misp-circl-feed/feeds/circl/misp/56e2a7d9-097c-4fae-9f76-4cac950d210f.json

5580 lines
1.6 MiB
JSON
Raw Normal View History

2023-04-21 13:25:09 +00:00
{
2023-06-14 17:31:25 +00:00
"type": "bundle",
"id": "bundle--56e2a7d9-097c-4fae-9f76-4cac950d210f",
"objects": [
{
"type": "identity",
"spec_version": "2.1",
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:30.000Z",
"modified": "2016-03-11T15:45:30.000Z",
"name": "CIRCL",
"identity_class": "organization"
},
{
"type": "report",
"spec_version": "2.1",
"id": "report--56e2a7d9-097c-4fae-9f76-4cac950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:30.000Z",
"modified": "2016-03-11T15:45:30.000Z",
"name": "Malspam (2016-03-11) - Locky",
"published": "2016-03-11T16:04:10Z",
"object_refs": [
"indicator--56e2ac38-39a8-41d1-8be4-4416950d210f",
"indicator--56e2ac39-d3d0-4638-b112-4a8a950d210f",
"indicator--56e2ac3a-5894-466e-972d-404f950d210f",
"indicator--56e2ac3a-7b9c-4adc-b36a-4e25950d210f",
"indicator--56e2ac3b-9efc-4073-81f1-4636950d210f",
"indicator--56e2ac3c-f35c-43ed-8cfc-43e2950d210f",
"indicator--56e2ac3c-ef60-48e3-9ffe-4923950d210f",
"indicator--56e2ac3d-6358-4eb8-9df9-493b950d210f",
"indicator--56e2ac3d-82f0-42ce-ba4a-40c2950d210f",
"indicator--56e2ac3e-3b5c-4f79-8e8f-4184950d210f",
"indicator--56e2ac3e-ca78-49f5-903c-44b0950d210f",
"indicator--56e2ac3f-1488-4cd6-9b86-450c950d210f",
"indicator--56e2ac40-fea8-45df-8079-41ea950d210f",
"indicator--56e2ac40-dc0c-4157-9cdb-444f950d210f",
"indicator--56e2ac41-d3e0-4f62-9c2d-402b950d210f",
"indicator--56e2ac42-4590-4f1b-8b53-47e7950d210f",
"indicator--56e2ac42-24b0-4a9a-8c7d-4cfb950d210f",
"indicator--56e2ac43-d7d4-42fa-82d2-4b14950d210f",
"indicator--56e2ac44-3098-4b9a-9bf2-4102950d210f",
"indicator--56e2ac44-11ac-48f6-8043-4185950d210f",
"indicator--56e2ac45-4514-47bc-86f7-4f23950d210f",
"indicator--56e2ac45-25f0-40a0-9a4c-4617950d210f",
"indicator--56e2ac46-0644-43c3-b122-42c1950d210f",
"indicator--56e2ac47-ac04-48ad-a155-4f30950d210f",
"indicator--56e2ac47-d58c-4b58-80aa-416d950d210f",
"indicator--56e2ac48-75c0-48eb-8b06-4338950d210f",
"indicator--56e2ac49-88bc-4260-bcff-4a51950d210f",
"indicator--56e2ac49-c420-4803-8d06-40df950d210f",
"indicator--56e2ac4a-6a30-4e6d-b15b-4083950d210f",
"indicator--56e2ac4b-6d08-49bf-937d-4959950d210f",
"indicator--56e2ac4c-6a2c-408c-98ba-4cdf950d210f",
"indicator--56e2ac4c-4f40-4b67-9169-40dc950d210f",
"indicator--56e2ac4d-1778-45ec-af39-4505950d210f",
"indicator--56e2ac4e-dabc-4cd8-b85c-44fe950d210f",
"indicator--56e2ac4e-a798-4102-9e7c-432e950d210f",
"indicator--56e2ac4f-3d04-4d29-bfb4-40d7950d210f",
"indicator--56e2ac50-7168-4011-b461-497f950d210f",
"indicator--56e2ac50-fe54-4a2f-837b-4af2950d210f",
"indicator--56e2ac51-8020-45bd-b682-4f53950d210f",
"indicator--56e2ac52-0a58-4b48-a9d2-44b8950d210f",
"indicator--56e2ac53-4658-4e50-b0b8-4c9c950d210f",
"indicator--56e2ac53-8e84-49e1-a89d-4bb8950d210f",
"indicator--56e2ac54-51fc-4f4b-b1c3-4eaa950d210f",
"indicator--56e2ac55-5e24-4fd8-96c2-4ebd950d210f",
"indicator--56e2ac55-db88-41fd-977e-4446950d210f",
"indicator--56e2ac56-c4a0-4094-9b6c-4a7f950d210f",
"indicator--56e2ac57-ae74-48d1-bc97-4587950d210f",
"indicator--56e2ac58-ca98-44bc-95ef-49ed950d210f",
"indicator--56e2b14f-a034-4bc3-9c63-44c0950d210f",
"indicator--56e2b150-6e1c-45a3-b3ed-4b72950d210f",
"indicator--56e2b150-88dc-4239-a181-408d950d210f",
"indicator--56e2b150-e014-4d8c-93f9-48c5950d210f",
"indicator--56e2b151-f3a8-4873-8183-4923950d210f",
"indicator--56e2b151-0e84-4584-83fa-4b8f950d210f",
"indicator--56e2b151-0250-43cd-a7a9-4e47950d210f",
"indicator--56e2b152-9b18-44e3-904d-47db950d210f",
"indicator--56e2b152-53ec-4090-b45b-4de7950d210f",
"indicator--56e2b152-9fd0-4f47-b981-475a950d210f",
"indicator--56e2b153-b11c-4350-8b52-42ba950d210f",
"indicator--56e2b153-6520-45de-b98c-4003950d210f",
"indicator--56e2b153-0c98-49fb-8ddb-4ecf950d210f",
"indicator--56e2b154-25bc-4a8f-bd49-45de950d210f",
"indicator--56e2b154-cbe4-4334-967e-4776950d210f",
"indicator--56e2b154-4d78-4adf-8e3a-4df9950d210f",
"indicator--56e2b155-771c-4070-8f9a-4c67950d210f",
"indicator--56e2b155-6650-4c91-a620-4303950d210f",
"indicator--56e2b155-a4dc-482e-be29-45a5950d210f",
"indicator--56e2b156-2e98-484e-82b1-4a63950d210f",
"indicator--56e2b156-b1d0-415d-aef9-40b2950d210f",
"indicator--56e2b157-4a10-4863-aa46-40e3950d210f",
"indicator--56e2b157-6e24-4980-8e7b-49cc950d210f",
"indicator--56e2b157-8514-4d3f-ba36-4237950d210f",
"indicator--56e2b499-dfac-42df-97fa-475d950d210f",
"indicator--56e2b499-202c-4307-9822-4d46950d210f",
"indicator--56e2b49a-96c8-429f-b1a7-4c60950d210f",
"indicator--56e2b49a-eed4-4f01-a575-462a950d210f",
"indicator--56e2b49a-8af8-4f1c-ac7c-4a87950d210f",
"indicator--56e2b49b-2d40-467d-9651-40f9950d210f",
"indicator--56e2b49b-cedc-43a5-bc35-4e70950d210f",
"indicator--56e2b49b-dd28-4d28-9478-41cf950d210f",
"indicator--56e2b49c-f9a8-4c29-90f3-41d9950d210f",
"indicator--56e2b49c-385c-4042-9595-41ae950d210f",
"indicator--56e2b49c-1c68-4cce-ab60-482a950d210f",
"indicator--56e2b49d-a158-41e4-bb2a-4185950d210f",
"indicator--56e2b49d-22d0-4129-9579-4468950d210f",
"indicator--56e2b49d-1d98-45ed-8077-4ed7950d210f",
"indicator--56e2b532-03d8-421b-8041-46bc950d210f",
"indicator--56e2b533-43f8-4a6a-8ffa-417e950d210f",
"indicator--56e2b534-a7f0-4508-b006-4c87950d210f",
"observed-data--56e2b581-9200-49b9-994d-4cb8950d210f",
"email-message--56e2b581-9200-49b9-994d-4cb8950d210f",
"x-misp-attribute--56e2b630-c57c-4fd5-bbda-4cb0950d210f",
"observed-data--56e2c2aa-b95c-4d86-bb2a-482e02de0b81",
"url--56e2c2aa-b95c-4d86-bb2a-482e02de0b81",
"observed-data--56e2c2aa-e180-4caa-897d-463f02de0b81",
"url--56e2c2aa-e180-4caa-897d-463f02de0b81",
"observed-data--56e2c2aa-7f0c-4cc1-93d1-450402de0b81",
"url--56e2c2aa-7f0c-4cc1-93d1-450402de0b81",
"observed-data--56e2c2ab-2b30-4777-812c-4eda02de0b81",
"url--56e2c2ab-2b30-4777-812c-4eda02de0b81",
"observed-data--56e2c2ab-73d4-4f41-83f1-414a02de0b81",
"url--56e2c2ab-73d4-4f41-83f1-414a02de0b81",
"observed-data--56e2c2ab-d2d8-4511-be39-4cbb02de0b81",
"url--56e2c2ab-d2d8-4511-be39-4cbb02de0b81",
"observed-data--56e2c2ab-db08-4c8b-b084-46c702de0b81",
"url--56e2c2ab-db08-4c8b-b084-46c702de0b81",
"observed-data--56e2c2ac-7c10-4aad-81e7-474f02de0b81",
"url--56e2c2ac-7c10-4aad-81e7-474f02de0b81",
"observed-data--56e2c2ac-c8cc-4b5a-8e77-4e0d02de0b81",
"url--56e2c2ac-c8cc-4b5a-8e77-4e0d02de0b81",
"observed-data--56e2c2ac-e6e4-4852-a5dd-408f02de0b81",
"url--56e2c2ac-e6e4-4852-a5dd-408f02de0b81",
"observed-data--56e2c2ad-b018-4b87-b7f4-4c8f02de0b81",
"url--56e2c2ad-b018-4b87-b7f4-4c8f02de0b81",
"indicator--56e2c7e8-e5a8-4253-9e40-659a950d210f",
"indicator--56e2e28a-df44-4bb4-9639-4963950d210f",
"indicator--56e2e28a-c9c4-4a5c-8233-4e96950d210f",
"indicator--56e2e28b-fda0-4646-92b2-4949950d210f",
"indicator--56e2e28b-dbe0-4a9b-b945-4c48950d210f",
"indicator--56e2e28b-fb9c-4fc2-9e88-4b19950d210f",
"indicator--56e2e28c-7618-4c0f-b8b3-49eb950d210f",
"indicator--56e2e28c-65c4-4e05-be5b-4b1c950d210f",
"indicator--56e2e28c-05d4-4a82-bf81-4fc6950d210f",
"indicator--56e2e28d-3ffc-477f-8d56-45d6950d210f",
"indicator--56e2e28d-891c-496d-807f-44c6950d210f",
"indicator--56e2e28d-0600-4256-8ab0-43f3950d210f",
"indicator--56e2e28e-ae88-4e78-a71b-4e89950d210f",
"indicator--56e2e28e-a25c-45b1-86ae-49a2950d210f",
"indicator--56e2e28e-3c78-437a-8450-45e3950d210f",
"indicator--56e2e28f-3c24-4fde-aa11-42db950d210f",
"indicator--56e2e28f-51c8-42b5-bf77-44e6950d210f",
"indicator--56e2e28f-1768-4708-b90d-4c56950d210f",
"indicator--56e2e290-f488-4401-926a-435f950d210f",
"indicator--56e2e290-44c0-44b9-b7b4-41e3950d210f",
"indicator--56e2e290-a5b0-4a52-b16b-4f68950d210f",
"indicator--56e2e291-34ac-47bd-adec-452c950d210f",
"indicator--56e2e291-2040-4585-95fa-49f1950d210f",
"indicator--56e2e291-b680-4dc9-a834-4157950d210f",
"indicator--56e2e291-6570-4e8e-b78b-4c1f950d210f",
"indicator--56e2e292-a914-4098-8246-49c7950d210f",
"indicator--56e2e292-60d8-48db-a50e-4465950d210f",
"indicator--56e2e2d6-4038-45aa-b53e-4bbd950d210f",
"indicator--56e2e2d7-f160-4368-a077-4110950d210f",
"indicator--56e2e2d7-3384-49cb-a21e-468e950d210f",
"indicator--56e2e2d8-afec-413a-b785-4784950d210f",
"indicator--56e2e2d9-08ac-4a2c-9341-4079950d210f",
"indicator--56e2e2d9-4668-42b0-a2b7-4af5950d210f",
"indicator--56e2e2da-31b4-414d-9782-4452950d210f",
"indicator--56e2e2db-d840-45f8-86e7-4caf950d210f",
"indicator--56e2e2db-d55c-4a2d-953e-4127950d210f",
"indicator--56e2e2dc-cf78-4df3-8251-4363950d210f",
"indicator--56e2e2dc-3278-4e9d-965c-4021950d210f",
"indicator--56e2e2dd-f6e4-4427-8fd3-41c5950d210f",
"indicator--56e2e2de-34a0-42f5-8264-46fe950d210f",
"indicator--56e2e2de-dfd8-417a-9922-480c950d210f",
"indicator--56e2e2df-c8d0-4383-a2db-4410950d210f",
"indicator--56e2e2e0-a4ec-40ae-a40f-4f28950d210f",
"indicator--56e2e2e0-e8c8-4089-a3ad-4966950d210f",
"indicator--56e2e2e1-f398-4716-a679-4ca8950d210f",
"indicator--56e2e2e2-b448-48b5-999c-48f7950d210f",
"indicator--56e2e2e2-e8c4-46c4-9832-49c3950d210f",
"indicator--56e2e2e3-dc10-42dc-a566-46a1950d210f",
"indicator--56e2e2e4-e4bc-47c3-ac6f-4240950d210f",
"indicator--56e2e2e4-bc2c-4748-9dc5-482e950d210f",
"indicator--56e2e2e5-9074-42cc-a04d-4c4b950d210f",
"indicator--56e2e2e6-3c7c-4112-8d63-4844950d210f",
"indicator--56e2e2e6-6210-4141-b937-47b4950d210f",
"indicator--56e2e2e7-d8b8-4c6d-98e4-4ae1950d210f",
"indicator--56e2e2e8-d23c-4199-8dfd-462e950d210f",
"indicator--56e2e2e8-7d60-4215-bf9d-41a9950d210f",
"indicator--56e2e2e9-f314-4fac-b5a0-4e0d950d210f",
"indicator--56e2e2ea-74e4-42be-bf82-4e3d950d210f",
"indicator--56e2e2ea-fe64-4704-b7f6-40c4950d210f",
"indicator--56e2e2eb-e60c-4d85-85e6-40c2950d210f",
"indicator--56e2e2ec-a794-4820-b42c-4caa950d210f",
"indicator--56e2e2ed-b874-4cf2-8cb4-4f6d950d210f",
"indicator--56e2e2ed-c398-4414-aee0-40d8950d210f",
"indicator--56e2e2ee-0d40-4330-9104-4174950d210f",
"indicator--56e2e2ef-2ed8-49ab-8edf-4790950d210f",
"indicator--56e2e2ef-93f0-4b5c-a152-4468950d210f",
"indicator--56e2e2f0-bce4-461b-8ba4-4225950d210f",
"indicator--56e2e2f1-4c4c-4617-918f-462e950d210f",
"indicator--56e2e2f1-ef5c-4882-bbcd-4545950d210f",
"indicator--56e2e4de-52b0-43e6-bc64-4ed4950d210f",
"indicator--56e2e4df-20a8-4f3f-815e-44b9950d210f",
"indicator--56e2e4df-69f8-45a7-97b5-4908950d210f",
"indicator--56e2e4e0-3314-4509-8c2c-4926950d210f",
"indicator--56e2e4e1-f5e4-414b-9e0f-4757950d210f",
"indicator--56e2e4e1-a0f8-4714-a3d8-458a950d210f",
"indicator--56e2e4e2-0bd8-456b-94ed-48bc950d210f",
"indicator--56e2e4e3-b330-4ab1-b91a-4ab8950d210f",
"indicator--56e2e4e3-7934-49f6-b4f8-4f37950d210f",
"indicator--56e2e4e4-7940-47cd-af34-47cb950d210f",
"indicator--56e2e4e5-1d54-445c-b5af-41e5950d210f",
"indicator--56e2e4e6-f568-404b-937e-40ff950d210f",
"indicator--56e2e4e6-5dbc-49bc-a644-449a950d210f",
"indicator--56e2e4e7-3cfc-462a-8ac2-4153950d210f",
"indicator--56e2e4e8-70c4-4cf3-a85d-4029950d210f",
"indicator--56e2e4e8-cda4-43ff-b0d7-4202950d210f",
"indicator--56e2e4e9-8c68-4618-a45e-4be4950d210f",
"indicator--56e2e4ea-d720-48ef-b2a2-4f6f950d210f",
"indicator--56e2e4eb-9d58-469b-abc6-4446950d210f",
"indicator--56e2e4eb-c684-47f4-b3b3-4e8d950d210f",
"indicator--56e2e4ec-7d24-4e5d-9a92-429b950d210f",
"indicator--56e2e6d5-0d80-4eeb-972a-4b00950d210f",
"observed-data--56e2e81a-90a8-4300-b1ca-4f9402de0b81",
"url--56e2e81a-90a8-4300-b1ca-4f9402de0b81",
"observed-data--56e2e81b-aa00-4883-98ed-40b402de0b81",
"url--56e2e81b-aa00-4883-98ed-40b402de0b81",
"observed-data--56e2e81b-4200-4cdd-bc5f-4cc602de0b81",
"url--56e2e81b-4200-4cdd-bc5f-4cc602de0b81",
"observed-data--56e2e81b-2068-4856-b447-42ca02de0b81",
"url--56e2e81b-2068-4856-b447-42ca02de0b81",
"observed-data--56e2e81c-64c0-4eaf-914f-4fde02de0b81",
"url--56e2e81c-64c0-4eaf-914f-4fde02de0b81",
"observed-data--56e2e81c-fbd8-4201-b674-408602de0b81",
"url--56e2e81c-fbd8-4201-b674-408602de0b81",
"observed-data--56e2e81c-ecf8-4462-a8d1-4cd502de0b81",
"url--56e2e81c-ecf8-4462-a8d1-4cd502de0b81",
"observed-data--56e2e81c-dea8-4f73-bab3-402f02de0b81",
"url--56e2e81c-dea8-4f73-bab3-402f02de0b81",
"observed-data--56e2e81d-2fc4-4455-b59c-47ec02de0b81",
"url--56e2e81d-2fc4-4455-b59c-47ec02de0b81",
"observed-data--56e2e81d-80a8-4b36-8ed0-426a02de0b81",
"url--56e2e81d-80a8-4b36-8ed0-426a02de0b81",
"observed-data--56e2e81d-1500-465f-ad9c-480902de0b81",
"url--56e2e81d-1500-465f-ad9c-480902de0b81",
"observed-data--56e2e81e-acac-4460-9953-408702de0b81",
"url--56e2e81e-acac-4460-9953-408702de0b81",
"observed-data--56e2e81e-9090-4007-aa56-441802de0b81",
"url--56e2e81e-9090-4007-aa56-441802de0b81",
"observed-data--56e2e81e-c780-43b2-b23b-4f4002de0b81",
"url--56e2e81e-c780-43b2-b23b-4f4002de0b81",
"observed-data--56e2e81f-73f8-46f7-a777-422602de0b81",
"url--56e2e81f-73f8-46f7-a777-422602de0b81",
"observed-data--56e2e81f-6094-404e-84ab-411702de0b81",
"url--56e2e81f-6094-404e-84ab-411702de0b81",
"observed-data--56e2e81f-3584-4a61-be41-469a02de0b81",
"url--56e2e81f-3584-4a61-be41-469a02de0b81",
"observed-data--56e2e81f-7d6c-45fb-9b37-472902de0b81",
"url--56e2e81f-7d6c-45fb-9b37-472902de0b81",
"observed-data--56e2e820-1ba8-4942-a756-4be502de0b81",
"url--56e2e820-1ba8-4942-a756-4be502de0b81",
"observed-data--56e2e820-da2c-468b-b1bd-410902de0b81",
"url--56e2e820-da2c-468b-b1bd-410902de0b81",
"observed-data--56e2e820-09f0-4552-b12a-440902de0b81",
"url--56e2e820-09f0-4552-b12a-440902de0b81",
"observed-data--56e2e821-9d78-4838-b5e6-408f02de0b81",
"url--56e2e821-9d78-4838-b5e6-408f02de0b81",
"observed-data--56e2e821-095c-4a0b-b4ef-4f5a02de0b81",
"url--56e2e821-095c-4a0b-b4ef-4f5a02de0b81",
"observed-data--56e2e821-9934-4c65-89a8-470802de0b81",
"url--56e2e821-9934-4c65-89a8-470802de0b81",
"indicator--56e2eb45-a1e4-44ed-81e4-40c3950d210f",
"indicator--56e2eb48-5f18-4a0a-b81c-6599950d210f",
"indicator--56e2eb49-9c00-4b81-811e-4f32950d210f",
"indicator--56e2eb4b-3ee0-4eaa-9e3f-410c950d210f"
],
"labels": [
"Threat-Report",
"misp:tool=\"MISP-STIX-Converter\"",
"circl:incident-classification=\"malware\""
],
"object_marking_refs": [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac38-39a8-41d1-8be4-4416950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMBba0hYYNh7VAoAALcVAAAgABwAMGI4ZjRmM2Q1NTRhMTFhZTRlMzMxZTBlZmI3YTZjN2NVVAkAAzis4lY4rOJWdXgLAAEEIQAAAAQhAAAAIjYWnb4VxyJ0JpW1myzXtfLqdKEGKTySwBKJdqkWKMuPvTgdY+q2uds6kGy3PIyrcARg8oYpDMig9fObXtiuDyWMyiQ1tnytq5fqp+qo2YZ7mOnLjP6EK+4DYRHWPMO/3fLRqc+s5MDYp+8nJpmhASbgGhcvOXAz7zOo4eaR+uCe2q7Z39UCZSVwjQ+0AHZ8SAzrmyV1rnVZ3PhstjBHwUVHcBVfiNkz7bepYxl8mofGekf0NkWVVrYY024gv8fTvSdE1qE9k6QIK2r4IlsFD3YfU36+onhNDr3EXKdw7eRr1z4B6u44t3PaSSBtInX4PNvT45o7x0Nv9429JYlGWKzu4K+ucDKnGLPbUESogLNB18K5xHXIm1sHkA6w+Rjrx30sLXS/SUsixiFrC02iDe/oIAUKwQvRlmWx/sC5m7SdhASKJlILVCH+eeWqK6gqPYJuAn0vwn5BAKM7VjEAROR07vvIV+CLyy7XpWXGDLyqQYuyO++4pWTtXiyChfBPyt46aOkjuMsf0KV1xFqJ+h1eGi/cgt7aj9npend+PiVL+MEEjH4awByEWcjMOoJyJv1TliRXEZZJarYS1p1VnsGnt9OadOlsUF3Aj3+LJ6alcpOli7YpKwYNy5eDtDalNh3ndt6TkG8y91pTJjtR67/2n/Lz74Wb1Tt8dZUy3Bcy8etzsse0F2F2AQOMPWW0qFna5RImRn7FD0gCV6vOQRoaTaOVkAHgqzfMyK9Q4qc+1I1M8PYRsN6CrBegwNkeUx/GaYyuTSv7HMn27TTNwOA6IDoXEyzSvZ73n827CU1DlX8MCvir21y0SYySo+TWoZNLFLyAD1bnjqU3PD0Qvi8iR3ZN4QrkI89ZLribauQsmbyxIsYXXvZ/sVpq1XlfIT1FW3lph6iZHL4lk36EXExU3KzLOjbYKNQVUUMv/DJoullUArSeAfzHqVylaEVuka5aLFxVDQ6tnWfIED/qJhd0pvkzJ0X87D6Sl9ZrE0LXR+ObNo9DvMep+KLQNprg52B5OBdpwCJ8enIMiPwmpC2uGHW/lqgVM+gbhVaAgbPe/GeNzQksUqLyOOTZCQqCCK5RBeVNgclGDaC9eyW9avIBuiPGh+uz10/jmQDpDIJKc/tK7o2Hdcp2irgR4qo4JN5jCbdw6/aFKvGXJg9jUTnh6gwO9ztQ14r9F0c8N4omgVzXPIx31kfLv/DVJu/eixPeWhbRID9bJK3L4ue1v+NE5+mGknFL76vkLgfMz0v/2A1gaUJPpaS8TAj4dCSrqpHBhmwg28nkNkdJ5uxA3KnMrUaYdOlniJByV/9P3ck8heFHLgyHwl5vBzuKaycKQe3zrzFRjgDZ4n7c+82t0IrW2xm5dNfRoyzMDnEUzjNjdt53v2u3bK7iWyN4FYztgGV/JLeIyo7tkyHI73Z2x7T5r0xyAmqPkYkSt7r5CM9iBebuoKfu945dZ13XK7tqcYvLQ8B6lEF8By3DAfF2fCCyNW9ccobSfHx0YByI6L2aWUOzdLlBNiVJEkSCOOUHeHVDEUIHEI+khk8dLdfv399nDeutHOpZrkH4n120gOnDnXZyXU9WV/1QquQhRIWFNjZfTootdNN1/4fCs5pmH9MEYt98/GEDyPYMafkdPyafHNRMik54Kszj89wlG5s3bZHDyKM5xsgz/zw9v665jcDrmUg9iDP9cvmVicGVJpBdfNROxfcaL/sc4nqXhy9vDPPUjcinBbaGaXogP3IheEbrmmTCIWT0JNrBFMokeWyMLScuvxo0oXS66kpa28bpxmOzXDwGCPISywxf1YrJuxcqCkHeq2Ms0v+j45fei9aZpAVm6QUpXiLB5AH/cPjEF7siZuyos455CYaTssqgwyPN88ILnmgg/gW+9IHOJVkyutrhg5J2OWKT65lUXKpoxzBlAOfY4dY3G5IL4/dzo2DqrbW/weNLZ+9oDmPkaj5dvOs7aXyS22HZFuPDJaLlr7oge+s5LHvlUe1wKAbOwClg/Fl/IpdPQ+IbuCai0tOEkR0CrlblXYq9ypauxfN6BINNk5qDRxJ/B0Qgopka8s6YgGeXLqk2JESTaf6YW4yMMGoTJGC0CzChQiMGKx43vZVFcEDFvCoOLpiW2r79FPdpTFP4xzdIvfS3PmBKZXdKEvRbaUb+tOvPFWmnCgE7d2DcjIO4CJNkGWgMuYJThslEhFy8uclSlAfhDqJFaUm9WkEWLHp8qJKpUHXK/Q0k2e09bVAvse0I0pInPI4NVrOZNK1FjiNAPx8FYJ8TA7jXjMxs5NfTN6uBWEnZzNaqFCONT2LoDSvkj3qHCebUfEbkbQ8wnnEZbGdqIEeUtvCnKrUWfuHI70qUIOlN7ZVb164HCSBQl2N2gNRlUpWOR2S8dbcp0yOS2K9wNHdWqqQuQKxLOuh3AdaJaN3IzDhLgl+NUS4hAkiQCkLKwH91bxGGMJnjKun+I+owIBwxXnvHRP/D/aFB4q7k8IC8KmEzgtNUWXultlUed5Sshd6oi1H79AOVGqz3VkL6Q4d/QJ2VIW5gIifhxCUCsRDE8wJmygmdKZ8FncbtSKEmeOxsCgzgHXmbTUnywYAVe4eFwOWV74dykqMeKzPOu576i48vABLAcqGfllbgMI4oman/RxevpGXtz/sQiBFXpiEpH08iOSx1SsA4JP4j+ALzClUrfCf2TLyU4TzfiII/7KsJitrxXHqz2NGpgnVPlKnVNgF8rLWTYGbUqkWHVvdtr01zFWWFQ/KRi2Smnw95R+m1VuvHN0pUBdftxma6vg83qQKTRZhfmPZm3boz+F7VMDwqNUSUw6oyOf0u1iNcAsWPWKb0dZAX8kcfAE13gCBKSM4rTQk/xlyEYV25MiJPNLWHs8rgHhUKUIlXVgyvmUXFdylEYY1PVzuQinyw3dHmok2HCcymjQ+v34pL72JdwkcxNP7CTPsWgfcq004VF+yralIJxPTssWjCvic8YMwAUoTH/pmPX5nQ9pHpCTTIUbrCkqMY8m3Rz5RuyF+9ghkXZvcOp9IxqJu9VkF/tbh28nxK98LE++OhPChSsAwK4J1+GLqEk5wvs+NJzQPNngN1bwlevLz7o0mvPwurTNpL+bVkz+vz9OpK3Jmbozoy122QELqNBmWCQczR3hGq8bdWrajoA0yecgXF424U9omjYdC9cQt2u7bx7k4uegFFoM+17iUsHVYA8gKNag0FWeK6r+23dgrGWmzdXG53bWBir5HEgsK32N4gX8lqkvzu+WTsbbNB7BKu4BdyaGJxMBvpQ0vUs71GeZ631JlhGln/nIr9HlGkre4dTlTRLOVnepaTXLHupFna90nq3rQT9QPttTdwrWUPcuyM+92+Aonc5RPrtTqUA9LhixYbLOwjAB5FJRB0AYMVDBSJ8Bwl9nLON/R8o1BVgt4EhqxNTkvxrcECb0yPuyeLaJEQimE7OYpo80cwYIzzqZKh6ZtEUMpQpAG/O5XyjA/ssZUnlPYp9V4UEGuSWBV+ULs3j5kY7NAHbBAO0lBLBwhYYNh7VAoAALcVAABQSwMECgAJAAAAwFtrSDFzqxYcAAAAEAAAAC0AHAAwYjhmNGYzZDU1NGExMWFlNGUzMzFlMGVmYjdhNmM3Yy5maWxlbmFtZS50eHRVVAkAAzis4lY4rOJWdXgLAAEEIQAAAAQhAAAAlwCzjV69yULIr8IuaTkV257m7LrVWtYTXbT60VBLBwgxc6sWHAAAABAAAABQSwECHgMUAAkACADAW2tIWGDYe1QKAAC3FQAAIAAYAAAAAAABAAAApIEAAAAAMGI4ZjRmM2Q1NTRhMTFhZTRlMzMxZTBlZmI3YTZjN2NVVAUAAzis4lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAADAW2tIMXOrFhwAAAAQAAAALQ
