2039 lines
83 KiB
JSON
2039 lines
83 KiB
JSON
|
{
|
||
|
"type": "bundle",
|
||
|
"id": "bundle--57738bb1-bcc4-443e-a002-4590950d210f",
|
||
|
"objects": [
|
||
|
{
|
||
|
"type": "identity",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:54:27.000Z",
|
||
|
"modified": "2016-06-29T08:54:27.000Z",
|
||
|
"name": "CIRCL",
|
||
|
"identity_class": "organization"
|
||
|
},
|
||
|
{
|
||
|
"type": "report",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "report--57738bb1-bcc4-443e-a002-4590950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:54:27.000Z",
|
||
|
"modified": "2016-06-29T08:54:27.000Z",
|
||
|
"name": "OSINT - Prince of Persia \u00e2\u20ac\u201c Game Over",
|
||
|
"published": "2016-06-29T08:56:14Z",
|
||
|
"object_refs": [
|
||
|
"observed-data--57738bfc-31fc-425d-91ad-4083950d210f",
|
||
|
"url--57738bfc-31fc-425d-91ad-4083950d210f",
|
||
|
"x-misp-attribute--57738c0a-9760-49c3-b44a-4338950d210f",
|
||
|
"indicator--57738c40-0f4c-4c38-97f4-4e76950d210f",
|
||
|
"indicator--57738c40-bdc8-473c-9a3a-46dd950d210f",
|
||
|
"indicator--57738c40-6400-49b5-b055-415e950d210f",
|
||
|
"indicator--57738c40-3a10-44bd-aa2f-43cb950d210f",
|
||
|
"indicator--57738c40-c410-443a-b154-4453950d210f",
|
||
|
"indicator--57738c41-bb5c-4f61-80de-4740950d210f",
|
||
|
"indicator--57738c41-ca7c-4349-b929-48d5950d210f",
|
||
|
"indicator--57738c41-2778-4d1e-9934-4deb950d210f",
|
||
|
"indicator--57738c41-5f24-48e4-bd48-4e9d950d210f",
|
||
|
"indicator--57738c41-c350-4a35-a9ae-4f19950d210f",
|
||
|
"indicator--57738c42-61cc-4674-bac7-42d3950d210f",
|
||
|
"indicator--57738c42-19e8-4fee-b9e4-4392950d210f",
|
||
|
"indicator--57738c42-9120-41b5-913d-471a950d210f",
|
||
|
"indicator--57738c42-df30-4ee3-83ef-4ed5950d210f",
|
||
|
"indicator--57738c42-9164-47d3-9abb-4035950d210f",
|
||
|
"indicator--57738c43-5144-4c7c-933e-4f66950d210f",
|
||
|
"indicator--57738c43-9480-4cec-887e-4d1c950d210f",
|
||
|
"indicator--57738c43-9124-4446-b4c8-4ff2950d210f",
|
||
|
"indicator--57738c43-daa4-432f-a0b4-4438950d210f",
|
||
|
"indicator--57738c43-96c0-4daf-86b5-42fb950d210f",
|
||
|
"indicator--57738c44-c1b4-4870-a965-4551950d210f",
|
||
|
"indicator--57738c44-83f4-463c-8096-4abb950d210f",
|
||
|
"indicator--57738c44-8290-41bb-a024-42ec950d210f",
|
||
|
"indicator--57738c44-095c-4ef4-a2b7-40d5950d210f",
|
||
|
"indicator--57738c44-6c58-47a2-909b-4c90950d210f",
|
||
|
"indicator--57738c45-cdfc-4e40-857d-4da1950d210f",
|
||
|
"indicator--57738c45-b760-414e-95d4-49c7950d210f",
|
||
|
"indicator--57738c45-d27c-4dd0-9698-49a0950d210f",
|
||
|
"indicator--57738c45-1760-419b-8799-4046950d210f",
|
||
|
"indicator--57738c45-66f8-43d2-81b1-4978950d210f",
|
||
|
"indicator--57738c45-da10-47f7-ae81-44b0950d210f",
|
||
|
"indicator--57738c46-7e00-4a86-9b29-45e2950d210f",
|
||
|
"indicator--57738c46-49a0-4986-89cc-4d37950d210f",
|
||
|
"indicator--57738c46-f6e4-456c-a380-4448950d210f",
|
||
|
"indicator--57738c46-f0a0-43af-bcbd-4ddb950d210f",
|
||
|
"indicator--57738c46-0af4-4d1d-ba6b-4a03950d210f",
|
||
|
"indicator--57738c46-6428-43b0-a890-4522950d210f",
|
||
|
"indicator--57738c47-b2c8-4d63-9893-4e0e950d210f",
|
||
|
"indicator--57738c47-5098-425e-9b14-41ca950d210f",
|
||
|
"indicator--57738c47-f7e4-42a8-857f-4ab1950d210f",
|
||
|
"indicator--57738c47-fa08-4e36-b64a-4cdd950d210f",
|
||
|
"indicator--57738c47-c4d0-4f8b-bd99-4029950d210f",
|
||
|
"indicator--57738c47-91e4-4916-96de-4f40950d210f",
|
||
|
"indicator--57738c48-15cc-48c8-b484-4b95950d210f",
|
||
|
"indicator--57738c48-4480-438b-b346-4127950d210f",
|
||
|
"indicator--57738c48-da9c-479c-b6dc-450d950d210f",
|
||
|
"indicator--57738c48-1a14-4aed-b047-426d950d210f",
|
||
|
"indicator--57738c48-f808-40af-9923-4b0a950d210f",
|
||
|
"indicator--57738c48-6e94-4cf0-9851-4c0b950d210f",
|
||
|
"indicator--57738c49-a8b8-4c6b-9f96-4294950d210f",
|
||
|
"indicator--57738c49-0040-4316-9d9d-432e950d210f",
|
||
|
"indicator--57738c49-2aec-4cab-a011-4a0e950d210f",
|
||
|
"indicator--57738c49-7f8c-453c-b072-4694950d210f",
|
||
|
"indicator--57738c49-aac4-41f8-bfe8-497d950d210f",
|
||
|
"indicator--57738c4a-35c0-41b2-959a-4cce950d210f",
|
||
|
"indicator--57738c4a-4f90-47ac-b51d-4ce7950d210f",
|
||
|
"indicator--57738c4a-fcc8-4e17-b7fe-4dff950d210f",
|
||
|
"indicator--57738c4a-a550-4a14-b6d7-492a950d210f",
|
||
|
"indicator--57738c4a-b45c-4462-b509-46e0950d210f",
|
||
|
"indicator--57738c4b-ea94-4aa0-8aba-46fc950d210f",
|
||
|
"indicator--57738c4b-2044-4a5c-bbbc-409d950d210f",
|
||
|
"indicator--57738c4b-fb0c-44cd-9e52-44c0950d210f",
|
||
|
"indicator--57738c4b-8314-4dbf-b1fa-4a8a950d210f",
|
||
|
"indicator--57738c4b-cb20-44fa-adbe-478c950d210f",
|
||
|
"indicator--57738c4c-ce88-4ea0-9196-4c5c950d210f",
|
||
|
"indicator--57738c4c-e59c-41a7-ae29-487f950d210f",
|
||
|
"indicator--57738c4c-7828-4450-b0e9-47cf950d210f",
|
||
|
"indicator--57738c4c-1e20-4881-836a-48a2950d210f",
|
||
|
"indicator--57738c4d-f8f8-402c-9f12-4a7a950d210f",
|
||
|
"indicator--57738c4d-940c-4a2e-86fd-489b950d210f",
|
||
|
"indicator--57738c4d-dfc8-4623-b3ad-4e33950d210f",
|
||
|
"indicator--57738c4d-4778-46ff-8c26-4f9d950d210f",
|
||
|
"indicator--57738c4d-7938-4015-a89e-4c0d950d210f",
|
||
|
"indicator--57738c6b-f884-4152-b8f2-484d950d210f",
|
||
|
"indicator--57738c6b-c3dc-4fe5-9144-4f78950d210f",
|
||
|
"indicator--57738cc4-18b4-4dbd-bce1-43d702de0b81",
|
||
|
"indicator--57738cc4-8dd4-4fc5-ae44-4e8502de0b81",
|
||
|
"observed-data--57738cc4-beb0-4b72-b853-476102de0b81",
|
||
|
"url--57738cc4-beb0-4b72-b853-476102de0b81"
|
||
|
],
|
||
|
"labels": [
|
||
