misp-circl-feed/feeds/circl/stix-2.1/5e6f46d6-d104-4a35-83e7-965402de0b81.json

349 lines
544 KiB
JSON
Raw Permalink Normal View History

2023-04-21 14:44:17 +00:00
{
"type": "bundle",
"id": "bundle--5e6f46d6-d104-4a35-83e7-965402de0b81",
"objects": [
{
"type": "identity",
"spec_version": "2.1",
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2020-03-16T09:48:32.000Z",
"modified": "2020-03-16T09:48:32.000Z",
"name": "CIRCL",
"identity_class": "organization"
},
{
"type": "report",
"spec_version": "2.1",
"id": "report--5e6f46d6-d104-4a35-83e7-965402de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2020-03-16T09:48:32.000Z",
"modified": "2020-03-16T09:48:32.000Z",
"name": "OSINT - new sample of operation lagtime TA428",
"published": "2020-03-16T09:51:44Z",
"object_refs": [
"indicator--5e6f4721-d150-4db7-9efb-6b9402de0b81",
"indicator--5e6f474b-9a14-4d6d-8a2c-98c202de0b81",
"observed-data--5e6f475d-d114-450e-9c53-6b9502de0b81",
"url--5e6f475d-d114-450e-9c53-6b9502de0b81",
"vulnerability--5e6f47ac-cd60-4de4-8bbf-4b9e02de0b81",
"indicator--04a60462-7d93-465f-9136-a3f7d2345c1b",
"x-misp-object--7448e7a5-3ee5-48cc-9e6e-4a6531d66e24",
"x-misp-object--5e6f4943-b100-4270-95a8-6b9402de0b81",
2024-08-07 08:13:15 +00:00
"relationship--56c414ca-4a45-4ed3-b08e-d40004621efb",
"relationship--b8e1591d-16de-42ba-b152-82be31e990c6",
"relationship--59ceef88-9706-476e-85f5-81a56fad6ecd",
"relationship--680f7cf5-e215-477c-ba69-49ab669e2cef",
"relationship--9680e5df-66c6-4afc-9ad6-1b3c77630525",
"relationship--1236ef10-1486-4c31-8690-290302e0ca4f",
"relationship--e111eb26-0125-42f7-9ac0-e409eb902308"
2023-04-21 14:44:17 +00:00
],
"labels": [
"Threat-Report",
"misp:tool=\"MISP-STIX-Converter\"",
"type:OSINT",
"osint:lifetime=\"perpetual\"",
"osint:certainty=\"50\"",
"misp-galaxy:threat-actor=\"TA428\"",
"misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"",
"misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\""
],
"object_marking_refs": [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5e6f4721-d150-4db7-9efb-6b9402de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2020-03-16T09:30:09.000Z",
"modified": "2020-03-16T09:30:09.000Z",
"description": "rtf royal road",
"pattern": "[file:hashes.MD5 = '08ebd6388b1194ca824199da49ff5769']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2020-03-16T09:30:09Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5e6f474b-9a14-4d6d-8a2c-98c202de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2020-03-16T09:30:51.000Z",
"modified": "2020-03-16T09:30:51.000Z",
"description": "C2",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '103.249.87.72']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2020-03-16T09:30:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5e6f475d-d114-450e-9c53-6b9502de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2020-03-16T09:31:09.000Z",