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac39-d3d0-4638-b112-4a8a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'AJK4145208904.js' AND file:hashes.SHA1 = '6c3ad8b07c360517ecad8e12c53611de812587f0']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3a-5894-466e-972d-404f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'AJK4145208904.js' AND file:hashes.SHA256 = 'd3090efdb8b147c970f2628ee7d881676bab8b52e5dacf2a90b9218c1a0e0b5e']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3a-7b9c-4adc-b36a-4e25950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMFba0iNN7kLFQoAAHIVAAAgABwANGExNTE1YTQ2ZGE2NzljYmQwMjlkNmIxMjEyYzRkYjdVVAkAAzqs4lY6rOJWdXgLAAEEIQAAAAQhAAAAr8Sbz2cu0HAP/Ziiah4zZK2Lcpoi1X1JZA4+xT4IKjWk3On5FnG2oNkz8q1O915mQltUAF06+1mjgaJdLpIiKlWGxCw42fFBUZrIkdefJAPVOJGewlsH9Gmw1m+39sh3n71Mdx9z9/QSzWYDfMs+8sTZ5UwkuTB7d8AM7OraEfM3CJXuPmlGRLTXBVBTKl+fjhGUWlFNApg45OLI+pw0rrgXWQfgqP9TktZPTF5axbPM3IRJhFfixClNDyh45J1Kg8G4tG23Rn/I6yZwxTELhR6/Njf9ijPPGRsapMYAJagCl1ViksgaLEYcY0dLjUSUXC3m1FBbAB3OAQa/UL0Eg42Sl3tdYCF17ZMgj1p8RyTtxuFRqQF2ZhTLIpkm5vcbLdW+QxEE8K94qAeS0u0Mq6oA1GBwXe/mHSOsC9EDrKvd4Vdts51/qWgrPmU/clfpLOXBNU1npD7k2ocBgLdRo7TCIxUMhgKnQv2rnZgGhUOau4wceXq/eg7+NzxMfbZUjwHsCWWUa8rMg3v8XsMORhx+lH7E6cC2y0h+QFY/1wbX2xVWuwzeY0WPRhf07a8tL8nxpKvVpw2omjYSUYrYS8YQyU2aZSNrrlqcgAM1cyHLbdbF/9VvPPTCKuyEeNkHG90o1ZR+6mtMFKh5BHYGegTAAjQt9cArVCmYslOrYYOAYkBS96iOGklCbm4dBDecDo3wzzOCtSFhZuoyAezlQmvAjVsZzhT9TwoxaWvmsSKyMc+C0xZPF8BdQKyN6ZGHXaykqfvaXYzfRo9M/Yp9L34na71sNEhz2ug795B2o5FES9zIMB0tEifZFVK9vCd97SpsLMD2S2Ymo+HuFs3DwVDWBwHpgltGIdNjvX2zsYWg+8msYYsXRwOqcfw2NlRxIR8a+8VJjLmGAO4hdFT9v2q9nGSkb97K/SWw919O6wC7uDjOLA/saNqAOJL5AIV+w9wI0vBU0pkYo1ffCOel6aZ10Ua4rVO9kfQIEqHSxqt5Ef+As0ioxZ89UNcZqUwe26cc5H6kMnxn+5VV9t/ayZcX1YynDYoHprCfCsng9kdh5q3lDdQ4e8Tzz+fSctzmTo/97AvWpsxvcADQhqugNpMm2CG0vTyYODqwF0UbcVkgrom6Q6TsFmol/fBrtzul0RGiPCSQZ5gBW+vZe7wBLrNnxm1h0YxY2WXyF44Ocx41CPfGrDfJXdvyzY9SY3BLFmJVK8u3907SDYYkmEt5G2o2dHDht2glg/RsSiLOxo1Az970NEYjB6B+Lxz3mXwH0lNzAyDqTbOh0KDpTbVSf+IQd6S3I/eWsc+oBMlgNdC72zFC8hAuj51CTfLnZ4vrTEWB8iW9zcg7vRUcgHEech8MsH/Bvb94NSH9qQWCKvnGF8v0gOXB7dkGaxsi+1paelOs0d4McUHhc11CqxnAL78psF9SQDf7E9HE4gKfgZr7ds0drPlUDAIcmt4DvOHkWfS16VsGS1Z4Ol0LK7kfM6BRhWURbNUs0jxQb1MEQZ8k/SnfGc11G8BrafzBAAnZTBVngUI+gL4/6jxieyGdCqMi+IMob7NMG70iABMz+1nIgpTkLrEMxPq1iZJhhE4czrE7KRNfq+CywoyKxK237cI9EsrfO56bzybcO3ChaXuEhYVjEHib60H2qO+OJV90+ki3M3MORthgOlhoZ4pxWtwdGGEs4pFxoSKreURr/X5DFT4+j4UCxuvDvRs1EA95Rg0b4F0xvqS9u919BL4ATM5t7bFDFkmda8WJLPByp1xNBOjpmTmUVljT5ICi1Qr4ABlRk75+FoEn4nrvJjxCbI+PCt+Q9BnEvPX+9kzKUpH2ROU177Q+1pMIELRXiS9yvW3EwJdbfgT+IvLAeDZzDiTlk2Bk2RXYC3kR8Zb+ZJE9z6wuhtw52khBUlwoERSrefPx2aLqCtH2qsvmonk3jy5TuA35x5VLl5KnlFXNcfgwPoDUjiemo+z8dbgAegU83cnzFfJJPgY0OKRp1UJ9PhmWFMB7SbD+jbGFcpxTWOeR4vA9284Zs37cl5E7gxeboCeYkWm4o/sH++Q2AZKJioiopjqxds6toCSw/OJkb5/6IZUZYNBirjeICqHzgrYZku4g4l9G3+n2Fry01F70Lc63Mrf9u5XuPNGnJb7u4o3oM2/Na0WBfGCql8JqdRKDNSf0MsIeGDiVTzTz16U3mtMwhtroKCUSJPxJpfTeDx262o1fD2aA8bRdOle5UgykRgLewZqLQqg+bttCNclFPfnF4FLVdssYwMWz0pixXkOaUFMdpcdNkVRxrvDFnw0Am7HkPWpO11hwiGCDig375ZcsYuN/IsObfhhV54pV5PdZa8nK2vIxth2pS8GtIs8ic3HCHD5Ea3W5OOBUWbK0r8zgYgp81y6y87CyDoGyiEETzl7hHyQgcKDxdHKjEspdeqz9tY60uzd3MeXm2JU45LcAKy7x6cBEP1X+y8Uzt8WdAMBRGOCVnvfHEhYxZmZDvX6iEcylY7dgMEPkDlqHHoS7riYL08bZtcCvAa7Q1jbC8bDa7fHK/1ODuaoNd6WWpHK/1wos6Gu1wF/0FCcBIPTUbQ/oj8mwglhScVU5hEcYEG0msQ0T1XUTdEoMPXx8TFelX+pACO6AnokdhgX4ZNom8CnNnJ7Y5KmmoVCwOaKq+tnO/w/fffuCKKbM8AIKh73YyyfQ5UynX7keMIafZtME1KSBaOlA1ZYtqOQoCfDSFcWUk9Cul/vSrxHhCwmxMMnIC0DwJj3Ejh/R/iXbOWi3h6HLJ98Sv2Hiqp3b0PFeUkkSFvyubid6fOqBNHTy343R/28Qi3eQ74z1gApswZeGk0gJIPXhVXmZ3NuEh1e+vjkB4oqdrmKtCnDPdyW1sySygHkp6mLpm9AnMaKJcZp3ye2+VziXcYQoFun/YVwW5wv2kOmKq+nzJbwqNZMmj9agv2OzdWNwtlHdyp+Vnc9AW/DHMO0L3r8jFNC15/ocKqCIbZ0FLjWentjLrPRMOfkDl65/yHW/vOOFH2KshTW/lzJ4gnZhyTbMx/DPCLSX0p9Ux/C4w/LIsLUb11rR0RMcaOpGANF8RpyaEmPpEepOAWbF7E/0/V4NEuLQ8kipq3tBR0flureBYuVCqJtYO0N4wQsZz9ugS/uIhjQ60y5tI4jYbrjcWejUHFvG73p8cQZE3NQp0N1bluwkKKoSSjsZcO8Zcj3ydXEOX5mwTuh1IvMIHlEb7WazeMDcX3ff+bmAJTcJhMgGOsCQn/wmV3sT/YJG9omevn1Jo5oO0FFEn7Db8oji1xKGiVyHbzOqu0cmKHPZA3FwAemG81n+bg3qeS+kQb5BjzEhCpFH0HC64WmskMXkSfm67WLS6ze4v51HRwf7kYlIragmc/+/YwQM9PrG+K11rE2kvYPtiRhnvpNbJGQXQI9/vtD9ziAgOVWol1BLBwiNN7kLFQoAAHIVAABQSwMECgAJAAAAwVtrSNUItNYcAAAAEAAAAC0AHAA0YTE1MTVhNDZkYTY3OWNiZDAyOWQ2YjEyMTJjNGRiNy5maWxlbmFtZS50eHRVVAkAAzqs4lY6rOJWdXgLAAEEIQAAAAQhAAAAH7IiQLJ0lIgwW20Jy43XZUInMakjulAOqxBlGlBLBwjVCLTWHAAAABAAAABQSwECHgMUAAkACADBW2tIjTe5CxUKAAByFQAAIAAYAAAAAAABAAAApIEAAAAANGExNTE1YTQ2ZGE2NzljYmQwMjlkNmIxMjEyYzRkYjdVVAUAAzqs4lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAADBW2tI1Qi01hwAAAAQAAAALQAYAAAAAAABAAAApIF/CgAANGExNTE1YTQ2ZGE2NzljYmQwMjlkNmIxMjEyYzRkYjcuZmlsZW5hbWUudHh0VV
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3b-9efc-4073-81f1-4636950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'BDI2937409608.js' AND file:hashes.SHA1 = 'f8036becd0cd8013f7a220c154b867aca00d484d']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3c-f35c-43ed-8cfc-43e2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'BDI2937409608.js' AND file:hashes.SHA256 = '167507382dbc428a0bbb59bf293f2fa21fc6f5ef6d9c2ff56382976f0b72659a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3c-ef60-48e3-9ffe-4923950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMJba0gNY3kDGgoAADQVAAAgABwAMTg5MjM3MDQ2YjczYWNiODVjZmI1ZjQ5ZTdjNDk4MDZVVAkAAzys4lY8rOJWdXgLAAEEIQAAAAQhAAAA1LrkYAxwZqd6HHXsHqHpjPdTuN2D5Cwjmxk2+tCUOe5O9hjLmn0gUQavVtXZzZjf+/vRThBf9jKta+RQviNivC0O85a8fH1xY5oiBrWLINSSVAI5FDji+MO9BnHvYER00PKo2uMb4GHf0zWMWo9n+g4fHQnyhw35QPWQGpNzdHc9M9gMuvqypU1mAa3kNpkkong1qeAhuhXz8Qrugp/qOICf04rWnE37X+Hp1MWJrrNIL64MMm8IP4c4s2BeRJDGkTBwdNqPslZnIEDcN/0J8CqsH3QUnjTB5GqYJgHeps9W5pRPAASwM0icViT8P+5q/zR73zjg2dzbkCswaHIdWU5Jmkf3F+NV0rS3/IDV+P9rlFcrn+q4XdQWAzUjzpEnop9lU1H5defTWhBi1LVSpjGTiGjLhSMZCBMuZ0JPxv/i39tX9XMuZm4NPZF5TE1CjQ/vae70pt2tOoZAjvL1nKdJJxKn2OZ+1mmBN7kjrrgOCcgHOpbBXjDiens1sG4yDLX1Bs4ug5M3dVlTYJG0auYMwbbkqSwWCAGGgcuNki+evwyg5ikc9php5II+ur33SDMKISwW1o9Jh/0ylOgUBiobQ1XdM8i3M9597pHFQsxCF59htqhgQr3MpRFMQUeFCpvxtTP9MRPjyYiIdBU0K0Ur9pzNuDIiHaEkLgUfXQufVelKhLW3PghNi/wVar8gOteKT5dqroKtd5dz229u39drproX6NRxq/TXZfcX85l2LGhAT88hZoQQUWu02GXvWvrJ68KIRYXTY1ySuvg2Zgl32BhgE7pxrK2foRs1agQrgr0qpXCb0cSwFACl+lSCeblEMdchK/Pf66DdVXJdLjvWiScokMpr6m5VdKZ8jcghj4SnRwcap4G/7XanWn/HKIO9vIQ5R+7rLfTWornLVdYNCuTFjioSkN49gccKjYs7LzDwGIVW8WG29GI1rvoa+TzHaPrDiD3caxjWUOCNnkMyKU0KEP9mop1gQhZVXuSF8wT1OTkg9G4pK55eTN9/8PnMIiQlah2hvzl7FEL+z5wbTdCZk6nu7vbJsQbKnu7Ofqgi1WgE7dMZ8MFvmQBGEpp9mNhCE8g0nokMKo5DvXryFSYpGqlbwIBM6pdZk9Zg+LC228j4u7bIkkKyPn+HgLshn+9YR9zJhgxrY6b7HTCukdDtmaFkauFy8hYitOa2TxCb+5MIunPWoLAwpl2WwS0SyxDEkC52SmiSYKsmXKRhe4luWiObQ+Wx1lNY+WMhUhy4Omzglgvdgq9BAhu9kjD6WjgvToBCr0gMWNYMXpkhzEY1vs8Cm4MKpSpIuiWWKkfHx8/p8OWWqXnQy17i3TCHvhTUHZeSqK55e6cHVb/hIc1VRSgSykl47MybsnAotZ3TT9f7Bz60s9O7Vnpj4Eu+NPr4/lq3KBGxXopr7wLV50DmMQiuABIFQtz7zpyIHylVLPhZ8IauIEUUteFAXvY1cdk/+FGVmxVHS0p+5483kVQ0u68SZ+T/FWqXOUimrqIv4UkuL/4nFy86E0t1U6EUQ1UrnpKthAy1ts01nZBmjU27UTgrDZ/YWzHUlzEsSore1jwPxYdNOL88has7GvlGI3Zmy9dtREKUKLk4y/wtjAy6p6ePXr09h0KS1cUpdY1aWmEEgtXEYcKhsbJWmji/W6GzgdMTvE3cwJdpchSsAU1d42TpZnvkzzvfSlBkuY8h1dymA0ChgroSoWxhbWB9YEBHYTq8puV9juQ5sAa20KWCBpQR7o06GYlL7tvezciKHB/cm+sFwMMg1di1v2SirWjv2ofY2aHpEg8+WV8v4uEAbstBSE2ehgHcTvTiWwLdTpeWbUcqsH7YfEpYSbOz9DAWShO5855JZGQXcn5bgS/5k3bthx2zDBJDgHF9RaLGNFyJLBOY1J4+zaSIpRV3lWShtz6ygrtPkeXdF8QZt2lMpriUQJjjg5XXuU60zqy/P+VEd7EFHxaT1l+Bj9XTxO3v/rRYeeVXZR91K01x4YgjAtUFXAyQ0ht2KAhDGkbViqAYwgKAbxRla7XtBvK5kunG4hKhkEh4o72ENn74iYy/3ps94xL8QYuqSER9NT5zdf4s3GeNtyf8Dt0adbOfcN/VudPGaNFkkZqT7AxacgMwgC5R/gQE0aoFBF+utObVMR2y2K3hRLzawYh8rFK1rX3oNBVg/qEvLSL4aALtOjoIoRcvasGW4BNKI/elmtrETzTVnhsc9J/umvvmTNXbrQj/Ct3UuHbZjjkb7pKcvJpor954bfNjJ0truw2Rkb8KOkNGg3jTSerC3tLQkCGgV6TZCsEiDq5ut1EAOvvhVQtZ3FtLGNDU68YOyA7bLgOWRAEHhxcN/s74VpBcZH+jNUJ0Z1dZhQivTLbUpLdTnn/ExNvzrRujEpyD0eH9Cxfzl7drXNNACTZ8H9prNYXnccRUwIf0xDNLJ0I3Bx/ZbP31MBxU9tX837/LI+bROhJW5AvCMIcakGqMHLUOuCYBLfzq1f3oRppGVLvoKIrMbHfheigxWn+b9XK26GV3SUafqkHE4rjikPRpqxWF6IKvDF15fiz/ZGVrgvd/hd5j2cqn+y8Q/YGTOUMT4PTe/LbkqGsoiPUQRHq5kmaob7wfgqHwhZTGnlrJllfcGO+s9C22mGI/5L64hHnhL7AXPKuOzlR3rOnQKH/ESUI/PzAtqVVzp9VgI+oVSaNJYpEO/vqC6TaTIHe3wn9PVJVxVTS1meFjz8UqswRDN9nLZXnQnsb5B/r8PTPi8LEF/7/xKftRZtT8rEGepA+A+SKazIqzyeUF57TnVx6hiZKJ6niU0wvKGwsyjOJV1djmDyHoVw6gNIYgcF0Lch598fc2qcFguYM4LBg9mpc2vtwkCAhp5jHNfWtZVn3IIlGnpFHicMtl/+a1YjWLkeoA4hhIP2eb6Faeiozw0EBeW0fxlCe2HI6EYQI4p2Elx0eGG5ghSYQ7QT8bDeU1InftF9G2RmOmcARvsIvlr/TMk3Xg/cS5FH7AmwmprFRoRPo/DXTGThcgZJKRhfdMfmDuTF5rd323F4kKf50+LI7s6u5UbCNpzsN2e1LDz8AIo/WqEgAQacrTlzpdzD2K8uvD9UXK19Ma6mKYprOKzFtOV3MHLkp/mBCuaNxPIZdcxhevICGRygH7K/UR19Wi3CcyLeUaJ3/Kbd/0KvjEKtAPgiWpe7ylxCjjMZNG2RJfpJUIQ0sKhivt1kx/ZfBFTYjvyvCaoiqwBXZs1KDUdGfrLpmlg8cCl4tJPTw3KihsN85s7P5xQRhr4QU5EAx+srKnhcamMz3L2v5RB/1nlTpXANW5T96VkiRHA2LoKcVCq3ip6oNtxE3V9I9ky9Nyq5escNE0wYXluxfQ4IvBMnc9+Y6ovkZuorspYRVWQ2nf26R8X/pGMVjpAdynMDxvunWYcjlB9rHIRUgytauHUEsHCA1jeQMaCgAANBUAAFBLAwQKAAkAAADCW2tItKi6OxwAAAAQAAAALQAcADE4OTIzNzA0NmI3M2FjYjg1Y2ZiNWY0OWU3YzQ5ODA2LmZpbGVuYW1lLnR4dFVUCQADPKziVjys4lZ1eAsAAQQhAAAABCEAAAAjeOrI6Rw93UUPke5tWmdlG+RI3+kCbtOnqH3kUEsHCLSoujscAAAAEAAAAFBLAQIeAxQACQAIAMJba0gNY3kDGgoAADQVAAAgABgAAAAAAAEAAACkgQAAAAAxODkyMzcwNDZiNzNhY2I4NWNmYjVmNDllN2M0OTgwNlVUBQADPKziVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAMJba0i0qLo7HAAAABAAAAAtABgAAAAAAAEAAACkgYQKAAAxODkyMzcwNDZiNzNhY2I4NWNmYjVmNDllN2M0OTgwNi5maWxlbmFtZS
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3d-6358-4eb8-9df9-493b950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'EQB6117771701.js' AND file:hashes.SHA1 = '1e66d658ae501808a5737ad7573347aa90d1ed5a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3d-82f0-42ce-ba4a-40c2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'EQB6117771701.js' AND file:hashes.SHA256 = '3f789e86a91efa6409a60728a05dedf950443f5a75d2cb658f84ca4db0ba9a4a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3e-3b5c-4f79-8e8f-4184950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMNba0hfDEa/BwoAAO4UAAAgABwAOTdkMWZmZTg1OTc1NWY4NjcyM2JmOTgzZmViYzI0ZmZVVAkAAz6s4lY+rOJWdXgLAAEEIQAAAAQhAAAADZk/RNu7Jzru+W+N6MMUbQnGKz3PefRG2VWyfj+2684VEn9u9dLhFw+Vkt1ZEZYmnCalayckcOi2LItki7bdXZlvERSqT7hdvzYCRU6utJUZlx0kNqJilolisHshGtfugM5fbuiWEt9e9alQmlt2fJkzJUQ9J30K7MNHpkAwhwBj3gLWgi1yhmNMeldZY2QNnod/gs2TgkQOV1Z0sd/TDnA7+trEofbJHlljCn4lQ9WP24PEGkTt+Wcc8ANGFDX7MzhNyt66mCS8ZhFV+G1nkPzuaB7hArvNvYBVzPTdtrxJrl20U502HsivkJxMtbwxD+cO2oPT3U//1u/hIVovURrwQUfZeil6GwoEWeUzfgO0R2hEmQGFC0iLDt3vQbiAyYn4W733wdKfHLDec7PmR48DGtSUPson21LzswzviOuefIhwia6jx6i6Fcl8Lje9CAnigSTQvrnlSosyRMjCTARdK2DILSOrfnm0YKPOZ+ayGLp5wgE8VyLdFRR2kblxnAfGLEnoK3cdAcRU/4amKtN+12gyP8UKRS4uUjB4tRmh5LpLsTL9NlR8TzG2bnd5hh+90w1xbyWgbh/0grT9pcv/G61d44wGbp7pqoC4kuLsW8vqPJgqujMi2PoZv/Bc6YlRk+JX1bWnOuFWxAQSkeOxUcQ8FTceAJlGFNpHlFd5RZBRIfwsplG6QvNhVV7hBrItFQrbQG7vYPkuaxDYbfwG4P40pViN4s2I3bfsj2y2cZtNG9POcWCRop38Iz5UeBCqrL49ilfNFK5U30JXPH6LZSgXg0V3yUH3oApyhkITRs3D+3qdIDqJshZgkHmtThm+fKRTCk1V3dbRRmgHB3p1y0b4g8JigiV1Peq4VH2HWaYF4l0I2OkE/sH/y2Lb+PdHTm63KrMpTUOj6rN/jGfjlSuZVDhagpxMtAbgk1R75PKSuaI1PPgz3ryKSbymuJnX0+XJaT76bru+cjtjOSe9cUL6KdZpSjfI2NIhrg1/oa26C9O7kE2oFC5fVvwGdaZGL58WBFJi2MUBHOCXcC8X4uteY/62VqjRVQ9FRuRHkfMtasMKIVg6dRN7BTeyQ515gdNoOX0KfmXeWYA1szFl7GtawRnlbWsETa5zbD77wAE9NvS8lhf1/lWvNuiDx1tNIUF4exmyIJW48Qbwkm+3RcWggA6FvC0MzHEKm0BYlVqtoJP/jMSD0kmXZXa02omtYCjmIz9IjTebl6WjwPT+wnFlmAOYWuS56ScP2bi8FGRojEuWGs18Us9CJid5Pvz5mWF6jmjmUD9gGvgvu9H4XqiyP7ifU83wsfCQkB6hbo1W4Cfm/lLKcOxgfsJD8Y/lwoWYhEzhYmpiZOrFWotgou6ya35wfE6DlpM9/YuSleC+z8cnY8wp0xdtcbrz9K0p8Sp0iwFjHWcrbB771YKzj0L1blxSvvrvPvm6DzJn+q3eE8JRM8TM6m73kxcNCEHyVPegg15kToqW9cQDIHrnfHTZ2Oql6TGyDflbE89wZDO5GJ6wz2Pg3Esw8V2FZdh6kbX3dwXxAtbuj4EJJ/PacAycRWEu4Ix5jdX0rCgQBdrccirUKGJLfNF/mkiZD1Ffo0J5+WTKLKglLa0ynFAInbgqVgEzLI3m0PADk/GxhXv6HtQlca/KSYoyayEgUfopDfknvYhC+uvUwosxOIKMaqSBuiDQhabCKx++JGxEKW3NCyBUmvsLewDtgkrHNceNCAJLBA6c2V9vJGp9dNHogtu29rmfK5uz+E2gyK/q8CUYxPJ3IPub6LIORCsSZ76d/QQEFZIELYekbLVuTqEeVakxqSxkFLmsfqeJHd0C3Z+luJ/g89I5N1eY0t32V3b9mGs6rXQYOFiZ1r6hd/5baDmkiAeIGzGHLfvSc3Undh9Zrq6/AB7iwmrt7tOEjvv+SiRQ5H6K8KexT+za5sGGkGT9eYZhPSZAq5cwPkIh5mWzCjC6/isutss0JRyvT61N7u+OgNjbn7VCcUbXIfEW9KY2uOR+JdDI+VqWWtdROS+4y/JRJpGpp7OVkTrTTHF6XgoHHh0FGq3yjpL5sf4Vi5ipUGf2Ups141vGTl+ZL182r1v8sUZhmGEg3OnltZzq0AE2ObFzVMjmhh+s60dOGR2QIzbjOnGaCdrfwNk3eYMer95hOGjbFdYJPfIDBrY96/YLYrGcitI6a8tSjB7rHYCdQ47/R74+i6OKH+PibDHUMnf5TcAfxnXdSSnhF/7m2vaCjBXCS0uwjVRJP84qvt+RWaZX8+Ucv7p8170XDhBw5TkTTfW+3FpVLAhDHvhbVM+0RepONaoVyPs+skYzzuGYfAot5NL6CQ9zmwKMM+jNoLCTqhNWT9mCBVIRo7AkgjAdDoKKi5siSQlXVuKZObbeuJhD1Sroh4fuBjPB7MpD7qWPgsTgc73TohEIdJLpB1MbVOm6UKUd9v/kdPKCC8IzWFfhIMYlfv2QlZyrKOoZ+z53MPysqynQw6h2fJELAjv2u0HTbnU3szFlVNOyMQw1MU0OzUvFiQ7Rz+8DmA8gJjqon2eArNisEdDsO2UqOEdqotMtVIh2B+tiFVdupKU2SNwak5lN2dnYkPudPu9Si0MjsWU1SYCbqCdvuz5sUwJGNx9BxkQ0Qvpye47mriAytA5MwzffqoZA/46dXdpZxB7zJ4KXAG4iNvVlCwilrsI6LlpyqEBoN16or/p0teBhHxedH0ujZLbanBZ+Xfg0+ZTo4tBda2bNS8Mej7JZzJoIguGWJgLoebz96mg5bWpctnMe1vvFRtL7N6z1+NGNx/gvh945VXoJVG/dUlOAtsr1BwZ0unG9LEicuGLbGyrxGLyhunOcN+jlkCcvSQZdVJcto5aFYdjduT+XqQRrYqzeJobwwXUCj/f3RWosIU2cZLEvH1xg/XJIzt7fkWkUZEMU5zZu0J0uRPPAt/HEUeuPgrXI6Z1ABPLJ5ZODeEdx/L4jK6p+udLq9KpTOY43Smx8SoXbWI+rL3P/dlORoNuiFq6CfU8EZNlC8zVnaxLnpn+3+V2OBmAKFKw4T/OQ1te3YTIlzPhMwtazVU85VJijW5CRK5SfxEehWYAZps1h8c3NQzTgoPfX/IH0eik0X8ml/nXKeat7QrkYAWjeEqcroXKBgf2cdAmWGhYJPTqeOXmsOTPsllLT4JGuwqC5bp3huBKXq5pNUtQRGy4o8EF5kpEWsvavW+7B6va3g56qe/aSGCRqUAmau3aOazdJZFaxabEOavRDqTmGLq/fD1fG+1hP6KMHfvf+BtkDOTHdwcA21xRy7e6NDw05U9wsx7/661b+qbHExwMxJK96nIQHfqdbA416QP/962q8nvxn8XihEHeJKvVcEjlk1qFlgrSi3JGpltx6krWf0xjVsY/gtlCk0blONSItl1vuGYC9v/pQSwcIXwxGvwcKAADuFAAAUEsDBAoACQAAAMNba0i6C87iHAAAABAAAAAtABwAOTdkMWZmZTg1OTc1NWY4NjcyM2JmOTgzZmViYzI0ZmYuZmlsZW5hbWUudHh0VVQJAAM+rOJWPqziVnV4CwABBCEAAAAEIQAAALwsxZ/kBrvRHLjyejK+OJhtJIftoaxOVKrgbDlQSwcIugvO4hwAAAAQAAAAUEsBAh4DFAAJAAgAw1trSF8MRr8HCgAA7hQAACAAGAAAAAAAAQAAAKSBAAAAADk3ZDFmZmU4NTk3NTVmODY3MjNiZjk4M2ZlYmMyNGZmVVQFAAM+rOJWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAw1trSLoLzuIcAAAAEAAAAC0AGAAAAAAAAQAAAKSBcQoAADk3ZDFmZmU4NTk3NTVmODY3MjNiZjk4M2ZlYmMyNGZmLmZpbGVuYW1lLnR4dFVUBQADPqziVnV4CwABBC
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3e-ca78-49f5-903c-44b0950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'FOQ2976283401.js' AND file:hashes.SHA1 = 'f54494053365a355ffb96bc3cc36183df92390a8']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac3f-1488-4cd6-9b86-450c950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'FOQ2976283401.js' AND file:hashes.SHA256 = '1a33338c6101ac66cdc79dbaed17267725d183fe37bd331c04b9580c69dde5f6']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac40-fea8-45df-8079-41ea950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMRba0gzXViJhgoAAAoWAAAgABwAOGE5NmM3YzZhOWY2ZDQ0MTk2OWE2MmVlZWIwODEzMmFVVAkAAz+s4lZArOJWdXgLAAEEIQAAAAQhAAAAMZUQUiI6P/LGWMA/+kscvXr6Q55oK1AwakHQhIlivUWSU3O3PAidTMXVP9D7M1zerVVp/XFVpCM4ab9NzsSgAFgvDtQUrhYiPeeeNt9FB+7AmUXpxwYtFnvvTRrqMTzamcCC7yM3PFU+ZvnoqIFut8y2uplULKOqQyZirM2ZidwGEQTe+9D9P9/NEQMXoQUsmwwr1TLWW+lhbRHTMqC94cTV7EB3fYUEmXL5P7L18B5iMuvj4oDpZi54dnxnTLJcZgLBd7Fwytn3G0+xyyjd96+iPIERrt3F0a3wgsm6vgq6gpdscDe3PkKhblRt7UPq8kjBGTpt9imPYqlYjxkA2/9GwiVoTzgXS2/0kHIc8H8NhohtZ6CVxdZYMbmqUa1EsP4uTlYTKLAfdTBZ00VYXyC5Xi+NiT8mfQSaOjStspO2LKxK7CYZtR1EGFHHZpMLcM2jhDz/pzf61HyPCM57FGkspQCTA/rWnwkuAJHkNsnP10oD7n73ZX9Lrp0/bgIkx34ErMH3Gpazd7b2jVkLLBe4YZKVoDuf3WAirY4mM6R51fVN2cT1Qh90d9RmjDa6Oya2gICVVG/0ZV9qhp+toQAtomJMCqzYjJYd6YAqQRL8jZt7axBvqEL1yRW0wUa6prc14o2HmsWCJrDkvFeN2vYqKekvjBG6vmWx9iBnx5ZWViRCoXi5O0NjVV4jGw8xuGRnQ5yPmac6mx3U3HTRQGgagJ5KOhy+85vpAB859ZAr536xilaJH9XMyQOas6gwiGY6aNIVmpZikxH0aKcD5Qt0l+UVJhYNHvzjV2akGycDaVp9M0/LXQkZDM46yTqWyWuTHLCoS8m+HwEK95/73UFjQAkUVv5XoloCpFCIYjbkCzE3whGxlpJZPrG7XpEN4Ayljd9hS4y9YB26WnbyXutKT0rRWGzwCBl047er3xGNYk/1UGle/Blcb4thrunDmokJmvmINQ+nPAhrSG2RbFyBWNCedKDJkPLq9lg2zEUtifGl9Z6qcwfmnFE/4t/qVKIqSXVg69esbTN98n7FRVuRaZYUKE3pTNYyHzbJe/UXMhmrMtEbnYU9GKzC4aby3gVYM5MQGR72gpPWP6ytREKcmXmOASEz1Jl0J29qb+lGpqSxYNUXBv80TM6YQdvzqBwa2MlFmfspu/P4XinmiZLfdiuO5anIg9F3Igmg6j3NSfHvg+V4x13VxsNIqBRarkjwDMR5XULBQXLpqeTP8lTvw7sOWi7+gfBCE+yeXndbLb2s66ZmMdIsl3piLzwo2JZ4iPvt7D7E56/TCo87DPhuToQcuR4qq53vLVDB/6lEkxaxTETFfEnMP0VcpTHTKdWXLos1l5G3UNYqCLiMs+VH+yrBnRL5BmejeQlAjeGLrI7VNPIAtIVI6Ru/0CD92W2/uMfNERx4yYDO45+T/PPZdkK6glbon7nSFismf014AqaDMpbsVlgoZ/p61y0wthQhVjxK75PkSiaFTiGY9+5meiDmmNOdZwJfML4UP1v64ExQs3huHpxJZzcLmM+qcRDyG07OgeX9SihVfnNb48CHpSe8xxepgKbYbA9axopdizfEOAoDxziYO0XnyYic7f4gCIlwJm8uMzNF1hD1f1XngEY7WgHHKSKZ8nwzNcpeYA2KS8f8x4g9WJ0OBQbrWyfyNmMd+N1x5nhxZusR6u9vfxPObwT/aa6KGfw2NfY5DIK8iVfwoqS4dqMJ5vVEU4t/1sHUNvAYvyRuD5RN5ELd8HTZaxwV8lm4WpB/kShpdwSl+zepQZ6H4T9XfqOsUoV/PkYmWR6AP9DMQz0/UgNcAMSuA/qjAcvV28WV7AwVCPIXLQkT+n+pjouiFtnpqUadFruUxFHnXIIb8JmaQffWgUGy4Tv2uXo4MLkC1s4ROOrwlILbgraa0OxwnzlGICI4z1+EW86ij6tDKBKh0Cfyq+funxnIDd7rqyQr5klh40bgzDYvKmM3q+DPZXW2mkTQwja0YlWOV5ymUhcEv/0hUIJjPzWGJzoTVtE2e15Zget9oOG4Dt7dTDJ6qeAMd8JrqcakXgzySZQvn+fNPoambUXv9bfgF6OixjzPc5RdkKnlzRpqRGZzCd7EFnTu+AVIID977gqpuXO+AkegLZ5ePzhbnhy8V9OSx90pJkaU+TXSVlFSGkiMiu8ydBXRW6cw2O0sJSehmMkciiHrerASfnACC7OUCbbjmNKD3QNGSgnGGS5L0JlzF605/TfGayG+7g6fmpKCR1bJo9pr1WsJu1v6BayDLUA6aIY4CR0e9GZvIm9zuoSeiZgVBBbRKJqygeiL2+P/GE1YI3ZU4QTqRe+PndBVSiTuteDoQf7zMYn59JUBLFnxtuiLjgttHGpYj8Jovkq63fEyIXKCuQZxxl9cTWh+aYd5dMCvDeq72QTHWuAAEAt41kSYtUzW5fIC3ArtFlumpgIOkmVZjZdtGfqsg7MEiOMDIdMzGHp5oaRIyWnOrD3rtNZdAR0XtIXXRPaX8ZbHwICDl6pQQgAu66wX7rc7fp3TNNSBia2uio4KXzUdwCgY1ZUk9MIR1/lNveLYKLuREDS8memrpG9uBMUN1lvFVk56nvJVTH86OBNSu+7PV9hF5CZ6MyLAEJNHLvCV3BtmLkcaUMX+2SPY6bo3xVWfIXAF16/ba2R2c36f/5T/vIBsXeAiN4oIcEymo07+nOGnW1yofViikIDQhKdtUwd4cZ51rhn6te/mvlGtx0lNMtK5JIWcHW6e0tV7CSrNB6vmP2nAsRNkRLC29p+68oLijqRNqtj+KwLilZu+zZe5cL804a/Rc21PUgsMZ9LIrXkQqT9Mb+CicOHkEYkaP0JNWMKqiy1vFDjibq7EssxModX5wcPdrHRAhX2/BihH1iutAHzh9tWCnwZ7YDg8mi8uH6HdGWppoKIwZG09zw+cuYk9EO6ly6Ky79Zi5rxtV7lAA3FQozjubR+E8c6SucaQTRUX8WHGnDVUEu275NHjQD0D6VM526pkT0KFbjETi8qFXuTO/NPRPFcH/qgd30yZgahuhfRLqvJsimarzBMAp/dnh9nTVvwWNarvr/ik3XWiuHtldNe2fpdpI/hrC0JK/J8HqEh3KRVxYSFk5Cg0Wp8viTTbsaI1W0abmV97Fpj2elQ+kBkyCxpSRv+/JQ0/dkzryDBYxu4YvDZOFPMNWk4pjbS+sqqtxqL/ru8eOgMHSMec1YWl4PBbViFapTOFrfZzR2dpdJrMoH4XTlo/y0DXiAYdw+kxr+LJK6rxY/yE5sxH2fMpFxHs445qjlMTVu7YCmJyv7ahSrQXezY0JcfbrJ5L5av8fjxvfC8rZ2150hVqxWqF/cpi4+OlujW9PEtZXwbIpMfiV9tLPWolFnOvruMG19Ph7eKshQtvixC346dL2AJ/rGjwh5Mb+UJYdfVEN9w16/nF2Svz4++MBwzvPdlyvAEmibpyRiSznnpX1TWLLhq59bDxHBURjkT/VzqHNJHRv8k2uf54SzFbrSlzlNaK+O9hada775+mr7GYL7UGJm6h158DBVOQkBnv0Fnk7p2sEqkLRbGCRLCtDB6TQLqYwxF3WhjZ85HsUEsHCDNdWImGCgAAChYAAFBLAwQKAAkAAADEW2tIqAlINBwAAAAQAAAALQAcADhhOTZjN2M2YTlmNmQ0NDE5NjlhNjJlZWViMDgxMzJhLmZpbGVuYW1lLnR4dFVUCQADQKziVkCs4lZ1eAsAAQQhAAAABCEAAACTluyhbSqbnhoAXhswLTnfd8QSjpZFcvbQaU/MUEsHCKgJSDQcAAAAEAAAAFBLAQIeAxQACQAIAMRba0gzXViJhgoAAAoWAAAgABgAAAAAAAEAAACkgQAAAAA4YTk2YzdjNmE5ZjZkNDQxOTY5YTYyZWVlYjA4MTMyYVVUBQ