|
"Threat-Report",
|
||
|
"misp:tool=\"MISP-STIX-Converter\"",
|
||
|
"type:OSINT"
|
||
|
],
|
||
|
"object_marking_refs": [
|
||
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "observed-data",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "observed-data--57738bfc-31fc-425d-91ad-4083950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:51:08.000Z",
|
||
|
"modified": "2016-06-29T08:51:08.000Z",
|
||
|
"first_observed": "2016-06-29T08:51:08Z",
|
||
|
"last_observed": "2016-06-29T08:51:08Z",
|
||
|
"number_observed": 1,
|
||
|
"object_refs": [
|
||
|
"url--57738bfc-31fc-425d-91ad-4083950d210f"
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"link\"",
|
||
|
"misp:category=\"External analysis\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "url",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "url--57738bfc-31fc-425d-91ad-4083950d210f",
|
||
|
"value": "http://researchcenter.paloaltonetworks.com/2016/06/unit42-prince-of-persia-game-over/"
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-attribute",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-attribute--57738c0a-9760-49c3-b44a-4338950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:51:22.000Z",
|
||
|
"modified": "2016-06-29T08:51:22.000Z",
|
||
|
"labels": [
|
||
|
"misp:type=\"comment\"",
|
||
|
"misp:category=\"External analysis\""
|
||
|
],
|
||
|
"x_misp_category": "External analysis",
|
||
|
"x_misp_type": "comment",
|
||
|
"x_misp_value": "Unit 42 published a blog at the beginning of May titled \u00e2\u20ac\u0153Prince of Persia,\u00e2\u20ac\u009d in which we described the discovery of a decade-long campaign using a formerly unknown malware family, Infy, that targeted government and industry interests worldwide.\r\nSubsequent to the publishing of this article, through cooperation with the parties responsible for the C2 domains, Unit 42 researchers successfully gained control of multiple C2 domains. This disabled the attacker\u00e2\u20ac\u2122s access to their victims in this campaign, provided further insight into the targets currently victimized in this operation, and enabled the notification of affected parties."
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c40-0f4c-4c38-97f4-4e76950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:16.000Z",
|
||
|
"modified": "2016-06-29T08:52:16.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '5.9.94.34']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:16Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c40-bdc8-473c-9a3a-46dd950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:16.000Z",
|
||
|
"modified": "2016-06-29T08:52:16.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '138.201.0.134']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:16Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c40-6400-49b5-b055-415e950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:16.000Z",
|
||
|
"modified": "2016-06-29T08:52:16.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '138.201.47.150']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:16Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c40-3a10-44bd-aa2f-43cb950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:16.000Z",
|
||
|
"modified": "2016-06-29T08:52:16.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '144.76.250.205']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:16Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c40-c410-443a-b154-4453950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:16.000Z",
|
||
|
"modified": "2016-06-29T08:52:16.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '138.201.47.158']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:16Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c41-bb5c-4f61-80de-4740950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:17.000Z",
|
||
|
"modified": "2016-06-29T08:52:17.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '138.201.47.153']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:17Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c41-ca7c-4349-b929-48d5950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:17.000Z",
|
||
|
"modified": "2016-06-29T08:52:17.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'us1s2.strangled.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:17Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"hostname\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c41-2778-4d1e-9934-4deb950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:17.000Z",
|
||
|
"modified": "2016-06-29T08:52:17.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'uvps1.cotbm.com']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:17Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"hostname\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c41-5f24-48e4-bd48-4e9d950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:17.000Z",
|
||
|
"modified": "2016-06-29T08:52:17.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'gstat.strangled.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:17Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"hostname\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c41-c350-4a35-a9ae-4f19950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:17.000Z",
|
||
|
"modified": "2016-06-29T08:52:17.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'secup.soon.it']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:17Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"hostname\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c42-61cc-4674-bac7-42d3950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:18.000Z",
