2wpIaFOinRhX7uflO4joPagP8j8XT1/X3mOgCzUGDeyXlZiDo0qkI/JMwIRNPSdnMkwQcxGlfOJvRWQ9ySqjH0E5omIvAqbEZ1E2silNE/Vx8B+oPCTP4crn72Duhrq0IMkI1Km7Od3EqH/Q/C0TGfnNjCfCKBCdsByPW6/YkpmoTuOyQg2CgQ2J/MUEsHCNX5HkFwCw
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:10Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d373-8d60-48be-8293-4deb950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:11.000Z",
"modified": "2016-04-28T09:10:11.000Z",
"description": ".js sample",
"pattern": "[file:name = '0024810_008149.js' AND file:hashes.SHA1 = '7f69b63d7a22cb976996ee67ecdcc8919c7b08f5']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:11Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d374-7e90-491d-a4a7-4454950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:12.000Z",
"modified": "2016-04-28T09:10:12.000Z",
"description": ".js sample",
"pattern": "[file:name = '0024810_008149.js' AND file:hashes.SHA256 = 'cbfddaa6edbd298f15852c6882e430ade5ba09aef33003794ee527480d08f850']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:12Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d375-a460-440f-af2d-4624950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:13.000Z",
"modified": "2016-04-28T09:10:13.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAEdJnEhjsdXWlgsAAEQYAAAgABwAZWZlZWQzMWU5YjJjMGNkZjgwMTI0MjRkZTJkZTFiZWJVVAkAA3XTIVd10yFXdXgLAAEEIQAAAAQhAAAAfeWFJTk/2AKlr4Uq3NR2Hw/oIAi5drvkO369+/Wf4l5cv90NhF2qxzbrkJSEsDItlyvhIeRGR84vEGj64NGHKbYLWrnpncZISkHwrAFOZkVIHFzYphhoX1tdrqoNG5bkh45203JnlQrYrhrM0ZbELof0KSUqIqyeR+pnwTnWiqOIaMzt8bV7xErWAaKLYEvKTvbMqbDNSDWlTLyDYypVI92JiCV+bl70uJQE7yoWBKTJ9MTmyNrxPRRdw4CqbhywZjiIYrzUeRXe12vkcfcuu1DsUgolbKcRsDcm/h5Y6GPCTYr1RWVAuGjpWASeArPl5bU6a7ezGnHrZi8w70l0MX/lJbt8sCYhrF5q9AcZs2K14V47wauev0HM1bZNaAvW7ee8XylIFdRh7gEh+AS4ERqyx6mM1H2giR1zVvkmqmGg909H2vcs+0DmQ99JOWZekjYOBoYfdCqtxuIe1UE1VeKq4oldOwt7tkHyp0bA5wQR1J0NMzrM9VQWxU/v8JucsjEXi3nsER/RSFRW2GFHttZMam39a8SNULL/a0fG/P3V5oFXla9QVI466DiM/fYpn/Qk2rsZ6Et3Zxyb9VbirQggKTEA7CjwPgEZWq0YTBCNuUwLywUfp39cGs++RE1+J2OQenWKak2oe/2Cr8o69DyYFHYZzUtY9zqI6HTwCMMYR3hgei5NSCVh7XxIjFFCmDqIFyWGgp3Y3e0Ib71mpnuc+KEEJVy2iLVNNqZfcSTXYNkMqzM5FFB4byL8QhrBMoXpxfgeinntXIl9KIfi5A3qIGsWuB02C4L2C9x8bMlOia+BoRjR9pLRVC2dCGkLjZA/IbWbWUZaTzflTJLPoE/EZqyLp/wgGakRilr7keBaT34tWcjsQkCBbMYIixG2umjb/08/V04hPKxz64wvo61TVFRwOoIW+k/oVrKAlr/MVG5KthlPqf6XDvdyKNGJauTnfvjVkrtBikPXqJMHCb3UQe/XxfIJJpqOHjYc2QdNmC2BORNwFCApxLCl0akvL1aEYe2+3J2Il6lwdN8oDSoc5j+bBIKLOFFIPLEajLsQFo95tUEEcLif3XBBVSD7JxqHF/0wzP6lN14odaYvAYfJQ3L6gXlxny1b7cDjMLT8HO9BGi93d6jOuv8ZS0IyKjWUjQUxuZVPHDjoDVcOGabd6C5np75u+qXqnggRRfyj5WJtlaOzYeTjNJvu9KF9Q9jOtq8cF/96y/3+eXRcKuGDupMwSyV1IFIR/AVkSgjkWLZFnzqTTe4SNUmHYaYxMvGa804yk5VPgSRrk3iM7ZUebXMOLTlDawk0kHOtyO4ZVCc1wzMQwd1rGEhYSatkraWnutlL5BH1Q1uDouPOEwpkOgyAfn/k47znKSDm9PC4NzlCW4nKUZbsbZA0WeVGpjSgsRYivhHWmCZNETdiUtzDVLNtXOtNZ3WXAXx24UOcJp9OB+gPe5pTx1o4euK0O0NMLhWLkz5Y+dDi0CrnUf5o5IjaRWHQjzsalh/XP1FQDZ/3oEMXRu1kQqVAvQhuPBwVACNqVKL9p694sVUDsJbSqOmkWJoFSn9OXz9dFSbxuHvaDFXJ5QvYYF4dRmX/x1Eryl+qyQuyNHtjZUYR0cEtpmaZfKJ5kPk0zjr+pwVdKoe/OEPjG0LOhC69uNfNawcS9XnPChGetl/0i6D1CVhZW6tz/ne3aKsFFVYpwFV5lyzL2P/14erEicJCPfeetJoFxJMCK0F//AhLFOSbzfl0hKNVAqMpHFL5hwk4ktNIVZMAmB1IcIrSdK0nT+066ZjWC3NTlW3Ql7igfuyEIoOROoICuN9hngXGj8/S9t7Zp31fW/j/YXM2N1G2PpFFzfsL2mZq6sfjhV9mVNMfiuhg81waWWKPw9hd1EvzYJmCNYsg/+vCP88U9pjnHhMIv45JqvU34evz/5bsH74xcZRf5NgGRGw3lx6Yn8BYsIDwk9z9hStFPXNRbXcPgBls0ef1mGLXFsr18oBBsKfidWA1ohU+2KfTEqWfdkJds5Cj7aeXqgPPRRw1QfyDp/zONP7MSWS7R7BoN5XkFr4smL2oIAnvwNAfb4SfArpSrhRYjjnDhnjVQvWiGHWDLln+O9bCbGZM5o15FwGc+Jmn6dnk09QFSvlWvcqH8apeBSbPSPiPDj3S2+71zkt37igEWHLm4KhHRQQqXlYBqK0uyUn0kLE+9DePqtJeM9M3Y5kEJXEWRL+eslwGYCaSWRsptjF6/ZpreH8qniVAamLVC1DBMcAEnyYNs+9aXBwsBFmM1v1g6RJLrYUBM4JLzAmtDkZxExlUh83ul5u08l/eeCHe/B5GQwM4K/Zq7a7kb3MOYaD3T3wSKFJfy67FCSR0qL1wQxxdlRrB8s0DZLBW9xQCWghQjV0Xny589IUVk2lRYlk2BtIIh/BP72p5wxm65gHJjwBr7XxH/ksZQPQblv8irMWjfwCpiVzeyCOx63PptjwKhH9nMnK8N4ABO/XUVtfbfN/8tqiXuMURmoauMG9V6NpYZIKrbGI4hogmcomWAPpNCgZdBklG+6zwWFYxmG7eZ/ksDSk+AkBAXkJuYDa4auHDqWNCvNxzTZic6SegS1USgPm5Y53QhGyn07WjkRbUtPOi8JJDeJ0fSiEk3HYPnbKsHEMx48hh6RnYKIBcQrisOiIk1/sfxS10XzptcNunLi1ISeWzVO3kXRhKnH39itRjv1oimhNGlO1ZTuAW8JvBVSvwywTTFwd4a0c6472Wj+mUD6vBqrPGBZ9EnfCWMdVy6ilp8CQ/d11X4HgRRNkL5CAdvluPNnQwsIRFSfVv+3IEPQLSeTzVgzdoUvcfSlyu3tHBmrMmVX2+VyTQ/2jqojZ2c4XdDC2TlWC8papYDrhPoFFuDRvg2ZyF6bAQ027xEpgfk5+hIvatFYwmYO7RsTrKmNgE8Q2Lrqk5b4xzNUK3uxF+gajBobw9eeYhpcLzkBfMqpe7XoR8FA4wBvVgCOSdiwSbCNyxZnjZhc/7d7RfS3NdincVS6qFSrMsuTDl/FmMuHvwbCA4y7B+pmNBFi3Tc7LBX3fxqLI3TtpXhp+vebRL2IQwHezKWzkGwrmR02P9ump2RxNgJwmFjEWtfU9NB9smCZwLswq17pt50D1W28SMh5//PY1pcNKZ/zEBjQcvbMtZMPcpYJjzlVn9Nccid4Cyn8+BqPPzSU57gGNj0BPpIDqjn/QJpwG68TwxGCHllaCWQU4NQBZvTYjRgeVz9aP7PROngPN2bV+K+YJhZU5xdpf1Nfg3acnr3V/CC4rfEhqiJPVTZpggqBGjBKWBBjB9tbsZD8p71yD1jTpbB9Hb9CNzXDhpEGRwyIdWvqOdedM5zTciGgf3Dw6g14iGrDzgrJ/CNd6FVkLjDOYY2jlwv9OwKG9qI3CbgreqVqvbTzMXWNDnEufJTsO4Ujq1NLZZ/FbadyaotVr00GBVDuItzNTEEtlB/T3fP+JgN8YH6aOHeWeIO+mzgf5xZUlZN2+M26RppNOOhhWHN6NprRFehTahXiS4KZkgLIxeV/sCJME99QDGbVh7/Rcxe4dzAiar/MrbW0XlAX+2wEeZ5sGXrAa6Bgiu0m4LzZ+VUDmMuDfTIdSBHYo7RXxuNs+yTuKJKv30Xe5ebkMTLVCniaFHy4Tx5XrZ3mwZ0seetcf1rM/oZQ6ysXdXlzjn7cV2PEPR3wYhoQ7M2lP8bsweWz1LURIuJKdkXgmClZqDZCt8NWWXrBDtfe7yxMACY1RjHVMOj5QSURBE8I+41QWQkr8sLQLOQ5f1yYxAmCHFMMP3iThDjjGEomL9BoY4c1yzQtktJrlc/IoTi8o7oJOo3UaGfN4a+NPjfe+A4/JQFhVM3Kjy5Z9d4wtePwpBhYU+6mhLsVWIJ+jSombb9hWWNt+74y
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:13Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d376-48b0-4cc7-ae58-4b3e950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:14.000Z",
"modified": "2016-04-28T09:10:14.000Z",
"description": ".js sample",
"pattern": "[file:name = '0040714_001932.js' AND file:hashes.SHA1 = '3e7e6f12f64d3be0c9696b90dd3031ed6ab0035c']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:14Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d377-8914-4b08-93c6-4e74950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:15.000Z",
"modified": "2016-04-28T09:10:15.000Z",
"description": ".js sample",
"pattern": "[file:name = '0040714_001932.js' AND file:hashes.SHA256 = '65a5d4a688b6c04bf7815c5e97e91c41dd8e60f435eb4a2bd3c179e9235a66e3']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:15Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d377-670c-40a3-a266-4a1d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:15.000Z",