"modified": "2020-03-16T09:31:09.000Z",
"first_observed": "2020-03-16T09:31:09Z",
"last_observed": "2020-03-16T09:31:09Z",
"number_observed": 1,
"object_refs": [
"url--5e6f475d-d114-450e-9c53-6b9502de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--5e6f475d-d114-450e-9c53-6b9502de0b81",
"value": "https://app.any.run/tasks/8937295d-ea36-4398-96bd-20e7f3b193cb/"
},
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--5e6f47ac-cd60-4de4-8bbf-4b9e02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2020-03-16T09:32:28.000Z",
"modified": "2020-03-16T09:32:28.000Z",
"name": "CVE-2017-11882",
"labels": [
"misp:type=\"vulnerability\"",
"misp:category=\"Payload delivery\""
],
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2017-11882"
}
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--04a60462-7d93-465f-9136-a3f7d2345c1b",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2020-03-16T09:48:32.000Z",
"modified": "2020-03-16T09:48:32.000Z",
"pattern": "[file:hashes.MD5 = '08ebd6388b1194ca824199da49ff5769' AND file:hashes.SHA1 = '0d2fbb6ab0fb1d736a867e51bcd6aff1d7e7c890' AND file:hashes.SHA256 = 'b7bebe92a5802aa922e5719c948e35716f908e67701cfffaeebfcadc7a6e650a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2020-03-16T09:48:32Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "file"
}
],
"labels": [
"misp:name=\"file\"",
"misp:meta-category=\"file\"",
"misp:to_ids=\"True\""
]
},
{
"type": "x-misp-object",
"spec_version": "2.1",
"id": "x-misp-object--7448e7a5-3ee5-48cc-9e6e-4a6531d66e24",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2020-03-16T09:30:18.000Z",
"modified": "2020-03-16T09:30:18.000Z",
"labels": [
"misp:name=\"virustotal-report\"",
"misp:meta-category=\"misc\""
],
"x_misp_attributes": [
{
"type": "datetime",
"object_relation": "last-submission",
"value": "2020-03-13T05:08:55+00:00",
"category": "Other",
"comment": "rtf royal road",
"uuid": "b64a5648-777d-48ef-940a-259e8ddca702"
},
{
"type": "link",
"object_relation": "permalink",
"value": "https://www.virustotal.com/file/b7bebe92a5802aa922e5719c948e35716f908e67701cfffaeebfcadc7a6e650a/analysis/1584076135/",
"category": "Payload delivery",
"comment": "rtf royal road",
"uuid": "45101ff7-1e2a-4871-9d77-450d73b748c6"
},
{
"type": "text",
"object_relation": "detection-ratio",
"value": "10/58",
"category": "Payload delivery",
"comment": "rtf royal road",
"uuid": "0d9d6de4-8d01-4de8-be6f-9bcf3f5d5399"
}
],
"x_misp_meta_category": "misc",
"x_misp_name": "virustotal-report"
},
{
"type": "x-misp-object",
"spec_version": "2.1",
"id": "x-misp-object--5e6f4943-b100-4270-95a8-6b9402de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2020-03-16T09:47:11.000Z",
"modified": "2020-03-16T09:47:11.000Z",