|
||
|
"modified": "2016-06-29T08:52:18.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'p208.ige.es']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:18Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"hostname\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c42-19e8-4fee-b9e4-4392950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:18.000Z",
|
||
|
"modified": "2016-06-29T08:52:18.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'lu.ige.es']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:18Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"hostname\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c42-9120-41b5-913d-471a950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:18.000Z",
|
||
|
"modified": "2016-06-29T08:52:18.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'updateserver1.com']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:18Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c42-df30-4ee3-83ef-4ed5950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:18.000Z",
|
||
|
"modified": "2016-06-29T08:52:18.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'updateserver3.com']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:18Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c42-9164-47d3-9abb-4035950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:18.000Z",
|
||
|
"modified": "2016-06-29T08:52:18.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'updatebox4.com']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:18Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c43-5144-4c7c-933e-4f66950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:19.000Z",
|
||
|
"modified": "2016-06-29T08:52:19.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'bestupdateserver.com']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:19Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c43-9480-4cec-887e-4d1c950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:19.000Z",
|
||
|
"modified": "2016-06-29T08:52:19.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'bestupdateserver2.com']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:19Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c43-9124-4446-b4c8-4ff2950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:19.000Z",
|
||
|
"modified": "2016-06-29T08:52:19.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'bestbox3.com']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:19Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c43-daa4-432f-a0b4-4438950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:19.000Z",
|
||
|
"modified": "2016-06-29T08:52:19.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'safehostline.com']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:19Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c43-96c0-4daf-86b5-42fb950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:19.000Z",
|
||
|
"modified": "2016-06-29T08:52:19.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'youripinfo.com']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:19Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c44-c1b4-4870-a965-4551950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:20.000Z",
|
||
|
"modified": "2016-06-29T08:52:20.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'bestupser.awardspace.info']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:20Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"hostname\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c44-83f4-463c-8096-4abb950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:20.000Z",
|
||
|
"modified": "2016-06-29T08:52:20.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4035.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:20Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c44-8290-41bb-a024-42ec950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:20.000Z",
|
||
|
"modified": "2016-06-29T08:52:20.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4036.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:20Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c44-095c-4ef4-a2b7-40d5950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:20.000Z",
|
||
|
"modified": "2016-06-29T08:52:20.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4037.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:20Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c44-6c58-47a2-909b-4c90950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:20.000Z",
|
||
|
"modified": "2016-06-29T08:52:20.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4038.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:20Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c45-cdfc-4e40-857d-4da1950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:21.000Z",
|
||
|
"modified": "2016-06-29T08:52:21.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4039.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:21Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c45-b760-414e-95d4-49c7950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:21.000Z",
|
||
|
"modified": "2016-06-29T08:52:21.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4040.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:21Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c45-d27c-4dd0-9698-49a0950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:21.000Z",
|
||
|