"modified": "2016-04-28T09:10:15.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAEhJnEj/5e8+sAsAAGQYAAAgABwAMDljZWE0MjI0YmQ5OTJkOTk5OTA1ZDU0YjA3ZmUyZGRVVAkAA3fTIVd30yFXdXgLAAEEIQAAAAQhAAAAae2SZgB7eZTdCT1UgDBVJ+3XExDOCpbm0C0ELd2rgiPOXP8+oeFA73hOHQ9b9VZ4Y/8boAZjnacNRTEUAU1GFT+0qFuYqxmbydLfGf+/wuxI+2jnz+pT2DvY1ZEeUr+yWZGSksXoLnFEl4fv175vLnvzzNavKEDS0tK2u/DCl2he8ysjg7cGGlPvzGU9xUViL6jTV8C1bX4IyBpUUFNaZOTVxRRK5oJQtQgoepEzVxwOiIY03ia1a7013F3IGKJYY0sbjq/0wLsBjEpmpck12hnR+ewWh7YABufD6uw5V+Wai2xTffAD5pjgprYYSksl/wUxvTdluh23jNe/GXTI2tehJIXnV4EAXI5FnNXHIMZ5a13nsmppvfjx3GC493qufIZcMCeeqKIpqrNqd/lduRWccK9xP57ghqPIqheUNqiQOO5qZE7z0rxKsJtmOB/uIgIasGkADi7Q/K6WwyaLanErc+npcuDMCGV5WaJUa7K1Dv8Bnq8ICape6/8BbdtRIb14vSNcJFOOc+4gIn9RpiQofUTCZwjeGUjwFtBI8DBXnvWrtYbSb/Kcs5C3jH5VcAhounRbt3qr2cZFgtZLeqxHQexrwtU0c50HGU608KaXyQC7PctCGRYsD9gg54N15kbPDJiBFO18ypTL9uSeIt5vTICxowEbzzuwGQQyv0ygN2zg+PXwc9xrRO4PhPK5paHVgAf/6x+2C+57YrWzifO7HmYDkIPoxouGy9TKDHZp8eKM32TStz48OYGV8cm2hsfhRIaEKDnsfNPvlQPXvj1uCdk+3BKn+TKBFPj+HXixMZkutTqSRdg7vg23gsJ4lDya8zfXqzj8/R/ifJe3SKuLhGqGa9daO+62f5qs+n97hIwgA1CmvlBvpyAemwM3y4i4Fa5jVwiXD6SYqcAm5klu0OlEOkTrTSlQz0PzXO+DP3o6H6dYnZTKBhqF5ZX/0COBwvvT2FFkAvNv0wht1utDLwscJ3+4y/690dsojlWvndbKv5EYRmypCoKArztiCBspUnCJ8Api8qiGsIIju4eL0C61Row6uYCMz9Wz1I332F68Zh3m5bKqEnUlGuvb0Elr7SxsRqxgAkohBGbCJZ1nGl6xuAeDhNGLaOFyQBfKRedzgQm0PbDTBy34PYhZCUEl1WWJDjM9mwCSAqN8dd4gpgMehdLe4hiZBY1QIRKbV/4dIDeqQjVusZOvKKR8+c+pCPGoRcE7YmIF++26nKaxlY2QV0Gj8N9QQdjgeWewP13waZ/9IMaFcK76Y2mBCM9KCmO5dPoEf/tY7Sx75FNGkvB2gu660d/x8o/xwY4fdzrdijosNsi8KkwVVFNJhX5ceJwx0CDiITJxs6Dtp05BewEDDJfGajIO7U3WF8vfXq5m/zBRCFuO6Dv1X+/ThgY+EgKWiI7vk8Pc+MpKWPxNnWLyyLM8ASS+80qS7Jx6DzSw9wzVfjlmtWkDI/rq+Kba3U/IuBoKDoXUALLSPoQrnZjIoBuWVf8Kh4fkK2mc5K0s3Oxp+0vAxKBN2A6z5N4iLzba6dPUqMjs+UrL/1UqG9Lyc3N0n4YQIWpPqGkX2V8S8icfwvRNU4+BN7NWirT4B9Oqb8pUWj/IJjrhDDBDk/eVgHCnZWIBO638BErqMgqOehj4nNkynMrmKe12XZ397zSRxMeiHNw5ekBFrHBh2hzxcvASjB/mA8+VUyzHz2/XWBEj1bax7m57QV7huAF/mDJ9FFS/t/cCR2zIRjdj+iEUptkB1jAEyjnbLax+/M6Eu7u2V3tVMLFTlU8JzoIp3H0NKjuIfTKbHX1cNM69rRmkyO/HGSCnvJPawfycL0zCOb4Bnu4gdSwm6GHratCT8hcmgAmIOKP57ec1zJhePsyLDg0Ee3x7y5axlVSpCA8PbXndFkxSpkqZlEC3cZQa2OlvDKt4swEAbkoL+bUGcpn0+/Ia+8EWxYU0qd6+DBUs64PTvpGceHavELt3CoYR4eFc53jWDtZU2sTsRu8losUq/NnoWzcNxwbe43Co/hdj+CXwrAkfJNX3u+UTApE6iY37Nyk+zuJd7wNIZE7WtoKWEt83IQQDWVkwPOIDkW4ePWND5efe3zRSRvfU65h8Cq1ryjSX2VEzUgtqUGdoOCfroOIIh189ZCELL2f41ae2ko0cYoMAmMbICxQvjiSLFQN2sVzV5lVrSbpj6xBUeHEHm1OZ2UCK/nHNxBO93318PQHcppl0OiK5JHEXuSkmyvXGdPlQwyx8AcbyRJ/p/6h1BnmITnCRt9rlY/vCih5nbE1uMvuan1HpmzUOtb5n3yxCZ04BTJMepRLigb4mJIuCnz2QMp481nC1YgM68EkT2NspY4TpeDUEZJAsQEnWZwHj1jechz83XnXzdvGPhqgE3wz62ArcykSDsD8vzmsAyh+ml2af3aVFs6zenIBhHZYEtSUbhFJMbX2kfmgbuAOyuLE3KvP5wL6PSg49XTjwNRSNqUkei2/YNWrutS/NZ/W7C/qkNkYlfZZXxyR3xC0BdFiMt4MAVYwbw1SAFRiuG2MHT2WKmAMyWMlMdB/jJe1/pP6nCxzaikNUfhTM0+dVzJloLeKJ3/1hg2meTBr40ePrdxRtD5P72C21tDNRxBy4R53f14Y4YZ43XvHAkxkOpHpaViw5NY02LN/nWvb0XWhSY1jBR70g40MpewhgDTH/SODdOXgIpxSYQ7wgnJwlpywb3xmwTx6GAnrY0u3GVN8h63G/FMGurGPO25ONpSO2fJTMPy2jrvPI0GK5u8cI5s6pwQuj65++/JtOB+tommPv0IhZz+Ecu9UpUfJ9aM8NS6JzMwYBh0S8llNgPzhmmvPF6i/mAP3ATCQGw3qeqWraNdGbPdTYqEcYNOxMu6p3nzwrQIKjTUhYXW7WRVDHZ4KUbLHRp51eVqA4mNKrfOtEz5RsMKGQbaraV7lJVCphuJFrJDGT7fBwOOe8+N7UD/InqahUqYgAQgtPmSlstmDSdhNJVgeENPtuaQd5MOyLLCyDaZw8+SpNOneo8Xx7y8/hZC3eqUw2Z17Sj/EhHJ8pD7ePxtuhv9scHy6C1QP152kKGIECfFc4Rx6CuZB7p7uMM7LJ61XXOi/FH5qhBV02vZ8BUSf9NUKKhTBQ2/RqGoR14wvOWFXsSDLjkbI3kfz5sd3M6XVq6SlvqViRNd2lxFyv5DtnsPbPnnDNVdsP3AVo3OLOEr3cZI0iccnzwZ6SFUQA89u4Gaku2dwymzh9D3FIP8LZKesLVqfDTPHZK9SNV1FCnmV0xgidde4U/xJJbx2pY5UR+ApsZbv+pLP1qOj3DqKMQs1cHfiUAWZWDDIRaXFpAZLMz61sUXbTNeZW3yHfYtxiOzonbyTYJlEUNq/dzgkJn51kUiZCWWa6xEvtIILjT/qcqGxski/cjk7FyB4PQDX5SI2XEUCsIRGeikMwmTtJrEcu7NfVgcA6RH3rBcEBztSgeBzJpAi8cLVOX9jmwAt97oC8rYvUIAuwCWtQ99iDvSJCw01ZosflinGr3p3tUzmFM3I7OfVtvNUgAC0rTJOzSOl+xXrVLMUVfC+nC/zoUQp4K31a5ZddSha3+zey1I7vQmHckYYBcia98tCwIdqjIbkWrhFrxVYyTqGChC1EQW1NeIdr0HXas9ut8xc+KfnFGUl/oSitujqWBVTkaEl9ljeUHFOhE4Gj3+BgRhCUj7QlgJsNtaqvirpjopGIQyTREqK8IKZSIQMORd1+m4Nkm91kqgUUMsl4CilQRFcqJp2eX4krnvQjBJ12d2hg8YIDNyKxUJWBUVd6cmcSECwhQFRw4JhOxoQXq+MS0Yxa+IlNGyEpTgwx7DDVKg/45VWFbZ6R1C1tP+c05OytdHRAP1DWsCuqX6yGQG0e9R9vL7i665+h9VsSV4pNVZ
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:15Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d378-0c54-4876-9872-44ff950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:16.000Z",
"modified": "2016-04-28T09:10:16.000Z",
"description": ".js sample",
"pattern": "[file:name = '0044303_001287.js' AND file:hashes.SHA1 = '2a48ffa6b99ae40445fba40c47c858900d704643']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d379-dd14-46eb-aeaf-4e91950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:17.000Z",
"modified": "2016-04-28T09:10:17.000Z",
"description": ".js sample",
"pattern": "[file:name = '0044303_001287.js' AND file:hashes.SHA256 = 'f76e38c3ccc2a52db870883e44018e07d5a5be6eaa5fa93b5dc5df1bb7e4f848']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:17Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d37a-cd00-402f-b0e0-4b84950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:18.000Z",
"modified": "2016-04-28T09:10:18.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAElJnEjp4ItflwsAACwYAAAgABwAMWMxMjNiM2NlYTE0NDRkYTlhODcyZGQ5ZDZjYTUyOGFVVAkAA3rTIVd60yFXdXgLAAEEIQAAAAQhAAAATnJt6bItUk7zjpkVgd3Y5Xl/G+73meoBCzQX9cgm0ZaKetnPUpMgbT5WGtwFHR2+wuNe6qNL9uGyMGOJYF+eOQX7u2QPTj9Dwm+kxUUoa0Fz5Vwh1cFxXEbgJozXDsrQ/5vcpI7Tfgl+mSobVkm1YPD+lcoqAs8xL6KPLFmTrVvOeQCetFL1aJ4hzCsgAOCqD15cGpoPeydzf/rbCGi8lKoDCq0plSHY3nVBURzgd+a2QkpkepBvKy3PnPtqAmkcbMTgPItudqvPQjeWwCebfTpHhSYpasKIsrSRNM4s3H1QkdaVszgj0WrdFPysuA4w403hyqJELya6yZPZ+HXBoMkBX9AAio/evfPm81WmLFgKIDmhn1O2+kEB1accxDvPfZwIGEWbVfdX4inxMAPKwPDZ1qbKxEWmNCXuVDPX2h2hmFNSoWLQpmoWslp9n2IxoHeV9xG1fMUYsEFZyedSuJ17SXBoXf2P9jSBiZ24JuEH+46oaSAP7/Mn3FHFfspFhbLiUDYgW+0d4izTtdLhP2htihGutO9NABLES8dJfM7W6qzDfEGOmXMyvp9xQqxiRtWmx8Fwmxvcdi3EOxRI0kTgmVbhTgNciqStkdr3iHegC9KCZat7h7ERXswgAVK/HoA0KuntNxZw7oEAjMV9kkW+KEG4G0aPz+04SnGHaxZ8qp2y/JEZD3Dr+xGDNGS7pwVKLfldw0vOVZP+7flxb1owq4G0V//niAvoXk+bbZbDxC8WEbFK9ATdhZFV5c2qISWiSWSmfYTGynAn3JBZoQVkVCiF2jFiVM1Az1WIRtJvVoa2jJp7/YF+NI18vmkLZeqOdJZS/2Hlt8OG2Ic3dnIZ6zhKGCPMGZpf4AhrhUf+PX6BzBO97tnheNwJVNP3WW4yZS/lN4nCX7a+O5lxVU8qtOIUyWa5gqS5r7LW5+45jKl3gCrY9U9KPO0nGWw7fHJx3ZoonRXJCtgaJ2m6c4PLxFjIL1/Xv2r/IYSJ7oNTggUz1VXaACk24VJj2pjICuZVfu00dbaFiY/JPtbuXhou40DfLjLtuNjQdP6fN/QR8qPAVfEEm6nbHrfnJ7L5uNy5NNpsE6ZqzlHXULAf1O5rKYrkLT5TST3Q3oBzHElECrx7Wu/UqIZrS6YllNt3BKy5XVW+vk2yxjcemf08jmuuDHApRt03bWAyrDFYZ3imAxlGHLldpudMm5cu91bp4CHzhJANrGlaSPmAlL6YqZAwhUi13pFviqLZNryIzzDb2m2UAqxxWvHYYh1nmLNl3Lf3Wo1hMwNBnebQX2gD83i24/4eEWKmyqqryIJ7sn4e4KIgf3b6SYIs3jCcgEtNLmprSs9pnzN09ksJw5jnfeaV56IzT4GVqjl3XcFVCYeTmJw2mXvjbypNWKAXR0PSY32NA9Oza66RRw/mQXFLr/K7N22u/t3qGdSHVaVjDzjFrQV51+jq4bUCR0gi73VdpCrgkqYp6Gki8Gh4uBemHgXfKKkjGpCzFk99rnunegyUADmL0SbglOWOVmaH5XOPekhtU1/AcRfFoyh/Dhv9YC0v8VvPKuWxLmaVEwan6BhtOjpqn0kkJkQJpl6WQW9c8kt0SK1A3MEPK8mc/f4JFHIXm7HXhatAqHYNvH2799WKt9xXnGLLT/l+PQE5waeWURdCahLpfJF9d8YraTg1d4NbiSaNP0PsXJiR7+2lUVkp3EMGo3dUrwTpwIQY6j8skJ/ZvaW4GURiG2+Brx3D8+z5boTNBErftABfsVagni7CreXMxmW8OsfhuKr3YB3LSURH6ypbGrZDI/ZRLlkZSddWoF+twnO/ute+Ysvnlz3olgTPRt0l/k9C8ZnvdhElwXtpJu0zsb6FV8ozhZiC+SbJWYT8uu6sNkIqxxcZIgcsH5ZByTk+hlUtZa40ylXpQj5l3sGdH352STBGMVoifSE/lHPeUmO/fBnRqWlqimj5boaj6Y1ZSwaAhIjNaH2zcus6AxlzoxT8I1X9pyIM8bIE4n3sm7mfIuXZBwcAm1Bni3/C7vSYja0mX+0XniW6d7IjENm6IL7z1SfYwAqwc4K/YAspqGe79g/K/z+QPj8C0tNyhZ5JIqjAlw7Q7ScoGqMVidJks/FX8oa9MAs3+Ym+nA7YRQ/s7RYOyJihfzX1igthyUmDaAaC5mpDvAps2YvMBdpG5eTMkE4a25YDF+xZ6xZ0UztFiO3bL1f8W54FFzcX3zZ8y+JwioFsrbmBA6zGS7gaoetxosSCP7MvLUNZNT7rgshYELv7D6uSF6dP98QmoH3xjxu//YpcHpZkfvVsDBDt8eHZtKPI88+/pEfEDE9YRy4UX+y9U2ZWyG/qb9pSsa82raq4udkx+4clfWNU6W6kXHB2vbnd8sa+SezJ+Em7JgB1k9wPe5sMz/F0GUqcD5/Lo2HKTXTeUr+31qSFYyZHATVazDplCe41BUg9JTO0QaeKfuPyavAWT7ng6BZRqJYY9BkkNgBaRKWCm7bMO8XyrLQGRhjgU4nERWy6IJnuJSSlh+Vc4cvrdCms98jVbK/akNgT7XiHKqOw4he2wFnB92Q8gv4FIaaNMfy7d/U6Z4y2ufksTRSRrsz6EF+yGuDo5dGHJZH7ri2NurAscsWfrfkoTMFKdlhxBoOrAHm/+QjyU0TDeSSYbdWuR83dANzq3+AD2a/4cL4f8erqh4dTkvTv/m3/CAGcQvTMx8CibhlasELf+xHjVbfpMHp7tqeO8iUw+gK7cqun/vsTHTCibieLA1ncNZJ8LuKa+IE9eciZVyIgBDPvCkdQgsbpa8picSpV2DVimMLNUixsNDbdNCltoLoGq8ffZLkubcG6yB/8mGNHgSelEFEWe8v/BtO1o+4ZG08w7n4KbZy3zhLHBmhKbe6Y9Kxkx4XW4TyNjcMRsPTgMWHY8OmXX/Tid6e24XwPK/ycPjexEo4AD2T7fMuVICAkNlrGG+BCoyGAlD0qx5WGqVz9mpDfheB6lkXVsUxHOdXuXiomIg2OgT8COl2P5gO6zsOlBjlvhxu1igdrZnf2BXM0ksKebg7FqbfJqjN6pl/mUAR/PJP54AIh1mywZu5pp2VTteOoivx4BtnOsoUy5aBSfw7diHzEmmSVb6Q0tHqqAG3NzPc8tcKiT03xCgOLUcxLCkL1F5MjFJmeXJov3kDNATo2IY/FRGW3e+LurYFSEd41hRLBPoMgodNACVVw+kGqGW89jU/BZWk1FXnsWZmR+cwgyWz3xxdwvI27QSjDn+VLZMCymIDikJDQ6rLNJpHrEl9kViuC8iErtHtDNPAeqLY6QXYL5KXb1APn1vaQTn4GW/J2Y4nkyXgNxyNBKz9yjrN60Wqn/zKEB6YCW87LrPAppHZ8LZLJvy3mOSK0vo1xwn/QyRtX9wG6Pf89wnekvqwOhJQxw0djDmY+JaW/+td/ZnwCynyvj+QpE4RBW9G04VQWQA8R208zhKRry/BBibeNn5XAi89E8TreH+HqFaOxol0d2iZT60Zqrcz7gBzKpGQb+N1V+EU5f9bvTf1O5cTI1Bvad954CW+uvadZh0sXYCOMh744ssUJZ+HOaxCObYz5jW89j1g5RnOYVk3tQL6frdVJCK3FVvUa+u1WDMJ0Y7AdmdTxlBi7krhH3gg1p/pJclmkDW7KxJGmRblhiCv5JJZZZhwlDTZGDcl7n1G5OyNCtW4Atv0NUq8389BBHSVfcMuQzvbmBE+Yyh5g5iOzd8CByH8a68hDNBg77atKN84VKZtRoE2xzjXXYV8fQp2Fly/acAbzRMHN/wFyxU0A4duplylXkHE90EicSbCaBG4c9Jfak7QZrrTxDFIojUFl54edTZYf1JXWlY3z5AuTiMFcb4j8Gq6wzHAP8+QhkO+7jukylAp00kry7lylkNp12XCGitDhR4
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:18Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d37b-2b74-4757-8668-4f1e950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:19.000Z",
"modified": "2016-04-28T09:10:19.000Z",
"description": ".js sample",
"pattern": "[file:name = '0050005_004977.js' AND file:hashes.SHA1 = 'def7015c98d3067a3ef4c2dbb5570974edc423a2']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:19Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d37b-41c8-469b-8b29-4244950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:19.000Z",
"modified": "2016-04-28T09:10:19.000Z",
"description": ".js sample",
"pattern": "[file:name = '0050005_004977.js' AND file:hashes.SHA256 = '4f685ed243cda576e3478e783b2bab053938ae58760bdc40981f19528cf0aa21']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:19Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d37c-2d34-40a2-81b0-401a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:20.000Z",
"modified": "2016-04-28T09:10:20.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAEpJnEjCydZbewsAANkXAAAgABwAOWQxY2ViNWJhZTI4ODQwM2VjYmZjZTg2ZWIzYmY5MjVVVAkAA3zTIVd80yFXdXgLAAEEIQAAAAQhAAAATnJt6bItUk7zjpoesMl7m6t+rKS+r/r4rQwzpWG2uJoT2OPyaQCQOMAAT/u5ej+0hkTcNj5weSwrRaQs8vvL764iRXUbb/Z1TQHYQPwXnJTWpB3YS2IDZc8jLVAbdg1SnF+LHSa8bI8IC76x+XzupO3zlOHdMdkXER1o6zvbRIvKWYTE2l3zERUlhv0M8FAoMNRfMI7hKnFQ0+bYs8rg53LcSxdNcYRadzQnLfcJPpzg6O7MgJ8fkEJv4/uiVdwNKnECTz/gup8c4eKGTHN6jZEG2bkm+lBQrEIdvwHd0ar2WBOhkbkThhu2hSzP7H8woLTtsgBYrzlqcsTaubwlj8Xt/eE3pBLltUwR+Rm0420XOlIh4TQlHeDS+5kVb5p/lRwHpfegvbdSvirgPuYba8gWbwUBKGhh1ryLTSa8x2Nf/69oLrGQtvraBD4sKMX+OIz5C0rs6FhRQkqzj7Y/GvyqImSxVFAahEAgfF15F1LXwG43aN7kYgf65EN6xuxE+SlpSWdi5JWoaAaS86bildc4SaOP0KAgwbrZbnzCOArBwJvCuQEQlkKW5yYVCjgoW+LoN5y9/FYoqW0wM/DJrk+A80NHoZV+ZUkv6+KboAf3+Y2eLch4sJiP/uiTDainBBLUyuZgvABUM+OoGlT6Vr/0yM9wT5WPdvVGllc13YPlH/esTL5YCCr8RHo6ENJ3TouMKVqid3hueIm5BLouGWIbnCuFVDc3gBzziI58VjS0SgvoXN3IzHPr6MI7QeuRoE7ejI1B/R9itDs+MWCQ1hKFeg0cCHQWV5xaZoIlp/3MkOqMIPxHqb7TCfKx+kaVxiUDx93i2GglIZe8qAr36RwsO7N9vyjyQrnkTTlzm3puK/TumzW1WG2UawUa9MCy5ShCCBe4XiIL/SzRG9hBp1OMwDCtqkm8ywed5DTncbINg1pjfFj02YSb44/Fc5iYYWB7a94+NJs+7Wr8ENp2aUL0zPbCgQw93P2Rha/xbKWu2JptmaHcGtQU5xlBaYQx/Av5Mt6hCJOwwj2Q8nnjVgTwo3NG3hV1/rSms0WmNZCwOF43+panHOOquVuz3bwJaMXFTyih7VX+KiUv/CZi48OaSp4iPzWT6E8tm9QpoPXgKipZ3CwyWieG+jUeRt14LWa2FFDC1Xe0VRT+mjqlAbriZfxcXy6TvmwfnN32y6lrMHmvrAAEaSoc4vH++NVfg6L7IPGa4u9Esaf2BgqjXg2XxlmSH6pRYL8roJYYR9H1HX12VleFkmv6WV4O4u3Uz+TAVTPSq7jAArRVzTOcUM5gHeBOwMGB2Rwfp0DE9Tv/VM/Qa6aPB7ChOlBBRfzk6Sr3nB1ZwwfRdd2oXTyX8BXYB2WIX+BvYHjg7dj55quK894Xv7vcE7wPgFcmRruhIJ3tV1DDfecr8AkkX3g/r2uzSRPoEufNQUh0rAHR6RM5dr4yZRu7jZIa+ZdUP5r5IO15hb+nmqmjbW0aZejjvnp1vQnathN4zBbRz81qptJ2vcncNIhN+ZWM1qFBKeKXSRCyKqZIujxSqI9EEEQFJGUCkMjQekgsLZEaemv/5/X9lpjQACxwtwUg77+fOcyKScROk+gxVShZjaT013/qE+jiaokiT9VT8IsiNC0zFj64Yebw4xHa3kf8csmc848WuPG6wbwhJ+D6aLLmN+f7ywv0/s5iQ0xi3OzpU+7KSZrD1WYqQTMA0B07kLK3KO5eJSwS2rbSN6BHaukNOOxclt07wFz5EWmWOGBLFec83NHH5nXSvZOdVyc85nM4wPNgNMilR8BdICSPqc0o3ooFZl8Cqd7BBqX3OJSuX7oqbQowDhyfMOQIVjq8Eyx3zhgIltKCRTH9EYsFhHoUPedaCsRrXiSK6uEfwjiRquuuqy4KajyzrNKI7a5SVRpHFe2SjLEMCGw99zgbG7b2GrPZZ9jtvJH2QcM8dVwl8RWqHCPBjSBVsMR4+tvUXQRhAedxUJJiVZ0ZRwmoccbJszVqf70cHzZGjthIObxZANk7QXCbrkJuXnsyaS2N/pD9lIDUb5KkSoerzyfkeEunNWhWKPbnNOVU60yinAoVtUtP/mL1gR3QNzOQc6TXzznIZP78vn1W6UcSb6tgYwhfUZDopYLZzkrlUagoGjQt4eAfhfe5wAtbuhm3aRkWalwdTQnhBK5VXR4yoO4sb4CFw8uSiyg4OrdESTx6/m8YlIwNt7gXQr9lOa8clMtyAGBMkI7kUVQX0oKdb8gRQTpnhjlr4q4wl1ugeIWaRlsijvX6/3Z9boBBFDOT/a79sRSqLkrp2Xch5PbtY38R1BzrDytin0pmB5BR9Wkw7PGedlNgO13gZwt7K5L0/s6tmKzqCyapnxqjtdd7EttDWodeSnOXPsVpvxVTbaTuQjHrDSKTFeAHAldwSYFbpC7Rt7UW0K/RuDnJaHthGlTOHizh+ga/rzGygBrJddizjpnCZMVHZV4ykf4vdAkxzT28ERSLk0/38LBNkv3JfjHE0jn/XTTzQh3BE8jn8N2DKicPgYTGs6PcVfYhf6KnznXBnGAEenVN0Bn+WTCXvM20uxLUZk4B0A/qnI+ysWy7E0vCG07oqUKrxg1AA6Q0jvssfrJOc6SDC+2tmuaPByb3rmy1B6Y8UqUEbuvUZKJPQ7BqyZxs/N5VlQWKzSD8JXj4dFlFkxvDToGpyNENu9cQsD7uDKoQfpPS+jfUv7ErPCw3f3Kox3XgOJ1CSaNLcHRPGI+wmSQGguFfmjijmwU4zUFrH0DR2T8EXNU65EuV+lhQrP1F1W0JSWHu9xVgAP5TAGpZ/NMjhWhJAGjtuXvclsNpafGiE4+Sq3Pj+gdmi8DlzWESIXmkzKzEgMu72L77mH2mWJ2EDDPypHkJIYWl++7O5UAKvFmYKSY+xH/mQ4mFm8vfikyy1WdDl6sSdA2oTfHk7xzXB2tL/vKB7jxTBQqZca/BhnvPaYqwj4fwK1Y7DtLVTQ/JOH6ecbgeBJE+rMEm4dzcnk2tjfCgFtU1Hvvl2xoD+iXvmAHMnBG073+hZ4+PuJ1Ni0zLhbL7IPNvQrkw/dhiUKG+LS3EO4kYiAITu1O9e+u2geGe7zH/JNnF6fMa2qVPErc5D6IbJd5uUppYf2RUVvOm7SaVgb5LDBp5UhZqOARku+CvmqDlX2AWur6KZkRDm8QpUKgZIBIL/uC9f/5QnO+ELO+d8dFx7bOg/4lBsCvyFJ32gjkPdbBEZo8bzd/g2C4LKJv8hUwFQNPNaoKxFDS75hrTY6tCVhH+QEBri3i3KBueRpmdkAJkJip4Zqubmj+EhDPPWxqmwRjmalHHdPf19clha5U/R26WRUadJN7fI2txkrRchYj0im2Qh6hpm2cvaYiSSqq3S+6BxbzkhYZ5IQqLqbZlQjRMpFk6LDLU5LbOLh91I8gNsfj2tNTyVwSeViAazxeGEmMYWzNq+y+s6KCrmdymEIlUTLz4K2azFfZz+ayyCCpslPdHYRa1HRO8HmzhL5LNC/9AxU/FRfI/aXeQ3eAwRq5BzqGqudwiQDVj7fc5EA9JVTnSxsdevhDK0QJ63eIO/iPJq65FhFhUIS0lIskuCFEq694ueDY8C89vRpJLvFKb7JvQYJVXe6QSV0yrG5AO3bxDk6tCgK8r57arZjasdfQ1vyDmgMOkNOUjTx3C67qC/V5PuaB2kDAAXmSqarUTyaKZvdg2XL+O0sA/u7EIFgtu9/IitbddZNFc89IXzbIc6kEL1EYyonbcPADVBsdt3piIhwLSqMgw93cIa9ZrcOl0ffMMncHLKp/9PcMPMfiTKmsuuZospo/+xpYV2n8R94ey3J0SH0lFRI6ZPSZp4uhM9FjUAwTXqWbnRIFSSJJbnL6cptL4EJU2nUqq+YSrUE9FEvJoCqN91Y4HjFv1TT
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:20Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d37d-19d8-4cf4-843d-4117950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:21.000Z",
"modified": "2016-04-28T09:10:21.000Z",
"description": ".js sample",
"pattern": "[file:name = '0051812_002699.js' AND file:hashes.SHA1 = 'c8c82a0f384c20875fef659251134e96ea668322']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:21Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d37e-04f0-4ef6-93a0-4279950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:22.000Z",
"modified": "2016-04-28T09:10:22.000Z",
"description": ".js sample",
"pattern": "[file:name = '0051812_002699.js' AND file:hashes.SHA256 = '7f4c78dbb4799e959da76868eb9b5c5c9deb7e33399aaa1790d68f7c430af745']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:22Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d37f-9ff0-4121-aa6d-48a5950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:23.000Z",