"labels": [
"misp:name=\"microblog\"",
"misp:meta-category=\"misc\""
],
"x_misp_attributes": [
{
"type": "text",
"object_relation": "type",
"value": "Twitter",
"category": "Other",
"uuid": "5e6f4943-31d8-4686-8c7c-6b9402de0b81"
},
{
"type": "text",
"object_relation": "post",
"value": "new sample of operation lagtime TA428\r\n\r\nrtf royal road: 08ebd6388b1194ca824199da49ff5769 \r\n\r\nip: 103.249.87.72\r\n\r\nTarget: Mongolia",
"category": "Other",
"uuid": "5e6f4943-80f8-42a6-bfff-6b9402de0b81"
},
{
"type": "attachment",
"object_relation": "attachment",
"value": "Screenshot 2020-03-16 at 10.38.07.png",
"category": "External analysis",
"uuid": "5e6f4943-9188-49a2-b458-6b9402de0b81",
"data": "iVBORw0KGgoAAAANSUhEUgAABJ4AAASCCAYAAADzByYKAAAMRmlDQ1BJQ0MgUHJvZmlsZQAASImVVwdYU8kWnltSSWiBCEgJvYkiSJcSQosgIFWwEZJAQokxIYjYkUUF1y4iYMOKKLoWQNaKvSyKvT8sqKysiwUbKm9SQFe/9973Tr6598+Zc/5TMvdmBgCdap5UmoPqApAryZPFhQezxqakskhPAAI/ekAfmPL4cik7NjYKQOm//1Pe3YC2UK66KLl+nv+voicQyvkAILEQpwvk/FyI9wOAF/OlsjwAiN5Qbz01T6rE4yE2kMEEIZYqcaYaFytxuhpXqGwS4jgQ7wSATOPxZJkAaDdBPSufnwl5tG9B7CoRiCUA6JAhDuCLeAKIIyAekps7WYmhHXBI/44n8x+c6QOcPF7mAFbXohJyiFguzeFN+z/b8b8lN0fRH8MODppIFhGnrBn27Vb25EglpkHcJUmPjoFYH+IPYoHKHmKUKlJEJKrtUVO+nAN7BpgQuwp4IZEQm0IcJsmJjtLo0zPEYVyI4QpBC8R53ASN7wKhPDRew1ktmxwX048zZBy2xreeJ1PFVdqfVGQnsjX8t0RCbj//20JRQrI6Z4yaL06KhlgbYqY8Oz5SbYPZFIo40f02MkWcMn8biH2FkvBgNT82MUMWFqexl+XK++vFFojE3GgNrswTJURoeHbyear8jSBuEkrYif08QvnYqP5aBMKQUHXt2GWhJFFTL9YuzQuO0/i+lubEauxxqjAnXKm3gthUnh+v8cUD8uCCVPPj0dK82AR1nnh6Fm9UrDofvABEAQ4IASyggCMdTAZZQNza1dgFv6lnwgAPyEAmEAIXjabfI1k1I4HXeFAI/oJICOQDfsGqWSHIh/ovA1r11QVkqGbzVR7Z4CnEuSAS5MDvCpWXZCBaEngCNeKfovNhrjlwKOd+1rGhJkqjUfTzsnT6LYmhxBBiBDGM6Iib4AG4Hx4Fr0FwuOHeuE9/tt/sCU8JbYRHhOuEdsLtSeIi2Q/1sMBo0A4jhGlqTv++ZtwOsnrgwbg/5IfcOBM3AS74CBiJjQfC2B5Qy9Fkrqz+R+5/1PBd1zV2FFcKShlECaI4/Oip7aTtMcCi7On3HVLnmj7QV87AzI/xOd91WgDvkT9aYguwfdgZ7Dh2DjuENQIWdhRrwi5ih5V4YBU9Ua2i/mhxqnyyIY/4p3g8TUxlJ+Wuda6drp/Vc3nCAuX7EXAmS6fJxJmiPBYbvvmFLK6EP3QIy83VzRUA5f+I+jX1hqn6f0CY57/p5nkB4F/c19d36JsucgsA+1IAoF77prP/CN/F1gCcXcdXyPLVOlx5IQAq0IFPlDEwB9bAAdbjBjyBHwgCoWAUiAEJIAVMhF0WwfUsA1PBDDAXlIAysBSsApVgPdgEtoNdYC9oBIfAcXAaXACXwXVwF66eDvACdIN3oBdBEBJCRxiIMWKB2CLOiBvijQQgoUgUEoekIGlIJiJBFMgMZB5ShixHKpGNSC3yG3IQOY6cQ9qQ28hDpBN5jXxCMZSGGqBmqB06DPVG2WgkmoBOQDPRKWghWowuRivQGnQn2oAeRy+g19F29AXagwFMC2NilpgL5o1xsBgsFcvAZNgsrBQrx2qweqwZ/s5XsXasC/uIE3EGzsJd4AqOwBNxPj4Fn4Uvwivx7XgDfhK/ij/Eu/GvBDrBlOBM8CVwCWMJmYSphBJCOWEr4QDhFHyaOgjviEQik2hP9IJPYwoxiziduIi4lribeIzYRnxM7CGRSMYkZ5I/KYbEI+WRSkhrSDtJR0lXSB2kD2QtsgXZjRxGTiVLyEXkcvIO8hHyFfIzci9Fl2JL8aXEUASUaZQllM2UZsolSgell6pHtaf6UxOoWdS51ApqPfUU9R71jZaWlpWWj9YYLbHWHK0KrT1aZ7Uean2k6dOcaBzaeJqCtpi2jXaMdpv2hk6n29GD6Kn0PPpiei39BP0B/YM2Q3uoNldboD1bu0q7QfuK9ksdio6tDltnok6hTrnOPp1LOl26FF07XY4uT3eWbpXuQd2buj16DL3hejF6uXqL9HbondN7rk/St9MP1RfoF+tv