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac40-dc0c-4157-9cdb-444f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'HYO4635453513.js' AND file:hashes.SHA1 = 'f5183d28ae5faaee607e01260e82b7cbab74f188']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac41-d3e0-4f62-9c2d-402b950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'HYO4635453513.js' AND file:hashes.SHA256 = 'f12631f1966fe823634f74f075bb79417a73f1db5a3a99091307b8abaefb4e62']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac42-4590-4f1b-8b53-47e7950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMVba0gr9GrHqAkAAEMUAAAgABwANzNkNDgxMjZkMzUxNzNiZjY3NjJhM2EyYjBkNzI2NzlVVAkAA0Ks4lZCrOJWdXgLAAEEIQAAAAQhAAAA3HzqdvANQsDOnW31M8pf4uphFCLMKjyjsE21HUz3HV8IKOZ49mdIuwUK1ROx3hLWxOefcIPTYqHRGhF+9Ws7IwiFL5RwPa6guIThA90K02zsgV9+YMsnPOkDzasQKOn10g9Wt9zbY2G4qXN1//wZ0kNcVul93GYp0N8zfUZsnQmprICVIYCBMyYEQ7whvJOkJGiBHfF54lU3MMqUufg5ogeJfhAjwIWgBbbg5KbtBOXPlDKJ1/dYm2l1ZOmORli6FrZLPpFmSOMLxPxrZHp12rBR5QMZj2YnqfQ20vgpqCAfXeDJCjrwOGENKOxye0IDX8DlNx0BNnY9V3A9pj4K0RZB17bDDqEIwiM9sf0eLdH8ndDe5anAsnrY2H6wIyyKHmO5qqznOgGBIygxRAQzFqmZPtkGygtlJxoOdWRVtRZvUqewI6UZhscFC4drNt4VLs2jtyKoiQc84aL0Wfhg7RSpRJY0yExtG9ixMXuX/OU/hPZJfxwn7wU0IK4fJz3DA3vx2nuboJ4vqj/BR2VvEmB0kdUIk2tJwwCODdP7HQvoVWLHDssjAZpsFP8fvq02PwxjMA6uQ8v9Y9upyfVa+5mhttfhftQuMlySRNHrwbyMFOE1hzS5sx5PfBLvCfx9wdKMc6qrO8Rz4Kc9yGbxgZIWMvAfSTh67KVNY7LYla7ELG469HPbnTKgy/ga75RrnG6qkhPbMH4cziRdk1PeZZnV3ZIJ7aHHwVBg4vypMhZnHwuMJTxp+YY1JlpgL0GuBN/LLADIPoK4PSdoJdU6A7/1q8RmjeeZjjyTAlpNhBbb8C4Nx30prDGXBvG6ul0kW3REAnyT4JJvst9eOxuHU5NJjWDpfkUQrxctvkC8ZYluvTNYHOtSM9/j92KWIHZwsRPZ+O3SorfrB9CRckqq4UWc+UKDFr3HoDuweNIE+CzO5zyGQ47HNs//0EnzWlzr5ybN80yI3wQDvm5KyWFUb88cSuqPK9KGYYjdTERI0A5brrr8KRKWuJhPy3BGRwjuLjUypRNyno7MGTBLIAv7C0cLEwGfI9YF7dbYCkxbg3D+k4IDPs+TGPLaeadBnL/4Q0p7rEIaxKbDImeqGExcFqEsa/XQIg0o47xUw/zSDFpxyPzaehR5x4jjCvgrZzj4AYAm6BvL0ghSEySYvD9W9YLJsrLghBMHMBwg1HXZ7bJoIRhKt2OE8+OB13ZpEsk1P+X7+L0LPk/oulGkbGQlp7iwLxGoNhg3V6dv2grrp5lKAmzTtyYm4FBMLEYNoDfMekLazxeZzxfYunhj52Z9Y1M3GVTLc92yo4FiCW4g+E64bL5AAcemsnEqC9aVghiXxeZQIkhBRRQU4AXKzGKizT9gDFSkSbwRPhcXUQWSZxK72kREYBtUz1U899V14mu/LDfJwt43riMO1fm/KQfMl8XS9QuG2HCuAmDCACODjfPkUk5v0nNH9Kc2kCSUzzsI3aert+V1uTiN4F0pKOa/EOjV87qeKUbShlCPIhRFan10dxZvXS1HXsM3HZSts/lX7TECqdHPSwNcXg832I1Eqz0nqJG8n3J+G2IkIi4I+kVNDzxbNsJRD37HbyTiVFYDCdHvwE32EOne9PsSvUxNoxdM3U7uiz8X5LvQYzb8XdjYNPDWXmLcpwGcUQgdvmplxWlMKM6s/zoCtQsEbFO9X6GndZm3bLH9Nec/bck9zNK/oY/fmGEHyt92tvG/lZJa5fU5dLhTdWRgZ2ukqt8/hsjc3dWEV5HdTqLnDdHEEX1va67xvHErHtw4tsl9w9NKvWWIkLEbdZc3/aYwYlTEfEWBQHTU43QdnfO7I5SSSF8v9P8gElqqxq6mtjECnRMhiRotlO+cUFbzefTSC4fDsHnzTxxwlLTXbX8yjQSJJBAa7HTDqxUo9uWrSDxmwRjOAM8m6Dmborb+D3D0HfIgcC0LJ8VFQkmQz4FiQ7e4I8Z9iA0kLj2wM4OUf2dWkKC9VTcDgO0qiRF2RVaLiDLLdtY8eQd2PWwn+gox9HszTdO+lbkmeHc+HP5Z1IRpA09zBZXQ7PlmyCE1anijh7H3NE84aGGnUJS9vd7AzZCkjemft2qwaEBvxMcVH3cSkeiYCSZ7UCZJAVjFJb/Bucl8kq9wWy6IzQX/ldyYI9DltwIxo2VFwKoA3uPCj5RqKAPnI22SNLQjJR7t/TDyo6yxfGJBNd9xdNidCN/BF+pDDLdIHvzNBdRqkFxLpDhVg9J8NRTjidMhm7kWHKtw+b4zFph5VDD6H/9OwjE44KxGbKsBaaoOmX2+C4AO+YCAUc/cw1CikxycFVy01BfMUbVH3l7xs4eWKS908qrBWuMAFsbAzzu9awchbIDqLAzTpMghyMJJgO2vsZMOFC4MgEiArXfXkwuwnlNLodA6AicoVlMt3kme6FOJP2+kNi32/ezptmEVm3aWg5gmFXJ3kjIqBvMPB3NDWWHByfQtOK2yS4dvSweWu1mloQR2KggamRdIcLYV8JexYu4vmXBv0dzAToMvz0GkjjcfsNsifdcy5yDgmLB2GVh1PGQUk37khnR+ph0EFA7Dy3G7bld7YvaNsyRohdqcUzyfy2vHRuMKEWkM+6/TEkzKnMz5LwWXLou9rXrPOQPRw5n+s0xSjYKYTqNCydpdLCWMmVY0orsM3O0n36bzGydUK1u/96SgTUjnFuNzbcjkr401Cj0ysKBX+Bm5aYBNbgiWfYZrbU+oqarR8Hms7uh2yGEOoHYX9yOjt7A0XciToR57SsU2vlmPjBBxs4HgMl9doxMf+srBFzZhB4KduGArZj4FR8rsjaYPKxiVhCxU6dZXAHK/ay4OB5HInaMrBrPPlGfkah4GrWjAShrZGas7ZXIkunLMwPY9c+DfaurR1c+9llFV11cUJcwWQsUr2JoQVTqkIsoALnIfgQhc8kk50iDY4givNgaC2P0bm/CRjSTV+0z6GU1hGiDUZE8maSIJHdu6qAulSOBgSiyoIgR8IJAeWBdPpqvFx+w5wT8nG/YH3VlsrkvMxfG4p3e5nYnlACK8DYovJLppBFnoHqPQuXLk6RovcgwZBIn5TusEeILgInSuR+YegpdO1ecgZyC+eCfIfK4Nj49R1buXgozY/Y7f+xvXRmjfDAcpXD54J8WVkGZd6W+ivnS2tj+QvWT0eu0dmFlnW5+mZ2VNnaUua1/zOwCXzXOocFJoPuOL+RnKKeQYhLPmErxPhvVo8MBu1sDt3VRERJCPKBqN+Yco9ru/UUMJIvH960+/Zan8soh1j2b1zgDMk7q/lHeFm2lxUEsHCCv0aseoCQAAQxQAAFBLAwQKAAkAAADFW2tI9z8GSxwAAAAQAAAALQAcADczZDQ4MTI2ZDM1MTczYmY2NzYyYTNhMmIwZDcyNjc5LmZpbGVuYW1lLnR4dFVUCQADQqziVkKs4lZ1eAsAAQQhAAAABCEAAAABIfgpxSutDg+V5nNy8KlXT8yC2oK8ga9BXHEuUEsHCPc/BkscAAAAEAAAAFBLAQIeAxQACQAIAMVba0gr9GrHqAkAAEMUAAAgABgAAAAAAAEAAACkgQAAAAA3M2Q0ODEyNmQzNTE3M2JmNjc2MmEzYTJiMGQ3MjY3OVVUBQADQqziVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAMVba0j3PwZLHAAAABAAAAAtABgAAAAAAAEAAACkgRIKAAA3M2Q0ODEyNmQzNTE3M2JmNjc2MmEzYTJiMGQ3MjY3OS5maWxlbmFtZS50eHRVVAUAA0Ks4lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAApQoAAAAA' AND file:name = 'IGL2479468312.js' AND file:hashes.MD5 = '73d48126d35173bf6762a3a2b0
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac42-24b0-4a9a-8c7d-4cfb950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'IGL2479468312.js' AND file:hashes.SHA1 = '13c1fe7433a10222e1e676fe1d9182429e3906d5']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac43-d7d4-42fa-82d2-4b14950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'IGL2479468312.js' AND file:hashes.SHA256 = 'f365ae19431e7accfcd0d9977fb52cc288fc5f4b39c63f483105c8d5ee3cbea0']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac44-3098-4b9a-9bf2-4102950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMZba0guIhRY8wkAALAUAAAgABwAYzY5M2E4ZTQ1ZDViY2ZhYTc1OWRiMGYwNDVmYTE0NTRVVAkAA0Ss4lZErOJWdXgLAAEEIQAAAAQhAAAAMZUQUiI6P/LGWMLes/2FHnOfHLakpz/7jVnzVn/rK2S3gxyyoddf1sxFcxQlkl3LY9q+UVW4pWSZkPi6mQ8cHiDftBecHDdw2r9HIvPTsa98dNEbfTlFuCFyy4BKUmye9rVEvjcV8DUR9HOxl6H8X2YTbxe0e8zMq5HhpDm32x/2RV4pO+BFU/5U7SaiQT3SettLW7xFWGAJX8sNPjE+s1IJfVaDZi/phCiqJRoRznDXvI4tnIml556Cu9ZnMy/sZ6L2daFgVF2pwAa6iCPDpjF/T5zTbYBQZjFtcsegvlrby0udyVgJ4tu8bgHEm/AgJQBdI1YXeLVKPsZ25K4TSbMfboGDGFNTNjY4/zHswmyCFIwxzRvPSvy7nNrHHRjI5rusHU8IzNrVtRSaXZ7SrxqF7qJxrs1Ek6B3ZEMF5qEyUTCZ/snvhhw91r2d9WxIXIUoHxHQ3Db7GXr23W3yfaQNFkFGiRSoZgxbmIZ4YLXz3d2x+Th1GNk9ILHwPk5oCMxE4U+dCoNwW84IjLnpFLokLOJzbf6EhC4bzrrm9SziQefev15U1tEIEQIORuRbPI8sUyKtAofVEVT1kamI2ePhy39014BN1oLYywP8soQHOPCxIb9AFCQjJhC/YKNrvYvOlwBjdxdEyRMqHimObqSOCZZfW/GwnVvdNWLW0ebRSNajco5ma47UiB8Lb00K4PIsKX2936ksoRkSr8NLKIGspRwvw3nj/czkYnhejUm5uFdDAafrPgyuUdca8h2gMtxL5bQIIqsLjRluTCkq1zx5yMZ1gLx5YD69o/eS0p6TsuE4oJepjUwBhf9GoSCqYaJaKmH31J+mEVLIHQes0WF3lMQmKVQadCsDdX5yXALA3ZUWxE4WjSQLN6ahtNWbkIDtNZNrPWTh4CuBJtbOZ/mjUH8b2RjYgO7+2NohoxUN4fnbBoliuEMJ56cPWZAKYeQei5PDjeRpmMxfLyuwnlKXzP2DUPuHYrfxSJO29PNoiRfic8S1BUoz8Y+uqIY/Qse4SeHTVA5BT/v3fKSdnbhprhtrJQ0i8+MSNkZK+NObYnCtTfZGeZutfUPG6zRvk3l1vPEbfuSmw+peO1t56YvD8XQW+fTtrzY6vtuv4tuT1xVPwiOgUh/KxtxOtQjMWJbYbJtDHe+bx7ZZPB04x4VITTrH9vNUXso8tYL/c/RZWiuN/HWtNyu4ZKgJHEGmoVgDYw1ZAWSCVaJ/nJN5sXFrUwCMocg7DomactXb3OTVtPagtIb39VbnOwZdNkOLG3zwri36J0nXLFvbIQSYRLFHmIPuQNwl0ukc2yUct6TfG6TchfuhGw0/Rc3NMdfKUesWqmbH6nYXpPTei1V1oCTD9HmutfCupEdCSSDKmAhqv7u5D08d8XwGiOhT9Nh6i7ucyGeJyU4QNIbASoCJxQ4l4b/bzwC5udFGMoA5MJhO26XWXYFdKsQ6xRJWzmZk+7GE0xHqLTaXQpkQEe8gxRoy+TH5Ini04S/0LUW7Tkp9NWq2Z9WJ0mZMm0QfIsIfqb5OGC971M/d7lRrsD7lNZ7BD1Q8cbkuJDrSTGxGr+pArAq1dc6DSBVS5H7/gmU/jgKCJBgB4JIp9vzR9fROCTpuMGspHj1xlzqkcwQsdejCYmlk3xA8qmnIQnGmcY0wUoE8VFUG830p9HrOZe9LL711glFFDyKWhsxZmNNsfI7nEPtRFDR+hm1acvTtHCeW7D1rNFWe3OtxdLrMU9m5CSHXjnzleT+vonc6hmR/u8CMKxfabXfoe+smKH46YHU43ha3qDyvT+leoPJglfcuvuPoGzSQdNp5IsQjLks0eZco0gIRTCxUjd3H8FG7AkhsLUR12D/Z6jA4YixKfOytIg/eP1oyabNFMoxys4iHASDDnqsT+E2PKcAp5Q/jJTVnQnOHPEyJYut2bfkG9LQx6nSJ/fWDkpEDFM6+M+Dy3A8i0SFmSLUnAYqOb6vEQy01G2XwLjk7WfSOYjj76efjXSY/IEp4r9xa8N5Ym2lbtFYQpiYwzMqgHDbnefLcxzZgqvS00BaY+BxsWOntQwaddmR8SiR85Ko3eQWipXSkYehcPDNoilxir204HLO5fSangPuIeNkNmA5Q2CQ6d2psBt5gAXq+eOXwgX1NDg5drYtZFvUhbswkpV75b+R07d0HcFT76mu3gpB1A23nhGCcYcKxz95Hpand5Mbth+wzpXMoUh5HdZjMlMCovoTlb6QisyZUft1/eF6EQhsHWNC0HfNtKc+XBBCuecjty07Aj6WLKkaR3bBSCPYkPzS5s+OT0x+AQeiqDvMXll+jSdTaSaHeC3DbiKEw0DhUBePXbwrmON4YZzGxS3nyfvlJYAR3pC+pdqB3sOfQtxRFs9QOtrdA/RqXHJr9euzGB9JHVizHMFzvUXjKFDnKGoLZ2DxLj2s5EMiX2vaf3rDXz4fAjDQOFn7XM640xE9RfFUHUTHAia8m1DrTINC5j//d/ka818tp49ZvCJ7XbjbJBBnmFyq/lyWAKfREkQKexBdC+zCiN/A7PDrNT8qGdfWqZZWQYYWGIj8+XnYVomCp48FLGdmFlvNmx9Cmgnry5uhPnfqm0hvVsoE7kEELVQc2YxI6E131vULdyJ3VVWE5dACJJgp6+qM38QPoeA0n4D4yZN/XjaCSiEUPWGlr7LafzvDMBkJUjCv+Wm3lhcfwM4CnPNuG0om6GWTl0f4g6UoSozPtUnE3qU6NS5nuhXz5IkaQYIEVkA2+5NYhhdzeQ0B+H8HzEIvv1PdEt3E8jqGevFDHAH9UvbBEP8rG2WeXerS0G9AuODV0u6yoLPqxwetDpdaAHSoaqX2AgDcsCCJ4+5edcFEHfarsb+OHKWZhYoqaRgpDT2p/ZEMJAUAb9fWfsCK8hoqAeu0qSpzGE1Z2dQAju7EUgixES4/Swo8Bbpyq6YLC6OWq30bo0aD14x61N5TZe06ynmN0Sihri57IGlMSDlK4RB2Ynhr2ciQvVxPzv8mZatcqm+l9Nvl0U9ufTGlhnBkfe33+b2jT1FFhtTjYkZCabMG7CtZlFPJvlzcglBX5gxpmWqWGoqdBZ8J6HET6bXztMeN5cmLPGXVhvyp87p/2Q0PpoJSc44cNIK1L7dFBJL4z0U6U2L6NB/f/ucWiqs8BjlBzCND1s7+9u7CH5ce7bNswwNbBtUbTOyjCYSfZEeEF+kgtXekOk6cYYZcINSUoK0Fx+EI60B2GGrBzmmWkYUj8FTl2otyREKydLH0dxg7RCQe8EQqQwU7lEH++KRk8OEEsnX6rHF6JKAB4njPgMxs1zljNyZzdqxirglufeppzJKokkx9TwJvYcSGn1IfppCWq17GjRpzSjIaYAoq5ogtEqTSY1m2zfAm6Y94ZUEsHCC4iFFjzCQAAsBQAAFBLAwQKAAkAAADGW2tIUjvKYRwAAAAQAAAALQAcAGM2OTNhOGU0NWQ1YmNmYWE3NTlkYjBmMDQ1ZmExNDU0LmZpbGVuYW1lLnR4dFVUCQADRKziVkSs4lZ1eAsAAQQhAAAABCEAAACTluyhbSqbnhoAXEGbAO3yejKir5x/c3Vu5hy+UEsHCFI7ymEcAAAAEAAAAFBLAQIeAxQACQAIAMZba0guIhRY8wkAALAUAAAgABgAAAAAAAEAAACkgQAAAABjNjkzYThlNDVkNWJjZmFhNzU5ZGIwZjA0NWZhMTQ1NFVUBQADRKziVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAMZba0hSO8phHAAAABAAAAAtABgAAAAAAAEAAACkgV0KAABjNjkzYThlNDVkNWJjZmFhNzU5ZGIwZjA0NWZhMTQ1NC5maWxlbmFtZS50eHRVVAUAA0Ss4lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAg
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac44-11ac-48f6-8043-4185950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'INQ6225561909.js' AND file:hashes.SHA1 = '966af3138fe44b092bce87bb333884e583fb01d3']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac45-4514-47bc-86f7-4f23950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'INQ6225561909.js' AND file:hashes.SHA256 = '0a884c6fbe5314727a24b65eb1196a8d59ceae4b57ca237f4c5c974673545696']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac45-25f0-40a0-9a4c-4617950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMdba0iKCcfi7wkAANcUAAAgABwAOTg2MTZmNDNmMDhhMDE5N2M2NGU5MjgzZTcyNmMwN2NVVAkAA0Ws4lZFrOJWdXgLAAEEIQAAAAQhAAAA/ywwXakle2AZOCtqrM5XsciPkIvuhRkrS8SA/aU/BobkqppkeXpH6Eb6WkNGfbaLbd29pA0CM6P5EbEeFY4nrMSQ4cFmqzI2gOifx0VZyJnb3ciMmsG8k/Cazdc5kQJyKXdnQ9rFHbFY6D3W1k2WcKYE6X6wjsvMEQE3gQPnLXf1EGhP1pdBmujZPs8RgUbSAXvENEDsU25Vl7hc+BWPuist8j0zdtXTWbRyKkR2uGMise9rUsP/Yd+gFJ9Fcbp98skgRQyMX37HLaRM48XOCMK99rHDfiIq4K1oDx6cXNsPp1R1YuUEOc+AKwuwY6IAkRJIyMCnxfCagiT48CGw2VzlbcRvgQiqorm/6gWsPA3QAi7bau3ye2SunGk1ph8axBR/03GnBE345h6xeR6jnK9V/VwWLlEz0kxbbj8VMd7flrpiExx1RfjGebVxZGAXkKCwuiygQzrOQKb/T7Howsp8Wan+iWiEGtpI/0oy7PLea5z2zXQJAE+cTE20xsnV9ZbiAkH5TEi1TBsgkq64CjZOxEJ2cPScmKzWOwXiXvZ8ORXBpznPY+oi9KkLaH2q8XWQzWaOlqPjyqr5kyFSrf636CLN2ToJF3DV6KMP8iasJ4VbEkmZA0vSoaG6GrUYuXQbWTtE4rhpoPjPqH5TRl5pWP1dFkY1LSvLiOxklsuzA98sml1CfvjI0TImSozrP3/f+q7YPs+ygKtOxhSAL0GTp7UPLH9JtBndQAmrd36HJwr1AOO7ptg3kjrctA5y48yn3Dw8ms8Usjry+AkbtYhlzT90V8Derd9+3VzGbLsFkptjwL1rUAhh3C8sRN78Tm7447r5Ew/3a+SkykSHLSKXtfjMz7MmmQa25LIrYBIOIkk3SRsBFMWG6oijaQ38TWa5e4fSe+MonbptlprZ687ThjOHbanjXEqtP+j769wHN+BxD5iLRs48OSfkzedIRGEW1DD+zgEPlba/Mq+zJ7ESKTTCxoUzin8szHl0Y0jfmUwvlsxv8KtSVEIqbznLtggpkk8dAQ8o3w1BshJlf/usn9dcttoyDLNlTbTXQJxVCtv/+WAFodNzxuWn7l+SfoMmNp8jcuXngtiKxAxS7q2dvMAIHS1J2sc0LG5EBiMaZGvlVoqaX4JYVtIXRk2FN3rGfScrXdZ61cYA2EZcTG8gh5f9n+l0Ozf22iCBZo9cRCxltd4NT+Z8EjoJSJG7Ox5+ywba/tiaDDFd9Y4GfYyo4xqzGhCyymaCm3PHLW4e+hfQu+Od+OkEFxJ51rLi54x1oznKcnZPdpBFSHmLdn5Kzr1sAA3yQs03KPdo+rhAx4JWAcMaTyj4YPG6BCvopW3nV+r7NzkiwodYRM0QYP6SxFye0Z3ONuVPkXNTd3RL50NCUrWjwPDjv58CRNyyqitZXZCpNhB/HIaJJRa5Z3pYIjkHDi7pO13AzNh9ifV6fd5WLOn/9uyyWXalGosgRig+DEQ5JD/k7OJj/7dk7ybdPBvNXcExtX0Hj3JWRtwbID4jD1zmpSyqOEWfhO1RWTOaVk5nAncaWiU2B8ZiEHJHjoGOswWgQ3hIOXOnblbvZrQeM0LNvQ9FH/y3PKinA9uitvXVm0kk+OuB05lR875acVZdboxwF95ta2BUdiy93+Dh1KaM+TftIcCqCZLBV/cJeg89LaOr/QydySMwazEbOo4Ge7yjSK3/K5zdwaIo3SuJXCa2lEG4bA9HzbSqD1eEv1rx9TcyPP1/K90OFkXHKBFVnLcbHiPtDP+QWcr6cy0uTHCUov0lA1BNZaTz+ojocNKhfkL+e3ZnloZ7zv4pWdhvjC5kus0MDy/1bYh9Lfd9vT19NiJw886mwVdC65eVdCsazSmbvInqSuaPMvtP1uSMsMk2uZXIomyMSqJWLrzJuE/YCuGyZPNIoQhZ97d4PSY6Wwq6TglEM58fIFWBdM9Sxvb0PaXzwjTfTHYxB8hafYwigGKEDO2ctYjv7BWB1aw7ERETEEONFOtZBvQpOVuaG1LB4EmC0GqduAyh7Qe70DqHrf+Iczcs1ArCNS0L8RpL+bF23L2hft4VEsjRzkZtNVgczfdvzvYgI9pyQRrUObKKqTgNEm3scczQ2M/WYH592BsbUtgYI0PKIPCL0tpD0lDttskYMTA/VVZOTIVhybLu1XbGi8pieixoGdMeYuQFGe68zBPBhWIp/2/GeTFRvkscA2Hi3BILIGmnHrf8PYmd+BnXYTXQg5MOnhwNgx7RWImw+orEdFE//DzspqQoTvvBiFfqee387DTV9uOAWcJT5+EmttnsS8TdwZ7qSioDpXovjy7iSHf+23dqaa0JwG1VrpMKTXZUKCKq9ba9YWqLjs2ZtuYsvNDkXCfztGnGKRHOHZAEM9ZaacNXxOOPwIYY9uKi6YVEBBb8juXlP2Q5NdazQCoNWMo9KNOoRtw+aqu+4LP+VpWMw8x1cSBVtfHOXuwxMUE4SHNRVwFM94TfxMWmz2cud++rsu13lIzGgWRobX4Ma9Y4uvkgS1K5y8HFk3LusKHpoSM6SUO4Nc86B8d20Cgzp2TSl5ioLppNHO270MUSmBYymW8WWHW2oknZF32BTI5K4Eu6YRkmEBOUXfIDStMj9omI8qOmLMkTvnX45rAQ6nJUTrbertNYx6273itvOTUKWJhzD7A7mXKhZk4J7U3EMwKjH2XY0+xGZcCVV6EWgBrO4r6QKr/561DEGsNm0TZchU6ClXUnijW5gOUAbs3+Y7FnCxDvzNC/0e7hmShrqyKF+bh3CV4JUm70sPxXUBZl3ZK2M5EoQys38wVteSMVb6un4prlhBA79j2xXyKUvTAX0AKeDIYZK89Y1c02kv1OsklBr3vqSfhvRqk7H7sMBvyPSBW+zE30um/K1zb3micjyPoWQm6oj2ciH6VwyO8anQkkP9znS4JNd99g2Hz2L0plPCjYpRLxcc9Vdvz9hZHY7VFU9lKbmfD2Q9EtSr0zrr2x++O7nf3jy+PQ60+svnGWfzbIbqNOBKijE7PYhDqtT4BqZwZt+1MYYNbVAQSKYXaIHsLAOTSUMehkI6qwLTcu144Gtv+quXlsSGqrW+JcZKpQJYDJunzEBIR8m1ydx+WSoVWU+tWaSJ5JKy+CXCTXP+wXwHwNkCx49qv2YzEBrxi24Ry24Ar50spKWFtxvz/gGzubWRkfoW+NcEyW0qYGLhaaOKQDKEIn5eiwjx6CUu8tPF8cdT0YNxVka1h2MKE+redlRhjMWI23Qqi4U/ZYcckouQLq7XZfaXikRyd2v4o9t6ef1urq/hzS1tzDJvufjbEUHaZhqQFdjQV5oznuXH7C63Kxcs1YH+vox1OLFE5i5rgC5OMn/CezFw6men7tWqkeSSKvcw/t03Q6LDpQSwcIignH4u8JAADXFAAAUEsDBAoACQAAAMdba0gT5fw3HAAAABAAAAAtABwAOTg2MTZmNDNmMDhhMDE5N2M2NGU5MjgzZTcyNmMwN2MuZmlsZW5hbWUudHh0VVQJAANFrOJWRaziVnV4CwABBCEAAAAEIQAAAH902tAvXyhDAljQ0JuktRfWQ+UWLDvfsZmYfm5QSwcIE+X8NxwAAAAQAAAAUEsBAh4DFAAJAAgAx1trSIoJx+LvCQAA1xQAACAAGAAAAAAAAQAAAKSBAAAAADk4NjE2ZjQzZjA4YTAxOTdjNjRlOTI4M2U3MjZjMDdjVVQFAANFrOJWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAx1trSBPl/DccAAAAEAAAAC0AGAAAAAAAAQAAAKSBWQoAADk4NjE2ZjQzZjA4YTAxOTdjNjRlOTI4M2U3MjZjMDdjLmZpbGVuYW1lLnR4dFVUBQADRaziVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAA
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac46-0644-43c3-b122-42c1950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'JCM2166401904.js' AND file:hashes.SHA1 = 'd83065d7552974bdf153c69eb52775addd6946ec']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac47-ac04-48ad-a155-4f30950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'JCM2166401904.js' AND file:hashes.SHA256 = '7cd16e8addcf6097c5e0429d7e5c2ea48ca674f5e6cf2c93a0e02932d4a44215']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac47-d58c-4b58-80aa-416d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMhba0gM8vvv2AkAAIAUAAAgABwAZjU5YzQ1NDhiNTEwNDQxZTA4Y2E5OGY5NzYxZjUxNjZVVAkAA0es4lZHrOJWdXgLAAEEIQAAAAQhAAAA/ywwXakle2AZOCQf3fMB7ci58m3fimqNVsHfDR+aqOC3/bh6S83Oyh+T0KVBd5ZO2BscjtwqGmfRRMdfsgkNpgwViUsHOtZhhP0VUL5VIXE1bPm9nN5ZbrbqcH8mNQMeq6SWfr+zZkMxLOYkbySjMpkUY2/V5pQhRjuG5mEHSX76fVpWEu/1dooPnxbo66y9j1lpsNQ/nORMZnxkgY88QOd3DHzlF0inO7dSRhq3d8rws3JTeSGCtKW5t8h+EqBGZy4HsaA+W6kIsDrbp/wdSoBVvJbOF+cj9ApmxMKJYA8dQoPPi0m3cwVlpx8s8K76UojDfaPMdHbnI2PPwbGr6JOfWl2wNd+q1FlN8qBN2dPQLaNahVhg9xLMjm2SYWstXjZcUyBhXxMPKV6J4L7hwFyoZ5Sx7z10KlbXXtRcOdQjn5eRiR/HbzdjeCvDpeR3/sQ53odDJX1kxTs4BmHx9vuAYYBBWNUNRkp8mUZhDfqTV3+9yseP8A+Z3pYQ4K1Hgwkdqu5PIAKdSEJ076Kl6rEqwhcHbACqCckBEJYIh4QXMf8GsWlpPgVNYx8YAErBf/Cv7zOjY0mu8jAaFduKZivwBRgFtDKEi/FJ4DvG+KKhrRCTduflVltWARTchdagP1zpGupX+arzFfsscVi+ZvhYPV4jP2YbJTwIViq8NZ1hG1Y+ygHMdgBNhAYYhjrvmpb7eB2OLFTogf4dXt4ELLQ2RPI8DmwQ4wHv15KT5QcBLec9Hrq936o12Mr/4r3EbkzEELAEjPFSV8bCrAGrZKRthIXqU2gzCHqDRPes+jSFs/fcvsBFgRjJMxU/HTH5D4bAcxIxudJ2ByYu3lTozlwzk87VBd2wp6ghjMw4I5aQlRKEIlwwYpQWlB5vqnWvcaiM6Oclu5gGha4HDyB6r65I7n0ALSE8SHpvI8++4aFXLIjAuu6yxYV35dOJUI3mnEBTAv3yI3lhCuaFlo9QiZjGQtkWCrgWG6VNL0Hpo/oyeTqOyiYxrlwScVTC89K7n2LrdBzsrvh6wnioK9WME7m7lklL7ByQpKOdIHusgfLdoHB2l9dypFw459D0vtR/UFiuOPtBY4Jn0skgRBmaUTgICrbTtA9SaTtuaN/aLB8KGLi83heW57N0N5/zwcD/mXQgonR5Y6ulWdsTieLda6/npbc0gHpycVHPJSk493X+zaKt6R8mzJJs3txoDIbTIFUmATEEIxlGaE9xksP0aL2cP8iXFNsYgJDLX7oFh8q1haa77gqr0Jd5yjr82/GPnUPw0o2hBBARNuDbC2vei/JHyxLaVLaLFTpr0dHAo2D2wW32OOZgFpL+C9wLNE9eHyFrOwOIf6ijdjhqlpPI19iUF/Na1pb8LyblVOqAtFicVrbLuqlOY2tfptsXmlZHnE8h0XAmxnj54vnwmiaMUFSC/TOCm8YpuPT4+Q9ySiDZtTnjRL0aPEa77KYlIyeA6qFKiDtAhp8ekPIhB05yuETHOqD5cjHdDJM8LjupyYEHCds3hfcr8pUtZPCrj1q6DuiVbqwgNsQqW6BSZH4deq9XipSNWkWmlEeCtHHuo/6kZnOK2oMB3aZ9HhvtdFiL2zF7nsA1o9YACl+NFjRd/PjCyOI+9kVim7N07h7rfKge7wp9HXu9Oil0iwU6g7R6AjBX7tldJFKSDBEJaCTLnjOCMhYvzP6Mtafj/u/KNK95d3/fpjb8riI2hgfjQUr/FQ0VZvyL6G/TT+lgNws4CLgCg4sFd4vnF1u0NHAGPLhRdqWCP82mCmeUPsDP8sjNbd4M3WHf8YB+5Sat1CePR7oPWcdkB+8I2tJtbOJ4gy8o8+riQ3UNFQdWqU5kYxa3+tWyq9AmOu3jyq62A5AhMvRzXquTpfjjuwODYL31V/3+NwJ3XPRpkAGdhY5gBRRF0EtpYG0HySjQQ7Dy2qP61HGoEvUdm3ZlDi85N7kZY4H/A5mEjV3LO9egQWzHN9Go6F6F4xLT8yNzQw3ifsnIboXCUzb4c4jn4EVn+nyh42O7W3Ul4i296kFoLnT4dOquf4/ZNF2QT9xWQwNTF5tshGBJPA++eyWAkLfkEaRsrCgdYlXFGVdj8xcKvkZ3QwNapXlSh/nMDhW5i2ScIPZXkAVbsAGYzi6kEQdvuSF55it9+PEFIamvDLOJ+4Bbg3dPoPttDKXM+tQLEayItFX9tYi6Un9HZHVq8l92kLaftpR2T/fgO7P6mEGkDHJ2sA4LUzQ6+PlRuGyOZscr2ISoL1V4feD6BTaSMTwVnwcMRHlrHeit5zcv8EZsWzkcdpB4dFM3VpVXB6wENiA14LUKcoRXX0P72fQDGj9rD882Mdpp5rvKvllFbwClFi8GSj853EWaFQb7DdknBZdle45VGUV+TGJWZ8GqRR71GCx6kmOCbV9Y1CrYPWxcFzAqY8l70oubPybxsJy9tPNqYjr8p9vXo2IeYC42cYDzWagkkoStdtShgGkG+UejmdpD5I6DH+dTo1+lLG7GR/K8s9coAJ/3Z6kA7QKPLb6ahFiPanxrnS3HtxOUkT4RsFw2In+/L4fOzdXO9Cam17Mhq0ZSBqvSNgamvuvj8I6BS1MVHHY0uVpjpWjL967VHvPjclSpz9zXyANGomu8qL6Hj3Ox9bHoVB73T5Lxa3j5p1/FHGvTEUcxh3CUPBUWpkkZJDttOdvuB2kkml+ouyTHA4hEwmvKrUWz1OdLn4FkjjpoBkywmUDRoHjuk8tFBTFjw1mhNzhdpYVcR0GMwcKdaMz23MRuU491gvPjHPN1ZF63x8AmEJlsyfbTymH2qtzx8NOYqsmrsna1fmZrB7oorpTC/kCibPk0BDhH9GbvAl5RSxqjQgju9iUG73Mwxe5mF6Z3lsy/QsCFJk0bN5yRdj/juOPNHCoZSFnZNGFFb2THXmLLAG9KVicwVINGW6LE/nKRspqWakCNfCK+oPLm6MmosTc4na+n/n0RI21NY5VZXD1BKHxk9ppfI1QPhobBYPsyqEkZvKzBIrhLwVgkHrHHpXcTphNb76TEAfWiq3tvmzRap7xALf0MnGdLLxMr58M2GtMEwkXTK/KQd7++HNezryrDbiO3WTvkhbNB34W247zTh4xCC8VrEMFyKJyEH2qPC9mFl/lZ7oVjFZdozj4wvSOuwqZIW4g1xnGcAdbmqrQmkyRlPza+CRL6oHnZcfP3VAw09Z/Z9A8QqvJG93D6GJEsPjvNKy1zh7QYK0DWaQ7gnI4+oF24epi+Q+ybDbOC6hztW1OP6hGfnrxmZSY+awxogvl9sz3s2OcSg/u/X23Su+Sohgn8UduMfYCHangpbGUogQT/ketGtE8x9MHnHRrbP/vYhUOEUEsHCAzy++/YCQAAgBQAAFBLAwQKAAkAAADIW2tI4oJl9xwAAAAQAAAALQAcAGY1OWM0NTQ4YjUxMDQ0MWUwOGNhOThmOTc2MWY1MTY2LmZpbGVuYW1lLnR4dFVUCQADR6ziVkes4lZ1eAsAAQQhAAAABCEAAAB/dNrQL18oQwJY3/W8JXA42W1sGAfm+bxnkhTJUEsHCOKCZfccAAAAEAAAAFBLAQIeAxQACQAIAMhba0gM8vvv2AkAAIAUAAAgABgAAAAAAAEAAACkgQAAAABmNTljNDU0OGI1MTA0NDFlMDhjYTk4Zjk3NjFmNTE2NlVUBQADR6ziVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAMhba0jigmX3HAAAABAAAAAtABgAAAAAAAEAAACkgUIKAABmNTljNDU0OGI1MTA0NDFlMDhjYTk4Zjk3NjFmNTE2Ni5maWxlbmFtZS50eHRVVAUAA0es4lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAA1QoAAAAA' AND file:name = 'JDL
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac48-75c0-48eb-8b06-4338950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'JDL1731398612.js' AND file:hashes.SHA1 = 'afff445d38b90f9b53a7fdf1ccedcc781790ec26']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac49-88bc-4260-bcff-4a51950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'JDL1731398612.js' AND file:hashes.SHA256 = 'c33babaf1e100437a8eac1dc30be2176f3ff775ef195b7f8a16577725b6574a0']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac49-c420-4803-8d06-40df950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMlba0hX86yODgoAAOUUAAAgABwAYTNhODA5YzdmYjhhMTJhMWQ5NmE3NzgyYzQzMGJiMDFVVAkAA0ms4lZJrOJWdXgLAAEEIQAAAAQhAAAAIcXEq26TFlgcP65S9FYuRco8T6E8MO5JZIRgGTcvDcS8ZPasbD619/hpRqTTWsRGfyeaGeQfmFIdOCG2hOrgyrKedOxmoPGf04gmORkO3tctGTrHvV3T+wdTaU+5u5utRw1qK0hXV3pHCSVZ9KsXpGrkjwQJyQT3k7Z3Qt1zkLTY7avpmxQCk8lg+9aqibXrVNnLzqOmqzPFshe0jTqFzekTSBkLGbIqVjvVtn2jiLADMWkPasOUhtxakn/FhVC3CVgkDiKI/pX/f7o1ZFEN8CsKsNnH1Ge5k+UDq12Ezsacdy5YO5qHFNTw8uZG97DkZjST6GbFILGdG/+/KSqHZfpt3Wo1Oq6ZzkHVdrivMWb+JshywdAuj7m9Xt+nFRDTINwKjzi4zY2j/AwxvYe9A3i13m/c2k9cHDWgYhDlPxTniAq0pDThI8gfwPwpsRdXsuisuFsWaB3uTkBI4361ISYNIPyNDTij0kxTXeU4/zZ9mifxJWSzbQGQPmblNAeBpUfR3deqNL6DsszdbeLF/Wv85GtVCrhNk3/RwT4SNCU0gMK6Midfwat5S7KkrEEfUvbpydcotyrnO1eekabMis/pFnHQZ16uCtuW7aG2lF9kO5aV3mG8Kjbe3mFYTw1DYKoeCln1TIZrrD3MXPB0svJCL6KM/Lj25dw00xO3ywmg0ls0jZrSgh8q38MXtN/TjsKB9FllVs4M0couiyIXK95aB00p7X9WhwVOoIH0CXM9zYBaVAJcfiIqBPIg5BzHVRZszGHjYqNqOv8IgxCK1vn3HMIMUnpoDZEZ/B4jbKorEF+Rq0Qh+j7JEKA8Aks+HVLxdhntQYVN6dpxlvkfB/D+W1SgHGnmy+ZunDxl53HxrnLzB3l6iSMfKVYD8I3ZipunNn7b/WabnW4sKqprpbDg37RBeG3zWMXf9SVVy89uPukE+UHjH2HpJIUlDxeSfLZr+loRSGhycyaJcxkWO3Tm2bCtL8XYSSw/f67mWvlco6eq7QS3dAkuZlVGIBHD7e1b9A2wijVbZyxh2hvmgwW+IFx5LeTOtK4I5M9y+wuGU30aXRxBx6quNgvKlfUviUqeNXfzvH2HVkVJC2IGYlfV/rqYUJcvH7jQbUdyCOhwnu7wAoFriBaU5UPLH1uihN8fj7h4Kh4YLX1QNOXQJTwmqC9jqyrU2bIRyt5V6dc2s03dL2exetcLjoI1n+9DTZ/EYfJxrpYaXS+PmtY8OpNlPhM9jXhvAuUEL6Z6fCfhUCZGIJUojg+n0eVloBvV765ikpGX0GrzYF+Ea3neUDMnuOhEVf1y26Tz0KHuffXz9bot79X44HoBJqsRNea1KODbZ5EbNmJFrOiBWx60iza05QYFTqWgpaahjr5VzkszuBzgczBFEjIlkc4IICyv2u8brABIqwR4g9Bwu5aPHmMJjpxswB/XHx6AP8/LN1lsVPyy43CWrXyoPb5lSkV2OwSJAgJ0c9TAFX65QlXXzYQWx2BQgJN6tpelcTlXwcKUEIgjeT4mxUtGU6Q1Ec1uytK3CQrfrZmPEn2XgQsfmZ3eb5WxhEQ1A52+dyAy+afogaNAzYCm0//5Bt4finCn9/QNe6ebqTCnBY5myFGd2GDyvw8/mx6zrKJxnkisz46rvHlFSkztyT9GpM7NlWbKXvP+qTU9g8FNYVmGn4YtnMHFGMfZP+WESWpJ8dvznpZa7MXIkeLbBg39bcseWb3bDo0mLKuO/DcngzpNw6t81Cq9R9+y74dJKSdvRNSXaVyHCTYPEztzbnFKFD7fQpEGEeyDvYuixxhiwiqacgFA8BDcf3hvoGMxMHPvaGLbHp+3LInE6RK7YPVIDvH/amVIihbiwo0zZ8qQ6VPZVACDxm5AE1gY6wUo1/rtOXcgjmSfZadZXK6H+UCQ/0a7QJc7GXIRwXqu32f+jZcCURuiPuyFQZeFn9XgVkyXnPRrpUbgGiU1nB/Z3yYAG6lBKHFEdOhraTrLk+ncxpaBzeMKWh0pzUytQZEOxyh1xtD9tnscswq3mXGIWOSH8xD76GbFFZGGA/WoLT/K8gsueeJtH48F4HatJt+C7qv34x53EocBQd8wLier8PCJEenf3aezSJWnJHBDBewUkWLb3K3v171iZOuxRpw/H5wr9kBGIU75LyUDUb+6hGpuJ/BwEQMhfXhDfdV8FG6NdG2eqWRevaf0PYUa4ZL3RtDBMaJ1SXVaWnDrI6vxKx9u3eB5l+Hx3uTI6yn9N3UA4rAjJscvcdYEj6KhlrTJt9KuY7tEN1KLMhQiE9r4DP35dxKDI3N5AGsElB9Sprby/XLfgSZEmSaaT+yPnVlCwuD8PW9D8qoDY5ZBZZX6CvGhkQ/JXyi7MwzFP83Stw4kW9vLthxURiaBXLRU4fahwzXb/bGpUh6vhgEms23TCxPOvEq018uIMWJRYfBgzdZzfLOrQTK3jEwsQuiXAXy+Xc5h9jH1VZUPjVTDNqanpqm/gMuyfRG0YMHNQs+4s4SYfSIwv3x8MlVm50YS+50zXaSrhbiIKZlFuDBY5BgtWqdB5inGJ7+EnE12ubjq2FYr4BzymRjvPFC0mOHIlh4Z86NdcqVATerjTlg0TxvQETV81xSvI/9/Iw/tvEfockdPQJjE7csjQvH1/8dcAByNkIjG3RrpSsYFPm0rRl83U7N8Cqq0IBCR0pWU3gzY3OjgYHyVWbc/TGdkUjLo+w2/Sw/+TBFtO8yZxvWRJ0NPFhDYxVlgE8h29h1l56Fzjze09Hc0PYAtnH9qScxvT6w27B/NjKwEpO+1645NPauEERqBlVEoJGdeB6KcZj0Ch5zmCy/Wcpg6LEDqmz1tmWU5X+Fc6NtbVJrKUwL23srHpzLeIdusZMxyDg6giQoFZpyB6hrtQp6zhNsBq0SzGiaLgp04FOsBGv7oDGJA4ZEkqFREsW6xGZvuuAv/ZAvcKrrGLvGo6GFglCNOAHkLqzPdfPNHD//URv5AaX2W14OgksYyxYFrelpxI2iKUj3J/v0VUuqBQDzM3Pim2tl7rtHu/WPk1DmzXKli9/t5LDG66kwTuNTKNtJ6SkfBRlr11mJDSj9yTIJ9lLmSAiz4XMtaISNhaOBqCbiIaEYIqwWBHEGpIxLPo+OaIQbQK+Qfz2XJzi2GeFikL5r13LwJmiH1naQysGwhTQ/zE3Qm1q6G/IAGTiSbeSKGGSby9pndB42znVysj0TKPpQSmnmZAKBNqd5GmLPi9+tmzToSd9Fxn7m++1ZUrY4O94zIp3s55FBp9fxz1tRXkPEJGkaWsRip8olSIschlXgJcMPcgRCizB11UufshlEJVSJx5w2BwUwsh4jXpmXmXbQ+cwdv3k27iJHf7sh5b/vjhVYcGpmNzHoF5Q3aC0YtJQAUOUHdYBvngbntC6UDMkht/P4j7dHxBIakyeAtUEsHCFfzrI4OCgAA5RQAAFBLAwQKAAkAAADJW2tIl1tibxwAAAAQAAAALQAcAGEzYTgwOWM3ZmI4YTEyYTFkOTZhNzc4MmM0MzBiYjAxLmZpbGVuYW1lLnR4dFVUCQADSaziVkms4lZ1eAsAAQQhAAAABCEAAAAvy5iDp4DWO0Pi1vvIsImGpVGmS4N+Sn+CaKcrUEsHCJdbYm8cAAAAEAAAAFBLAQIeAxQACQAIAMlba0hX86yODgoAAOUUAAAgABgAAAAAAAEAAACkgQAAAABhM2E4MDljN2ZiOGExMmExZDk2YTc3ODJjNDMwYmIwMVVUBQADSaziVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAMlba0iXW2JvHAAAABAAAAAtABgAAAAAAAEAAACkgXgKAABhM2E4MDljN2ZiOGExMmExZDk2YTc3ODJjNDMwYmIwMS5maWxlbmFtZS50eHRVVAUAA0ms4l
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac4a-6a30-4e6d-b15b-4083950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'MWH8989955508.js' AND file:hashes.SHA1 = 'f92a435a982d05ff3df983a3e5a3ce7d97c38454']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac4b-6d08-49bf-937d-4959950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'MWH8989955508.js' AND file:hashes.SHA256 = '5df6c456ca6136917a8dd1f98c5316d4bcc438639196afca58f61d31f8e6e6c7']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac4c-6a2c-408c-98ba-4cdf950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMpba0jIKpwD5wkAAOoUAAAgABwAYzQxMTY5MTAyNWYzOGUwOWMwOTY0NWNhMTIzYjc3YzhVVAkAA0ys4lZMrOJWdXgLAAEEIQAAAAQhAAAAMZUQUiI6P/LGWM4JOVaZYOUubvizJzWelTXJ46NsxnQU+x+trq/aREcCFMR4ytiJGMUHHzwbajMq/GLm42AMvUONkcXfuUE1lL2G7igFxeZ8n+cB4U0nvqzr81uC9Nh6cr/gg/wO7QFQlUO2nm6dyk0p1T+6yAFOIytCwMi91r4iSsbI27sYL2Ka7sLuDNGkbIMeYTOqtyHiUg5vq+5TTK/cQU6wNyS9L/nidZDiQ0tw1BOxNXQacmxE525/tGSt8ZGxv7F+XmdpWQGJSaWnKhK3ME5GJ5lmL/xxHJvXfgN6AfchNzfQgfV81dV0hqXgKrPlvJALnDRq0kyyDwZnDHb5SDVfsbqZgDbs7x9aArProqAYbWdDRCUVPzYBCQZ1X1it+IX+XJl8F1Fng1nav0RbB13PMtE14AWynCsdzo/wNbhm9gruyOXwmJK1Fei93CjDamCZ8M6sTTHu+R7BcnrXghHem1zOsQah+DKxV2q6+K1mEhmW/yHonqsBp7bzeNFA+gI+pwnP9DAegmzIbE/+w0ehjF3L9/8746pTzEnt6hUChFQ3nH503/Sye2s570hcwTsXTsbF14EiNmyn6RZcly/hu0xswzVcWFE++aVBCN1SQFj0PeX/c7H1qssNtg4fS/YjdAgT3C2mghuBhebw6Ac4FXpHzc0OJkqZ9cZSb5iA4/1JOCkK9PJVwgWu2jOn74dYcEPuitiUA5xRVWKtGpE4JIenyj+hsFLN3yCc8HDZwdoEIMVme+BVnoxnSd4Vc0fwKHjttmaN8CC9TpAPS07YGy5GTFKCrk+l0bJZ3B6COebSHzIhDRp97LkY6KlJPiCifp+sJGIpxOpRxGJpC7ZL20J141Wnk1mH00G2pgpfn0FRqWfr3TkkgqYkvyVsk1dYBWthOSfV2sBlPMPXx8nwZeXWK7m7XxHrDZ++8SDDZiEeLHUDbKVN4wxTGU0QVbf+HlLt6x0ywkRenzdPITk5V7ioXJzyrfUVrvMrYeD+uKs7oW64Rwr4t3r2zlHfVTEOGqsuXdNZjmSU+VR7Nm8y0hvBjI+tdkQvvqc9Cmzn+H9zy8ygxtzdMc9zcaPqOZviq1d4Z4UPQY//KhgBMNyeZC084m5TS7AiLueMQ5mBYoATyEjD9Cc3LjkQdh//WuUS+Esy1idqDObF2DHHC7GHm0SQCqBa2QspXJL0ImzGbh8GGyL12INsMMtrrG0Q0epSPgu7qz4EYuqWkVDnG1CcPVar68qbV89+Zr1vgCXEpWwfaYWXle8XhRA4J7a+rYKvj4CxiwTTZGlKtNGGFSwW/JdP8RwL7Q6o+RQEOiNKlxjBRnmQiM9Epi+AJVqA7v0FfXG9bNQTkxgGSLVJ1FGkaDP7MnDsFutCXpiubRwxMxfzWZwGXn2GQ4+zmDfVhZfwYG3T0tORkH5v74GGPZcKN6/TP8O5WyDGeNdEFXB0M0mOUbfleDad/k/2rH6/oi3UOAzLpgyARLp+/Xw+g2TTCq4ItUSPHFdQF5yFTj0k1dyczEzU/hJvkUnuLHOGnw1SFglOCvRGMNC1FQkvERuM5qgKHqe6znGJ/EJnGg1nEG1PPkj1Gv7m7ABcrwNfqnRhwLd83zKLt/e2rFSV3gFBdZwfmatEGA1iU9jqXqvWLdGj+HmIub8T1DqiWXKQI70qWY3Da+waPBTPTquZaa4FL6Oh7m+eqq8i1C0moMD5moM8pgNjqdlTAC9ZzrUddz5hLCcLQy72BHrk/HFwve0d3/ZgXkzMWrJxgzde3p/U6y5jOG4ma5Nr/hr4A+B1WJAm0kwKtqx8xtWeBso8mXHpjsEBCl11eYbHC8QznKoS6rLCvvbu+0zOj9EzvzK62W1OiCvbKUSePmkdzXUDpz1Uj5NI/JngFCbjOvpo4V+eM8uAt9AaaaG2dPpaYAyN+2te3T3q12WlBTIuUyFithyORU6PfbZrWKUGOZDDOTtDzfN9oD6nM1cK5bSi35Yw4hcDnlHRRGXLTP0P/cLq/ei42hiY8DnnMJKee4Jxu+uGruXrI5Nhe35uOWRDUFtezgjWQ3Z95XOg2KnRDDMh7E8zpuvwdNNJamFXEcwePR02eOmRzSg0XGWmPnc+1sX2tglXcEjN9MhE2r9zsWjvdOeh/ruyl8yQpmSUBAb7FNEyZDDg3NsHF7nUiXc2cJocR/dbWzhQCL5bvYqr1qY/zwki1u1+AkQz9jicMIJvcDCTJlReX3Ap3E35IaKZJmzq6UYdMuSaJMIUyYU1F6pt3dF1vSOr+XwxgVrc6zUrqcG0HaxCHZuxzZfMLsP2xwOLBQCc7og1pcdM1UL+MofutRXwB3t9guLi4OMWjSlkxihauRHKpOwp30PUMARQTCOFVOmWVoh7kZ6PxMg/1nD/zP0SiM2GRagp3X+7QdwDByHHxurHsYau6LbvROE+kM/B8WhkCYuOsTjgKqp3wD4vPs0VBBqJTiTjbXanBRUA7uE5bIfc2+R8q0+TpPBW9HLvEnQCW5+MrbDy6wWp+nDhBqzzrBw+97vRs2Ygw+TgI7qbo6Rr0pDLQy0eT8yRG3CxHFGtkT0urrlrtOjh/6cYW7mqtPDGknCsXPVQad1eKbUjYHxi6vnv9wv2dG1VZgwlTlYlt7jVFDy7ZMOM9/rBCPB6I5RreoQVxZWyxoKv5/sOKh6kXxTlMKbU31MLZDSNY/G4209Qs93gY8uFPNzb3Q5hKEdqLgmbma1kRpZV/kKMYRNTTp1XnsVytfx+CMhu693mYrlIlnUwI2VCO64az0BBTIicx5Borb864jpTrEz+X+lSVkws7XffMpkuUjP68MIl1eiohITZBvOnH0IySk50At9BaB7AhIHMonye4higzQRL8JIwjjIm9/9bWF/72zsZG3s6UrP81gbLg7xQyEH5dLz4irPB2XjEtx0Eb5JJgdDPeuYsTfP6zERsGJS8Ll2lQ6mHx9/BMP6pNbhx6ZVKrwHqNTLbTtdELSVQbrhIhaiUT2o6c6/uFY24OAqgFYqM8DqVBqn4VCIOJ8wg+2JEsSUraRVJApO6ZNIllhdmEx1u0ggqpV29DCp+GvYZsW7WQdDFSEnepcOHCd9miWQMTwHz/MFpBRjB9C2mADbptxrZ3YygD6ll6Eizan0vzfPQd136d277q0o7kbpB9V+3T3S9mBT1mhEMyazWa7EfugzNci6OhufRkFUCpX4ILXLUEw8xTo/Ly1jisMYqYzKKauIpyzaNuv9EhUOX1UHbERIJ+ZE3MFO6EOGQKKT3H8gAViHP92kFTCaGw+ApYnHuYybiStqCvgI/3ckSiN0nDg7sqk5VVWNi/KcCWNPyM1mOFmVOsRRCTW08fAI8RMp9dnvl3UgoK81FNKUCCOQZk72cUEsHCMgqnAPnCQAA6hQAAFBLAwQKAAkAAADKW2tI99ir3RwAAAAQAAAALQAcAGM0MTE2OTEwMjVmMzhlMDljMDk2NDVjYTEyM2I3N2M4LmZpbGVuYW1lLnR4dFVUCQADTKziVkys4lZ1eAsAAQQhAAAABCEAAACTluyhbSqbnhoAUNXuWU8ak4l6QSQqLfIeC0LbUEsHCPfYq90cAAAAEAAAAFBLAQIeAxQACQAIAMpba0jIKpwD5wkAAOoUAAAgABgAAAAAAAEAAACkgQAAAABjNDExNjkxMDI1ZjM4ZTA5YzA5NjQ1Y2ExMjNiNzdjOFVUBQADTKziVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAMpba0j32KvdHAAAABAAAAAtABgAAAAAAAEAAACkgVEKAABjNDExNjkxMDI1ZjM4ZTA5YzA5NjQ1Y2ExMjNiNzdjOC5maWxlbmFtZS50eHRVVAUAA0ys4lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAA5AoAAAAA'
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac4c-4f40-4b67-9169-40dc950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'OCX5024341206.js' AND file:hashes.SHA1 = 'ae4fc4458af409defde4d2be0a5fa07591325700']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac4d-1778-45ec-af39-4505950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'OCX5024341206.js' AND file:hashes.SHA256 = '0e1a591af36e431036ee8ccc2ca2b1c339f45e05fef95ad2be3d3ca4632ed457']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac4e-dabc-4cd8-b85c-44fe950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMtba0gIV81epwkAADEUAAAgABwANGIwZjM0NWVjYmIzYTk3ZGQ5ODZmYWU4Y2Q3ZWE5M2RVVAkAA06s4lZOrOJWdXgLAAEEIQAAAAQhAAAAWKERFvp7OiZab3sVySqbaLlP5CwLm5agsTR8zq97LHkK5hWk22tKl57dy+KF2fqf9pgPPbDBIQOT75VYUUn/f6SE6Y9CGzjVazVkY24BAdkQp5Vp3+UhqgRGkaNZodz4Kl61MjhA9alFwfHWR7Ucgfb+OLNDx9dr74Z6B0K/R6/VE9RAiRvtmNtLXWBMOviJ3WW4+R6UZnSJmvaPl5kzp6+Wvjym53skuEMs93cLV0ge+7lRjCo1lx7Y1dY6H5ys6tiQwAXjxlPYHvkoyY33Gg620HKC/pbJxObhFzYdTWcYNpA70Az0OfWndDXlkCCtLegDQBbeHaqmJSo8R1JO/4/JZaYnWOvsR5VgT7jJRWq587lJwVSyfseGSAqx0VkmcPATyvya/L1HBh/r4+izcqW0eVrfJ8asbpKQq7LQr4B0hUJXhEVmuGk2+TyIIGswVa98+ju1nXfsbd0WmBWZO5DVyqzVca+pZ9JtuctOit0aBYsFDU23zfFvty0iQ/PJcqVN2FuzyLeDrMW6G3/hPN34j7Ila4i6jVW+LhTGbTp6F0qnhb6sIhTT2e2UYCdruIGvXHdRPsht6UnldtYrpFLoguIFyBBKJOX1IFij1uqRm4GZjGaee8hBsxXEIMH4ro74FLhWK2wt48Pmv3Rqaxo4JkN9Pmy+cXkN94X9eypy/MmyIAyDHheJPt00fbLCbodyuo5J20brjwlyF3t7mcoppM7nH1u4ar+kwCZNN3cG7xe3N6cBRajGyA4EVI1XuQ2MrFeyZfsqSr0o2CAiY0FIhL+Lz85jKL56SGUA6MSNrfxEW+m42YBo57fB0jS+6fQQJNXk0EzcRaFJtkR1LDTllIcKjB6ubArj0BZK6lxwSONtx4sIHavRAr3dD+uvz2prx8BXg2RxLVJkHwL3lv6hVLpo8N68noJlfG5r/wmZmmZ1vy5B2+xqA/UOxjjfNFJCSWJJMDO1Sbb5E7gvz7uQdiUuEIP9Db2vd5gFpFEGA8OBO7qf8+HXurCzOVobWUDxr5EMxPy4TkI8PVJRB5jgNfv8kLXTDPtIEvdiOhdQFAJtVFoaqtoDjrnxAHe8Fb02EhvCVcjkCuDU7FJQFwZ8yu2TU/4kwUMvw9M+GFKHh/V9QFreALi2VOz5312AIUpvS1zkTuZkrphyd0QrpXXlkipIAo/N+IqezonJgEoyu7Yq6zNQiNgoTuFr2n/phMHf3AfzMhgZbU0oreiXWYDAUSdFyQbjYOf4ZTEQ2HtA6TVOMgsYsLT2H29bCXX/o2IGn88bsD1k1AO8/BONIePVixplFt/lN1RlaRtML8dh7BXDTvhMOJoEqu+Y2JAAjmuWDrQeK4TM0fkFEUm7kEcVgIludh0PcSdH7vFuiglZ7m0hP4ZGri5xWuv1Aqk4HiJCVJvj4bnfnjAo9ZcevZFV7ibUgxFA20nahdJ1OhCcUgBM4Kh9BW+Nvkerp8ayElkMy1uAGj+YHunTar3V18s3SQ8GHWhyxLt1HhaarSeooCRQEfqFVdp5iGTvU9cEmVxx0sUt2cpXmVrNEw/9S9m3ye+OG26W296XXlcyss2A8aVTrAfuDOHtlWJ2iS44TbMDlXpXBPmDhuw2g4HIWxEjPuvm0QPAir3LOYzBPqdvWIBZQvxZS8fXm2yd5lCx1dGK6zR6GpOj0Rg+8h8XlAlGsFSZeG17iq5H0IG+sh6kqcM3Nsl+OIqTkBSr/kUZU0RGEw8+4VqDGzPcATSBm4A4harXuiAOjR2SGa8e8zDo3r1tOV80EcnNZYK8r83IbY5Jj5E+nQIKsKhL3DrWgwfvhT9X/OQyqmRKwS/uglZIrpXVQ420w84+FUaae5I8xNjsTxuQvYF1BmgdA22TMYZx3p9/858Y4O/NMPdIWbM8Msp3fvbhj67y79FwBMulDxEJxL7MnB/9Ss1FVZHo1/+J9IB7+P/yKz7Ahhb7ho0QARZzFMyOgyKNt9j4hV3uqrDvNxAWzSDjZm2r0IULDLnlTqyma1LFQl5HSeKoX7dbKo7GMivrb9ljPaBzX7PzqVTlBKspoErQViE0mIqbhV+Ml/r7jAeC0+FoP5aVcpd/tt9JiuQP+d+Qv18y63F7ZWWA7ht0Ab3O5EMQyc+XKBhwURtKpwXYyNvB7Ag5XkMiRLzO9NDS/by2mkdFUVKw5NKod8md45oyCdXOLaXKgJWQzL3XxaGJ3mz7BeUuE5UjH9jB+fa/xITciT/jOEBpiEJNhzMKXRG8GCmJRTFk4Qj8CGHkStsyOXJNsVTuIKxSJK0u3dqt7qZuOkyvgnX9ZJaNAwBUZIQUOdBDUAXgh1JkjiPKWkymdWy59Isje8Ez/ykBAQjUmqE7Si7sD/B46w+27XAYjWlODB3VS+U/I+R/uHnRaUJa1ot1QPpwN2X9EfEDODT88JAktGch3b9gtJp7h96yBHpDlXlyhCLUdmlFsLZhI+gvUCWwgDRtvOGAVUt7gHR5nM8lxCoAAmdjCAkm2jSYl08dY5Y/T4YJBppGfQNRxP7/zVEC5APZtVPd/TWhDLWl9CzzXQuCSviWulRXoayUzuPww92MYnw66aTXlSCrhtgrjWSSsP0Y6yQHlIKGBFHS4UIR/XDwyLLCpzBodpOWfhxEeX9s37bU3n2en4eldHoFKrmysg7PjfKCYiSb2N3KhBZv1wtuOFW4PsPSvP5ItFek3C3H9aGw1iN378NRvXn0anAdHrik2Rcu3ldS/7cE4wuHr0Es5B5J+GnCrVgCmm3w18QL2qNvMNfzLxrnBxE4Qvzou6osYJ8wF7u6xLXwKmNQxeESigsXQHIGq6iwLXIgPr0W/V/uzAQVAC5WP/EQrQZqdnU0o5tJT763xo3mWUxNVnGg4NUYhZwpe6jaL5n2YUoztgYbUQQ2ihmUpMTRwsNnvjFsrqaSuiE70doEK+lkCoQhSS0eJ9KiQmwNMyJIf02PaXO+1drvY07ZEcczOL+RuMWhccy6OonBqvMvGFVGzAOng3co6K0HAoxoOWWR/apD2HnQ6pQGT69zcKw9xbknGh5fGzoZorREPTamub2y3qtZP/0zS0/DPz9lZ7hIpMsroSNlkC6a3H4Q7lqaXwyl38W60/J2iCY/ZZtwJgbThZHCsRMVWquv/srAxllofDoHkA1SRUOtMZKf8ISagBAbTdah7cBBZCCKxhRDc2Cjz2+sWyoCn7P8v3XlVnspukJ9Z/eH4sogQBViHAR5/XEAmLVti/3gtpxw6EUtZ2n7MUeLBmYECvXwvF+tzsr2oWtiGUNUSmwGzaHPX+lQSwcICFfNXqcJAAAxFAAAUEsDBAoACQAAAMtba0idD+hBHAAAABAAAAAtABwANGIwZjM0NWVjYmIzYTk3ZGQ5ODZmYWU4Y2Q3ZWE5M2QuZmlsZW5hbWUudHh0VVQJAANOrOJWTqziVnV4CwABBCEAAAAEIQAAAHLNSfZ2k6gnnhannRdSOt7eZNVX+97Ss0+u+j1QSwcInQ/oQRwAAAAQAAAAUEsBAh4DFAAJAAgAy1trSAhXzV6nCQAAMRQAACAAGAAAAAAAAQAAAKSBAAAAADRiMGYzNDVlY2JiM2E5N2RkOTg2ZmFlOGNkN2VhOTNkVVQFAANOrOJWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAy1trSJ0P6EEcAAAAEAAAAC0AGAAAAAAAAQAAAKSBEQoAADRiMGYzNDVlY2JiM2E5N2RkOTg2ZmFlOGNkN2VhOTNkLmZpbGVuYW1lLnR4dFVUBQADTqziVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAACkCgAAAAA=' AND file:name = 'PET5580821306.js' AND file:hashes.MD5 = '4b0f345ecbb3a97dd986fae8cd