"modified": "2016-04-28T09:10:23.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAExJnEgNlZThoAsAADEYAAAgABwAYTg1MWVkOTQ1OTMyYThiY2Y3NjhjMDVhZDA0YzM1YjZVVAkAA3/TIVd/0yFXdXgLAAEEIQAAAAQhAAAAae2SZgB7eZTdCTmCNglTkkIAdxdBeg3ZPczhW3BvFBGpsWfM1VYV3QMJtMq+M8k92HsgJ4ZM9TNhdZR9Z5q7I1jdglIBdl3LNx3D7powDnKu7o6BdGqVWmw8f93N+wHj2Ue6YJ1eNZTXN85PEujCjDL4wr5MOYZoN9iXsbUCHVR/pJXxhTmzV14+0O1i0Tii0E8oWucPmk2iJRqco6ZbLUuTNuWl4e9Nf2CMsZk+Lug2nBMGAvZJ/Wo6NxqK3SuOwg74hDWNHdBCGVq740Z9X/SNDOLheSvZRkoURub2WJ4dy4MJYPnYaGZBqeVa0V5lVaJE6taBoVd7S6M7VujLy/Dciw0EMgr5wDbenAXzldTzZV9HyM+RRarVMbZyHTd6O6HoM2fNOZ4VzA1nblOecAV5YSV9L9ozqSztHzGe0YmfhJy3tI2jsn1lTxKufbhRHwkJc8xaEoLRnc+vDG5m9kUQw9YmC1W5lSqoigh3sRq/f2+6UNruAESxEI9jzTsTLhGwnxKJ8qJDXVMkZN2lMrtBmOv2ax/s+yKyBAwpFADywIec0PfqRXHaEQQCqrXZ9+fJ2f8bg027rbmiB7VguEiypS0vWVZgj5oQQuMg/iQlnw78KbmqwRbJa72dsiGsj8zuIKP+DJLgtPMboV3FeOZI7gFNyxI2IusGkhlXgzBMux4bNeeol9csOJE2vJYMUxlFqk8jm+o3DjRiRJZ30uCu493wFw/CQRpWoikKQ2BrZ3Fy3wKCdIYvN0smUUGb50dXSEA4mRFmFKBqa5hvzwsXtJyYUHQXJXJOaji9S1qkFyy2ScTebwpcvwvMqeM10I8WVxdjh4XZOXjUDpTce+b/ScSG4bAPjDDCjX4RNuX/76WEa7nUsKrIScjhouLVX0KvoLga1QPBYxGb7DFTT8xfmoRCeeOgmY0MbAAwnMxUc9VjZRzvvCSuw1HOpXpfCactxXUb5LpQZ26YSOp99yXlKOEhudzb5tajZLlZGyAwXxZbSBFPc1wGrKVPmzzzLRqpO47vHRR6nZ9DxZrRpZrvSgNbpErxdTehanz1+aUMeDCNMg/k0M8mYGyWmRI417Z6MN31025OtLEHUujHe0XwgWKwr2CdOehBTmq08nD4bx3DV8QZ1t+XYHEHFQze1UbuyJB6AtQeT7Frv4fz4XD4TFq2GRwlCE1a+ibLGy1bbTsKndWCCUpxPj1lyORYm8fu+Lwl28khxmgdafn1waR4zCYbOFUAs58lsJFXDvNXOBHj58FH6MaHgAhijL5fSs5vUZEwSb0C8p3q0rfkT4fGfwEJl6WCVQtaERVVVdQRoveKhgq5HX/S1MSfSaGC7Bm8lXquWOVM/U3u/Yscg190L/DVYRhpOHae1Cc+y7p3NI7/N5shqJHFUnzDzwguWKTfaEqBzOkscZ/5kT9cDEn/szG6cL3dAd0fRrgsCFRw2E/sdWvfyAdVs72WBTTbB6V5/3smUgUSceVsKIa/Rj3ELb2DEEaaAZgHp99XiQdFeVzUtrKjZld7xzGhhBg0W/Xy0lherbHnSE5gnpGEkMZZb+ngbWKXeUtEx1K4agnbfVMxOZt5Pbwp4HhuvBj3fhd39NHonU1HzcsKW0EkthcTGKEYPNfAZ+6bOFesPDK1sS7FkaxqcciOx22ivrDqYU8hN2PBGRc9l04DPA6nTr+EdeIo8k9xy/hSOHEnaJufa44yF0gHqpE59yJLWORYcOJFv2J7T4pkakKBK/LgEseGfx2b9j8651nQ5NrmZuuyAlMYCKP+uiuoD+vsKrLVknQclG7VFGF+ive8ryUz6ZB6OYJ0MfEhZgCO7CkyIFsbwgWJzNIQ0uTHx+i88CsH9FACrZsVNtZPDsxQBp4KXmR+8Y1U09V2za/04FLP5H3f0y1vDgYBeZ1RDUfNfDFgH4wKCkQO8dfeIi8olUwB6CQa4n0S03zw6rGbPhhtOjc5J5LdthG1ceDQHvZdeZxeSLCcXP75dVp7SrTsd2TIeJGjgWUw2LZyofKw4qEpYXnDtiwNd1QBXhWqI+NTTzajG4e6pzoFsqyITQsrqx0lVCG7CqQhCId0Lz58IThWFTKIAIfakN2/5sCIoVlUx4Gcr4G1UYq2etv3ty1ehw1f9wFqCBEbRWu1nKmTESMhhc2JBxJwm3suZmQP0d/H9lgIDa4CLElZqQPGGDy+w9ejiocmQuFL90likIYVfgBpSJjvwoDqmdURHobtklxbjh5Knq+ymh3ZuNluDKSS0wPq6PwUx6X5IhIef8fZ33/lN1Vne0jHVRuuGTGkpJJL2mea5m1+7IlnZtnQfHaSYvch6dcbL7eu9/uWVxr1gwBh5IBrjprCJuZwEumbkl3vETez8pxR/l6AaNif8xE9F7itUo5+g3D4JOlNVvViVHfgqjnbEWxuATKaNAg34A441L0nO2ha0c/G96loTAOM115X/krS2s8Fsb1WoRCCxy0TOIHTlne6FQBNvCwX+HWABNa7hn58JqYCV6iA6D33Cl7wzTZkT0ooQ7oyp8Jc1BZAhi3otBS0BRjYQbkrwfLMuJcbDU03ZzHarLrZfQDxMC1yhS+jXwiTA1g2QaWL+qW1GRDd/m4/mPic0Hn7+lKjNRy/AZOSQxzsTtL6W1Lx+DaqKBWwme7CjzN4We/S7noB95eylQHRjsfl6ZyXr70cnG//r4tvH3GtIJP4/2fl68LHKE4Kvf8WP7kDeJSMWeE4qDCAuCWxmOiyY1DqWGyk4FV8EEB886OQJZ1y0KDEJd0ZxrKutpXu51CaFNlsG5XZ17W362ybbvscXCB5wOIh7mGIdP8T7ICpLuvHpwM8y5f2uRz7Zlqem3PYPbvVbdzuJ+iNzEqhyjQvdQKc5tPiaxMsmmOgZU/kh6A/XMg8TpCHqqyxQVUtOtHU/UPaN+r6Da3xcR1CrepVgvaJG945zQXccMY9HL647k8xtgJy+P7SedO8Rsl3yK0s2RudjrygvJP1z099n2Ak6Fy0ET5NfNzc7VNrP/jTiYbwMzeBVUktGDmR2zigmqsAaDbITsmu+Wsf3jJJQ5bN4jB7mgR0OFUz9ss/GWkaCiHda+EifaTBveFaHcQA6pyRm+ypgVfPCZpG3kAmeGN4axglilMPWHO3u/H7NBZxPk/pZlZffdwMx9xGuYidP4c0pL3zkThBQ+6oWTf5tw3wKum9m+YnGBa80wD3NI5Ak2ZqgUHnZvyH88ghx17J4UAQZ8RK14fVWIP4vTS7iXlawS0U78gmairB91UYhW7JEUGGlYIoAkZA0SnV2KKXsIRr+459sOvaCtDPvOQ8vhmynQwlxbYNHwS27K+B8GPYeLjVmZOajImUZ/A/AGJ64wIzXr05TUPM2kwIrHShaQtSZmkjxCt3Sp5GK9FU2QlsLt1foeR1p4MU1kbgij5X4C439OHqI9Sl6ibvl5Ycv7kGI/5PgJw+mpszB+fVwTQsPuMC5BPVz0i3wlQ/M29MoOmClWfRbSYRweThrTYk6LRHFrRyaj/LlWevw0KE/MxoUvH5DIqnN3Lb0+uQDD2bc+oJyAOaB5rwlJam0SxLRUG367DgzmDMYHPfMB/B5dzfI+UJ236FGqrm9neZ9MJWzAKOv8JA7KilDq+jggDwqMeXaKk1Pyc09efiyQmgPQX4xP7eQOnWgl4zPmiDhwM3tAhITSbH2NGFGcnlAghxNAFr/892ZvOXtJyJdRConZL+rDLHGOZYuEvc4ewPNbhmrz+kOy8aKyQUds8RC90ejjQuHdOQ6FDXaxHy4t3p8EbGT5tj2XTQOJRUb+90tQP2XRc3/j5Co0dd9E99lXKR60TqyUTQTyZVWi4ahifs+FhC/lcC+f9S2RcvZHZukZKrLhf21l5A2gehbzNBkCsLwiEiCSKhaJ0R5U2JpPdE/AYNMV6Isp
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:23Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d37f-0cf4-4feb-a615-4e7f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:23.000Z",
"modified": "2016-04-28T09:10:23.000Z",
"description": ".js sample",
"pattern": "[file:name = '0052610_002572.js' AND file:hashes.SHA1 = 'a6b0c19994e7917551f1b9e16766d31e8d9d8ccf']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:23Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d380-7030-4ded-9dac-4c36950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:24.000Z",
"modified": "2016-04-28T09:10:24.000Z",
"description": ".js sample",
"pattern": "[file:name = '0052610_002572.js' AND file:hashes.SHA256 = 'f2c2e7e56e4e04346d6bc330ca23504ae542a29c4dab3cc3c8049cbe8bf407b3']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:24Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d381-1d44-41c4-a495-4565950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:25.000Z",
"modified": "2016-04-28T09:10:25.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAE1JnEjtW061egsAAOIXAAAgABwAOGMwYmNlMDdjNTJmM2FjMmVhMGU1YmVkYjk0NjljZDRVVAkAA4HTIVeB0yFXdXgLAAEEIQAAAAQhAAAAUFOiYr5bbzljfaobFiWeymFI/GzjkZZdWyQ7NqWiqVoApJ70x/QSn2J7PIC2c2LGwM4rRLTLSSAABtvUryz5TCC5ouZTKpEsU0VHf9BWaIUcs4WLyOLnUFDeZcDA7TVEGsZS3eecJww07o5RWcuo8Z5kh2bwJ1ExrENUvy6PSjVW+fUNXmOwuXoK2txeRwxUJJK7Yco/F27Xbre4n1HnABWCuA18lbD5F71aOhlxxoJySaxxjrI/GwdfTSs+18bY4Ap6pgA83TCtKgg36S4zb9KftsQnED1YCYXKdtNUi2e5CQdFNRuinpOqeQ+OeAML70WfTRe54b6FTIfMnY0nBEqtlmclYAyd7SiIlb16yCuowwHyEp99bly/5qVlRS2gzglEgmKEZXgs+ctnmSH293cjved0C/nvky1dHcTh6uidrqLVCjPemfjEZxrhv0k5X86bGmk+7ffj2xq6AbQwIymHo/SSBtSZgFtWWlTcnmKm1U0djgJBNquTdRvEW3kCBMx82LdkU4+ghHqvdFq0+E0QIxryMx7CfpcbcQ6N2IRIWWafiWRLWmOlSZc44mfakoeN3DzDOhJwc6vcSFAJmE9Hzihf5DDwdbfvDG1MoZ/eC+KtD4YhFu8JWgyB4M0PQ/RzDnW8B+xhqPS1/EoqQqyhqQYWGgQ14EaMlgUDNtCfJU+app8HRkukHA/Pop061NdebVx1L8BlWbwB5JLWZpYvfX6lPyWNuIh/54tGO48OtcWlQ2i5Vb3i868bT8xPl3xk8IeGI6KAm3U7blOxOEi++PbHw5fez6OjqEnVCzNNtlJusYcr6RuTyFJGb5L3uhCeH1cYmArbWe10F52xuID8UygXYQS/S2WHVFEH+6/fS/RiUct/zY1oY4YFfXYCsLp6DlmWbpTeYZjzZBuC3j1nZhoc54FB7cXDPkWZ1VEY0sJTeRt6OB3OrgUgiBU+xmHrFXyvjijo4tBIdS+eFHb5t+4QUDC6kNP9OnGHv4S4gpL1wsUAIWa2iIv9oEl6Rs6XKRQ9pn4ebjJ93hPD+iuLJynwo/0rIvEqoMIpibm6iVBY5ORO8NS5vcGNeClZ2VpvwGhNHl46IM+SRF4r2ncbP+vFbJffnwBbd11Z+92GlFzYqP8/SUYY48HDe1Etatcc0RyTZCQW7v64hoVcDhXLGfqTuuiHA/WkhGlqUXXObztgn/yXzNW2ATGAl1G74iJSsFnojO6xrLq3KV5ZN9LVHEIsuiFO7V0FTtsO1cf7TDGG6LhCL3vwwLxXRatMB5ZjmK1VV0GEiBnsiVUOp9RSr+TQDcZifeC5JNmMu8W9WD9LAkdK/muYUBlsvdBqTXtifHg81W22V5M6g+mEgAtO/ITm8P4bifkD+qfBt6Y3+S8QmpuEIi5Xs1+PLh2jkuTtv2A+17z3Oco7dG8nRH+bSJisSZoYG74jB6OT7oWUCdGwZoS6QcDjGR92k52khXSlcBHidZagZOk4GndVUgLi4kFdopSvJTtYBMwGn+o3qMZJaFnkv2rbA5O0LoMoag4E/doulk7ZUpU/OHGf41Y+uNQZMVHMIo/m2KnXJTrMPppObuRcu2mYA8956lI/SV3idyLoMjgdv3Bzi0FZZL9a7YIbeaBvrK0KHkOSsdobhUHDHLiICyLZKXApO93MBC/8M7L7pRSQ28yMCgZmxU5a+5HHJblbi3s8LcRq3aFEKR0aKlNdEIYtC6sGO+JH3hQ9OwX9vngJcLMfAX387msMfuMtfE7XFPKj7bPnI5LSSTYKnpfy9LScjz6HWe+DwWtHDcFZGMGF8gpqDp3PZw3Qph5W4BPJIIv/OHeMxg+pbSZxZiY8Kks0//ZSXczMoDY1pNED5AB1rKEmzjbLhiAyftemxLCAD6i4yT/xFfpF9llsRa/2Z5NCX1Jtdn7fSs7gaMCX1L/nfQC0y4FOB0J+f91v1RtNoeIiNe5736CZFmtmuNHs6EoC86FqrL/nWA1jAwguzg5IlBU9wmJ+rS0Me8QHK9UvTO2RuTF68ekqQoYmMQYQYRfr7viHlins6cZSgt1uY+C95Orn3E3cX166VN3v1Opo0KxEMx8ICAPECTmcG+/TFvmoAQY8BD3d1QuXAao34GOBcnq7LwCmpdQvJfPKMP1G5CymbErYbZqQKTa73q8rqoBLPiuQlOcQ/JHiPc700RBluTEEkMQCqkDCpMzYigL+0cNNxa/bMMSsW3UI3iFGxJE3mawFN27R3UbvcyenJm6FDTZMAj+0o7o7oGUCIn4ZPKPNMManN8X6F+qxQSUCLBMiljUtF2Dhd72T+CqWF0AbH6mhyz8T5wR246+p9NR4Nj5NLjzJLr22Rif0YSJI3aLoFWRvfm3ewS8gl5oXhQ7pTrUQsqbXR6JQOw8JZe6oYJddNbvGMBFAZejYLid8OlPPZ0ZQWKTiY6M5+J2A/0TzvHF5H2cfQpB6PrJEICZypjR2/eiAxRxwdOmRPq+KxyoOESgsNdmg5udP0diEVaaSukWAy/i7XaEfbShHrpHB5L2mYQ+/10L1s/0TA/QOiBQKIDRJGULR4nMjmjj7Vxq4IZovGNLNFtI828eKTHshPXm/pGWeYvCPqTN6IDBy8PLQmRZrc4/UgYT2enalWymdK46wDfugGtxDczbUil5clej43SuM3i5lQ3SEJYJiO59SHD1rlYuFhN4YfB7DouRvpKia9nAZiYJY/6t6ipkftiT2zu+rwDTDJxitxk1C6KINZWoDpMbLZ3OdFOArz9KBaZGFT5B+fDDMT+UFtsxzwTpb6BihOJbJGWHCdo86/MK9HgAOyG4BPV1kDW09Jp0vkjIIABf15wF6wvAYWXX/xLkwk0I6foA/adUhwcAvz/EcD7zYZc/fecTy+e3ZDzOzl4uNlCZISwgNn+g9cjEjGlhbZf/KrclnJkL/2diSbnKQZdDCBHp9K0hloPP+JYgclCz7u9QiwCn/1Lz4H3SPX+fS0Ji1i68Wmsm6BrhVZIlEB3VhWfzCMb65C6iaWnizXsq2PQgsqjFZWOfglrYgEG9B/ATuKWPSHUdNnVzJ4EPAazN43xeBA82Gzuyb87Rn2+ZSwWr2Mn04bl26AYnbR8HvfxyVF7GC1/YCRQpjtykcL4RcfJjFq1npGsYstCoXdfqBHWyuYHK8yOUD2sWqcIGk1mU0aEWDxRlqV1G8cbK5IL87JfamQsCi4QjpXRzAfEi4Ori1xuTGS++1fuKsJIg0FhbcX3bu3CGdD/9wNNEyQJSqj/6s/45JnIEktsmY5el9Fe1fFdhfOvHX/EZy9ac099BlS0gSRIWrG/sWZ5Dpw4wDokZlSxwyfrog65bDEc+yVIKNcpdjEyBWEenqnoHYvGY6W5+ziM3oDl5dnaInyONj2uKJOzAPPW1ok3B0aVflx+bmiDvkvnB6VaJvcMOuq+wodL1YVU6ONBXVkr4kSkCHYy3appOTXsKkyEWUv2nOcIUwa6bOTt3TvePmgCvVKJoIVbXJStozk1TtbDsKzQl780fsWvvKB7aQ4YDcwsggyk1yDXEtkBlk6mjDI4MRxVEDhleC97uZ1TYeSyfV8mHRO7DlLqhKpagsCC4X8tK3DCZtX3MxJuQBwDUurbsylWEN6Ay3VePvyJV+4ktYABsmi58DJkOyq6wyqfOOxtPtW/zvHG5Q+l8p9ptnpCR9CkLXpmbNyQzIUNci3RmWuYevC7hhx1TLwDTdfjuoPpt5Q4X7F6KezFyxMmSmFqTeODlglN4a8wIqXIHlYl4x60QpVuPPgZ5zJk0i3St7dzV3BLM0C0dGZDRAjrP2htGpD1tJmrBmqfCOxccWhxo67nOsIn4CyIxht/7Htc+EcIfqL6ePULg7sMEJXe1/IbzRuzzmr/qsVuQJcrBOjsFTWMYEK88rmRrzYfZdKQiUtV
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:25Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d382-0388-4df9-acc6-4d30950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:26.000Z",
"modified": "2016-04-28T09:10:26.000Z",
"description": ".js sample",
"pattern": "[file:name = '0054211_001113.js' AND file:hashes.SHA1 = 'f5f1d0d3369fd071e6e4eb39360a79f5767fd52d']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:26Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d383-d71c-4401-9c8e-4871950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:27.000Z",
"modified": "2016-04-28T09:10:27.000Z",
"description": ".js sample",
"pattern": "[file:name = '0054211_001113.js' AND file:hashes.SHA256 = 'd8d3cbe26a34d4592c4b9ea572bb130b3ab4f2b396702dac9188f773544471fd']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:27Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d384-6aa4-4b45-b0fb-4a2c950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:28.000Z",
"modified": "2016-04-28T09:10:28.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAE5JnEgqtn8qgwsAABQYAAAgABwAMWZlMjA5MDIwNzQyZDkxOTQ3NDkzMDRkYzljODVlN2RVVAkAA4TTIVeE0yFXdXgLAAEEIQAAAAQhAAAAhw4QFW+nGFoqW59cpFzbUhJsc3nTUw3H1u2Tv/Oop/CMbSRUkcWpK0dXc9Siv96R+5PHVFhYZV/65/iQXNF3yDzxK3aPg4+ly0hJ6ERdxJpXgY9gBlNJAKs3HYMqHrfZc8m2BDz8b2HlQw5tQU+PNtUeq4NJblwT5SArtY2k8aaP8ukWBrEnrYNo8U/SeMQkYl0W9JqiZYptIvAnh0FqVrl4GRE0NGhuDBBayQRlfRs763O4LJHC4wbyPOIi/XvLrazj7j7uFvjDsvNkAhWUa8w/SpdpuFZvTSuA+C10HAxaaNDcsskEzS78fd4shWkaTcp0D4RioH4wO+cmIwwbRo37KEHE9V2V3hyFlJ9PXtMT5yOx7GYWX5Mj/eZvY3BTcX+e5u7A50es7EYhjzRffZOVt2fFVu2xE/sC8ahNBIp/wD6gpr/Sg3ejiR79bo43dxE2vJqexp7505eIBxhDYKvuLr0V6fjTFDZT+YuS68iFqexI8m+X4WqzFwoN3KxEcN9vVS/ExYL9Bi9xP28nrTyHD5CnInb1tdmgwLQJ2lp6tzuYgCEQZDZc7W3tcEuoxvql9a+/uV3sKYAB9JQtvzR26ejGsYRkiv9hjg8JXApC6/lUp2/8fb1HV6YhdgBQEJSZrCV9jg4fqAmlifbdbpTwIdSOtF2ZAt/Eik0yRK8h7kUQbg4WltPJSfTTJMUey0tHax4v784ajpEQxQ3Q+Pq6G048qekZaLxvrT8NtdjSYdmSS9c39D5S1JHJW1TphFoDGc3UPVjQxbwABq7MuzEMfLbCjrXdGOZNn3kLORQqU8UcMBAL2oAxJX8NKmOlU/W+MMpfB7r5z0AoFC5BFAdBlbcXkAnAHtXg0dwrUEmc+vU8OKJAv5OImJZvam2b+eefKjdeMDcxgngatQhkAqchKPhRYNZ75aBjKh2xqlmiGyZLi8MSURkwgcFEuqUZx5FRxQOCap2yCcgsJu/c4zIZ7BLcIKuz5H8G1NFk7ubNP1UPAi5whhsy/RogX0IRAfV4WGwpv3NFUIcZV91Ecj5f9nBoxK2h0f9QaT0BDijVkx8ngfFsIsK7aBa0W+lYHLB1UOMiMtDEWhKpm167MGnrBa2nu1CEgPBiQ9nxJdnfr/iuCqPjuYqboGQ3IRj3+PjMMdEZH2Sz/UKlWs6o5eRzNT2FGNaBGZQIG2X84+gyAcKgoDuC+dvti1c0NyHOfyAlZzp1sep+uOC26Lc34FzdVQmE0yEQbo6dP25iJN694OSJH24Kl10ncgNp8iizMfRkr8k8v/Ck7B3JKDhbLauaJBWTq8Ws7++nqimLqgIFzxXoLmPjEH3yLRiZveJqGa+nIs2mvpH9tIodbPY3X7AcudYYhivcztKHakb7YAZPanfTJd6vSxXZODZoZA5PfwALsyFoevMQYjngAcH8OF7h3wmujhrj1Py4U2LYRZe8A8+ZNJ43dm2+osDt/TSHDx2giymWHjdR6Io7PZF2kPYmNFC05801Ro4MtT1E2i9XHNq4R0P9GE4AAts6wO/S88YRaHLDU0x5IwRhdg0mYt7HApUeY10xG7ENLcHCZ4Q6JNHaJGbbbFhM+lNYbbZKkJQYAIvOYvVClgtTwGhjOL+tRTI8cxsiSROLiwmkdBhLWIGcHc9gj1Kz+5rRwclgNLFibjE8PtqV2dnx9EJxqR65+KVduEfQQZmDoOQK3LJcvarLJQaWbqGC6bN7abwklRt8Vgdk8du2//8ZAAMFazBf2dtUn9JjpzFh8B3oOuBMHTuvtjHvFfhAps2ywEb4F1HtYTDcVGS2o2EVCSarsP8p7WsPoYVHY8rNpYbDPDQlgTFs2C/SY5XBLYi1UAFJ2Kphll7nSAb+2yi81bGwB8xhBvZ0PsdjRs/uWW9Op4HWKrv8k4SN/kV4R22CdYcEBosZ9GiXi0rOHbg8h9PdvSNBwQhMU+QY78/6WgbFADNw0zKT76HvfI3ecRnLDNP4vCdTOzOJ5eYE08Jp7HubtIFVRGFlMClbhh2baSBFNM8TBAalU8bj08HNYpIxVmfQ4QmkcmKtPPsjZ6H5VI+cbSXgC2wzxG7RCxxlU/mfnWi6FPXX4DLCg3R8CMhw60tQlUnyf0uye0X4Jf3pL2fKdWcYhyUEOD2Ioe5ah1TN/l3by5FkoMKNKMFKBYb4eluJ/XwAREjlhY15XXxMapToaJi4ScJWzX+uOErVpdTUwBOxQAtK6asvlNJIuc6r+9SuyxnqhLTUkNefEQdXBtuwy6cKW+ZC9KCBvpRXnl1WycLIi/8HCVb9sxdpCuDCCZtgCPfRXvKJW0P4+drNl3o9cwlMCJB98QV9Eb/mf+x3fEJZq50fQj9EG+995gKhUktmWHTiVJJDZlaCbzd+tv/OllAT++k6eD5z8rTcEW85/OcFeK/1+u5mGjSJV3yt0fNFNV1VbdNJiX7DCC5VewzxVBz67PF2r4f+aao9rPEqYhtq4RIGXK7gfwG33KthT5rF7tkJBFtCBKzHulZXgKDHB2QeAIPidwoLhquP2nHbPV2Bg5LH2XiuQnkh56E2cyi7nS+wl9V2sX6B6GZ4BRz9Rn7mUjRB2es42ngoCApIYtJUAza/06NCXQpquxssUQTKod8SfwYSA0VlpMKl/cIlsK/BgKe/nG2qZjH2SPVQ6s4ltmUfdKw2OeC6d17FDKv5tDn2fGspmvxuW1lMUfJNPrD2ZMkYYTqjBQp99OHtjUjZBnBI1k5XOhT/zJqkdg/SZd2FRVcRGdBH7jDEKkwKrVwkhhFRpYSqti9d3bBSxcfRnEAqOUTsTN0D7+znL2cet9P8L7YCTFg1KRpg4eSz81sknrkt3jFcZTBcU1JKgSSoRFVeMLs/3J1aApDAWP+IHqywZOy0W3sYZZYdO8YxouxhdCtebc6LmygA3p4nMFE3KfAPRlD/PMDvACNqs2FHg0p+iAc7YKQL8faADdCU64q/79MABJalC8vvNv5Tu1zPV3fQBgKVXulO3P0jw0GeAMmcqYA4YjTbVjJXkEKsl8LlFuQnEu0bUVLEKxtcVhIHexUrFaKNNbO+4WCf3nHNJbVn2RABvj2QCDV9hgdXQzNsUJ415eD6MqYeKwXJ84CBSbfv7jPSgkKwDuZ8WKrwq+ki60UDHiA1ixPM1h8cOfxfcIzIban0HGa+Ze4g3CcG5uprk8SydLrstmTOgGGNtjKU/ZPknW0C+QAx72at6pjQLHly00gaIu/Xq2n1UfZ1Bl6Gbg1eZS964iqccfxcFSrPo9tYSRZZo4YNT0/QouQMLaFvGXB9qr2q9wQCzmc4qDWRBGhZO2njSIivcO5Y000UxfgzGBgqAc1nQUX08+e5O7m4oBpoo+hFr8ktQ49j/uOvXDVIybOdiSyTgpCNTLsJfvJGsv97hMXV3jk6CsUl2Pak5C1o6vlZ4nwvfSOZA0yETC3YKnymUWjlwiEBiQ0MR9k/b5JmNbB7yhAYWcEWSd2Nnb7IdV0bC5bhK8y0oTGWj+zT2A/iZLdgt3eWcjzTNOdb1XElyuzk75cABR93RNqd/GPuWrnviJERTwt2WC36NEhVpLnCL1KWAFpEB2zx2Gk7+WgXCtgaAQBqFRVdFYmgf72sMHNZXle4x69f74eh/so3eaxB6zZ1uQ4eujOJKFaSx8oTqpiYRI3Ury/gkg/LEcN2jkbyZDExzHkJDdfVL8EamrgfCHA2Tf2zKiwGrwRqBUosvM1UcG9Mv4018yyVlnHoT8cDTj1od+XNP4W6VnxV/ErQQSq5yL+Fb4ZiNSxbDS03nVlPJLNsLLLEZXGhgnXNMy/8JKZqZIMeExM9YMs4Mwe/um18PjLjF3S3RmFGFD7QD1ErWrJmoAwvSbCwXit4hAQLE8Ql1bkQsR0ThFc6iBbEXjDLuKveEaa32RNiL89r+k