0j+h/5iBMawZHAafMY+xmXGK0WFANLA34BpkGZQZ7DJoNeg21DccYZhkWGBYZXjYsJ2JMe2YXGYOcwlzL/MG89Mgs0HsQcJBCwfVD7oy6L3RYKMgI6FRqdFuo+tGn4xZxqHG2cbLjBuN75vgJk4mY0ymmqwzOWXSNdhgsN9g/uDSwXsH3zFFTZ1M40ynm24yvWjaY2ZuFm4mNVtjdsKsy5xpHmSeZb7S/Ih5pwXDIsBCbLHS4qjFnyxDFpuVw6pgnWR1W5paRlgqLDdatlr2WtlbJVoVWe22um9Ntfa2zrBead1i3W1jYTPaZoZNnc0dW4qtt63IdrXtGdv3dvZ2yXbz7Rrtntsb2XPtC+3r7O850B0CHaY41DhccyQ6ejtmO651vOyEOnk4iZyqnC45o86ezmLntc5tQwhDfIZIhtQMuelCc2G75LvUuTwcyhwaNbRoaOPQl8NshqUOWzbszLCvrh6uOa6bXe8O1x8+anjR8Obhr92c3PhuVW7X3OnuYe6z3ZvcX41wHiEcsW7ELQ+Gx2iP+R4tHl88vTxlnvWenV42Xmle1V43vQ28Y70XeZ/1IfgE+8z2OeTz0dfTN893r+/ffi5+2X47/J6PtB8pHLl55GN/K3+e/0b/9gBWQFrAhoD2QMtAXmBN4KMg6yBB0NagZ2xHdhZ7J/tlsGuwLPhA8HuOL2cm51gIFhIeUhrSGqofmhhaGfogzCosM6wurDvcI3x6+LEIQkRkxLKIm1wzLp9by+0e5TVq5qiTkbTI+MjKyEdRTlGyqObR6OhRo1eMvhdtGy2JbowBMdyYFTH3Y+1jp8T+PoY4JnZM1ZinccPjZsSdiWfET4rfEf8uIThhScLdRIdERWJLkk7S+KTapPfJIcnLk9vHDhs7c+yFFJMUcUpTKik1KXVras+40HGrxnWM9xhfMv7GBPsJBRPOTTSZmDPx8CSdSbxJ+9IIaclpO9I+82J4NbyedG56dXo3n8NfzX8hCBKsFHQK/YXLhc8y/DOWZzzP9M9ckdkpChSVi7rEHHGl+FVWRNb6rPfZMdnbsvtyknN255Jz03IPSvQl2ZKTk80nF0xukzpLS6TtU3ynrJrSLYuUbZUj8gnypjwDuGG/qHBQ/KJ4mB+QX5X/YWrS1H0FegWSgovTnKYtnPasMKxwy3R8On96ywzLGXNnPJzJnrlxFjIrfVbLbOvZxbM75oTP2T6XOjd77h9FrkXLi97OS57XXGxWPKf48S/hv9SVaJfISm7O95u/fgG+QLygdaH7wjULv5YKSs+XuZaVl31exF90/tfhv1b82rc4Y3HrEs8l65YSl0qW3lgWuGz7cr3lhcsfrxi9omEla2XpyrerJq06Vz6ifP1q6mrF6vaKqIqmNTZrlq75XCmqvF4VXLW72rR6YfX7tYK1V9YFratfb7a+bP2nDeINtzaGb2yosasp30TclL/p6eakzWe2eG+p3WqytWzrl22Sbe3b47afrPWqrd1humNJHVqnqOvcOX7n5V0hu5rqXeo37mbuLtsD9ij2/Plb2m839kbubdnnva9+v+3+6gOMA6UNSMO0hu5GUWN7U0pT28FRB1ua/ZoP/D70922HLA9VHTY8vOQI9Ujxkb6jhUd7jkmPdR3PPP64ZVLL3RNjT1w7OeZk66nIU2dPh50+cYZ95uhZ/7OHzvmeO3je+3zjBc8LDRc9Lh74w+OPA62erQ2XvC41Xfa53Nw2su3IlcArx6+GXD19jXvtwvXo6203Em/cujn+Zvstwa3nt3Nuv7qTf6f37px7hHul93Xvlz8wfVDzL8d/7W73bD/8MOThxUfxj+4+5j9+8UT+5HNH8VP60/JnFs9qn7s9P9QZ1nn5z3F/dryQvujtKvlL76/qlw4v9/8d9PfF7rHdHa9kr/peL3pj/Gbb2xFvW3piex68y33X+770g/GH7R+9P575lPzpWe/Uz6TPFV8cvzR/jfx6ry
},
{
"type": "text",
"object_relation": "username",
"value": "Sebdraven",
"category": "Other",
"uuid": "5e6f4943-336c-40cf-b236-6b9402de0b81"
},
{
"type": "text",
"object_relation": "state",
"value": "Informative",
"category": "Other",
"uuid": "5e6f4943-f268-46ee-8bfd-6b9402de0b81"
},
{
"type": "text",
"object_relation": "verified-username",
"value": "Unknown",
"category": "Other",
"uuid": "5e6f4943-8ad0-4b36-bf9f-6b9402de0b81"
}
],
"x_misp_meta_category": "misc",
"x_misp_name": "microblog"
},
{
"type": "relationship",
"spec_version": "2.1",
2024-08-07 08:13:15 +00:00
"id": "relationship--56c414ca-4a45-4ed3-b08e-d40004621efb",
2023-04-21 14:44:17 +00:00
"created": "2020-03-16T09:30:18.000Z",
"modified": "2020-03-16T09:30:18.000Z",
"relationship_type": "analysed-with",
"source_ref": "indicator--04a60462-7d93-465f-9136-a3f7d2345c1b",