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac4e-a798-4102-9e7c-432e950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'PET5580821306.js' AND file:hashes.SHA1 = 'b132206de69e8b4bce0540e7d998ecc63e823371']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac4f-3d04-4d29-bfb4-40d7950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'PET5580821306.js' AND file:hashes.SHA256 = 'e2689971c91e31f8216c3a66c59b429305839ddbc3732f36021b54039eca670d']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac50-7168-4011-b461-497f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAMxba0jGTC3/yQkAAOAUAAAgABwAOGM4MWM1NmVhOGNjM2FiOTVjYjQ3NzRlYjNkYzJiNTlVVAkAA1Cs4lZQrOJWdXgLAAEEIQAAAAQhAAAAMZUQUiI6P/LGWMgMOzoJVJ2CqF0f5mE54bz5hv+3XzM/xrxm5DvtIBBIlz6/tl2tOCwP7a9IsaXR1ont2qm/ejYlukYPWnu8kBXKRJ+No1kIsR/6Eo0MD+ufVWwtLa/5t2ShJcvn0SlhIBTZ5aYNWy4bAjzYSV/Dd4s2gDI5RYLW1QtE89swTEqIpVDLI+QpoU2yYRWHLRJBkA+lN2EyoROhAQtWtZZYERIFUPVVeoBQ6ZSC+IaQSrvSIi70iQfsbU7HT0/KSH7FD1KzYzRpYZFxA/VlezPdcsevUn1VwTyFArUwKLps0tZnV5FLzML26CMNphAQVqniJ71HiZYN7rw/e+FcCAvmJoa8/vYAqIO1GFpp3Z98xVORBmj7i9EZqPvRnPZ/P4l0bKHPkq0mm+TnaxWPiu7jOBv2BTAN0GNhXdyOKwQfMN05H8VyTFbp9C3Tpk5oEnHfAK6rE7Y7VQZUqK1sFBBbeAbkxuazrMAfo61jD6Izl7AKTB7l0EzzkMKMOhbBWCD9TsVU+6m6LI5BrRBHKZ+WFvGY/d4lOqV2+sh5qed8D1ps2Wt7XPCgQb3Guh8mAzwZztB2y6KWafwkBKIyOf/Giok6EGcA5gIP8UebD+Cm/0Wusz0duX4UPMo2oou2Zb/b6AGAwLXsb6bGTob576eQzf8i9ZoZtJSLNUL6mu3AGyUxYRVoeqxhHqRuUkOju8zqqYzsZZY9FvLOaJc6SH//3Qj+gTJuPUSpyU4iUNVqvUCcFogYGSRuWBKWhIsjaXgiZq0TtArtqgEiOIJKp2oCBV2bPr6+f0MD2u8tjJbQO5jL7KS5aKtzQ74rtpHst4C7XTsAC19iZHTQ0jVH0dsMmvD/oC+qx7lb1mp0cP+QG+mdmG3sLvDoTYIbiBSuYoc1zB0fELFMVIMqfhaNrvCnT6RdLaEMfzmzA0eErd3bZI9yQwO5k36Kx8EJ0lIUfPQvg9pqBLAfra80OsF1EOtmzR9Zyl67nm49P0Ww1/B7MZvuymB2ym4hBKBjw5Ea8ZbMwYXb6IingVhPrvG4DeXx2ALm23CzPTTizHmYwVt7wd2dPuZq6rs73VlMZqfY7IxcG9BEIbbqKFZhTLlSN/EWiU/Si+olHRMNx7NP/B7ouzsSB4UUuK7S60MnpNdg2sgHYNKoKbY/rx+b/buOxCYBmKrpAV9sNkhGl4bVASL4GCd+DDKzlT56BQlrUg9rnPJytD/xLKm+IIaBgSehnziTgXS9rKr32m69qQQ7lz9srQj05rLhpbknADxslYhEkCNpjKqDNSJIzEYDrN+6WtrbTKdz11PrmSyqQHNeog5oUOwM2fPHQscXXoNI0FD7t8WUYsqGrpWmUGlVGf28ClUBNpX0hwXyOlW5QYSzoeFszkykLKyPTRek17QsnvGCUxgPL9PBv18Pef+VjbDViFCz46EHT3/S0p4lYi/vFqL8LRzYEcSC/jyoV+hHlqvA+nCa68pWtzOI0AqiLOSbHXY6xDjwYQQeGw0Sg2/K6KsulGUb3F4LkUqyXkt3aIUWAZRaKIukzHrsgI6IsSYrF7t/ON92pf2NNK1jJAcli6DSqajVc+nMr2GwxotLrYxUSr2noL6ePAVNlWiVF6epjn6uLndjGrNbm5sFJbMpu8fPH3u06dv6TP3a8RHI3uYd9KpdbWhTm5tRkyIclA+PyOJiONhvc0ZneVUsztODTq8o2w0PZlGOgecymG/b7JceeWOqEh348oMD2RcpRh5SK/pvLSrNrepsiahM2tQKS05PH78/sSKKezAGr+onKjDQXx8ySRGaDDsZk4YGT0vwCBzkI3yQ2f4QB1I78Dme8AcWEMPIR5jNpbOArzH9jjwxx7Zb6VXszCzdzOKDknglkDUideeOtxMH4j+4Ysmipn3pIMuDFbINPq1LRzOGeV2/jopMv7NkP/y6ukgtHgE8zhIQ8QoG+EWKqR7hgihyMgWHcgkehx0ohZH+mfVfkg7yuYlyYmaXnlx8JWM1vN/XLlcaA7y/8abKu8rcxu57l34yySqZtJNTXjy3lajPm0kz3BC1cCB+3CVbP4PamGjooOihh/1dmSZ0kgV9MVo/BhuiK9wJAnOv11wlH3k/W+QMJPr+UhADcFuFBKy1Qa9uU3A+S3vVqJ/ZzjXZhOhCN/vjNJXffwHJ9ilYdwi3Q/NIjxRYs1ty5WnLgoyAGG3rmzV6ok0t52t0JtTmj5oNZP9ML0z9S0UcB1ANJAsNxf396J5fLuOIgwyWu48HKkfpEsfq8uuxMnDwo3jq+/Y6yciT0LFTfJlYq06v4uVufbpUHfNK6C+r9dkmeL5MgrDd0/4DQC9SSnf8Gsx302Jb1rHGxVWeH9B/BZUqbiai2s1sn1122Y+fOknwOReXFKI/6ZZz1LQukdrMt1atFa9u0IEHhdNew7bM9iPeQbsS2L4Cn9K5x2BjGkA7uzvjP3Nl+NVZ6LEDT9c8OUD9PFnVkpks+twnaMyMsERrH5i7Ub+kytUgiMTrAjPmFh7mXCbwtzG4GezNxZdVDFSs1EfgYqp3HnMFVX0v8OaqYNW77mrfsm05tM1QVnnbgpxY4mFQ18H9zc0eYrepfFxVyylZlRm7a5mtpBDeCtMldV+Dtg0x3ajtUJGiN56W+928qdELXUgKcL/NuKVzZQjL1kglp3L/m+mkAg7Ic/SSia0mPAufdb3Z43X3/H1Irs0Idu8LoFmDXoPHzSvIxPg3ifo0bf0q8TIWoxEwNSHyJXDel3DMH7ju1me4zNcBPXWeh598quO5CD2mDylGSXsWuYlsU5TBQXlLAUAQ6kEXcW03KjG/H4Suye3ce5D/bPMz1kXFD3NHGBqr8Wc9SWVMviGkqLEoWKKvPm5+YHclj8U4BPzvXrvtPpWyryoae33cIOUpjhad7A49bQP0EZDPrf1k4IHkhHtAhLxlHzALsEon3G410Mk0daZeviEnKR1DoBclpRcXihMlZzUlf5zQm07hPWPXLo/seb3Jiw5lk00Ey0YnQOoQFD+moYAXCMfbZLwaNAo6QxMuXQ2r6N+o9CwlxxjgIV/rsxm61FKM3O0H1QFJSNIBsG524bZdKVgPUUC5pFKbrMG2y0+x3YQ1qlevBUxPhZ7GIR/7sCJUsXd8v7FWC4z9RhvjjsDm5i/FZTB5pU/VlebzBEdFNxJetgHNpPtAIK73jTRENVasSyI2n0m6Qf2F7YapOBhPMNsSmjYm4gz9j1+n/QQh9Gu9YfRxcv8Ch3o/gYzemigNA60hdGcogiSlgPRXZ+lXz+qRpHcRvyGp27HjwMzHVYIjlxz8cjU2HWm7j/TBLC83Q5jv1apNRyTKUEsHCMZMLf/JCQAA4BQAAFBLAwQKAAkAAADMW2tIe7MQAhwAAAAQAAAALQAcADhjODFjNTZlYThjYzNhYjk1Y2I0Nzc0ZWIzZGMyYjU5LmZpbGVuYW1lLnR4dFVUCQADUKziVlCs4lZ1eAsAAQQhAAAABCEAAACTluyhbSqbnhoAVs7sxEtD7LQpGabThqPUO38rUEsHCHuzEAIcAAAAEAAAAFBLAQIeAxQACQAIAMxba0jGTC3/yQkAAOAUAAAgABgAAAAAAAEAAACkgQAAAAA4YzgxYzU2ZWE4Y2MzYWI5NWNiNDc3NGViM2RjMmI1OVVUBQADUKziVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAMxba0h7sxACHAAAABAAAAAtABgAAAAAAAEAAACkgTMKAAA4YzgxYzU2ZWE4Y2MzYWI5NWNiNDc3NGViM2RjMmI1OS5maWxlbmFtZS50eHRVVAUAA1Cs4lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAxgoAAAAA' AND file:name = 'PIW8665135806.js' AND f
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac50-fe54-4a2f-837b-4af2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'PIW8665135806.js' AND file:hashes.SHA1 = '36738c7d86c6be0a956c127dc4db98f9070d27df']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac51-8020-45bd-b682-4f53950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'PIW8665135806.js' AND file:hashes.SHA256 = 'f6d8eefc4f1bbb2577de5d7d3cfd9317ba92459883f6657319c8babd97c2d7d5']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac52-0a58-4b48-a9d2-44b8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAM1ba0gC3ofAXQoAAJoVAAAgABwAN2I1MjZjMzA0MTQzZDZiYmM2YjNlZDdiMDM1YTE2NTRVVAkAA1Ks4lZSrOJWdXgLAAEEIQAAAAQhAAAA3HzqdvANQsDOnWWm078BRfMgqZiyI8MCAPgDeLR3s4PHWLTuVXx/JaWxnB0QymyEe8/TMyArpe/Re2+MPLqwOM9NGayKoXp8aC0pJ3K8kgfcxZdcZvTN2J1e180qqAYNLJrSS7oq8GOWtA3vjswsACN4UmbTMAHQPxZW82TjC1vjAQaBfh0ge4u4rmUDpgbSg+sqAMVex8EJQBh/wHQxvVTObUHPWvFeAHiXfgmeQmAoIhox+6FjAAWqKbSnP2/VMwhVaKEW0lyyoW2Cz5cXtPxFFes2HrRihrm7KHhSNJb0KIc18veIXgMVc9RBACaofxsLEZjsInXi1qFprEQt9nn/HJs5OpbxqjNNsEUWydEll11oTCQrJkMzFUxvOadjgEJapWxkVcQZXBwH0/GEJK7QGFZiHxFdCtT+FkD0TZ4Pbe4Wtl4RR/zo2bj/Wv34Tk4LLerPqVSD+444FExe8hBPsRJuRQKkRcVLsJPeHLVbXV36D9Z+lnDdNb/HEs102cQ62tqVgt+dB4LeGDF5VpTwS35GovAgzmYn0t7DyU/O9aQE4Up9xpnFy8dxTw5WBmMUZCW0xBGksjvG3CUXW8/VbTi1ZlOBVVVR95HEtqGkLKK0zEzn6zpMXqMxEMxs4dKMRgIsNYmJnFiu7mY9tjwGrOi8rJPUx/wl/gcZEC3urXFJoMIK8SycBF7eJXQDiA+U2WRu7sMwcX2CmlfrpOm0Z949urSCqtoH/n0ODGRoTf1zmHpJYJI2m1bQ2Q9RPiXcsSk8X9GsUR2FHPjgsvPSmPafTttt4H1deOsltLPcbOPehUDaoulGz4M7b3WirOLZleFV1IwEZN6IFG3eQLNgJSmVL9w7nRM7Xn8sWacgwxt1J77282gCfdiTw2t+WKBsqKh+qtjbL9nHIEAKRVCbSdc7HAwKsYsnHHjQi7r8qNlusLEjOKgViXo33PPk0AImoqXCr+mJORvb4o35FMYTtTJ4my7w9BMkbLb+EJoovnaD1j/Qsu99jz3sDQPBBH3XQtKMuu9t7t+o23uSbb3JKu+6wzZXprxotqpnJx6mE0aSvErnZyDmRXAND0nXyjTj7WHHO41l0qlN+chvOq0Meu+LAS1GaHImBJAeGE5veBJxWQl+3TAqy1LxiRLI1f0hQRx9gI3cja1C4QmqzYVtWnNXO/ySgnclgitxrslshWxUHYIR4GxyEUfO6g3yrO8FSeU7zd0bc2QizM9elsm2DdQC721lT4hvwA1Gljy2GYBg9j1r4yyWojhZNFLoOkthSTvqNzLwjSdOpOK3p3gZXb++c3EUg0uH5p6H7jxrHGNZ5+Y/GADSxwpNUP/NhlD1gfeN/2KcUxR9Hekqwwt4+leHcMR4ImgQi86rlhq/usZcrgD28x+QEpRs8FQBDYoLHjr9kf1Y/ZM478xVqKWYBqNagz9qwlSK1oRibylz8Lj0iPH+OMpuT9YdI1OXtJ44xwS331rcqPgkIb3YWUAWAIlnzjwsV5M335FaQoS0Pp0+4hSdzVuop97l3UMEcTOpN5vkaWHDwp9m7zjrFx69QHDTFPftI9iw4kSciBOOox/SMQdnkKtnGXBD1hFY7nd+UQENSeO0uExYoC+/jfe6ZOD4vZBAlZMxzZMWwyC3+3etgN3em/Rt/B4U/Xlxqg2OXM5L1jvR47BJPiCvtokKOOaTNZ2qev2awYZJ3BkgvOzYD9gTOwkGDoqcMILPAZiuPA7Nee5yLcCH85sczzKcdA/NROrstP53VLiKdjtedcChdx4S51mFZwihoboDRfnax5485/OkvMAGCj5DhKBMK9WP81h4iu0p8HQUS3p+OBCP+dTzC2CIpkUnD0n5DFTS0sKtlKEIFmLJ7p4KVi2dTVyV4whIezlEF1SB1wVJiqL1J7hybPWWXiywHDCB0ZeRCb/xcMrfyWIDhen2O29qRC7wGUHXRlsnzKp9VnDBHi3zwCINNFGZ5OWMsUAcIT1dXQAZJFYC8NwYhQ30ibc3XK6sI2yRrtiinRayRX1GWsVV3e9PG56aiipsEOLaMbMblsaj1kyNLzVNVSKTgw2wK+81wqU8no2ORcOMlDXtJkiDHazkuCikLg1tWfvAd6p5rrdllEbaSsw2JDKzr24fn7zFpqP9qSPj9fw9KHxHm0iDnbv3tslMjOk696gihmwqExOk66gEY/gybZEf3rV87C7FvLHG33aEFq1tBaQJEI+bebv0fTCam/KKCXcXrSnGTTrM4psjGjlJk6nOvISlQsDGfUx4yyXJ7WN+5s7m4C6/uPxXov/lVg4m5adLGDSzP3G1TiO3LnOEK1YGMkx4Smo1HCzVi2iRXcKoIIjMsH1grMhRJE3g/uUtk3PKCI1NmwD29NiLlfAvCjK7O2qHiQeNlgM25BSt0SMA44r6XjjB1gvdXHQqPX/AEUN8lg/OVBSWpKwRNOQgj8tJeZC+dsPKKuzUhAcBLrkmbYQm83gI4D0Sf0GRyIwXyYQdYfvTyNZeLoIcI1i8heZogdeXEgP6wbbFV8gyv4bJy134l7+1AI1rBg6zBsuA1ZTl9dWliE0Jgz+Mb2jyfxmlr2WT6GQ90bSUg72gYG7Q0QLoiGUXp9AWP1+GSWnkxJ9lfoowThyZvSowVqwW/6n2pD36gO/t+a1TJhTr7t7OSmkTnNejkVY2Cv0Eh9w4X81qRDOF5Dfhs0fQx9Zjlv5+VCQrS+o3CK99pgaA4a5/9OHhIgrt1bN4fv46NTvwk9jWcoBCasM8ToWO39RxUmT2U07ICsf0G+m5/HC5FcPQ7ah7qHd43oU924Vi9WTBICa8K2iymmb7z/lVGh+AfFo7DEIJznarsjoa6jC/Ljc+R9Nz72CdINojVYV325iemjybyYE/befCv6wRuihtn9EOC3iHZ0ykjtHSgd2Q3u/OjqAZ5snk0BDwm5vJ7z6tbKUtsH+ELVpVWfSidNj38UP3NSLNBvG+Xcf/vIV4UfAg/ilzN93Vs5fmmXC6C5f1C4chkRCDSv2X+HePm1/0Iy4TSK2hnzfCE+CQo02B2b5iGOL0qriPvlg+70nwAb1KwquwGtsqf22XU+vnv1bBtGb3v85/68ZRTVVZdo5+xxclZ8NgK5ZsfvNq1vwbZiCd9m30OY1d0jtK4Kt37ImVctsd/Y+vrvT2pj8QmHLZ1Ams3NDzdAUxLZJxTtAD210M8pf/lvcwcWS7PzNrJ3T4F/3j2gfH5+hIb+sjr0xKzR+tvFfFXRuuaLU+XXEKlVAbCVs3nd8mnKt/DuiqTTqUPgHI6EuwvkJ6/0HF9rkJCNdRyYxJAy7syYQyIRfNWMZGwSyfElID0v2TnzCmCbck0m4zqENxbEHqjOIGn5g1PdO+7+xapBuLzk0QYtBO6GW5k32E9I2a91n83HAQGJ50WrJGMjNnZ1r8opUAhlTZqeDYJYGgTf7GYTH5qC3JWZ4Q7mQdwZcX6uOGiwQV+bs9xIiqGLXwvG6Y3r9DiSAaXH6p1hw1wS1bOANNhDfmMJsAGMSzSUQPA9l7dGFmEDzsF1BLBwgC3ofAXQoAAJoVAABQSwMECgAJAAAAzVtrSMj8fEUcAAAAEAAAAC0AHAA3YjUyNmMzMDQxNDNkNmJiYzZiM2VkN2IwMzVhMTY1NC5maWxlbmFtZS50eHRVVAkAA1Ks4lZSrOJWdXgLAAEEIQAAAAQhAAAAASH4KcUrrQ4Ple7vCdQ/m6KjIM6jEleW9LLEblBLBwjI/HxFHAAAABAAAABQSwECHgMUAAkACADNW2tIAt6HwF0KAACaFQAAIAAYAAAAAAABAAAApIEAAAAAN2I1MjZjMzA0MTQzZDZiYmM2YjNlZDdiMDM1YTE2NTRVVAUAA1Ks4lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAADNW2tIyPx8RR
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac53-4658-4e50-b0b8-4c9c950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'RWS5019517002.js' AND file:hashes.SHA1 = 'bcc6f840bbc51888f64a3b5a4857bd4b18764003']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac53-8e84-49e1-a89d-4bb8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'RWS5019517002.js' AND file:hashes.SHA256 = 'a2e54950817f09e61a655f90e16a20781e138a926bf7e0557a62741840b07317']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac54-51fc-4f4b-b1c3-4eaa950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAM5ba0j28qz29wkAAAcVAAAgABwANmRiNDVhYWE4ZTU0OTEyODgxMjhmZTM1NjVkN2Y0ZWNVVAkAA1Ss4lZUrOJWdXgLAAEEIQAAAAQhAAAAMZUQUiI6P/LGWMphfiYS4Ez7czLDvXKxiahnhAiC7ZbDV2Tws86ZrL+0wussQNtbhmpbfcpJubW1pYrxDxhfjXEjAmrf5xjA86wFerv1C3srrr8HryiMYOeew8n4w3zUtyFFUVpehuhMjzbsxQhz/sFQ/Ep4+Y95tOP1h263mqDileL59SA7HIgbsFieFBTKQLRkedAUEgPwUiQ1DHcxNROjBDlEJX9VPHcdIHLc+GJkY+sABWu1Bd/30jBgCw3Flj+eNH9u+iZfhya6Qxis5G4w0ZUlShjz+gLf+9ghYzOJZ3To8gmgOfwahZKbPgvIQSg9imwTP/5KfI1Z2LZ1Z3iT1cuglmeYm12FyjsttDpyRESeLWpVey72hrW0b6m1hxfQ3eovXuGfqjKDxjVm1q1QNcSPxfZCYJ0Gnxv9mdI4hZOlCsrExnxU9OEzwnFdt/eWk7yJ7ZXopSCkUwRB/GAOOZYpFtSkp1CnfxbXlghIyUGRaZtyIqGITsWfEwxcqoMGy/wm5gwy0peujddA7LySGelL2TVHxtUoUnIIIEyIziczU/qBrkf/G+/+uxgJkfol43gz6c2hjh0lR1N+PV1q6gnKh3UwBMnLnJfKwuBje1+TN7nYx8r5eWF4NX1a4CQSqq2OYfPe6CPSPdhuvfBrrbw/0kpZCxqbc0tgj/PIY9iSsC01dum/jS4hO15KLvpc4JGpd2c3RDyVkSmE6Q77D1WQTqCt8NZsgIrXPIyKiOQc0ojc5iv5rLDOtUrk/WQP7a6s8W0TP09fmIqrQrasuJpFk/+1HzqAXVx3yChiQKii+MZy4AaTQb5RdmQxcw8Ouj9ysIqRLDWH8IGVchs0Bko3dM7h1aF9YC2Kov+HR8OsPO4TvVXaBFtXm38grmUp4HvbjSBRaI1HOKweDogfFq2THG4aR3mSG357TrfKRDFlnnfEwyEwYN0w78NuqXeVfrcdCrZJPzzmOc1rvgdxOlSDWEqB1KMK7EJTfoA6oo6x+hYHm0erx3hOlK2gbZFchelcZPTnJeIH6HAioCPpkQXbCGpQcvWbOJM/IOLlvgah8I7Llj0VWMNkFkX+jO7dqfdpIX6ly/d3qt0RWZsDnTNrl6Jur0BRzSuJdCsumjo+jP2tI3pEbP6AlSqsG1RLrq4hxyZO7g1LngkN8aGeHDcy+VmpLtgSyqs+ISryDESpLcAiCRGcFzmkkUPhsVcMpAXkqJkL9IXKoFoIrqWNMpLRpwMvhvV3NigIiX3zOPs2khAMfaMFNJtIGIdxC/+rYh6yR8aXN+P2Cg1mICGxuToOyHzbbU379CcmUpOHgmuaAOxLL7p43Wewpid5E893RmbCA4ObhEg+E8eXCfRQYpdJYnPhYktN7vWzWgd10EyIUe9Yc2ejnIPHZmbYfpQNdfFjUSSQe3dfMK2S2iTltYMAV9EZxomUZkBCP9G0+iI9Zm6hb9ZE5L5oXTPUmlpvg0cLbJSklnQyeXv71aL3GoW2qdgGTkfvjA4zDiUXnNDbG7Zf35nrNv1vdCWOZiOuskqoPrieR15gCMShgpMk0IieyT5u8iF9tM/h46rZwdes8kHk1mXAfuIoO1/rpW4UHKmAkoHW7ys6LSUKGoNNWE3c0ZZFolA3Z0FZ8SuWRNfu8JfwdP6oOVN5wapxzOdIGLEvQzHA8xPESMs1h3/dvJGkikdMVE2lRZQDPgw1Y+ERhBG2UK59m4so2qH9AejoIl81+gwCwm9L0zHtPYxUAssz8bgKR30wKIyz9NzOpu2+YVZrhjTxv5iE34D+Yd9uv//59vKdT4qglHRk2k8L5C4QZo5EjTmzJRkFwmeuyy0pIo4Xfxsd61EryYXUecnR2yRo1P5gUTY5qTx20iPi4+kkNOQRkFXBLZrQXz+Sb3T2NC/MVUMYSgeGmK7d+QF5B6M+zQM+gZ2GF0b2Z/+GHrC5wqtT3wxLnqLxNx4YGqdO2he30JmsmMpVPoDF0SV3mswQee8vf15H1J3Mq9TkOab/JKqCuVWJug24CJtstnYA+sW3RBP6JS+mW6hhumNQCCx7DyVDrA6qy3qz4ToSB/ZWsqRsjw8BwXwZlD/xLVQ39vknWojSNfvW5/Ytrz1J/8yxdSPzwjykNw3c3NYSV+dhndQ75vlscRiKf4RV3FoQ5P0ecilJiVWMX7C0ei0rYPu1FVNvmve0+xRPLdUnSU1Qh63aRAl34s1TXRIynC+hN09Sx98bASf0nTo9R+Eu0uHl8Cw4+vbORwOm0BtmI1bi+0nHq8e1NEkk+ZtkPHbY6QkZGOCLwGgMsHxzppm7jska516RgBClHTJEGCwo+Rs3zIqCkcrUA/hcXaRhD3sc9toKCba+k7pzJEbO7cZ4RLItzWaeJwV9tjPewgcfdJN0rvRCr2DcMU17xdsBhgPVvSzcyqmPP7QKGF6mDOrG/nKL3q3z/fC4cB6S+cCG8t1BDa4RTu3eHnIJw4nCLx6H0jtmZSfAHum78Awd/Zsc5fYvjg+Z4giJ/EjWel5CpzSot+qDxLiYRuhbvLMdQrPs6G7N0gX5lqYhv6yHwbrBLZoBw9GicRcwYEjdqcfFWXB8ni10IpiLi72OZrqPSjBjSIf+BYOtVC0yaeEOG4yqGN1NhhcFT60mLae4ziGoDwAojBRQml8fTrkyIw02knyIrsCO3l8WjJ+Sj84K4RVrb246aPZs0XEXqX8aDL7J2fuWl9cl4way222VT64CNwBRY0gUAHzHyPxZZl8ON9ft5U9XcvLl+cvVCAPM7IqRpVlH0uMPoGyo9niSf0+tlZL/FvT6m1KUKaVTzuf6dWu424GgRT8kUkuVX6RYJv18SSk0iyu3VLxXF1AVhaiCah76FLf3HDeE4cO/WSi1ewhYjU7/Ld4lgQV7db6lhCy2jUJR5R5mjueNyW019eElNXt2jbt85O7W4ORywB3dowgb/79Xw9HJdP/SouZR0ZRt2rbGB4vmVYwgCMLvCTyF9rnhFnpFUY4GwZ6FG/2sGa4LEKIAMprffk67BK7h3kK6AgAlcfgUWvh/d9ODlI1YF3J/IjLqb41GDPxAnW1IZShEehvrWTrzUF4rHHLvV6Ey0SXEIBAGrVItYHKHHraPFgcrxYRIGfHVZTlYw0zx73wA7suG46hySAEh+ARlV8OiCMU3wwZQl9wE4MnrW9LRSumwCk4bcOs59eDUy6KunXEStk8puZ2yBCOQdmi/ZXN+yxM3i27JmyoI8FtYYYFf0QGtzsXow84IDCCxnZe/JTNPGsWNbkpkCMg/HRTdAvtZmbsbsYAVNBDxpcudo0gFk70OZO9FpFQkBU2/jG6aEdCDDp8jfiFme+UOefiPdTuMMw6/Qzeq8rfcK/7VH3jqFvlE8FSbi07ueJ9kuYaVGdyi/0pXOlBLBwj28qz29wkAAAcVAABQSwMECgAJAAAAzltrSDTlGv4cAAAAEAAAAC0AHAA2ZGI0NWFhYThlNTQ5MTI4ODEyOGZlMzU2NWQ3ZjRlYy5maWxlbmFtZS50eHRVVAkAA1Ss4lZUrOJWdXgLAAEEIQAAAAQhAAAAk5bsoW0qm54aAFRgoX1mIobvYMv5Jhrmyw7kLlBLBwg05Rr+HAAAABAAAABQSwECHgMUAAkACADOW2tI9vKs9vcJAAAHFQAAIAAYAAAAAAABAAAApIEAAAAANmRiNDVhYWE4ZTU0OTEyODgxMjhmZTM1NjVkN2Y0ZWNVVAUAA1Ss4lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAADOW2tINOUa/hwAAAAQAAAALQAYAAAAAAABAAAApIFhCgAANmRiNDVhYWE4ZTU0OTEyODgxMjhmZTM1NjVkN2Y0ZWMuZmlsZW5hbWUudHh0VVQFAANUrOJWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAA
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac55-5e24-4fd8-96c2-4ebd950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'TFF3741597706.js' AND file:hashes.SHA1 = '0c4a4e8f341913e5c0bc7c7100ecbb5197a7f1b1']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac55-db88-41fd-977e-4446950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'TFF3741597706.js' AND file:hashes.SHA256 = '1510b2e001378f1a1a7ed5582a35f89269d6d32bf8e23f13a06f3f9f131fc4a3']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac56-c4a0-4094-9b6c-4a7f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAM9ba0iELfrNrwkAAFMUAAAgABwAYmZkOTAxZTk1MGM1Zjc4MDYzZmJjNGVmZWE1YjZlZmFVVAkAA1as4lZWrOJWdXgLAAEEIQAAAAQhAAAA/ywwXakle2AZOCOPU2Ox0xf0ycZ+bfCqfyu7NEEB83x5vHVwgL7uyBBYB6GE3mQ1ZhG7SJZTWa1c2qGi5HFDVYhrswxKD2a59vQPOR/2ifKz/j38wFxUtsw50coENxOJ2wmblRq3ve7tkTbWG7bNfCQlP+UJ38OR4WOo75kVnkLJNTTsxNYNgxIJnNnnyjvwD1Nyo6720vX7lIu54m+wsiQKTL5r3cn9AWTlIO0zFMr+MpVMLyYajbqwLgkYfOVlPKG+GGepfIG3wqws9FYl3qcqISO3Vy9Mwo/ehWPmAELR9k2yTQBc3IFCjEehT3Bkp4b3oDk9njcODecqRtYxl8LoYAZq+fORptBOGQtRkeZyaWQVMpq85N0Q6BN2J9jIQNRo9SoPOGaJ3LyeCPyEYaOfng7CL3XSZXV9PmW2vGblHo/2maRcHgD0XI2ksx/w8JyyA1gWbqFVJ7ZOmwq3d8RGe8XctGjhRl+SK7FXPFTDX3+S9HMiNukNMeO5qgTj52tozPSY3RC8hZfGpP5P1GI953yVtI/iGsVZQ/PvASz8PRORY97j6LhW/hymzNxQVj0GzzvvBbyON2Q7+VhG5rDEuilBV+zvWc4VFSu+JGmeln3mp4GVpzM7Z9xqx9Cp35CgXgxfs5J+jB8jj1MCXBFFK5/QS8S+GClqnC/niuELJklno2E9WdFkVYFelcKTR7IbFzaZw62UK82SgmMkcQkWog4eiX/4al7OnFPlv/8ahxTuBxT86VbGcxJPTigHT+UJOe6UJFvgC0+Uau7qD+3vfLVtAwd1c0Yfr7ZW64BN0ggW49qObsNf8bbEfmMNdWz0UggHXtoMlNBKnriJ2v3FslfM5R5AQhmfFL9xIw7cRQ2B6k4c9dXF5lrBg2iRp5SdjAAvbrsuyLPEeArxCiSVuRgv9rrxea/QSsHaGZ/xYdNbCBpskjzutWN0Fiy5j7IpLnO1RnVFjhfKBuHO4n9ALwHybIkbABIqT73E+mj0sDRs6YOp182NaCfnyr3uaQAEcOzCTnc56qjfRPxWlgcYLcwma/3hwa6Oa3prMDHxKwERgfaefnpOt4PZ+WcdQ65mIwtI8lBPJVFIStkyC5r5y+8AzBTjI/jEVhY0AZ7iF0LYQ4zsSi67hGoBQDUpb9SXt5JeoNJCxC9+sQY9G/aGL7LnleruIh1DiHSqoIX7zFB0SITRNumMiYvSIFE/1edHPOJrcIXwqkic9lRa4yJMldXgkwVQK5wYBbrXxj70SaW5GAv8NMD2B9eBJPB8UPftBsOdMZwAylkKCdPi1pmAisE8i+Js6owLX4bTGvxeiemAHHfKlDDjq+ISwv6FjTYz+Y4yIZxLIfd2QVPwy9ROx3ZXHrOipnGJkoM3x0VeH3bieX9yMBzqsF04iOt8XQ06S36ChcfuF73wdhuUk06dqO0I+vfHsBG/+M2cYwj9dK1Nu7wi5i/7Wa0whiyJoibmRCVoWDi7ZpycwuGMvf9GGL8aDxwGn+c0Y3hlrtQdJgA3fADieXgxV3wWfOvYnFRZfG9ajfYDH9wdMDI66ugmuY83rAZMHAPoh9BMXEapuI7K9uDj8gBQoZgVcXrxVZwovQt/k13vqEORFpSpl5yx/vhpDJTzkWHE7Csyy6VxJtjr2TodUDnGb1hSciHycOdBI8kK0e8Ex/XNb5Md8ehzYC1+eAhfBmF8yYHX2mXCyqikdijHhNqvWPmGH5AEihNm7E4/HOyCr8jB49XdPDFoxHMDZ+1FJsq4bGVotKF7OmGoR1XRLkFAoyRDb/XnOWF2IkUxyikhhIF3XjzUNjdrJi/u8ZYyqa/0k31PzzVOt69lnWs2QXupudUZzbw3kf2HtvFQ7kMgmmitWshuD+Tv3XD7zmdKMwRne9GrO83fqPKOrtjdoyl7UiyLKFgneLfslaxqjXefRs9mBBTQY2avfyGzkRZqxzZQF435RPsCU3uYF5Qg7PBLUEWqbqSuD2DMeTwi6wZXbM2pJY1YLQhaIrVuPGWlQ16eBQJz+ufNhNo/XA6/L9yLa35EyihAnfQair++o6S6fCh6C7xHfWXwcmef/XsFNYPUWxNVqR0osdTgy4hCYxJx3uXylw+fxhpYfovC/cP5Bfjt0s6Mel0oM3gOfD6j5KdvasSivBUZYtbAVvPPxduvLNdJZatC33hdfhj9lz5S6D46Z30qedGwarfHxhOeXfnnCsiB14suq9jwDtFky4bNZVwrhcnwVV6V8Ee8nX8XAjOT0dL2TvTY6+oQ+yeWGC91UOVEAcP7LLuGUxPFWepPQsY8AD+qhAaHbmQ6nkZxn9AUnArKNueAOnkpdn5Cs0k2HuCkr08OCGazTzrNJ315eD33jRL+qjfzVL1SgbbGVn3QjXiCfFt8F82/p0z3H9r5v9gFit3YnNejqEkrP9dYwpC3qou4mF+sm7KIBop8ilsO/GlSwMZQVWzCESpb9BtswMfv72u/yQvIwZt2f6ibYsU74KhKD8gSv8KxqU0vX53JwbUMkRcvoq6qtV1gtLizsRceCZJU9k5N2uQpTqa+gbMLOT1t3zyhx7TxxsphhLVoKn9bZFZKoM6FRrBvqGQuQ53ocS86KfyBWGPI6faowGt1dBSOvDW024JHGbvMM8QjPwS+JvvHBN0VCn4MmmAWD6ILrBRBnaHN0Xqoqg7AwtDcQNypPiMH2gVcPyuXl2MqYPHp72OSN/c2LobRVwFrSPX/2ubnNd7HZLk1JDoQQ/gD8S97XAxwW3PYfKYbS05QzzAi7WASWdO7Efc8gQ64l31m/Ut3Btmcs3vDXuyw9nsg3DKEKgSORuEISd61uTeKwRnXx8Ql9CfVQE3O8MHYCKM9gZEeYZuemEaZC9BVzWcldvngNcL9WV8fz+8DegodffLbiMaMqGlKtcq8llpVSwuVtbasoDsL1H8xD/4IBY0OFsL3nalgOe5+zatoCQyJ5tFEhjLC7EDdN/qFq643oXw4SH5c1JK7XUVkD5oZGSd4r9OX8fXGtIaEqNnju2d1VQEe8mdRQYaJsoLoA9bx1Fh91/mm/OUXH4gylNFgFTJEpk/DPz0MxR4hr4+/BIgKncOaDtleni6aoD7BO3DPG+X4kMvVk7GGhBpt8GkLKZmL/sk2JU4EmBYiTfsEACcQ5kF+9kDpx0Hy+mDaTYWnNBx49vWyLK+ajNbuB4wOYAVhUOivecXgziDxM3Xyk0pX+2IGVsBPpALzYyz2n+XUw70Qcp9XTe8krKIWvWSnJf9mIknZ0PjEvj2uXnmXCZrS+ztyXSSQDgS+K/II0mNfOxZnFFBLBwiELfrNrwkAAFMUAABQSwMECgAJAAAAz1trSFkkxwccAAAAEAAAAC0AHABiZmQ5MDFlOTUwYzVmNzgwNjNmYmM0ZWZlYTViNmVmYS5maWxlbmFtZS50eHRVVAkAA1as4lZWrOJWdXgLAAEEIQAAAAQhAAAAf3Ta0C9fKEMCWNhi7KpVevROg3MNzJMGZhixnFBLBwhZJMcHHAAAABAAAABQSwECHgMUAAkACADPW2tIhC36za8JAABTFAAAIAAYAAAAAAABAAAApIEAAAAAYmZkOTAxZTk1MGM1Zjc4MDYzZmJjNGVmZWE1YjZlZmFVVAUAA1as4lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAADPW2tIWSTHBxwAAAAQAAAALQAYAAAAAAABAAAApIEZCgAAYmZkOTAxZTk1MGM1Zjc4MDYzZmJjNGVmZWE1YjZlZmEuZmlsZW5hbWUudHh0VVQFAANWrOJWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAKwKAAAAAA==' AND file:name = 'UNO5784927613.js' AND file:hashes.MD5 = 'bfd901e950c5f7