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:28Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d384-c72c-4e0b-9f93-465f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:28.000Z",
"modified": "2016-04-28T09:10:28.000Z",
"description": ".js sample",
"pattern": "[file:name = '0061315_005449.js' AND file:hashes.SHA1 = 'ef6cb95b926d0fcfd6cc477f47d7659add7475ef']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:28Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d385-ced8-4127-8f0c-4c2f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:29.000Z",
"modified": "2016-04-28T09:10:29.000Z",
"description": ".js sample",
"pattern": "[file:name = '0061315_005449.js' AND file:hashes.SHA256 = '241e358cfefe6fbf867b20da703564541b32d85845f5569cd6d2c4894d31ff6d']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:29Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d386-74d8-40b5-b205-46af950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:30.000Z",
"modified": "2016-04-28T09:10:30.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAE9JnEjT9mU6mwsAAFwYAAAgABwAZWJlNTk5OTI3ODY5ZjBiYzhkMTE1YzA4MDI5ZTRmNjFVVAkAA4bTIVeG0yFXdXgLAAEEIQAAAAQhAAAAhw4QFW+nGFoqW56AwYGTqNLDnU/rWCHL1w7qZaFQW4ekQVQmMt9VomBjJaXDBKjtNwwr+bc2dERzaZL+ZamgW1ZoAwP1gGYw7sxGdEWc2/XUGCDkcSV9q+78Cs0pbFNnVZO0XFIo15c+jFfr0b91vHh7SGIewujK9Zo717kpQfGLYZd8fxAKb6RaokVNm55a23NfJkqbNXpsBtPvW1FEyQf4aBmFncXkAbAQcC5Z7pg4YTUccumkoxJ+RPrH/faxJOxG9WLkYsJhsR7MzcnyONqV44Oqes3sQAJE1SuYs8lIOy3tJnly89ZVr2n4KrNYH+UcZpQQJTHm+wyra98pW5LaN4lFLZ/E1q/+WkvWW+ZurD0FC73GiNcVhMGp1jWFsn2qCYbiXh6NlCynEWen+ykRIJYAXlrAND8PjyJ937PPge/KtUs1HTxKNHrQezBhlUlToLmhVZFtJbHGpARUh1P6+dYArMYOe32oqPi+9tfH1oFreDC3dFBJcY7E5okvUn8XOw8u1tbqoGjXLtaUx1mepveZzmfgIo8zFtkSA1E1FgDhLBmCWTK7TN17vhr1rTRT2zAFVkIX0Ulzs1lXOUrXY8GKXH5+rD28mqiEEaqf9tUUoVEa75E0Tz+ikrFWlHhktu7sS3gmpIroneh/gcPkJqwsxxexrY5uibbZuWzqOHxUwSR0VUGuirhIHdgaZlXkO0FoNx4KDbMt+p79aQnFeqaobS4950AfGoD8QjfOTy19laP9DoXo8bjfAjby7uvJTv20VAdyDtt+p8ncqVbwqxD/4JKLm+G60T0vd6dNR01aJIvpUqSIyk52F8EUNyjIe8U2w2kPu90X498XBFuKQ62W+PsLZKm/T2XRQaa+uDN+rVe2ZIBS44+S4z6nrbXYIPGwNct69hRagKCflzp9UwrbnUuf0UuwJuRxB4zc/cNrrK5WTOMnjvoN/VRrkT9PQ/nmbKw5s++Su+uRRNDSxsN7IlPnfUe8EHP5n1pY6NlzPkq1uByDwb5FdJ7V6SgrR+oTgQuuC6Lk1KFNWL8pI0Ybm/li34jiAMRMdv99bjJEdq6PVTAqmsax0JxKvqqplX8tcY50X0vL1eU5wXtX7CNIsqOUGpC8z7gxHecbOCVY8EFjUT/y9seR2rFr8KqfSq6ezOAYWNQWVoAokhHnvh2huiQLnvnW8dlFySDkn9p2tDgcT49r3nQXlmJLEw7GQcibeyr0sW3O09AOxNnel5jCcjoLym4d6etrq1IIGPS9L+oQUns8TDJtEmtJnYZzTDDK4PdafB5kI6zwH5+F4lh0mkORKxQ+8emaGqwEQ2fVKu65hE8CWYvP4S5j3YsYO8ge4X21evC/ZW9fxTONhLOLtGwvTVZIz03puj/JT4Ha0jsJqsDbZVsvkHOlXE1zD0b8gTxom4IMwX3EroKo/psM8ccS7r6+D/HaaXDe6CYnpjvEEtIN+6w/GqicQ2/dwDp/w2hp4qZ6rzgvVLETXqeR010S2ah2oEyGRgwGngz9f1aBLjNgDcRhUBkewMpnjjRIpOXMDbF4Ft2Rm2k7uP4opaARDB+YJPdKPP06Hc1f1oVNrWJWpVkgXn68ak98h5jBlHtn0Xme4nsNLhLGD0UKB1TGvlcoZl3detMt7ai5dHcbfjwOajUe7PQLuDDSNBcbB5Al4pMdHybkjqDmXoIL89yGpU7OkaiDEa806rA5rxwzzngP3amYff5tegzp5ea73pZOxUynFyXoSeK2JrZCoRb+cW5LvalqDw2/9HzWz9omZDmCmJasTM4L+mISrw6nGCtsmTnpOx4DiqldPC/90G4nm9IC3FqBJmL2cQ0uZkhVfNeVei/Q9dfJlD8ni9VQiYjimLEcyj6T6W9kw/kc1m1+Gc8lOvDXuAQ6++m8xa5G+Zn3y+ViyO+iKoOPFgcMOvuJp+z39AU+SzY55xWXUIcacfL/Y3/PTvAPc69b2CvXCyBWzFEA9FKScOmzEinmCt/WzVPpTYky//aCM09KJ6VGpfwYQINqsM47JWy15YjRdWOEUgf++XBmbVbhqkpnS0wQOvF40q1/4L9PQyHAkiqsSEiUzyn1gyXLG2MpwapwMR5t+5VLUGFDIG7Wj93JO4e2NwtMmfAEDSuKG1LcFx2uG5vY6X7RSFUiSv0L+bZtCdwilSJzObGoXP7TkAGBDFSwuqR8PAWPWqzWY/y0sZwDKxFt5szhqnEatoLKlCNRZLSpA0J/4jcfGWp74OMR24PlqNlYt3YLmBnN0Zdp8mkdRyK7ME1HrhIV4ZxVYUJstzFWQPaopkLIpcRN3i2sQgoWXF4utNXjXlvDsQo2TvBz/O+OG2vTPCRS9fRGfuzYlx+SIqqjmiltmS5sYZDA12ZFF3CSaTaXyQQx253r9kDqHUIwUTB4ci9YFkekRO+TikWE1XqWaTrC53kEsX+r/TYlaQPB7IwTbXsyeXSDPNaf5mL1Dd0djNi2Nrxlx2g+SOrh5tzmcGqTGRizkCIzxDlT0gu9O/G+owyYBiKoMJL3WB5nDQz0lhCgRu7at8n3+xkEUgqB8nO8mBrQ0NKm9ztQYd7mgE1tjcQR5Z+HnOc6oB/N16dNayYZrVxWaPJ4oIoksxLhBA8pRbDP3qeFZPkh+JvVfiZB6aV/pj5LVMs/2Ye5+jhierllQO1Ud5pcQA+U4Rp71lyuAW6zaj2g7A+qOUWqV1OilffDL8KHvQqYM+WmOK275Bck95vyUuiQh07UVeHRdXqhflpAdDrSS0zFaDv2KyKWW1IawVZgftXZksR0swOS/ZK/irAyX4LhChBoLyfTyNkSm24oAtGPKZNsfcM7fDMUvB5geZb7QTOeLGDTYdROzppQcuJTl+8duBf73iGnQUwZlu2tosZ6FQARblcFYh/LU3HrXCA1EY8LufELwI25TGHYQSJT2STK/XuVPVRcxssnrwLlOgKrk78usNqtjSnPJfwUnFDNeCwZFOG2ZiXHXK0dkZPH0iqiGAEG37LjD0G4Qw0geWrxM4dGf1cEAiUk477+fVqJEl7dlmjTqzpoOhHjXVVf3O5p29ePqZGNwidjCxhMRNO67QEAwtXBrQNd8HfXI83UyTvw1XYt4RSqk7ZbuhpIQTlZL+oIq1UAgjNUmL0ISqlb+tGQguqGNu517xnDRF9xcGwUXoUHWZg8eAFOghmnv1oYnE79G9LNy086TRaDfSL/ZVvKrHtSM3rMk/FWCb0YPEQqQiiJqoUwpLcrfxxf+H84m2k503fJJw5G7M9O9ibUOqbUXVOmW/OfyWKa3s8YD02bVZ6m7yalrKmNR19pgGVoq2b9ULWpNweLHwpZsLr9rDowQzm+LGxjMlW1xDjwdngnkRA7AvSOL58qtkVxMLaz/+ldms2Cy/VOeeJp/x+NW5mp8oLWNwkZsw4srAH1vP7Yw0brTJYMl5sLFXtSPovQNg+DxDxTZvboyWfKUkRGbWFbjbKsa6+h8Z+zaTCxCAQ3LBQ9qINcm8I/l+oAq2doTBtcmfM+TPqRhASOEO16EzS20N0/IsJGdMLTU/oSEzqSSCiUAeQGpSus42z5RBJwXvHlI4UYMO12EJO5bRfRzc2pbHK/SNRJrcbM7DMYtnT99FM+C1+/zPgft5zyiFjAe655+n/xmE496rF96UmaVg1mC9U3/LzBorB/i/RRrXB4kuAHkwiOcvvOwvQomxcyCrK+QY6exlSlsFtkSFAGPPrIS1214r03bpV/BSjXp/yMpdJ/5g6IV+wjEJDZOxfUfDQk2/tqt8WuXzLjILAQiOPfkp8qjZR4pVMUP7mwgzcOB8VsMc5S67DktT240DFTnHdC66EvJ2n/gytU1ZXEaSd/7FnPRFNhIyKGVV+O3NJaPgHK0l3OrnqKs2ZGj+jDw2uip7gMubostBIfTOmRz9eiwZ
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:30Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d387-034c-42ca-84f1-46b0950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:31.000Z",
"modified": "2016-04-28T09:10:31.000Z",
"description": ".js sample",
"pattern": "[file:name = '0061705_006774.js' AND file:hashes.SHA1 = 'aeb4459b694e20873c24640b3e7ddb85671a8aab']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:31Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d387-21f8-4ace-9340-4d84950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:31.000Z",
"modified": "2016-04-28T09:10:31.000Z",
"description": ".js sample",
"pattern": "[file:name = '0061705_006774.js' AND file:hashes.SHA256 = '7c2850c4e6f0d1219f313ae6895d2b6cd293284e2246377169059f886007c593']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:31Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d388-dd64-4a9c-9371-44f2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:32.000Z",
"modified": "2016-04-28T09:10:32.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAFBJnEiHiJ/9ggsAABAYAAAgABwANjQ0NDYwN2MwOTlkNTgyNTI5NDRkZjZiMWUxZDBkNTJVVAkAA4jTIVeI0yFXdXgLAAEEIQAAAAQhAAAAn4pdRjiKPyrXPLkNPZGRAFcXaF94fNqAMP/1PYOr3fnvqXe6b5QLHO6Y3HFqSR5QP5B8/8feIgKaDObvAAU/tfGEVLsMZnQRgyk6isdOWt1um36QD+dPKRrOlENVuqDtE7UiX2uNwdlnQDd+fCo43nu42dG3Q4iU8Fhv49XuLCufIaTOpZe9fBuRugDcUCnubYQ/JNQbJwJRvoPtObdmlwcFNcUUTcTjK9L9kxJEV5yPHFB5JskqP9446BKv1xZzDVwNedoaI/isFiN0F8eBKcDWIaSu+El0Vg/uKTqPms8Kx8OaNfR9YrapQewRNfVyYF9MzG5gv8exbJgiKHua+KrDkFjMA9L3w9qTlW4U9LQrYS9omWtehqhEn6UVfaW8psvMkMU4ie35W9NrmFPRgBUFC4dlFEJTxo0rl6raZ98gpryq8JonIRa12BWWdeYARifiz2BPIgAaC07Y64B2fpu8WdGJuhLY3nklSnBTbVaEpMjpYxAEsPpHMKQbXxpVisnd3hpy98dG0zgzfk9i7g87xuOwQqrsRYiBPGBf/dBm2MjeUbS4d2X1/VeV2hwANeoH84AFYNeLoT8331cq1Q4slNd9QkVglzXYiJpJYwqvftjuCwvOS7P7/LfGfSlarC5o1S/dqeoiVGc+K3VAUNzjZluaAklx1Q+b65MGmAwWhpGXgAnWEHEOUCdR+hI4FHA4TuUB1yDZ1uwYpfTEMW9rfp/igvpkFhvVQFP+WBeF7P1kdLKaIyfy1GYQQ8nm4tSq8EdFVQzPYN3kxYshpWeTnIWt2Pr3A62xIW5PY7iwNXTdjMuotEzOAGq8gw4tyEH8v8TPtgExrc9UHM3m2K3pji15/AyTWBrinxwPqEetuBf8Ino1N8IBO/h/LPKkBfbU20SvBXDxGa2ym0jtNIb4u8JiEPSe5pSzBOJP3DUlKCSRrh7KN+e4SQ0jMLaldXP+eqFgdv5gGYBrrDnt/kZK9LOJM1Z0YSFh40vEjKnJOMzWMf0/6vSqunCnEQvypGpOoGulSIx1jOXng7zbzKD0fGvKOKpFu1R1I6uBOTmSVKt1AJYr7u3ZlRhaC4ZxZIQwpRRLUBQmzexZjmcDpGG9QKAeWqv//3X5oJf2dTNaHt6Z9CiOC3hTdkWMEBHiyv4wz9vFGAT1T9AR/bDh6rMa6dDgjRWUNlHdwr2MRUDHPkxpIhdpA6hZvO30kVmG23huKsX/2sQMA3l9Mx5vYPMSzN0jq1d4YrNsaNAG1Vd+NgqpBgO7P/dFXmWAOJk0VIIj5NVKozFflw0/cxsJxZZG2w3gvIWpLF9TDkd5pLqA+uRU86xTV+7GWBpoJ/WPklopRh7/A8jmD4ra0NQdt5pOAm6nfvRLTjZ9vM6OiQwZTYQZ0GgQ6qsekuk6xJqatrM+uqRNE/4A2Pb7KiV3hv826uQZoD26QVRNEVYdSU4WlPrYU1ZcgZJb0UT7Q4lsJ7pqEg7CeS7W48/GkT2FRmqHn8cAOz4Oup8FeS7Zw64W6VYptqs9fBoc0OMVoBu9jDF7I2Ur98T7QbnblFijEkA5ZzwM8I87aIZU5kMzVXofrLyeqNKSF+TJI5hZgauG+iyG+mhzooJlNX9FsgrBsOLcCKD+l6vGkqXJfqupSlCWyEbNIxm56QL7Z2uLvt0DoD6TQU2Fa5cA1ODp6iQN8K7pPt1NoYOBzazon4n+KTBij+u4glm7MFWEZfUu/4yPt3MQtUZ23Wr62XUgJkbBVnbGrUft5nK8hxn48uoxk9qlY0jlZNKxMNFkuvdZSxjDSGb4vB5TmwWRlp0DGvHGJiwC1OhXg8mjLwCCATf+OCKkQkI3iSoU+N+MbFtQWXy414Pkq75r6o+o1yG3IW4zujExxUOPTAvzaH3uBwpb0ElwbyvKerDyFSplskQf9n0V1aEUOR+QmD7xvpLpWD+kUvJ8elLYgVMCDO3ZLBSdWWZunv1jKQ7N5jJkHngNiwJge5eFIvdMVDbloGTKh+6BtJ7MWON3A+jOr8kTCfHLCqlCDXIr4c3PsnqRG3p/z4LL1sWuyCDyT/4RKuEujzEqICPT6XURs7un+PD0WpobNGtXGP5SKqVYjpLNNPm70F8l2FZGLMqKv7y8gA8GUqiGdIeNnvGQw6EQsboN2Gjt9YId3NjuXte5xbQ3VYGuVD3QklRVG5hBhxxN7qZG8dcjtdNBweUv27wHEfV38tRO/ISE3e2uS2om0NC10ItU7LEy8Zym0TAhTZ5fcmoLNadMQugFrPHkLJidYR/wQCHKaWrSQodCZIX+UsZPmlZW6EOShuBiXAmDyYuH8oDxgfcYYtlLYDgqqoJIJir+d8wuMQZsU28KfC5PMxw9gsm5jrqXdRZy0mFOTDAqzzsunRLauCpfeuBhjPvuMgtzlfpSC8sYGLnkqQ7/aZl1HtSGYj4kUMjZ1tVDTmAHEPaVrQ0ttgkoq97MVgR/WkKJDEClB7fmDEbZDI0Wi7h5bDJdzW7vwlDRxCM4XgYz5BsNq8y6Z/TvqXtBfdyboBvBBCjaFP/41nK6zp93LhbuQI0eFpmm1/B4eAKx1mbwNV0zrfV4UFCEytiygqUEM51jScZihO0wYSSwKu1QyJPkNINj5wPav07N96IQVxtkOmQNCMsod3p3gXKV1cf8eWG7pB7dzphnj6Dytxx89uEnDS93Pt1+q/j/Hx+td2FO/ARdBO6jQaUWXz12SaOf9I5ESZJsXF4uiD3osVDt/Xycp/1HX6Jh76XaGqEgZF1OOdgy3hKh42NBDwxV2Hbrgs1+C9h6/Pz3Ys1Cj+7DyaIzv7HaI7aJAGw0To+YLdCW7lPlhoqhfOaCuGmdNvryXt/1vxsni9QF8i5Ht7DAwMXaZvSqZ/lVBOLKr8m25Um32qzqV7U2wFvWCi+1UTWwiluuayuvYEkf7ujNXOpadu9UewESSYSSNYxzNH1sT1Tuyw2CDAll0N0LgU37ZX4/awLPla8sG8mJiIyFxHHoj2TRvXFnaQDJcqyEX1pJy67uawwprm8cuxYoTR65rCfG9myQI1vtExzDeleLrqdghHpqS2qcPDUzQ7hc2sUfgPRmN7xXLTJaKaj75aUc1ZI1Q36lxpez2Zf1In2m8RyoQI2W80hTgXxEZW98cLxQLBwChztINkh3ZAKL/9543Jbb7e3x2p1W1XBXfdzakXXoX40qUUhu/Q3f8EULCKxpi+/b6iBFY6fJzzUpD6yMTm8ZSbqtfB3zBdY3HL7EaNDEAxz6paMwoA/Z/i7T814AhHNg5WvdC86BWgImKpQI26aVaOhQCkWsJ44L1hUe2tzI0xHTkm16WFV6K7TQH3ldZMvVLXn1A3dngRPkc99FRK4K1tjViwrYGgwMU4U5knBgUFFDW+CSB7vgIHQ5iCWseJSWr3d3IPgdcnBPhbJyDg2Mcqs8uEyCahcXLhNWIwJQJCEq2HB2R6eD+9eyzkrjQg30KMQ+9+FAmDsN5jG66yKtMVYWEpiIGw/Q2vOQPLvYlRfqGfkanDmM7VvY+GZmnivdIe1LgAfLCDGugqkisqHLOwXzj9eCxtAEnSn3IQ6OpQdmOuR3T67I6Kp5YV37OUNxzFWKpnjSQPm0CMAfkFU8OTZv0W4T3qUr7ZOsMCXO0TwJl1i8aOB1AfcvXELwm5dQRSoNJLQIeui3XROum2S+Yll70S0jJtYzzo94QQbR4rjHmwEIcn4syQGqqrPlgaGby2Td9Xvx/RHuAV/Ez/N+o1TLvRv7BTzNWqBjGNmi7eNzDX2+oUOW8jB65fQAB0zJUb6Uvlh7DnwjNGhpotCZELKAjwCR8BSZW0o0rSXs3MSpOt0C4C7KAwglcYPvwCazpsQ6Qedf2DGXqP1pcCFtHq4n8+ufFDM1B70F3Go5IzkOHHuEVGYMztGYu2JiB8XShM
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:32Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d389-fe24-438a-9c77-4411950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:33.000Z",
"modified": "2016-04-28T09:10:33.000Z",
"description": ".js sample",
"pattern": "[file:name = '0070704_004304.js' AND file:hashes.SHA1 = '08496c8e28b7b28f80ab22c0ae87692e71fe89de']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:33Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d38a-780c-4a40-bc95-47b5950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:34.000Z",
"modified": "2016-04-28T09:10:34.000Z",
"description": ".js sample",
"pattern": "[file:name = '0070704_004304.js' AND file:hashes.SHA256 = 'd15359165c95df85629893c0d38d8b50e546e2d638e52d446c83d5bda3f33f44']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:34Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d38b-61c8-4235-8d09-431b950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:35.000Z",
"modified": "2016-04-28T09:10:35.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAFJJnEioJaFgewsAAN8XAAAgABwAMDM3YjlmNGU0MzQ2YWVmY2IzZDM2OWU4NWJmOWE0OTNVVAkAA4vTIVeL0yFXdXgLAAEEIQAAAAQhAAAAxXBzAcRHxVVhE70XIGLxBvoR/HDqxuFrUDXAP3tFENMN74VdHLmn+5XVEXLGRyWWPGVgbDXnMEf8YcZ3NQrk2mh187k+XeTO0WVG3rZDGX+Vglg5RutLgYe/7LGJfyuRaI04SXUOSq+a0XSnDs7dtksZztJ5mQWDUyftw+B/R1+ohO7lTLxvr37yJOhzdkQJJ3Q3x7950OdqaS06JnCl33PrUW1UjttQnv1ZwG5mKk59zeCqWS6SFMq1d7/yvX6mDW1WlQ/zIrQPHta9qgciLVbUcpFmhBC76rZ19xbjx4JjGHe3G5zCKOgbTPulGgJOWh/+sgu+1Li3ZNT89eoLU5PAkGX+dTkm1TqlmjEu15T/LG8YMNHvbnPwQJJ4GnINPQF+3y7tXfZfKSH9gn05RKcNBrnFO7BMQSbxyzDReC5p+dtQOG0w7k7r5kNolTULnN40YXLkIdEjSown8fL3fqmt5qXiggOtf0+2ZcD1uGoXKu2SUk+992P7G7LRgknG8L8WCzNYDzXD+syZlZ9x5bYJRlxjCA5uPcyTmUa+g4oDCrHbyEVR7KEOgnA//Z51f/hE6HnyLsFX7TBKw6p7JkHZv7mhtLT4kqQzRlHGD9GWtNsKsnBgu0QB/9RkYBwaAIKVPWkJ9MJW+oEzRi11/s8Ckoxqx9m//V2wfIEm6p1WL+ZXNzaRr7kBzpHtL08AuR5OQtLZTpaCKbGPHEoZ+Ml1ZJrbShI4Px7uIObzjIuf8jmcAQzfB/c2azH2aFUKBGcHidC2dX7Oy+rwmcNFBZxnxi9DV9ecxkYaBI5tfYqkcrzz7GV5QtSu7Sd51ji/2rp6uSAz53AqUi9gT6lcOwMl5F9L2jpol/xHdW+2tpu3L8jqHdhbRzkelw1pcM1uEsiyXf/zbLgEck/vMIpaT2gGAA+NgB4nm5DDkXPYXR4CPP8fZO4cvp6Nt1904m8zX+nDppvkyK/XelE75P99HnFJIbIH/Otl5S06mfWoGA2G8UiQiSS0XcLXO14EWQVBbhgqaOII643onoxcJNP20dktYuGn7vOwvDC6IYRlMdIV7+hiJHTnrfqgVfVmMkVQPAzdbvQ3LMC0/tkdeIG/CzdJojGstbZIuVeWUJE40bw3UsUzWYxvoydQUImGZeRhrxnpILvEm87671gB9zXfDLcVuWcShwcf8NTADh+EZi7P/mBZt7Eei+z0MLy6g1r9N1PUVjYzWg1KOhMhmWSEmzZWspp6nxIvkw3y5sP5ErJ0Zg6I9J8FwGGGZMuNTmAEEmnDjiUCN5Vz22VwdTMQ6dKxLlblDJ1eNZOKoM8sLGbt8bHrLudJmScgoR9knyoyh1i9XFJT5yzrpEDv92YgN0chsT0BwPatFPD9UKLinCZzTHQm+sS3Ty+k+xQCdNQv3u7Mt8uvMkp3iknLTYWtHHvMpGOUPciDkfN+VIwwOc7u1A0lwX2Yfzbuq1Or7wWgJZairm5WyoE0oxT/hceqw6keHslkTFEbTu3PRUshNSw7KyeJ1BS+pas807BkFMfPftvFJ5HHiNCDqDlQARkQJvxaVIr85XORGhsmAC2VXt0/7jGEEFKbOnS4EJ1oY3XMngt3St/wL0ItCR7jlR6/YVDR+foyrzKJe4VcjOcxNalV4CkuqQUoWocBzR84Tx7mIZSpI3j9tuXDKrHnYwZVIKkKRDXsTjj1Ywyyz3janmPqjytJDu6PGwcNQQcT/dFt+iR+1nqVsxSaHTJs9z/rsjUAhMSbIxICmXvhAjIQlYexKuvcmr8K0Xi76JkmKtF5GQRtYZr4RlupwMpzTUFMvT3vOF8RxYUJB08tpsU1iKguWDfrUAx/UoHCBB4TxsQ/IYZsWxzfDkFqyefnnb08vl6Rh6M7c6Vozw5GS3hROL82eMiH1FkiCa367ymVKQBp2ReNKcEIepPI1i2zdizeOfDP51vVfpOXI+208J0CulK28EhqGSPwFLD46RErz2hMvwMh8zSg+gth5i5nITP2VuFZEl62ycwgnC9/EhUsJKekqXEcU7G3Q0+hFnInFjVtYqsAjaI3LrOYDOlJ66KCDhsy8HEHKevGrPkUwRLyOd21pIHZIBiL3NWrPP6bRthDMPt5QCaU0kVZjXr0u5CECyNg4IMpbm3MthEFk5KCF3Tmut/KN4W/UYMaenH04lkSXeXiNaZyT9cI/CNvjdejO5rv7YU/s0tIyphMVZzF2Q+G0peM0lAPPXFiGzp/9pyCfdm9BFHRTsZ2YANg0IZl1DPp/ILDF8eubiY0omMe03/l5PDKCi4jWF7HP+hhhCycUKd9xIy3yrvj3VDnwLgSFWkrztWkcqX6ZWNrHyW0ceE4n7+5HdNnGAHSHJVcHysucUYT5xRbhcRxZWc2ai9Hr0iVHy3GFGvCzmNAhCxcZjqtGdB78Wn5WPfOIDIjKBHlcxD1C6dEW3yt0COpZKijoPsHF2y7Hp0/q4FZ1I/gf/vSPv+4DFQu9wByakkCzbgfAU8DFsb7BoBSqFzswtWxFAXli+DSvf6VaVvlFMINhNtUgJWaTUsMX6dpAGFoCdZCO9hHmo87puE+JaLAnHFwhhEBGq0Ncu4u5h2VnfreQMDir0X8mPAaFnGvPZBRcd8sFg9bNeeBqtlo78RArKNed9k9lAtPfhyDc3+zCLyW4Z/jSDVsQGb9NG6h9neFf8eaCNypotkcpFZCTJqMBNRsAXg+yZFGWb3PUpcvZNc9qZVZQxw5YuTMUuL95m/9RonHuZKeIwXpjdT3mnXTn+SuVy1sc+pRkiwlQEUo9SgHmqekpWVV2wVSNdGbRdat3mFQMQl3yHFmBs/I4Ao+gGrPlPPtJYfBDWF66Gl27xk2EIbiTTPb0Ykply40uQx9upRkx14dk344e4dVai8matpMPFVBFAZSQ7vejYem5HIGX+hva9bT1EV3fR0/jJarDC5fM5OQfKgtJW3UymP6tWSJ4peFC97nNw43VY3VjRmW+ajtONo20oz3WDf+dtbL5V/3iKZBu8CsERrAW3pj8ASFCEuFJTffPXsRyCAiAH5xeoozMldbfidDwEvtaTc9jYZU9n2OfzH0n7qrZi7bo2qMlO6q28sO5C4kawW+Uxhi3m/6gKRSD4/5GUzQFYnDVzi6zuNDheX79K/ctgkY1wmgT/gGrMd0m2iFTlkSc3Kx78VgQuyubvRzSiX4Agte0kd/siHq12NWJ3e/ePYGWeMHWGTXOcic80j0c0R4BVBlL9+/kSpqnu0vDPQ7JHWear/z7AwOFtHXeZKB99XJq5O9g5zHfrO0AmNHXy0KELSHL+D/7QwZf17YVEshant5C6v/o610/TcFMEGOCVafiLAk1nPCgtFm1AgZ8ciN7MByNGs+WlGvn7GeCnXn9EFPGloYTFYuN1HzCZyAVqVju4IUABI/4VKVQVb4hQWnst2lwwC9eK93b/1zRz1nuDGTuJ4MllQPc3WUXz7J3u7DWe8TfZvq0+FEpTNKUSnAlZjr3AzGFc2ikucqz3YR/oQmeOiSJwu7yb7LMJc4GVIiTWgBncDU2EE8RqvCn2SvIM1XTBkx8KcJQlbfPDg9YpqwqGjGqBexjkC03vHvB/twouGpByVXqCuNjWZrTIB6B4r/7Fs2Z/XbY1VBEa/X5iLNtlEjRx+xsb6nlh/jcdFBONdliEDvX4Two5WgERM/X78cJmPJ0ZMJpdfgu00nEsjJz8nExKURX4VuIZIiMTPgpRuix3hvig9MZlqCoIgt2TOMuXPojxhSOOrX8sSp2+lsuye91g45JDnS6AaclZXdtFSAdPPGYfDVPBgW9k9BMYGmPrLbZNOfPONs60nQvC0mayoibwP8DQRdjH5vl9LSsCOXHamIug3v8/i/7XlmO13SzWWyu5Twdpkr+//vPuqZzRmJFRDr83VwTegJrz