"target_ref": "x-misp-object--7448e7a5-3ee5-48cc-9e6e-4a6531d66e24"
},
{
"type": "relationship",
"spec_version": "2.1",
2024-08-07 08:13:15 +00:00
"id": "relationship--b8e1591d-16de-42ba-b152-82be31e990c6",
2023-04-21 14:44:17 +00:00
"created": "2020-03-16T09:48:00.000Z",
"modified": "2020-03-16T09:48:00.000Z",
"relationship_type": "abuses",
"source_ref": "indicator--04a60462-7d93-465f-9136-a3f7d2345c1b",
"target_ref": "vulnerability--5e6f47ac-cd60-4de4-8bbf-4b9e02de0b81"
},
{
"type": "relationship",
"spec_version": "2.1",
2024-08-07 08:13:15 +00:00
"id": "relationship--59ceef88-9706-476e-85f5-81a56fad6ecd",
2023-04-21 14:44:17 +00:00
"created": "2020-03-16T09:48:31.000Z",
"modified": "2020-03-16T09:48:31.000Z",
"relationship_type": "same-as",
"source_ref": "indicator--04a60462-7d93-465f-9136-a3f7d2345c1b",
"target_ref": "indicator--5e6f4721-d150-4db7-9efb-6b9402de0b81"
},
{
"type": "relationship",
"spec_version": "2.1",
2024-08-07 08:13:15 +00:00
"id": "relationship--680f7cf5-e215-477c-ba69-49ab669e2cef",
2023-04-21 14:44:17 +00:00
"created": "2020-03-16T09:45:11.000Z",
"modified": "2020-03-16T09:45:11.000Z",
"relationship_type": "references",
"source_ref": "x-misp-object--5e6f4943-b100-4270-95a8-6b9402de0b81",
"target_ref": "observed-data--5e6f475d-d114-450e-9c53-6b9502de0b81"
},
{
"type": "relationship",
"spec_version": "2.1",
2024-08-07 08:13:15 +00:00
"id": "relationship--9680e5df-66c6-4afc-9ad6-1b3c77630525",
2023-04-21 14:44:17 +00:00
"created": "2020-03-16T09:45:58.000Z",
"modified": "2020-03-16T09:45:58.000Z",
"relationship_type": "abuses",
"source_ref": "x-misp-object--5e6f4943-b100-4270-95a8-6b9402de0b81",
"target_ref": "indicator--5e6f4721-d150-4db7-9efb-6b9402de0b81"
},
{
"type": "relationship",
"spec_version": "2.1",
2024-08-07 08:13:15 +00:00
"id": "relationship--1236ef10-1486-4c31-8690-290302e0ca4f",
2023-04-21 14:44:17 +00:00
"created": "2020-03-16T09:46:20.000Z",
"modified": "2020-03-16T09:46:20.000Z",
"relationship_type": "references",
"source_ref": "x-misp-object--5e6f4943-b100-4270-95a8-6b9402de0b81",
"target_ref": "indicator--5e6f474b-9a14-4d6d-8a2c-98c202de0b81"
},
{
"type": "relationship",
"spec_version": "2.1",
2024-08-07 08:13:15 +00:00
"id": "relationship--e111eb26-0125-42f7-9ac0-e409eb902308",
2023-04-21 14:44:17 +00:00
"created": "2020-03-16T09:47:11.000Z",
"modified": "2020-03-16T09:47:11.000Z",
"relationship_type": "references",
"source_ref": "x-misp-object--5e6f4943-b100-4270-95a8-6b9402de0b81",
"target_ref": "indicator--5e6f4721-d150-4db7-9efb-6b9402de0b81"
},
{
"type": "marking-definition",
"spec_version": "2.1",
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
"created": "2017-01-20T00:00:00.000Z",
"definition_type": "tlp",
"name": "TLP:WHITE",
"definition": {
"tlp": "white"
}
}
]
}