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac57-ae74-48d1-bc97-4587950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'UNO5784927613.js' AND file:hashes.SHA1 = '7c26dd5cda76b8c32e6588f3271b37ac4b348b9b']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2ac58-ca98-44bc-95ef-49ed950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:38:16.000Z",
"modified": "2016-03-11T11:38:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'UNO5784927613.js' AND file:hashes.SHA256 = '40d5b469de8f79e87135432e23b6f94c185e890f8d0aa19c427b89641ffbc49a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:38:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b14f-a034-4bc3-9c63-44c0950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:43.000Z",
"modified": "2016-03-11T11:51:43.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://ghayatv.com/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:43Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b150-6e1c-45a3-b3ed-4b72950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:44.000Z",
"modified": "2016-03-11T11:51:44.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://yander.by/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:44Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b150-88dc-4239-a181-408d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:44.000Z",
"modified": "2016-03-11T11:51:44.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://solucionesdubai.com.ve/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:44Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b150-e014-4d8c-93f9-48c5950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:44.000Z",
"modified": "2016-03-11T11:51:44.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://lapdatcamerachatluongcao.com/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:44Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b151-f3a8-4873-8183-4923950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:45.000Z",
"modified": "2016-03-11T11:51:45.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://nhinh.com/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b151-0e84-4584-83fa-4b8f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:45.000Z",
"modified": "2016-03-11T11:51:45.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://dolcevita-ykt.ru/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b151-0250-43cd-a7a9-4e47950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:45.000Z",
"modified": "2016-03-11T11:51:45.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://indianexporthouse.eu/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b152-9b18-44e3-904d-47db950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:46.000Z",
"modified": "2016-03-11T11:51:46.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://dropshipaanbod.nl/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b152-53ec-4090-b45b-4de7950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:46.000Z",
"modified": "2016-03-11T11:51:46.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'dropshipaanbod.nl']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b152-9fd0-4f47-b981-475a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:46.000Z",
"modified": "2016-03-11T11:51:46.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'indianexporthouse.eu']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b153-b11c-4350-8b52-42ba950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:47.000Z",
"modified": "2016-03-11T11:51:47.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'dolcevita-ykt.ru']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b153-6520-45de-b98c-4003950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:47.000Z",
"modified": "2016-03-11T11:51:47.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'ghayatv.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b153-0c98-49fb-8ddb-4ecf950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:47.000Z",
"modified": "2016-03-11T11:51:47.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'nhinh.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b154-25bc-4a8f-bd49-45de950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:48.000Z",
"modified": "2016-03-11T11:51:48.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'lapdatcamerachatluongcao.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b154-cbe4-4334-967e-4776950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:48.000Z",
"modified": "2016-03-11T11:51:48.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'solucionesdubai.com.ve']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b154-4d78-4adf-8e3a-4df9950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:48.000Z",
"modified": "2016-03-11T11:51:48.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'yander.by']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b155-771c-4070-8f9a-4c67950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:49.000Z",
"modified": "2016-03-11T11:51:49.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '83.137.145.89']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b155-6650-4c91-a620-4303950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:49.000Z",
"modified": "2016-03-11T11:51:49.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '65.60.41.170']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b155-a4dc-482e-be29-45a5950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:49.000Z",
"modified": "2016-03-11T11:51:49.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '5.101.152.85']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b156-2e98-484e-82b1-4a63950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:50.000Z",
"modified": "2016-03-11T11:51:50.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '149.56.40.120']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b156-b1d0-415d-aef9-40b2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:50.000Z",
"modified": "2016-03-11T11:51:50.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '103.254.12.55']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b157-4a10-4863-aa46-40e3950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:51.000Z",
"modified": "2016-03-11T11:51:51.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '116.193.76.66']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b157-6e24-4980-8e7b-49cc950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:51.000Z",
"modified": "2016-03-11T11:51:51.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '64.250.117.68']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b157-8514-4d3f-ba36-4237950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T11:51:51.000Z",
"modified": "2016-03-11T11:51:51.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '5.63.152.50']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T11:51:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b499-dfac-42df-97fa-475d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:45.000Z",
"modified": "2016-03-11T12:05:45.000Z",
"description": "C&C",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '91.234.32.192']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b499-202c-4307-9822-4d46950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:45.000Z",
"modified": "2016-03-11T12:05:45.000Z",
"description": "C&C",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '31.184.196.75']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49a-96c8-429f-b1a7-4c60950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:46.000Z",
"modified": "2016-03-11T12:05:46.000Z",
"description": "C&C",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '91.219.30.254']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49a-eed4-4f01-a575-462a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:46.000Z",
"modified": "2016-03-11T12:05:46.000Z",
"description": "C&C",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '31.184.196.78']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49a-8af8-4f1c-ac7c-4a87950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:46.000Z",
"modified": "2016-03-11T12:05:46.000Z",
"description": "C&C",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '78.40.108.39']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49b-2d40-467d-9651-40f9950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:47.000Z",
"modified": "2016-03-11T12:05:47.000Z",
"description": "C&C (DGA)",
"pattern": "[domain-name:value = 'sfsopnegjlpc.uk']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49b-cedc-43a5-bc35-4e70950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:47.000Z",
"modified": "2016-03-11T12:05:47.000Z",
"description": "C&C (DGA)",
"pattern": "[domain-name:value = 'cdnhxeqqnn.fr']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49b-dd28-4d28-9478-41cf950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:47.000Z",
"modified": "2016-03-11T12:05:47.000Z",
"description": "C&C (DGA)",
"pattern": "[domain-name:value = 'wmodsor.it']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49c-f9a8-4c29-90f3-41d9950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:48.000Z",
"modified": "2016-03-11T12:05:48.000Z",
"description": "C&C (DGA)",
"pattern": "[domain-name:value = 'ynwfx.yt']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49c-385c-4042-9595-41ae950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:48.000Z",
"modified": "2016-03-11T12:05:48.000Z",
"description": "C&C (DGA)",
"pattern": "[domain-name:value = 'ilrxnlulyhyphq.fr']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49c-1c68-4cce-ab60-482a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:48.000Z",
"modified": "2016-03-11T12:05:48.000Z",
"description": "C&C (DGA)",
"pattern": "[domain-name:value = 'vqjxngkokrm.de']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49d-a158-41e4-bb2a-4185950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:49.000Z",
"modified": "2016-03-11T12:05:49.000Z",
"description": "C&C (DGA)",
"pattern": "[domain-name:value = 'fvxpecebn.ru']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49d-22d0-4129-9579-4468950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:49.000Z",
"modified": "2016-03-11T12:05:49.000Z",
"description": "C&C (DGA)",
"pattern": "[domain-name:value = 'axbanu.uk']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b49d-1d98-45ed-8077-4ed7950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:05:49.000Z",
"modified": "2016-03-11T12:05:49.000Z",
"description": "C&C (via DGA: fvxpecebn.ru)",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '37.139.27.52']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:05:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b532-03d8-421b-8041-46bc950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:08:18.000Z",
"modified": "2016-03-11T12:08:18.000Z",
"description": "Locky",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAAlha0jj9AUQ4dIBAAD0BQAgABwAMTMxNzQzMTdhOWFjZDEwZjI0NGE2Yjg3NDc1YzQ4NjZVVAkAAzK14lYyteJWdXgLAAEEIQAAAAQhAAAAz1vs0iUHN+V/zmrU9JhjSmjtOFeLiu5vMkcIL1yD/30LtaouCGo7sAlyJUWp1dFBmzZV6LraMF6gYoc5muJbIutoZtICk2ryrF5sIW/3yZXBPC4N6CNN2TiK/W0R7sRGexo817Y+vIQU/SQ+pUEjiZIHuA/KTIfX9PV+iQ1VyH/RN8PaNQH1+JPneniU7dPnsReuD4SyvZvZv6pkkwDUcB73mCN6Jl19atQv9t2PFrQjLTWEAySH7c8044Wja9oI8PQXJFUFLSGRxeNjHV/wDl8pnJ7R2PtJRqiPWmLWE3K6VGfWhyGR9rHCrricR4rKJI98rN2UvPxKGmxKdd7nsnG+aIOXLnQgIdY3bGT6SboiHdcwyzJI4+++p4RpRN9Li6lWVxnFga/FjmBQOL8eyP/ZH4sxIv4xX+xWB9yqjUBM85qUI9Y1OUiPmR+n1b4LTBnD1dVL5JrIhfUGArkzyjK8O7vyt71CFfnS2zwc0ZVOeH+rpPQaVZiQW8AcyVuPfFZr3QASJG+6s0Czahew0lb9TbfFAWqLHAq0sZ+5A6Vti6wtS5haJd6rWEWIrTsCfcV/59HUSft2tZXu0XbQH8fuCMfxEPpVYhqEegmAOmggYSKqU1FSYApv+RTmiyHq93f1VpZ+PwPW1xc8Jzpi2AmMNXX55b+5Ge6AWp3xPZg1jjgVl5/GaZpVb4eT0n6JY+Tem+VLQh0e4t+eVPfThvUaaxAN2Y+4M0QabmUYWYawZ/PAnYYr3lG3Yw+SLI9qxcRmkYTb4q1bYs4bMjTiUL2/+6/fRHoKEeSK8FKSBBg8izpwvjdAZ1SlTk3ux/pxgWeJeB93ZxIzswYgm4PPDljr/X9t8ktEbFXe2rQYZdjPOSMdKLwkXgOPwjz9/SBER29IIsd14r1mq5Eagve5CvvsbYM1qb2ZCEBN3LaeJLSlHonvi4XoEPFIHAcHce/2v9fslzdd3MPmo3Zj8UvqQLDd9TghYNrDfGtYDPBORjs7zu4HJMgzHIwMIRa9IYvf7Y/sHMgN6FD8kYK1+rZrSixtn6xlo77oT3iCIq84vZS0iuEIwB0R4WyAKv9+b2Vzu3rNFvDjYvZvBzH898Pb3IVBtN2pBW7DYSu8awkAdA0X9ibRSGZMa0VcpGR6UZUqjzl9sRtQGUDf/zcXMoVHyft/V8vTP8wtVj25kngoyIM5zx7OD/SjWbxXzvQcV+FmDF5wG17EfFO/JcjhoJLGC+HNS3QIShA5HZ2KlaQdQfUPg8VepGHIMtmVjNqJEezZYMdgj1eto/HCEVvrd87m130+aRtwsLVUmJHdu2jUTxJn3RR9+/25hwRDVx/pG+YDGobbIPiakK/HI6INBOh6O2qYsQKPuTidC0/ep4jzPlpF11iAbTdQ4j/Jbi64yBSaw+27TPRQQ+5zl3kmes1rxdx56UdX9KT6jN4vscPOdoepIZmdlU6ZfptaEniEsq3RyV/4XqsY7QMZ1lwAImWo1nxm+4XZ3luQn8G/H+mE8LFoWO5KC/34M71rSd1LtkFLByS7kKUHk/if9+h9JJQHUHXr2rK2MR5U8m9AKvRgwb22eOCxrG0SIZFORCt/O/feQLs0XmbeR7QzpC3wX+nAuX+TU4WcsSw1z2CJmm+Pk1PwjKCl5w6mx8Es+5I/rbfIxjkemYeo7ZVWrqUnj34rxirl2EBS8o99Li8OCm2srxAcz4LwFfK0VWeBwJT56/JBA8shPlmXCP/sMjMX+M67j2hyfPRniDykqP5awCDDTkJ1JDE2h7CY5L1LsjJG0c2PeXyf9kTniJQ0KpEMY9SWg5w9NcDkeiZVrJM2BlgiQp3m4H+jCUAGZHhcPtwFOgTZ7AF6OZQ/yORsAmExf2vqV1v2MkcYYCPqIZmkehijbfNcMmiopyg/no3SBgGae69YpkGsFwrE3HfEaN83y0e5DyMuZJGP6BwIWlscYsMa0vvAa/gg6RgDJP9y3rMR19+NXzEB91nyh0Mup5BFJkyqJQYwZaY/2Bh36OvQ0NInugj+VVHhvAa1f80PtcDbdfBuuBz2iKwmhHhtcV7UM5FTComysdQim3fKnlZS9BF5ibl+ZfwEOwgKBt7oH7ogprY13Mvr9MIFZakXaASVv/PpM35vL07YrnMpl/Uf15R9vjeIdh1zbHqIy7dabxfhIeB48qzm8EucSp56QLUUU6i9J9PKP1/veVGReW1cXBIjhLWc6e484wllLHkP0wTEbj4mUsFlQMgKHfiJBI1z6hP4/kGtk0PJi3oP9EGQlmuiu8oE9wDfuXZ5FWk1Qn/Qdd65YcQhOiZ5MfATDrQOmaZ4E4n81jT7fW08GMDflw3dmmoqbMMpDynRe2x68mxvmrUVaFZE8VQf/iw7LBKwnSiWZQVeMH3uDWis5gWS5z8JkIGPmOFM1y2rDKs8qmBBhCzO7PxMS5koYA4Cb5shhXfe2zUV+FAR8GZUj0AtMNXlbJHa1PS99FHrlnd0B28vpKZ08mMv4B1SiuXxVzm+BuK2a7uMjDbeH27WHVQTySst4XXT0gztB+tQVM1+rKVue4mvlRGqsgZQHYvq2OilRFIX0xF6gW32O2DlMRs67exqSLGN7esgBmuFLGeoduyh6spPZxyOgeDAh78eL7de/CP/aaMR95xEwuYFwAVik/FoRoIl5sUZpG4W8MRdKP5UIhhpRMZcFFTd8eyaMzt2HzZ6KHi30rJc1cDCU8+4NBuQzMmNB4p2vptRyFhw6Ss7wRxfdT9RpBZokow1FcCZxVLtI1RyB8ucdLYi0eocWzdfoL3KOqIEhHqj53Uh/9pOG/n/ljw1WaGhVf1tJnelxt4AKkN+qBG4XI8DKuKaFYQ0Yd5WEWznrWx4dkkPrS3Q9p2wI8uUnvxKMapmveJ+4vu/qzn0TehsDT1k8kn2/n+ryl6s+ItIrA0IW0uPcNl+bNO15oxLF+1Wp/63IM2l6OUyUJifcq0s0wB4u7bJns/zKsX3/Q3Ra0glAsl6ggCDgYv/c39O841A+GQCDomoAUEA3VwCP5an2vWGD8DcxP/DWqtHVMtpnErYUOB8EFc5M6PkO2t4ZseJpojjj2XVDOmygkBXmqMaCqLwXsQpQOiWrDfnUP428oTXd2iI+NSXDRbbajdVwdODbavMG31OIrI8INsWPKVuT9FR7e8ARgw5BpwQj1aQTbJhgSh601Yzd9iCqitgpQgVYJkc7JfGRLAjwDKcHHdaQWfa6Ry0Z4UwnDRisuPr+Ts8UP9A/7SNkObBrMlFC0BH+29rW+VBzyTmFoPP2Fqle7JaMmNQQy+UVt9/9szrJqWOS3JkYWzw6DG0lgN+zMtKLNT2EiygQ3ljSK11qJ2ZE0E0/cBrLTVOBBNG+QXdKSfQn+E6zYDVDORBe+iq8grQl9EVMypPeNycsLxKubTX9Hlz0872mCaS/f636wUED1iviKE7uiVFaoVSRo5V1eMJ5M5eIfX6BauOekNMRMzamK2b3PVhGWQLBCTBTrE8z2hIBUZCIMTd63fAy26PtivabIXmG/XUDoaS4Ej8A5v8De8GULVSPg9My1cHxS+qL1jY4RuAc321VZ30RJww9pjka03w/ZfVHzocDZ2rIMo5mFUTE78akYzSnLDCCLTh3JMTWb6gC1HivucPj4u/ARk9X8EQ7tsq9M6zGcsWKHbj6j4tqicAraa4s+MtAVZ2VQ9SDA3ziGA6VC0Ctxp1+WnIukVQii3Fw+oWkfvNC8KH+RkfHcrHFQ8rNpPgZcHgtCWuwvR+/2COSE4aJUb6Ug2iay+FP0BbgFri4ZRNog0Mjq9bP9nO/cYHTG2WS3p/c0et0kmgSQvZ78Yuc8hCpCq2q422SNVcQPlJwxTToW4K+R2eyqVjjQGmlgQgFU9ggTLCVGE3vDjyWL6WmCf4n2K2Ur2dnX
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:08:18Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b533-43f8-4a6a-8ffa-417e950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:08:19.000Z",
"modified": "2016-03-11T12:08:19.000Z",
"description": "Locky",
"pattern": "[file:name = 'uy78hn654e.exe' AND file:hashes.SHA1 = 'e25418fb175eeda2d30e8a8b981753bd8844f9b7']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:08:19Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2b534-a7f0-4508-b006-4c87950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:08:20.000Z",
"modified": "2016-03-11T12:08:20.000Z",
"description": "Locky",
"pattern": "[file:name = 'uy78hn654e.exe' AND file:hashes.SHA256 = '7bcd80f4ba829652fcd4514585d00052ce8c8bdb48b3f7b651846de264bcba32']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T12:08:20Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2b581-9200-49b9-994d-4cb8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:09:37.000Z",
"modified": "2016-03-11T12:09:37.000Z",
"first_observed": "2016-03-11T12:09:37Z",
"last_observed": "2016-03-11T12:09:37Z",
"number_observed": 1,
"object_refs": [
"email-message--56e2b581-9200-49b9-994d-4cb8950d210f"
],
"labels": [
"misp:type=\"email-subject\"",
"misp:category=\"Payload delivery\""
]
},
{
"type": "email-message",
"spec_version": "2.1",
"id": "email-message--56e2b581-9200-49b9-994d-4cb8950d210f",
"is_multipart": false,
"subject": "Scanned image"
},
{
"type": "x-misp-attribute",
"spec_version": "2.1",
"id": "x-misp-attribute--56e2b630-c57c-4fd5-bbda-4cb0950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T12:12:32.000Z",
"modified": "2016-03-11T12:12:32.000Z",
"labels": [
"misp:type=\"text\"",
"misp:category=\"Payload delivery\""
],
"x_misp_category": "Payload delivery",
"x_misp_comment": "Email body",
"x_misp_type": "text",
"x_misp_value": "Image data in PDF format has been attached to this email."