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:35Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d38c-dd20-4dcf-9930-4c94950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:36.000Z",
"modified": "2016-04-28T09:10:36.000Z",
"description": ".js sample",
"pattern": "[file:name = '0071511_007254.js' AND file:hashes.SHA1 = '038c8bd7080e4c0bac4e16c1d0a3f676308ddd4b']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:36Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d38c-9dfc-4897-bc35-47e6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:36.000Z",
"modified": "2016-04-28T09:10:36.000Z",
"description": ".js sample",
"pattern": "[file:name = '0071511_007254.js' AND file:hashes.SHA256 = 'a599ddc94896ad115de74abaccc5fff8a4a6f405d1c11027d0f2c307b61790d8']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:36Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d38d-045c-4b49-9166-49dc950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:37.000Z",
"modified": "2016-04-28T09:10:37.000Z",
"description": ".js sample",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAFNJnEicvx8jjQsAABEYAAAgABwAMjU4NTk4OTEwOTAxNmRlNjRlN2U4ODFjZDc4ODA5YjNVVAkAA43TIVeN0yFXdXgLAAEEIQAAAAQhAAAAxXBzAcRHxVVhE7wjnC6KV8LTzkIJglpgdvlWrsLQp/1xN2G4mSriSd+03njcvAlvBalB1DbQfj0uZubAclGOmpACopobisXd0qJt1qtpaxoaJPdFJZswxuoGsj7wkiwgBcz2z84CFlxGp5TQJEVn+vqNXzkiK17K4rbQGrFgfanrsdAPyzz7tdZ6+EIVO/dxOCdkwGOQC/ygHxDn7cAfhnn7Onlq61AJI+KubATaRcy6iiPQHjuiAp2lJmzWBwbN6SsaxCPBtODFwWUePa6RHsKLsdyQVGt9hRPOTC76Ua7AJ/4h+Rdly1NlfzXKt3OVUXi4oib7xP2nTLFbgb7SZQf53gOCDV7MppJnBkYW5WVk1s8X3pP4m0BSScrOijHjfvZgOD6qTJHCBPV5W3qVUzg5A4IWNfXADI7W1IhWzy9oFDAX9cJvOFqFpVUsIET6uLzlAOrpEDbl4qYEIokG1dElp2y69LvZYNS7AsQs/1s+p8E50NT4/wNRAdSyS2nr92aHGJhfe/gg/jQlVVJ3MVZktlGh8LHy7GOLNryVDgm945SbT6vW01AXc6Cv0xD7cPBdiR3N3Qa+qKUltDolfs3rm9TWhCHL5YO406gCw+tr20YPFD71HKE/kGi+WdIWiRvnE+ARNaKDnfZzhtorWSlRYzx0ABGokkNjhqTIAhqjEf536jvm4pRyImNr1HP1p/qk4B3VHl0zclwEA2lEETBvHfTCQuCEr9DYhpTcQLd6frfN7yxDuiMnUIjaY/PVQVDHuLBuoG+yNob+y8xRFHA3eSy0qaJ3DRwOpDqTqwouJfkD6z+CedwgSfLO3gzBQxO0bC1OJ1CI8JDgPo5vE1ZDImsscx98rOfxwK8FZmzQD1Su2U7Sth/VfQ0a3aw/0sZbEIogocOITTns1OP6dv2gstHeEmt8yf6FDwHaJokucKEIee50o3PZzv9MeyZiPpQbezxhHIbXv/7tcrLVF7W1WCAa7p3cs6cffQzoStc97/87k0CzvG5ZDJaeqJVom/SbNlAXmCYwuOGuPRzHeBiULteSUssOIr1tdmR0ojoykvJ3IISkCvFaQU5Q1YxgRF/ns00Bt/Ui01yuN+QW0MMlihJHPE0BiW1HhrBfINeeznmGZUL0fRQu4jP8N98udePUn4MKuxcCyk5VdzRh+rEYgu5nuDQWlhxKacZI8WiU2MAV3X7BgmJXl3hxj1DR46Cwz1OJrmUbumc5ardOvTl0WBjqFagLhsLv6PCiuILOmJJBWLxx63sUZUGeaLvdqa1AmdQCHo/wKYauFaOBJqgyp8D66I0YoW601cZSShj+z6PWEkb28hyAmW/qdlIEU44GTxZwz3j79ZjgFA21PKWAFoRxlbYkUstzOGNb9L6tdTVuElNVJxDeIabcXD7dQxwKvAVhLZb3ij8FW9lmOvtgwEe397wAe5v5NATpWWpY10WZE9jzZQiREb2zVHk49xnS2Ww/uROhiaMzcyfrDp+zeTyAUO5zKMBKP1rAmlL7UVnTtrwu5SR2m6TzBd0f/akaCmF3ldgUZc/fUKm2La65abM23LzY1Y5SxZh3N/K9reAEW1TdbIhR7C1in1AFozlXHkedqs0DT//rPsVlyJG95Lbj06nTXn+uwrBeVHmZarSC1+l5RPEvyqaiDOhl7RnsfeTTtu8ojrBy5AtKE02RyudzCTeQ/91XPwm/PX6SS9R6mPSKga92rBiakihDMDeKz0oItGjiJKlHV7YXTgxC14iXiIi5ZKTvNtDK3oJY/vebgdaH3MDTSWP+MZTXpuXmE3uE8bXCwqb1YpizmbWvqQUcRd8U9lGwa9EDCL25Q7TfmE63ywc1ez89lrnG0ZzDEEPYOwMJ8FWmya6NllKpvhAvZNkkxWG/YPUvFR2QFotoEkjnYVUtjQ9+chVNYl/es5xd3VhFem9fp35SRFS7uWPyHFPFlsyqUwSwXGHjzkbBiL1Jnb8IIBPh2xbeQKpG0Ko8yjSu1HJVJHiSICvDSmJRcu/ftfnxkT63fWrGh3AdiiamZE3gtRQjMTbmkyahcbchc08J3sNiOa1DLp3O8KfJXxNyqX1OW9VIeKNHzIi7+B+b1zo9Ccpjueo+JlREmcIUz41iexS/7o3jm5EQWc5+DIVu0x9187TBc2TkBovT0DjH0XD7CBUljqDtjQfbLI+TeuS82wDBCGoTrgIXi8XxY8/1wdv33g7f0r2/qjrFXJ25CmHj5/XNadLamSXTkvoGh6bJGBP4h2PaKhsr7sNw4Vie8bpwI2Bw+YCrqj/yIly6zUT3jxURhpvZ2OV3O5ymAbGeUDy3NHKbIK64lxU0Cuu9Ecv7gx3KnPRXwm6pVbIUkdzyCzpGwEzRKxDTOVgQD1z24hfZlwJWKyvy1PSF5vyYKJBJdinUSWMRZ28x3LH+url0VgSVHKd+kZnfxizUj5HwZeRq/t7aT0nWBu2xHXx4wkWTwQQtYQaFhUdR8OOYix2Dl4d1YD0MPRx/yfA/3vDf1CEsSrJSAsDrh2WjguM6Lp0IkqHuRwLn/qh3/8v2fEYJvjk8cPlUvyJbQp2g7Lg2ourEJk+jflqXAt3ZFNe2sfk29X0tyegYLl5W/idnkpn/DV/CR0CTtW9Qb7ml1ipJ7KKwCPN8fuiGZF5wCze9Rm5a8rEKOou/22ovsDI9J4q9Oso4g/zauT7xWuKPs1Ea0tumJOnqIVxFrVtJlQrWMvWAdpNrUxKxOfSHzuS29MVL6tmoIQebmzbekK53ff+qBSMG1xvDTtPqGLxEesTSu4vwqQXQrnWAywuJNS1Kf+XbXsWDpJF8URiaJmNwWS362yww9cQ1fAV0Re5QP9+hhMJlPexWpRZ0Aj+KK0sJRBZIBzxaL6d20ZH+s96Rb9Gca/pYG7X/ln7KMN8UgxIxv4xzpm7oTWpCUYxzEvU7MkPa0Nq/Jw0sejTDqGvJe3bXPJmpl0R7nCw576K15zI0F5mLWTC1y/U6Vuhp0dGY7BSNUheUvMM7E2svUpy0B9n/W0AhSC/apQFki2eJfQNbAt7D6s6C3Wo3dURGO9gX4E8CJ1GdnZWfSuLKyIpfgWLsl9NrA8DDjpt8HVkHWqCCldA7utcOwtu1suS9mAVmh8p23I3oNR/OtLm7mxl2ab5EWVNDc3ijpiTu1Hp1BaUEUpp2alESWLZ98xdp4q7nN95FSWyBlHD6WzLrhDJIatwlZnV7W35OHRvOSIeg7xm1evGSD2SbTk5Pi+cPwstw4KaMiosA+fSvCZrjYr8qJm0ePkAUlPq1zjwRqvIm7IKBzCKDnTtpTuvCRy2QyaCAqis3DsD68Cs20lxj3x6N4aO3w0wZXttnaYo4dh+wlxCkpXPuZ5W250j6cQheEJKiZTUXWZ1O+jprp1JyyHvxFU8t1An5GKhVMwmR616rw2vf3hN2DkoNPu1EiZcN85Fo+Vla/PHI3DPhpXtUjBZ8Unz3u+0kq2A6GjRcT+NVpOaJNF/69Z/ZHvYK4AdhxINlVQzQttANLUB98pQQEgYZbmdCEDbPzPcyTRFbtGij+XKtTLvFBn0kq8Aq/yeWnSol3lmzyXbcUB7H2Hn4cZQ7+6eruYUbBpfCXR+ZkCtnWvC2OMCZ/QNZSWW4kSua8JHUU3b/iKROiFhS9HNdqU0gemOdwGnTelC5uIA8Wcs+J/8TbxJNG9YVbFWqWtdQYq6cZ1y2w+9PIGkPhSeBsc5jjuKckCmBhwxqMJS9Wx7MjV41jiY+OpNcCV9RskRWRSLqsVNU6Fs+qMLqMlSq7XmwHMy3mQ8rYDVWI/hzqqrfUperXBtgkEc9ykhfJ/dKwfINjDh0l4kdh6HMESurLPM9q0fV0IIrOIqYlNVXnPZyK+831TvIVNvFmorc5NEoz931MfFnzZdTPZ+PAtztEe7fz5EMHv
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:37Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d38e-dd90-42d0-a988-4b2f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:38.000Z",
"modified": "2016-04-28T09:10:38.000Z",
"description": ".js sample",
"pattern": "[file:name = '0081809_006429.js' AND file:hashes.SHA1 = 'b5e244e8e023df2142c6f0a69051b96d7545d2c1']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:38Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5721d38f-dad8-4820-919f-4565950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-28T09:10:39.000Z",
"modified": "2016-04-28T09:10:39.000Z",
"description": ".js sample",
"pattern": "[file:name = '0081809_006429.js' AND file:hashes.SHA256 = '27a94b6254be4e07edb64efdc0c12db9aed1225f370523816fab15615a7fb8c1']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-28T09:10:39Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "marking-definition",
"spec_version": "2.1",
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
"created": "2017-01-20T00:00:00.000Z",
"definition_type": "tlp",
"name": "TLP:WHITE",
"definition": {
"tlp": "white"
}
}
]
}