"modified": "2016-06-29T08:52:21.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4041.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:21Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c45-1760-419b-8799-4046950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:21.000Z",
|
||
|
"modified": "2016-06-29T08:52:21.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4042.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:21Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c45-66f8-43d2-81b1-4978950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:21.000Z",
|
||
|
"modified": "2016-06-29T08:52:21.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4043.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:21Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c45-da10-47f7-ae81-44b0950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:21.000Z",
|
||
|
"modified": "2016-06-29T08:52:21.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4044.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:21Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c46-7e00-4a86-9b29-45e2950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:22.000Z",
|
||
|
"modified": "2016-06-29T08:52:22.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4045.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:22Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c46-49a0-4986-89cc-4d37950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:22.000Z",
|
||
|
"modified": "2016-06-29T08:52:22.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4046.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:22Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c46-f6e4-456c-a380-4448950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:22.000Z",
|
||
|
"modified": "2016-06-29T08:52:22.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4047.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:22Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c46-f0a0-43af-bcbd-4ddb950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:22.000Z",
|
||
|
"modified": "2016-06-29T08:52:22.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4048.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:22Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c46-0af4-4d1d-ba6b-4a03950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:22.000Z",
|
||
|
"modified": "2016-06-29T08:52:22.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4049.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:22Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c46-6428-43b0-a890-4522950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:22.000Z",
|
||
|
"modified": "2016-06-29T08:52:22.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4050.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:22Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c47-b2c8-4d63-9893-4e0e950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:23.000Z",
|
||
|
"modified": "2016-06-29T08:52:23.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4051.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:23Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c47-5098-425e-9b14-41ca950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:23.000Z",
|
||
|
"modified": "2016-06-29T08:52:23.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4052.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:23Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c47-f7e4-42a8-857f-4ab1950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:23.000Z",
|
||
|
"modified": "2016-06-29T08:52:23.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4053.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:23Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c47-fa08-4e36-b64a-4cdd950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:23.000Z",
|
||
|
"modified": "2016-06-29T08:52:23.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4054.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:23Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c47-c4d0-4f8b-bd99-4029950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:23.000Z",
|
||
|
"modified": "2016-06-29T08:52:23.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4055.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:23Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c47-91e4-4916-96de-4f40950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:23.000Z",
|
||
|
"modified": "2016-06-29T08:52:23.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4056.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:23Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c48-15cc-48c8-b484-4b95950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:24.000Z",
|
||
|
"modified": "2016-06-29T08:52:24.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4057.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:24Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c48-4480-438b-b346-4127950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:24.000Z",
|
||
|
"modified": "2016-06-29T08:52:24.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4058.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:24Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c48-da9c-479c-b6dc-450d950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:24.000Z",
|
||
|
"modified": "2016-06-29T08:52:24.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4059.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:24Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c48-1a14-4aed-b047-426d950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:24.000Z",