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2aa-b95c-4d86-bb2a-482e02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:46.000Z",
"modified": "2016-03-11T13:05:46.000Z",
"first_observed": "2016-03-11T13:05:46Z",
"last_observed": "2016-03-11T13:05:46Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2aa-b95c-4d86-bb2a-482e02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2aa-b95c-4d86-bb2a-482e02de0b81",
"value": "https://www.virustotal.com/file/7bcd80f4ba829652fcd4514585d00052ce8c8bdb48b3f7b651846de264bcba32/analysis/1457699823/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2aa-e180-4caa-897d-463f02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:46.000Z",
"modified": "2016-03-11T13:05:46.000Z",
"first_observed": "2016-03-11T13:05:46Z",
"last_observed": "2016-03-11T13:05:46Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2aa-e180-4caa-897d-463f02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2aa-e180-4caa-897d-463f02de0b81",
"value": "https://www.virustotal.com/file/40d5b469de8f79e87135432e23b6f94c185e890f8d0aa19c427b89641ffbc49a/analysis/1457696636/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2aa-7f0c-4cc1-93d1-450402de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:46.000Z",
"modified": "2016-03-11T13:05:46.000Z",
"first_observed": "2016-03-11T13:05:46Z",
"last_observed": "2016-03-11T13:05:46Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2aa-7f0c-4cc1-93d1-450402de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2aa-7f0c-4cc1-93d1-450402de0b81",
"value": "https://www.virustotal.com/file/1510b2e001378f1a1a7ed5582a35f89269d6d32bf8e23f13a06f3f9f131fc4a3/analysis/1457694578/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2ab-2b30-4777-812c-4eda02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:47.000Z",
"modified": "2016-03-11T13:05:47.000Z",
"first_observed": "2016-03-11T13:05:47Z",
"last_observed": "2016-03-11T13:05:47Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2ab-2b30-4777-812c-4eda02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2ab-2b30-4777-812c-4eda02de0b81",
"value": "https://www.virustotal.com/file/a2e54950817f09e61a655f90e16a20781e138a926bf7e0557a62741840b07317/analysis/1457694765/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2ab-73d4-4f41-83f1-414a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:47.000Z",
"modified": "2016-03-11T13:05:47.000Z",
"first_observed": "2016-03-11T13:05:47Z",
"last_observed": "2016-03-11T13:05:47Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2ab-73d4-4f41-83f1-414a02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2ab-73d4-4f41-83f1-414a02de0b81",
"value": "https://www.virustotal.com/file/e2689971c91e31f8216c3a66c59b429305839ddbc3732f36021b54039eca670d/analysis/1457690823/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2ab-d2d8-4511-be39-4cbb02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:47.000Z",
"modified": "2016-03-11T13:05:47.000Z",
"first_observed": "2016-03-11T13:05:47Z",
"last_observed": "2016-03-11T13:05:47Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2ab-d2d8-4511-be39-4cbb02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2ab-d2d8-4511-be39-4cbb02de0b81",
"value": "https://www.virustotal.com/file/5df6c456ca6136917a8dd1f98c5316d4bcc438639196afca58f61d31f8e6e6c7/analysis/1457693068/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2ab-db08-4c8b-b084-46c702de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:47.000Z",
"modified": "2016-03-11T13:05:47.000Z",
"first_observed": "2016-03-11T13:05:47Z",
"last_observed": "2016-03-11T13:05:47Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2ab-db08-4c8b-b084-46c702de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2ab-db08-4c8b-b084-46c702de0b81",
"value": "https://www.virustotal.com/file/c33babaf1e100437a8eac1dc30be2176f3ff775ef195b7f8a16577725b6574a0/analysis/1457694711/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2ac-7c10-4aad-81e7-474f02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:48.000Z",
"modified": "2016-03-11T13:05:48.000Z",
"first_observed": "2016-03-11T13:05:48Z",
"last_observed": "2016-03-11T13:05:48Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2ac-7c10-4aad-81e7-474f02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2ac-7c10-4aad-81e7-474f02de0b81",
"value": "https://www.virustotal.com/file/0a884c6fbe5314727a24b65eb1196a8d59ceae4b57ca237f4c5c974673545696/analysis/1457694016/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2ac-c8cc-4b5a-8e77-4e0d02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:48.000Z",
"modified": "2016-03-11T13:05:48.000Z",
"first_observed": "2016-03-11T13:05:48Z",
"last_observed": "2016-03-11T13:05:48Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2ac-c8cc-4b5a-8e77-4e0d02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2ac-c8cc-4b5a-8e77-4e0d02de0b81",
"value": "https://www.virustotal.com/file/f365ae19431e7accfcd0d9977fb52cc288fc5f4b39c63f483105c8d5ee3cbea0/analysis/1457694289/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2ac-e6e4-4852-a5dd-408f02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:48.000Z",
"modified": "2016-03-11T13:05:48.000Z",
"first_observed": "2016-03-11T13:05:48Z",
"last_observed": "2016-03-11T13:05:48Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2ac-e6e4-4852-a5dd-408f02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2ac-e6e4-4852-a5dd-408f02de0b81",
"value": "https://www.virustotal.com/file/1a33338c6101ac66cdc79dbaed17267725d183fe37bd331c04b9580c69dde5f6/analysis/1457689951/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2c2ad-b018-4b87-b7f4-4c8f02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:05:49.000Z",
"modified": "2016-03-11T13:05:49.000Z",
"first_observed": "2016-03-11T13:05:49Z",
"last_observed": "2016-03-11T13:05:49Z",
"number_observed": 1,
"object_refs": [
"url--56e2c2ad-b018-4b87-b7f4-4c8f02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2c2ad-b018-4b87-b7f4-4c8f02de0b81",
"value": "https://www.virustotal.com/file/3f789e86a91efa6409a60728a05dedf950443f5a75d2cb658f84ca4db0ba9a4a/analysis/1457693541/"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2c7e8-e5a8-4253-9e40-659a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T13:28:08.000Z",
"modified": "2016-03-11T13:28:08.000Z",
"description": "Automatically added (via uy78hn654e.exe|e25418fb175eeda2d30e8a8b981753bd8844f9b7)",
"pattern": "[file:name = 'uy78hn654e.exe' AND file:hashes.MD5 = '13174317a9acd10f244a6b87475c4866']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T13:28:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28a-df44-4bb4-9639-4963950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:46.000Z",
"modified": "2016-03-11T15:21:46.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://joecockerhereqq.com/80.exe?1']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28a-c9c4-4a5c-8233-4e96950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:46.000Z",
"modified": "2016-03-11T15:21:46.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://joecockerhereqq.com/69.exe?1']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28b-fda0-4646-92b2-4949950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:47.000Z",
"modified": "2016-03-11T15:21:47.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://cazasports.com/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28b-dbe0-4a9b-b945-4c48950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:47.000Z",
"modified": "2016-03-11T15:21:47.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://perfumy_alice.republika.pl/08h867g5']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28b-fb9c-4fc2-9e88-4b19950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:47.000Z",
"modified": "2016-03-11T15:21:47.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://galit-law.co.il/32tguynjk']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28c-7618-4c0f-b8b3-49eb950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:48.000Z",
"modified": "2016-03-11T15:21:48.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://peterdickem.com/87745g']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28c-65c4-4e05-be5b-4b1c950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:48.000Z",
"modified": "2016-03-11T15:21:48.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://stepsaweb.com/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28c-05d4-4a82-bf81-4fc6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:48.000Z",
"modified": "2016-03-11T15:21:48.000Z",
"description": "Download location",
"pattern": "[url:value = 'http://vaanifashion.com/system/logs/uy78hn654e.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28d-3ffc-477f-8d56-45d6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:49.000Z",
"modified": "2016-03-11T15:21:49.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'vaanifashion.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28d-891c-496d-807f-44c6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:49.000Z",
"modified": "2016-03-11T15:21:49.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'stepsaweb.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28d-0600-4256-8ab0-43f3950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:49.000Z",
"modified": "2016-03-11T15:21:49.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'peterdickem.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28e-ae88-4e78-a71b-4e89950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:50.000Z",
"modified": "2016-03-11T15:21:50.000Z",
"description": "Download location",
"pattern": "[file:name = 'perfumy_alice.republika.pl']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28e-a25c-45b1-86ae-49a2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:50.000Z",
"modified": "2016-03-11T15:21:50.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'galit-law.co.il']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28e-3c78-437a-8450-45e3950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:50.000Z",
"modified": "2016-03-11T15:21:50.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'joecockerhereqq.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28f-3c24-4fde-aa11-42db950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:51.000Z",
"modified": "2016-03-11T15:21:51.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'cazasports.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28f-51c8-42b5-bf77-44e6950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:51.000Z",
"modified": "2016-03-11T15:21:51.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '149.202.206.107']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e28f-1768-4708-b90d-4c56950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:51.000Z",
"modified": "2016-03-11T15:21:51.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '198.57.149.3']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e290-f488-4401-926a-435f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:52.000Z",
"modified": "2016-03-11T15:21:52.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '74.206.187.130']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:52Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e290-44c0-44b9-b7b4-41e3950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:52.000Z",
"modified": "2016-03-11T15:21:52.000Z",
"description": "Download location",
"pattern": "[domain-name:value = 'republika.pl']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:52Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"domain\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e290-a5b0-4a52-b16b-4f68950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:52.000Z",
"modified": "2016-03-11T15:21:52.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '213.180.150.17']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:52Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e291-34ac-47bd-adec-452c950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:53.000Z",
"modified": "2016-03-11T15:21:53.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '91.202.169.123']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:53Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e291-2040-4585-95fa-49f1950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:53.000Z",
"modified": "2016-03-11T15:21:53.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '202.120.42.190']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:53Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e291-b680-4dc9-a834-4157950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:53.000Z",
"modified": "2016-03-11T15:21:53.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '54.212.162.6']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:53Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e291-6570-4e8e-b78b-4c1f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:53.000Z",
"modified": "2016-03-11T15:21:53.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '78.135.108.94']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:53Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e292-a914-4098-8246-49c7950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:54.000Z",
"modified": "2016-03-11T15:21:54.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '216.150.77.21']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:54Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e292-60d8-48db-a50e-4465950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:21:54.000Z",
"modified": "2016-03-11T15:21:54.000Z",
"description": "Download location",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '98.130.48.2']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:21:54Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2d6-4038-45aa-b53e-4bbd950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:02.000Z",
"modified": "2016-03-11T15:23:02.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOF6a0iea137ewcAACIPAAAgABwANGE5MjJhYzFlYTJiNDUyZmQxMTdlNTE1NTFiMmU2NzVVVAkAA9bi4lbW4uJWdXgLAAEEIQAAAAQhAAAAgd98FiR2l7VeTpZ3AnxfOZ/ndjLYNTzum5FbLRAlCPjnPFMsnEOKToIiQPz/tbqxPOWTCHt4/kJeE/9VJYy7sI8n18P4zX2rJ0kIhc7Y8rOHtKC8eymhglKe++ddWUd7+v7ZunU8WZKlhB7/eToY92tR2Vb7GBPlBH44cwdGsgYsYXow845pdJhvtEimeMi31eQJt832Sv6Y4OFZtqFMIA1c44K0/D8pVPtWIqhrnQbpOpvhm1s3L87rjuhHvDP/eI7hZYD1PGSJXHdSRqGEraO44NE9TuqdZeb2tlJVDkYf4qiW7k6/2FVGVZzUh34CyAa+Q8nd8OS+vm36xMA58KYMPdPfCDhfUO66FuiG7xKXwAHvPa2fcwBT3nZltPS5T4Iz6mmueC8ZD8c4v2SeLsVprSZRq0O0WhBXvpyHJcTo9RGlQMTsDUgtnug8gRafehW4IvzxHs8ZXDfpYIsvFVdcPwjgwe4rUSMp1QzB4Ts8dbdygG0F1UFguwL6UdMX1uAiCbi0U1l5V8x6sphs5JbjTDSkSQC7q0Q4Y41v7iiOvBYrQLjTDASA1roetCf78dDNbl2enGHMUochJIlKAXs023u1mLDzehXRvAFvVbedjFjwDwRZuynhcvJT/XSef26osb4tSGtxckNqjKdV3aezEbvbMS0iBcwfe1ME/ndu9Y7n1lKAsuckSTS8LCrKOq6D8rIeGum/nR3h/KCwavSCtmKMx3e4jxphJgZL5HLSa24InQE8X0qPUHh9kCJ/SyS3Zdl3J53rFpnl1EY3di8mg2ix6X50KbEyOQfdEY3s+/aqFS2xgJCIALn+Mqw8UOnKNCK8fT67TM3dmG6OH27BJUmrew1wm37BLz3ok6is1CqhCeA7iW6BHU1u1xwfnAp8d4S54ji8ewq11RmeCCOYDltsHotlRQNshAmnrTE5nqxzd7Bkz+PYxuAB9z0p2xzgO3AkjDyvydEtPmnIaytIs7gQXqqt9wvW0W+liGPTrtB5dWwKox2vrecv6Iz8jHD88sljds3CTOnKw0jeYqvGG3bBG0YheuLhmLmS+MC8680tIQmB/EtuRDavaS5pvJifjLp7gndp25IpPyb9+82SDzW4b0weesueRrTmhs4rm8m04izWhQd3UO+SBlbvzCLJmkZ6O0egUTM8s6HHcRX3rnKhcN2x+m/8lgeQ7PK2Jpge9c9xIW3MJergwNOS+VOq3iMNAVQk/Vs4g4kPX2kA6J6c4c8chGqLO1OidBtm1rblqz7U1gHwqU5fCTn+ZG5SGVKTVbROsqtf1Yr+6n1YLGtey7m3U5uxVDXaI1FpaypakmJwqUqLu2MMQbK2LFnR7En9C2IG8DwcSMJLwhkFalZeKqJqegmsgR8NJmI42LZmJ5N6icAYgiO/MD4VhqYcf3JfJ+FZk3sRkI1+Uclu4uTV/B2pa7EGR1/I0Gp/VO01jP74E45tD0YmPezgIcjP1Dp480C33OTlxkES8dBbkIGhrwgC2xoZ2hGuiJAHNShCXNCym1AluftuYkZAw1wYT5wuiMGs0GvwQILtFLLTArEhdRI2JJJMr24QKqCZSfvr2FhEUg2So4Vuh7I3DzzOa1HHmOjSuQDBVShgzWehVWSxCXnf8x85ygkQroyLqJynIDfMoChY1GTkkUIuhY0HnglagjeGAjncy9oRJNeHhQYsVv9sIU84FoPhJ1sVBM69aiW1y9Vg+XDQyHw9vQW1cRnuxZmOQVzi2wTcQh4mdNpuyKwiQ7e5v5xAi+T0u0vhrWmxq5JAljedn+E5Y25mnZ/p1ubHvrgHo/ZtEY1XdKv+KgbwakVTTmzPGos0NxJPo6ZxxFUael1/SmhKxa5Y2bCKmS8Bm+ZcrA4LJ/xmVor1JLF+lnzXpuWFht4xpadgjENd3/2piiH3lDEDtf8vkeHbnpeLHTSqSqWDpgfsmtqMBq1S5z6IKG+lyBDSHzXS5IT4YCk7ni4BL2xScyx0tRvMeqwBfSd3uIiDd7t4/cRbcwTsCIqvBm7A4kziHhKjY3/r5BmE79dNN2dRqKgkid2rePk8WVYVqWlrpi9eaHe5X43LiQYFCmgaSgDGOVlLXPQgK569i0lcWJwnUcmBFkgXMJEc5zENzZ2yvvAK2ENu4aXyydWsaTCeJr5ti0rNyBCIeRImk4CUPaKbwCpDJfthSzjabGoEqamiKRALa8/z+ka6rRBLk7Xs2ktPapApUk4uIaaICiGc8leew7gw/1nXtTvA1LVilfE066VX8BLYYGP/0E0hoDQJeROQl8BkPxQPdyII4BwDjZOUBAF+17VAkqkqoPLsk1+qJtOWsIn6vwe4Oc29Bt4dgFQqA8QUVkBM+tgZy3q1FPps9Zsufa02sEqqP5Bh0ZwL6PorRiCS1PXILEsk0hIFrjXpIlppm98SGalt+U9eH+NfbHTG8ZdLjqd4TFNqG+HmxtnWCSJ0kCis035efry0pjWK2P904gsEeqsidC9FIPWNVr0RQmMu9wTyENLoRdlFckaVYxC3r9VP3ELG4li2amT4pzj0eiUO91E871BLBwiea137ewcAACIPAABQSwMECgAJAAAA4XprSBRypVUdAAAAEQAAAC0AHAA0YTkyMmFjMWVhMmI0NTJmZDExN2U1MTU1MWIyZTY3NS5maWxlbmFtZS50eHRVVAkAA9bi4lbW4uJWdXgLAAEEIQAAAAQhAAAAECqFL2/kvr47PeTgj+hK8KUmDZ8o9FWMe5Wg9udQSwcIFHKlVR0AAAARAAAAUEsBAh4DFAAJAAgA4XprSJ5rXft7BwAAIg8AACAAGAAAAAAAAQAAAKSBAAAAADRhOTIyYWMxZWEyYjQ1MmZkMTE3ZTUxNTUxYjJlNjc1VVQFAAPW4uJWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAA4XprSBRypVUdAAAAEQAAAC0AGAAAAAAAAQAAAKSB5QcAADRhOTIyYWMxZWEyYjQ1MmZkMTE3ZTUxNTUxYjJlNjc1LmZpbGVuYW1lLnR4dFVUBQAD1uLiVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAAB5CAAAAAA=' AND file:name = 'details_AZXMWC.js' AND file:hashes.MD5 = '4a922ac1ea2b452fd117e51551b2e675' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:02Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2d7-f160-4368-a077-4110950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:03.000Z",
"modified": "2016-03-11T15:23:03.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'details_AZXMWC.js' AND file:hashes.SHA1 = '0d1a7e487a1828cc7a75459116daea3e9ba10250']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:03Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2d7-3384-49cb-a21e-468e950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:03.000Z",
"modified": "2016-03-11T15:23:03.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'details_AZXMWC.js' AND file:hashes.SHA256 = 'e02251de5222e9894cbcd875114a1ca39b526a1e3e0030cc5d6fca3f28a844d7']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:03Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2d8-afec-413a-b785-4784950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:04.000Z",