|
||
|
"modified": "2016-06-29T08:52:24.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4060.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:24Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c48-f808-40af-9923-4b0a950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:24.000Z",
|
||
|
"modified": "2016-06-29T08:52:24.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4061.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:24Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c48-6e94-4cf0-9851-4c0b950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:24.000Z",
|
||
|
"modified": "2016-06-29T08:52:24.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4062.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:24Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c49-a8b8-4c6b-9f96-4294950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:25.000Z",
|
||
|
"modified": "2016-06-29T08:52:25.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4063.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:25Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c49-0040-4316-9d9d-432e950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:25.000Z",
|
||
|
"modified": "2016-06-29T08:52:25.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4064.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:25Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c49-2aec-4cab-a011-4a0e950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:25.000Z",
|
||
|
"modified": "2016-06-29T08:52:25.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4065.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:25Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c49-7f8c-453c-b072-4694950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:25.000Z",
|
||
|
"modified": "2016-06-29T08:52:25.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4066.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:25Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c49-aac4-41f8-bfe8-497d950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:25.000Z",
|
||
|
"modified": "2016-06-29T08:52:25.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4067.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:25Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4a-35c0-41b2-959a-4cce950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:26.000Z",
|
||
|
"modified": "2016-06-29T08:52:26.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4068.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:26Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4a-4f90-47ac-b51d-4ce7950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:26.000Z",
|
||
|
"modified": "2016-06-29T08:52:26.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4069.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:26Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4a-fcc8-4e17-b7fe-4dff950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:26.000Z",
|
||
|
"modified": "2016-06-29T08:52:26.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4070.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:26Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4a-a550-4a14-b6d7-492a950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:26.000Z",
|
||
|
"modified": "2016-06-29T08:52:26.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4071.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:26Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4a-b45c-4462-b509-46e0950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:26.000Z",
|
||
|
"modified": "2016-06-29T08:52:26.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4072.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:26Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4b-ea94-4aa0-8aba-46fc950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:27.000Z",
|
||
|
"modified": "2016-06-29T08:52:27.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4075.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:27Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4b-2044-4a5c-bbbc-409d950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:27.000Z",
|
||
|
"modified": "2016-06-29T08:52:27.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4078.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:27Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4b-fb0c-44cd-9e52-44c0950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:27.000Z",
|
||
|
"modified": "2016-06-29T08:52:27.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4079.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:27Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4b-8314-4dbf-b1fa-4a8a950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:27.000Z",
|
||
|
"modified": "2016-06-29T08:52:27.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4080.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:27Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4b-cb20-44fa-adbe-478c950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:27.000Z",
|
||
|
"modified": "2016-06-29T08:52:27.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4081.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:27Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4c-ce88-4ea0-9196-4c5c950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:28.000Z",
|
||
|
"modified": "2016-06-29T08:52:28.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4082.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:28Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4c-e59c-41a7-ae29-487f950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:28.000Z",
|
||
|
"modified": "2016-06-29T08:52:28.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4083.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:28Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4c-7828-4450-b0e9-47cf950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:28.000Z",
|
||
|
"modified": "2016-06-29T08:52:28.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4084.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:28Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4c-1e20-4881-836a-48a2950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:28.000Z",
|
||
|
"modified": "2016-06-29T08:52:28.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4085.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:28Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4d-f8f8-402c-9f12-4a7a950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:29.000Z",
|
||
|
"modified": "2016-06-29T08:52:29.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4086.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:29Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4d-940c-4a2e-86fd-489b950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:29.000Z",
|
||
|
"modified": "2016-06-29T08:52:29.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4087.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:29Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4d-dfc8-4623-b3ad-4e33950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:29.000Z",
|
||
|
"modified": "2016-06-29T08:52:29.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4088.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:29Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4d-4778-46ff-8c26-4f9d950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:29.000Z",
|
||
|
"modified": "2016-06-29T08:52:29.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4089.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:29Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c4d-7938-4015-a89e-4c0d950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:29.000Z",
|
||
|
"modified": "2016-06-29T08:52:29.000Z",
|
||
|
"description": "Imported via the Freetext Import Tool",
|
||
|
"pattern": "[domain-name:value = 'box4090.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:29Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c6b-f884-4152-b8f2-484d950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:59.000Z",
|
||
|
"modified": "2016-06-29T08:52:59.000Z",
|
||
|
"description": "Infy version 31",
|
||
|
"pattern": "[file:hashes.SHA256 = 'f07e85143e057ee565c25db2a9f36491102d4e526ffb02c83e580712ec00eb27']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:59Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"sha256\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738c6b-c3dc-4fe5-9144-4f78950d210f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:52:59.000Z",
|
||
|
"modified": "2016-06-29T08:52:59.000Z",
|
||
|
"description": "Infy \u00e2\u20ac\u0153M\u00e2\u20ac\u009d version 8.0",
|
||
|
"pattern": "[file:hashes.SHA256 = '583349b7a2385a1e8de682a43351798ca113cbbb80686193ecf9a61e6942786a']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:52:59Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"sha256\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738cc4-18b4-4dbd-bce1-43d702de0b81",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:54:28.000Z",
|
||
|
"modified": "2016-06-29T08:54:28.000Z",
|
||
|
"description": "Infy version 31 - Xchecked via VT: f07e85143e057ee565c25db2a9f36491102d4e526ffb02c83e580712ec00eb27",
|
||
|
"pattern": "[file:hashes.SHA1 = '53e145f8b3be90f11d40d88a2decd80c168610f7']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:54:28Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"sha1\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57738cc4-8dd4-4fc5-ae44-4e8502de0b81",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:54:28.000Z",
|
||
|
"modified": "2016-06-29T08:54:28.000Z",
|
||
|
"description": "Infy version 31 - Xchecked via VT: f07e85143e057ee565c25db2a9f36491102d4e526ffb02c83e580712ec00eb27",
|
||
|
"pattern": "[file:hashes.MD5 = '4053ea6a7aa9cde6d28a85c6d35f8e4d']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2016-06-29T08:54:28Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "observed-data",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "observed-data--57738cc4-beb0-4b72-b853-476102de0b81",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2016-06-29T08:54:28.000Z",
|
||
|
"modified": "2016-06-29T08:54:28.000Z",
|
||
|
"first_observed": "2016-06-29T08:54:28Z",
|
||
|
"last_observed": "2016-06-29T08:54:28Z",
|
||
|
"number_observed": 1,
|
||
|
"object_refs": [
|
||
|
"url--57738cc4-beb0-4b72-b853-476102de0b81"
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"link\"",
|
||
|
"misp:category=\"External analysis\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "url",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "url--57738cc4-beb0-4b72-b853-476102de0b81",
|
||
|
"value": "https://www.virustotal.com/file/f07e85143e057ee565c25db2a9f36491102d4e526ffb02c83e580712ec00eb27/analysis/1463612524/"
|
||
|
},
|
||
|
{
|
||
|
"type": "marking-definition",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
||
|
"created": "2017-01-20T00:00:00.000Z",
|
||
|
"definition_type": "tlp",
|
||
|
"name": "TLP:WHITE",
|
||
|
"definition": {
|
||
|
"tlp": "white"
|
||
|
}
|
||
|
}
|
||
|
]
|
||
|
}
|