"modified": "2016-03-11T15:23:04.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOJ6a0hTLfOmhAcAACIPAAAgABwANDdmZjFmYjJiN2MwNWE1ZGFjYThlNTM4YTlhOWMyMzhVVAkAA9ji4lbY4uJWdXgLAAEEIQAAAAQhAAAAUf9JXWvahWNfGdHH2ZMGzTeokgu0QTrCEQFoPlQhvqSRU0C2FBQZs04Z1/ervIp9UEA7jz+Wcllb3Ew/V0i5L9hUcFDwu/3Tmp/kFu1Klld9rb+xaNzcIE0Ljbgf7lh2qwo8qyUoBRLYtXWl0AJ6kpfc3FzCA/nkSOXQwNdcTuLgTQoAcKjn/GIuyQ8uIEbPXfW3QUGTYJCKG1xX6hG6/diW6V8puoXZ14TnDMFYY5+ITpPM2bxGAUJmL9wmnwYzlUsnY6tnMRoHBKRAPdGtXNdZOXzbx1uYPL+vPuzDh8/xrgZVHe4m7TJwfcYdAFVBq3qByDZqJDfNAWPTs2WOwK8adO3FBSGcrI3fJk/DisTUp5O6IZaJs40W21R4WyOKxpd+4t6IpPSEUDzXpxR/TEQM1P/y3Z4MAKsMu+tsB7cR2atlG0DLchLzvTHxdqQ1zuWu7+paSuD72HamD3h04xgPP4zdbDrbYpZWRj7B5YMYKcQwtH+JRXOkzJbT7oJopOUZjuydfPArhlsJMkVqX8cEUkohKkijFzgIEKRl5JMFZZuRLWuG9dHaSBPqiMzunUzI+tVtgwFp6G9xLn9ooz/OQ63Jk1SFOQm4YDf11XrvVsQa3kXuEfmtk6TDyFnPOQGhz/t6HxiABvecfUn+yIxikV3rV8SVoJB/vW2NRnz1Dnhkn4AWg4QqUTubOeApnP83Y1tR/mjNpTTqfZoGi29EubMDMBh6l0monkRBH2MoZZ5DLX8VEHqb16ZUvYoWMUwjIspOqmONyS87qbAWS4vo2KCztLhwQzYZrRtHGnKnU2FPYkU/u6QDX5I+4M1eJLySft0PHx9Lnizsh5uVTIlKVu/LTMxxP87URx5rgZWZ2Q/DGyWV/Yjj4PUiFLMvyg/02TdBT5KvNlG//5cU/HCho4FEYMnXccR0xNg9mzqM4p73sDoQ0p7SpyeK+8Dxlu52NecCm5iMUM2H4ITlY30bM7FnRJF5nGgBByvIgnj6CeMiOYtIlUmOcRSp6EG50pqrE8iLl+KEJqVkHJKm4dvvjfGzOxnfsZIwQ9FcG5hIWoxZiAwdOAi8OruBuk84yhoWyZGNc0A7d0LashrcIL5awamDMVXAnNXdDgb8ECz3mDrRoJt9QDgIRCp5w9+KcIHjlQK0kFvRbbuTVTU00xrEuV0SWv+6xfW4wOqvinlplnUnNqM1FFznBdfztsLCunBY832uFz+ey/ZLz+o1+pOAboDKFx5cYKqwG6T2nuw4PeaQYOZhQEp/MMz+qSBddSqsdJdzC6N3WIUnPcMzuEwLYzmoA1lTJh+KXqJzbfxSOr4CiST2By5WuQMZjKxpJmeN0Ha7KXG/kX6AByat8yzJImK60dzA8C9BCXZyqTfudD0oZb9DxgGYVO0rI7lcgcCjcyKvEH9wkkE6e/yV6dQ6hSgXXvZJKo+tnxBmMB5sD8oSRFR0S0vLxbeZBW7z8CiUtPo66yJpfNklmPijYTzBXITsEM9RQ6TRRsNJIkhidpbplPpKNEaKm9QWqW9LIlTnwUwdn5ft1knJ8Ti6RMcT1wmgVsZCraWgbj0njM8mjHt2gxHwDiqcVB5kGYf0luopTTavYr9rc+P6wNIi+vjtgikwtFWN8xbZaWonVXErOW3ANrvC3wxyFkfd7wqNPHvopRwz7TInvrwzSdmNC0VkEGpktVxqvaFpyP54PJ58cTUczJ+aAr0O/CGolc8b6bmulmnPmUc0ersoC4LSl2M8WFOa9Y+fgXSwTH1LCrJnbV0eiHaaIMxh49+FIC68HMwLWmb4QC7XwkVf8kSdxTm1GENtknIUa8q1szc8EeBik/BkqqEpr+P2smRNWKId9PhWA88qulu6tmfhI3YKhRWNFC2FYFF0nkbkFQ6+e4rGGSKUYtOusk5mUw/qhzpipoGWKAv9FoqmpaerxMitKPD5opVe47mADzBIUE1OFIJ5k2FbqrA7ESCtkOzLiIKFpgKJ9cH0lB8HYnIL+WQPCCqmXEto5iOrmqsgJcSs782a5f9f6qrO6KnEMk7HNYU81kG1P8wJ9LlQ5/ykBjvtvZI8njaqC3fbhE6lemMunp3UcrsO+azHWoDjwGkZPknTh5Fz7dn+doWXyGSpN5doM3dy1o5efTmjAH3HskrW1Yx0jiI2pe8OMbvl/A6JronAa7pvmFB0WTJgPPNbygFC3TgU3s9CCIXYHKT9uM/zXYgHWIM5zqvdvjLuogAAPeLqFyk7vGhF4WNKSDNRrdIPSv//Wge9zGk80NihwJdr7ZjI3gmXIgipSs35pZRuHCnQvzWodNla30vO0ieitX/YYL55VqC4Sa/OC/Ge2SciY+6oF0bF+s98BsiYAdoiNcd6gTqXeQ2wRBUzBqaquQg/khTS3aoG9T1B5g6WypMa7jrkSvfRkoywRdzU0+cAKE58MSDNB/d6Q7xqDXKYDt/ZrzloI0n56zLSVkTfoJOSYKrK6RXBJNt+bSXRotGqDbT6Z+bp9JrJhmUQtiAxqKirfX60mzbpkhjoaeVNYLJeoGSr1om33PVO+hkCLziKFeEWDUrfw1BLBwhTLfOmhAcAACIPAABQSwMECgAJAAAA4nprSFJQAYwdAAAAEQAAAC0AHAA0N2ZmMWZiMmI3YzA1YTVkYWNhOGU1MzhhOWE5YzIzOC5maWxlbmFtZS50eHRVVAkAA9ji4lbY4uJWdXgLAAEEIQAAAAQhAAAA7KCsEr9FK/DZGyQF4Coyx/B6N0p2noHivOm4p/dQSwcIUlABjB0AAAARAAAAUEsBAh4DFAAJAAgA4nprSFMt86aEBwAAIg8AACAAGAAAAAAAAQAAAKSBAAAAADQ3ZmYxZmIyYjdjMDVhNWRhY2E4ZTUzOGE5YTljMjM4VVQFAAPY4uJWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAA4nprSFJQAYwdAAAAEQAAAC0AGAAAAAAAAQAAAKSB7gcAADQ3ZmYxZmIyYjdjMDVhNWRhY2E4ZTUzOGE5YTljMjM4LmZpbGVuYW1lLnR4dFVUBQAD2OLiVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAACCCAAAAAA=' AND file:name = 'details_RedcCH.js' AND file:hashes.MD5 = '47ff1fb2b7c05a5daca8e538a9a9c238' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:04Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2d9-08ac-4a2c-9341-4079950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:05.000Z",
"modified": "2016-03-11T15:23:05.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'details_RedcCH.js' AND file:hashes.SHA1 = '7fcfbcd04b93f4dfb2996c17ec609fe1261cf417']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:05Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2d9-4668-42b0-a2b7-4af5950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:05.000Z",
"modified": "2016-03-11T15:23:05.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'details_RedcCH.js' AND file:hashes.SHA256 = 'b92aa998fe6fe5667bd5418ee1f7773bc4d9634d9fcff440ab78e66d6c58d036']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:05Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2da-31b4-414d-9782-4452950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:06.000Z",
"modified": "2016-03-11T15:23:06.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAON6a0gt+6OmewcAACIPAAAgABwAOThkODZlNmU1OTQ3N2QxNjQ3NzcwOWY2YmU5OTYxMjdVVAkAA9ri4lba4uJWdXgLAAEEIQAAAAQhAAAACrOCV5VQZGhAQlOhHgsg9PuBIl8vS2yZTON3mfEBcHAbjkdZteU8GvQGLRysvu7+9zdYTjaZNHa3BcjBZQ2UyYOuYgOFydJq7lNHRMrNQl1Wn+tv3NQoBRfvg9S4jPJ1WgZT6zfRkLX6kS8625eq9PjnS70qVpBtgZZmLt2QlSncf2qbtPQ20R1sffSAHNu9r9Ivud7SOwZxtT9xfEieEFOPqmPsONeFRV8hkvCZ7hVPim/jKFLrJhJxMkV5pKBoRHmWJD6FBa3cjx6KQTtyB/0CObzJQfUt3l2uIHnQuU3BU8OCEwq+PRSm8m2p8svqYOC+6+z/8xAC2Z5oYmsGOewRfbjnCar5rhk6FXB1EbLVL5PnG9g/kQ6lB2CU4QNrONvhYyKQi5WVMssK7Kfx5A9+C0muDIqvLJnL0Eoeboo2Jxs7V23FEea4NxsHG4G692wkS14PQR8LXPR/oLjoLojDb6a0oNjL4iJzQmkTVkR4nM5L6qzcth/NH4z8dpJ2b86JpvS+Tr5fDu77OeWCzZfq/ysLdOt9eZxi96Zg63P+VUv6KeGp4DsRsN8OVEh99dr7DlswG8ForInBeZ6NNksfAi46Xe2rwPsNkgu/tOgpXUyh/gtUEgrS9nSnZIfFeHCWKU6GMbvno1rXu4VCDqCoW87hRSMRORZYSiEW1qy+36o9XZUFOR/+nkpNr97xrH8UYmFicvnvhhMl4/dsZVZR06eZ/r6DREkMW9eosSPUqFP62T3F2dQI0GWZLRmh9lcbsWAoZUM1EI9aBqftyU9Xxjz8jtEAuKYtNk6VvNh7RieAcbQJn1nnSMHi3Pa3wthJNEhMQzFQ7rt4h3lWm6eE0Bke4Tzm9SCRvY27mNz0qaPmETz3uoEQk4DlQooyDNmK6TLD+ERqLaagfPACnwciXqskj3pwZElm+k5AxMYRHT2045jY5SjXnp66OCK5fBS3BUVBlWROhYjmCO1vKDR3MP4qHHUMqoVCszPhUwpI8ko3ARLDQiXna12UIhAw3XJtl3zWNahLzf3wYZXSosYwo18AGvPpwUkFk8ZH8owitZMbbLZ/d2uemL6HQWU4JKZlSXu6Bdl6sfGOZogFQuTSNiWCXSLs+PPsom+csNRuVOQR3c+WOYHkUbs5iLGaRF9O7LuE+CsKgOiz99pi0YmIzo2iy1l6zi8fSWuB1g1bhEEl8b4xXcmFBF81ItW0Qh3MYrn9PRrkgaQA5qfXjm7XTRWgyjgQ1BaZ2Zjx50L/LnRQfi0cCuDGJcswFSmh4b4m4V9ALnI6eKieMIs1zdqKkIv/uWYlWAeeTMXn93DbRYXVcU/7zbLZ9Ixj9g48l7Zi3rO2u1pYaYArnosz5qFRHScVpyGo53m50yQvg+raNcTTpA/Okym4p8BDzgudfcstvCMwOysBeZ7SEVlLSCs1UfMpfWl/SMO8Er2qlnHTsARbxDW7EzDH73Pr7VKqYgO8iE1y+mRCpWh8HKK3MXpPR5b57XWjga6BB8sdQns22Al2aBQyrpnuchjhlmP/TBc3qNc2g/MsIyl/dYIis3RpuipbIWxYPALcx0QsEP4cUfePy7dsdpxn21pxisrp4b4zRNRaGbpiR2qOZzm1wcsaZvGdGzRB7hED6MvMfj2V3Cr8Bh2kp4ZMZhFZCNud8MDfclNswjUNAvUfBDGqp6JNgFLPcql24GAhalmOgePXUm/x2jGUjmwo1bh6furkZUPfPPk0qttr0LOoYsJ1idH2y/6/vG0W2zV77Aq0fbTdLzvdG6oVMA5j1XHWvcgvjUASAict0y8em1/80rg4GTNdjuPMW8gPdsSAcV2qLdrXaA66nMkZcKsrBqpILd9mvkM40v0/hM+UrQHnOTIDARCUwFUefEXoftaHF3D0aQadtoOclxWuL43QkhlfgeM/yWa3BUfLtj7LKPRY9csTWzSqFvH6kiyFW6rzakFAJNvpMFnh3bYsup+qai4npk+sGJHfbBnxUvGphpOTqzb24vBiZI6zUbi+Gha/oXq4LUs3x5gOOu3S6JmYpRUBBqR2Et+W9Alh2XOn4V9rLaVoWc3KZ+FyYZ+it7O1LTPZ7MF46bkBR+WEE0xtq16V+APgKDawUEqJFbZ+oo72fGKZmeY/38sBDf2KPlXV8Vc4Y6jrEimcBjd+rl8skpiXYfR2JS/5VVATxXomzfY6EOZ9SGCREpVBOftrrCi9MlCV0ODlnUOlwVxifmrdJnz4aNKr7qIZ4qMyIh9xvNiHhMl1lzowZKjKnZO7MfMDVxztmo+JR87tqU9oqem/+CW6hP4cy76VHSO2zDmJaN4NrbRiOe9jW7DuJCjxghciDftpZfiHSTzLXwKPs0g6EnVW4abbH/xfva8ClqK4mXdgTvDaINI0cjT8ByTbmadbUMJ/mZC5xgCd01OPG9Y+mdQcvkjbGEc9rMdLJFuc+2/8THml0tG3pTVf7jk2gUCvlbbIAzHveUI+sV0sYHmjRQIntwweyohgdDrYFIfKVaZBBYhsQu6i6QfG/I1t6gja3k9qu1zA5J5UDtvPCHPpnFBLBwgt+6OmewcAACIPAABQSwMECgAJAAAA43prSF57JjcdAAAAEQAAAC0AHAA5OGQ4NmU2ZTU5NDc3ZDE2NDc3NzA5ZjZiZTk5NjEyNy5maWxlbmFtZS50eHRVVAkAA9ri4lba4uJWdXgLAAEEIQAAAAQhAAAA0cZ39vxgAk60ideG867U1So8i/0Dkgluk+KWD1xQSwcIXnsmNx0AAAARAAAAUEsBAh4DFAAJAAgA43prSC37o6Z7BwAAIg8AACAAGAAAAAAAAQAAAKSBAAAAADk4ZDg2ZTZlNTk0NzdkMTY0Nzc3MDlmNmJlOTk2MTI3VVQFAAPa4uJWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAA43prSF57JjcdAAAAEQAAAC0AGAAAAAAAAQAAAKSB5QcAADk4ZDg2ZTZlNTk0NzdkMTY0Nzc3MDlmNmJlOTk2MTI3LmZpbGVuYW1lLnR4dFVUBQAD2uLiVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAAB5CAAAAAA=' AND file:name = 'details_WSgYuW.js' AND file:hashes.MD5 = '98d86e6e59477d16477709f6be996127' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:06Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2db-d840-45f8-86e7-4caf950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:07.000Z",
"modified": "2016-03-11T15:23:07.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'details_WSgYuW.js' AND file:hashes.SHA1 = '0ef7974b66135bfd95e03e93e128f3382e919046']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:07Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2db-d55c-4a2d-953e-4127950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:07.000Z",
"modified": "2016-03-11T15:23:07.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'details_WSgYuW.js' AND file:hashes.SHA256 = '873fb560250755555e2530a4c9a58553b1aea9d52fc4282e5547edc20fbededa']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:07Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2dc-cf78-4df3-8251-4363950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:08.000Z",
"modified": "2016-03-11T15:23:08.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOR6a0jADdhrgAcAACEPAAAgABwAZjkxY2U4YTQwYTkyNmU1OTc5MjgzZGY2ZTJmYWQ3YWNVVAkAA9zi4lbc4uJWdXgLAAEEIQAAAAQhAAAAOZZk0ufCK7dWSCxUqEkDoEHKk6ceYjqAc4Hd9Qq8hMj9EqKAwU3dIfQjXKT+muw7PWpCD/owNRSYsI0nBELlCFPGYboaXJhP8E3YBFo97OBLhc+kqRMCWRG4ILlE9D35SJr9O/xC5s8uS7OQlIinntQaODIcmzenxpDw4Kd8oqBn9ahWkv3kxLPLyOb/h0HAuHJkgHizi56eCXW1u3KP3GnxDYpyXsLzHiP4rgFdP5fG0Ra7ivkmvPOw/1qjcZ/hAQC8uDQW0Tv8nCi1IyQGEoiSw6tJpZh4KJmTm/KTysQiGoxh4f1qRqpxQMVVJr4OY7wii3RocW/izLhicGOFpFFAh93nkWedvwI5yxslpiMuvuLICY7DKXeH1qeCL79ZTxhW8HRhRD9A7oPLTsuKcc0dKnJOW2hmE0kcOJnXcccYCF497a/F54kt0SfziuRIwPwIQLhZ3+tM+e3h2QpFaMQjEEER3tfDSAEbGaU1ENaK8Z5oJToUsTjnSDOCmSWsyFzIBVVL82WvhPiqBZEj7HdF/ONLhhuBM8Pe9lDtwmme8FoqzlgD5psSAH3QJR1Rm7TSEH834/0gHKaUJxptuxtC+qC1IPc0eF6DPgaqSroHgT6lj2SZ/jdCKYlckjxpAd522y/hO2zUwRC1xcw9Z8iAiuXmH99eBepZ2PiuH6Yt1B5cNVgSa347NxKqxPicXUr4hL7qywtaTACfQ0nmZbJ1PW2aIb/0baDII/kQYoDl497hlJ0QRDDoqHdWcgTo8DY2ZC2aE4KfbW3cZytjhaGMcywWIKhWLrub29SAhjVXSSFNVghzUEH3AryOgvNMLpQpJnST4aotx/vUC6HP7rqMx/kYO/jWO5E2GNgwjhquKYATi7qlcyaJrcWd95yo4H0zD/OJ5NLlA1V+zfFAb70K74kbmIyYyH9pMz5CfyT+dlRIc1r5SvPGkYhb5jXh96RkBENGnLtUJP+p2+WQec9X9Z81REhm2R3jCHsv39UAJxP/2Y7q/shcpPudC/bJ7Gf4v5QGD3XpY52fdk3xv5oMnodj3567U6EfACtm1wvvxygyBhYpiO2WYRGWMm5Ocz9GZLTn8v4NK+7uO72WjXZrJpfoR/WOf3b4RgWj2+Al18FNO5Elgqjtjzek4cAdQHq5VHfgPWsVzpmrlykUU8YAtCHaStoDx8wpExmAF1p82N53yTo3L9H2NIEeGGtBmMRiwkR0UBwFyR2VB4tTRHZf9pmtRS/WoHjrus9p9W9Df/t5KygpQaxFS+n2gUVHSPTmGBp/7DgL+1GTLXikQmTt8xyW7cCYO+yUTMTw7W6dSkFXujSO4gmt69VwoJePaFIZRcbedgJs7+EnR7h18ZL3DwpXYVWg7pHsw5l2j1aB3bWL2G2iO7sAi4511o/HJsyjc/xZ0a0gmPjkJ6I46u6eiKyV6aEwXtZnc6meSz2IsoMUXK2OfAoKeGmUPjDHl4KVGv5jHD0K3ndmldSRUjPt51321S2ymsWpgsMkNTq0cTAkM5rX8GMLP4gqqVHeT3k+EXOkaptHZ9adKyrzGc+B+TT8j4YF+gJr+lihDZmOMxVJFxsx6cWEPGn+VfzPEnlZN+fMSbxjr2meLUCAWNUHRujkNvOt889Kynlfd0GLJGNOZPtVcPkTyZVisZCxm1lHsqW1AWdsM+QPDBNaMTh8BdhaULZtZtpYwyDNEAH9mNF5Lom+sqjxA/yW/DRYeVb551NmpzFJyry/tCqx+4hKWe6Xp2Yt/FyyyXlSe55TeTAwvo0W69OQZXxcHd4sFG8s7CUrjPZF9FTN6x9CMUdqzaTCoyeoT/Yl2SympEkzTIxktAK4TyQ/SkFGox+on4oo4a8KnIzFyU4yJj4GW6FU/HfWXWeHPbC32LeiFeND/rig6tSJHm/0IvZFevlKmrdA0E8NbFGQpi0yfWyLIDYSGaYVlVqT4xSqIM6gGelGwWKlntpsV6juCc5tVGbjeuccE2HNK0iQIlyFCX4v3ShzlNYWknH3APvFHbNsIYJC8uBziK89UD6EmsLtDBat0VlKZVQnXbyRuPfV5hxql6oo6mCxpLhOjvmu4ak7i7TZRZh4ddqp3BXKGRgcRXO9kijy4KgfSTBKS8Tkl1M6fssst6XE03WKX6nKT5wrmy0CEHCD8h80odRCjGFCJGScJv1RWj4IuA84bjz7Zjk1+H6cTrTB7OZPLZWvFcVhDznIrVEfAe3ZzyWnfAhBcn9YCm/1a5sfJeF3G9KQZcvxBugAA4kM9IzH0X5bmCihAgE9S2KRc2AhRYvB0RTSgulSK435M0y3QB4SXb5mP86c456L8KD67KYmm2kYaCgbYdMkVNavfPXnRzbHbx18sgwqbQYHnHiSzvKlOnnMcyfkJ8P16logBRzMG0GW7/GkwAqclgPas+wb955iqy8ZLupUd8yHvD3okHEfJV70bAT1RRczb/Rm6X99kB/cugou+je/Gu5ITdNHMK5cNRV3pk2xeu+yaTRqiA0XO1gqsytjVB7nUNhpKuA2nykC9iUhIorFs6hgWUIMZnHJZVgjz+vmUEsHCMAN2GuABwAAIQ8AAFBLAwQKAAkAAADkemtI+RqCWB0AAAARAAAALQAcAGY5MWNlOGE0MGE5MjZlNTk3OTI4M2RmNmUyZmFkN2FjLmZpbGVuYW1lLnR4dFVUCQAD3OLiVtzi4lZ1eAsAAQQhAAAABCEAAADcY/vTn6G5LBQKQ3Q2ndQNcZknu5UdPIOqXo1bh1BLBwj5GoJYHQAAABEAAABQSwECHgMUAAkACADkemtIwA3Ya4AHAAAhDwAAIAAYAAAAAAABAAAApIEAAAAAZjkxY2U4YTQwYTkyNmU1OTc5MjgzZGY2ZTJmYWQ3YWNVVAUAA9zi4lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAADkemtI+RqCWB0AAAARAAAALQAYAAAAAAABAAAApIHqBwAAZjkxY2U4YTQwYTkyNmU1OTc5MjgzZGY2ZTJmYWQ3YWMuZmlsZW5hbWUudHh0VVQFAAPc4uJWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAH4IAAAAAA==' AND file:name = 'details_ZleWjn.js' AND file:hashes.MD5 = 'f91ce8a40a926e5979283df6e2fad7ac' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2dc-3278-4e9d-965c-4021950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:08.000Z",
"modified": "2016-03-11T15:23:08.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'details_ZleWjn.js' AND file:hashes.SHA1 = '1e2a2ea134cf982b1ada7c80795d499b670749e9']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2dd-f6e4-4427-8fd3-41c5950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:09.000Z",
"modified": "2016-03-11T15:23:09.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'details_ZleWjn.js' AND file:hashes.SHA256 = 'ae7ae85fa40082dd01903aab3b519dce955878c05fb5618d95aa3610de719fe8']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:09Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2de-34a0-42f5-8264-46fe950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:10.000Z",
"modified": "2016-03-11T15:23:10.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOV6a0h/5Bu5lgoAAPUVAAAgABwAMWE5MzBiNmQ5ZjliNWFmZDAxOTljZGE3YjEwZjViMTdVVAkAA97i4lbe4uJWdXgLAAEEIQAAAAQhAAAAFTokxVXsdkGbjxXCw1t83abzeYSwqAHD4TBWGznoJZCB6B/wPrhauXWBv+NKsV0uGnmMR8DHWgttHFvsz9SwLWpiJWmIQvCcOLDJNkmW5+Uc3d5lW1Ca5QLVKIGehk7KNIXzyGKriy+WALat7UFTBQ3P9pz5qFOEvPAz26GMv1W4q3egExlNf3nhDokEFLIc68CcjJd6vuzaOZNr1OpCb/DkLFhEqTlz/LykZREPRMKQ3McJTX2l24aKTePcLcip1SKXbWwNaLWPY1H8x7yFqnoS/U7JvVcbWeMR9mbj9ENPPE5iAhhdovVDpnigESXkYq+kJJYsgq9oz3dS8JvevrK3M0sn/HsfRnebANJcsmSIpgUYMqu/zzwKCM0/fpL/BR438J1/a9br1/UDUXnuffkuoi5PB/YyKK2D39KEqA8SppC+nCDrIgoDJWmefaDCzLcpWA2Xbhhkhmuz3TEaE4c/l9NZZFIxLx3NzDlXMG5q2TSMkyuXfB3UslaYMnmPMNA9P97rJZTldwk9JrYnO7Bm0xCHh5hBKb0Er58FhHjeVlC3FwUYI7SbPwAzzerK9v7+EfCnXT1dY9Rvkj75FwXyJv5MD9ygoCcpvnbgiH6GxIp34VDzBeXJbNMbvOps2CZiPrxIcjtTbbuh+qTzAgtoeCizsVxdultFxEDu+qigWo2SP733YUA602e2C4394CIEJAubYN4iDfxcwV/M3nxsuFhjkyoqAxXJ258va2Ul1rmoGXF8zQ3y0Zx5c+MA/dseqwfdq9WrrKUQsNRwcAtYLKltFjKZiViswnMJ9FK/TVUSVYcab9SD52Q4MheySJk3dO8SsdJLYrBfalO7bRxfrDFnr5+FymGycyLvDqQjHaQuavW+cKeIn+b2SqFrutevf+jGFniO8Ka+77N+lrx/aSRPgIVK5Q7sJbwW/OA7lPUKBtO3iCAfgZCbK0jFQeA0hzKxFrc58RkNS0W/yBmWf9ZS/oGY/LokplB71UzUpZ6Zk7lMX4GjfullVvGBU2j3OFupsD0Qk217epLv9yTQQSssEVX7XMIdWeHHsfktohJj3tiQs0GH9Z5uIaK3pe7udCIQZQ4y/irYGQQbY97j4lA/Af5fR/xk8+9wGvx55HYeuOE1kqm7hmUcHX/aXBaj0zYFn0oKlMHK9LhNqGN3qanFuns3trh1AVlLxQmgfMDvuNUuLJ3XJopcJCcUWGV966cIuLwp/2+1qF4XddFhhMQ8RuxLntK2Qb97psFFhpKgAF8e3uqWmXivoVGW7JtSkjjPXu9FZpWiHTVM3a9MsKxE4HlNlUJ7nWVTEvxIL4gmPlLFWtfzQeRDoBnlVaVuaH6csLpE2nkT32rOCe0gT4b6gOXEK8fy9SKjrSX/GnbLn5gx/oCqjgI3WYe3A+2K8Nn3CK+wbDd6rXSH79YGtljLcQoK3DzlTT4FiZ6/Q6Otj9Oz8lsNQALsUbaFHM9wRuN/CqQad1SRF8IytqOO+d7FSZjNgeL/x8H4/ueSyEk/wf2byhjITiRNMALTiGGhfIPvHi0ePqkaoDrhWrmkUIJ1jwdeuFcWNcX0NeWssvIw0BvdtVW5VTYugc1oEd44YXf6JnS11+8Ge3dibhMZqEE1ltRg3vwLpa1X+oS9/fIoBhdqoX0KiIaGwEOeBWustsR8fau8Wr0rKhrSFJCYP6khWgeb1c1ClCDqyRYCmG/hFrrGjh42LvIPaVr1VjUmzwEYOwhTBv88uyDMZ+CCPzpVdORJUNjEq4y70lVH9aqEks5aNSwjwpMlR57/O5bDRHFtFun+lYUxHW2RzAXKJ5ZZMOk/dm8pk90V07BRUYh2dBMA8MwHIq6R8s4jbX9d8SNuLdgM3vqBJ05LAjsTqHm4C0PpwXHQqyG8PsJVTXIp5AQ+giDQblwOtdOf2okZEeBDT1hGXvAFmtIQ8edVh59sqHafW4B1CiRNw55iCwr9PRBYXci45bYhgzrzzZbNaijMcF8dj8FIzEeI5WF+/RJgXLRLzmzjufhLyi5oknVX1X7kRIjX/sbK2lSCBhrk1gY86aVrJFIhaddvilyiVR6TzgLQO07Wwxrogv/arCZ4RIJavwNy+qVeJnyqo/Twkf5gNfwwqVr6oJZZKiMbfYtPFzFi5FW/Ajl+KqitzLJAi4/qnOuiSRdSpohY+MMD7D7QF8sA8p7eXdTf87MDS786/e55suvjh25sMe4TA2VuZjS65YMCMSeiBc/Lo93Nz5x36bccd9Rs3MMXYHTrN35uSD3f0vwXnFRlyuBjyLU+s3hMTkdMwk7HzxdkPdwmMpUKwQK72fa8WCzA0QYFN5lEU5vjuX4qxpt8TZA4NlF1CCSFOxL0gdGnTPx/fZGImNz2OE/kngO1+lkKkkPlQaj+Fv2udq5jgPKwOJzuqBizw/HnTfWu6lFRpHXe8ysCNvJU0z28eRS+ulGfebp5pcKLz1RkIp3Xwrn8JPRREgYa0nxe5nwwGNkP7K9YefLj0qVrU2f2C38A0FpYC6zuaAeawNCghvYZ64zDM2WJo85BqBlyXkcmW1OqJPUoyEU3V4FHpqlSX72792bVhfDL8TD2D9xoLoMmcisfehcBnQgJ8TDUnEGU0texsRYSSuVPbOkTL2Hr57ITMpILDiorJSFOmhJDLaYAGPmvcudeVkhX976sr0a/2oKdLfqOyvTfuInOEVnJB7WVuv71NEHgfbSwbKA72J7cYgVL2j5gfsT4QnH9L2Zr2IE77B/Q0tI9TYA+7tc8gaBsRYXqpETm98lRBcNK+rITRAWOVC4HfLgozub+sdaRn0E8qIM9Ws+koTig23SVq8XEskfuRFcbf5PHtky+8jsA8LE1+315rp6YN3JfOeIcpECvLCZRri0e5KHcIPmSQIZ7uUVklLSa7RCXLtz7bMbpYW8KTmtxeu1zmpjum5/I5wIZxm6TEkI3o8pvN1yrSlSAKrb0AIbuVJ6huwF/oRL0hVfZva3iuYP2juxgZe585W2yj/72ohPtT6fSyN0ifzNm2CynvGVeqDgdqW3ySHCdKLAOIznlTrGjFYttIGbZ4x81M3euEbB7RzyGZRomIjw6UAIr2N2pKnOp7vkleXTI4F0KQ02PC1s6T1+QHLkMj/6qupUUv4P25TEsdF7yhxc9aYYxbdEIMyI4jp77jGh2mSoFxwOIQA6aIuydsZs1FkIZKI2IfZtSAiqAxRx/cCRmCjUSd4ysl6bVfNXUipcZpAUcTrOmYHeJltrrI7rF2sM2dBoT8xmirGVmmXOy5rC/7CLnIkKNquxVfO3/bPFVQDbYOADLH923xUwvh4dSzr1V8gW/zmVaFCrCN+YfDBFW8iJdIB0nWkKsxTcqVhwxSNSdSNRPL1kyMg+qZaFWUVzZGIj3YZKn4roD/Qng81Qo1IFGz0Q311aduKc3An0ykYHoyNrJmJBIJgAzKiY7KTF4F5T0wWqRjBgrKUbZEJ3lkHB8mD16xO6hkkWPvESwybhY4rkuwc9EUB8yiDyi4FnKLIEAwcvjYUljC0hnoJj7G06udiinVpWV1hRgefDLzP//DiTefguKrQKu68Z9fqP9bo8yYOPRgdlOT3mn6QLt4w5j56NS9sZkglBLBwh/5Bu5lgoAAPUVAABQSwMECgAJAAAA5XprSKF+NTQcAAAAEAAAAC0AHAAxYTkzMGI2ZDlmOWI1YWZkMDE5OWNkYTdiMTBmNWIxNy5maWxlbmFtZS50eHRVVAkAA97i4lbe4uJWdXgLAAEEIQAAAAQhAAAA7sFTXcSUrREPzKux9dMkj3X4Y+s0ssDN2kghYlBLBwihfjU0HAAAABAAAABQSwECHgMUAAkACADlemtIf+QbuZYKAAD1FQAAIAAYAAAAAAABAAAApIEAAAAAMWE5MzBiNmQ5ZjliNWFmZDAxOT
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:10Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2de-dfd8-417a-9922-480c950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:10.000Z",
"modified": "2016-03-11T15:23:10.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'KHD4983572607.js' AND file:hashes.SHA1 = '06e04084d8db797abed85f08d3446aa46c1d87e6']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:10Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2df-c8d0-4383-a2db-4410950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:11.000Z",
"modified": "2016-03-11T15:23:11.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'KHD4983572607.js' AND file:hashes.SHA256 = '3204df9176fc0cf9e2b0a255076b125c69841673b96e2d9deab63c203b6e2977']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:11Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e0-a4ec-40ae-a40f-4f28950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:12.000Z",
"modified": "2016-03-11T15:23:12.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOZ6a0jiW61xhgcAACIPAAAgABwAMDIxMWU3YmM3ODliMWJjZjVjOGZiODA4OTJhNjM3ZTFVVAkAA+Di4lbg4uJWdXgLAAEEIQAAAAQhAAAAYdrTrT31ZLhNqu2nsLOfkdvJFgNkgj+8FaOQQgVpVs/CqJKxEvEzMW7+aNa3giWMY/tYib07bzCgzP5ACtM8YHbAdAQLzLuTLP2tyAe3Yy0qjtqqJtYATYU1QRAE7cezLCi5gBnO31yZrn+Z4CDPoThHBtNkhLTjQDV6PzZ4u5ThyYUckw46C7ZNDNAmkj7eDqE7fto4N5RogVQuqryCUuc5kWQeuJ2mfdSIgrfva0PKbfdotGN0JSFeZbHQOlb21uoawMPZUKePzgmwv56RL2WwCRwfp6oFNHB1P7ck8hhKupSlQUbO4WhRjXHkCJBX0QSPnZ54810lUqA+UpoT62fZhMdgLgvTvCi5A+fq8j34FFplS+j/5FKdCc2csyfpFa97BGtCiwwYdYn3x5qZEpv9dOlGNCCfrF787GuK0j1PuRBb8sl+2pJr12sKHpd9UakWryGnVH6GvursaZJXwqStpSR1bq5CSTGOoqNGTaOfZp+DwJQkDQZQky2X4CAqqgRCLGKwox/v9NIityU5bMn3iS5d3LpKWDYI/qOY8JZ3Cide7eAf6L+MvTCZlKsrPh2xxZeID9caZjwMP9pky3t5wA45302ZlXmr0dT9bNxcYgAEAeTK3QpBikpE/n3bgzyue6HUjlCxdKLVMXoXoo8f7YP1uhuLxiA00zy2yk5UhNB+ePfhwaA5ziejDy+HwOiEt+eqZ4Dl4ifxazXGV5TbQHZFdaCNyNuH3lAaTRRCwfglb7GMNKrxyHMBILx3VOCn2mZmgwVqgLmWJF+EGHOEMrac3B6L3WkuiV6A+N0nxLeCafTtNxZNjOG/D/3bl+/vrGFOWgtDbtg3/3lXT9n9b1faDU3FTR94ecYt/f43DHA86A+y5jB5c1JPJTMhDibKJgYfrpS4eAcAAbI8a9vGSXpbj1Eil6RfBpK6by8HZXMWMOQWeJ3IiAOmaMFNZ+4fS5xljSZrtvjQYj+FgPlN3kw8/nFB6C1RblfL0PbfdLHD1P/a2msCEwDrlpVTye+e8c0gctHyx4JzZ9ZuP6HHExbmkrleo4vPS3qkgQDCHFrJpIkHaYy5seRXosmEieau6t0+ubgk9sXKyxGUDPlGxDyUBdu9XFELydcTyT3wTTM0ttcgDPECkqNfjLEKQMOtQ2ON2LxVXA6jwRj1S5WaxqXdBjfw2XGCpRN1WzV4Z+UO9+AjAt7z+eP4V+7TfdnODcykIN2YyhDmx2ePWYhSglPdYmcCaGaHBHNxe7hSnajTNM1tKG2uhFyVHG6+gX8/01OCcdtMlSckgasHUBxWEGPf/d8SLvmogJlN44wtcOCEhucIJXece6Va791RgwlCNkF/h0Pye1e2ua3sgp7SoXML71kGWHCZxSIUTfKliJWZhJeOJH8DQEFdIltS/5Dpd9X5H9+azY4WtJswC6gDGiVqCGS3DQK5Piij4AHndteGlJm4zRZ6mi5wOLaaade8RgblVBeFTd1hC2JDPGuypYqJ3kOW5TB7KnnCD37eWIllSMy746kT6zTvFmhU/CmorP5XSWXZovY+HQfV6bba6YhJr7Gln1bshpaFnUk3tOFA9NE1zzP3X+Pv2kl6ZWA6eB1hfRBeoO+ctoM+dt8drPoP0TMJ3b/MeXJxODXzfil47QS6k5ts+LjTcwCxNzyjaBcA+t2/q8Hkhs5YFi88Tb0oQQoXgpVXKmWJzMCiUofuS/lo6nVikeLXz1BZQVjntJkpB1FhQZ5QryqHZMndkxTD1a4LMi5yCedaA9wuRjaoPx6kN5ELo8bvVv3HI5xGJdDOaE7HU/NCmZLal1dOmfCFbb/1PdjAe0jHS0Ezqof7wriT8Cm0qu9TZdhntQiRp4YcVqxb1BGyLGeGOdwncLBWwuSncD9iIaFtM38StVvpJQRd8Z506gjZIki/KKxsG096ecVldpQ13kzumwnRywULdlNvOkpBpIWVSjBHCX5Zdeh+OgRQD7DGZBWWlEdM+ZdFZJIB4J9JabjvDNCHNkeXT8TAvguJ6/Ub9BiitVgqgIFcjEMawNmEYz+sDW+duRjNZWji4VM4YGwzULAvCthYpLtgiSDdiS8vLfFF6l0/a21aEFZYN0S5imOlObqVXOZo15EiRZ8bXjnuspfw84pQRnT20bzzoGfJ1v36Z+2+RpWSRiMokU3k4qrtluWPEITnv8d7v187dWGZybeXzPysJz+VNAW/A24JTEZ8Im1ek51apUwUqaluo015xD5cyCntLWWrUce3vN87pcJ2WXDAq3KsyeMtZj2Vn5S68tQXtKkBLskZezS+J+hnZ1Y+DZP8MSzwVt3Q5MBF65jxpkdbbYD22AVLq2cryBUfEKqPAdx1uLeOyfSNWyrEZnSUtTLCNl8CR8H43saHpnab/SJlyGIQXygDxAGv6akpqTK3VKlU5Cg11ttUu0Zfm4/CaNWxTC8JSnf/K03wt1rqw/PxPaEY1p6lyuy+Gn8+2VcOdpWDqMi87xCHP2F8dJBWgQi1uYX05xEZ5Tz3M1slRT/etTI6SLHSGbgvr6T4kCqfxd+OoOrakNiyxWRCYJ6plQcRUEsHCOJbrXGGBwAAIg8AAFBLAwQKAAkAAADmemtIrHDnWBoAAAAOAAAALQAcADAyMTFlN2JjNzg5YjFiY2Y1YzhmYjgwODkyYTYzN2UxLmZpbGVuYW1lLnR4dFVUCQAD4OLiVuDi4lZ1eAsAAQQhAAAABCEAAACS4bRolT63+fDHxmIjscERAy3Z+XSmoTnCnlBLBwiscOdYGgAAAA4AAABQSwECHgMUAAkACADmemtI4lutcYYHAAAiDwAAIAAYAAAAAAABAAAApIEAAAAAMDIxMWU3YmM3ODliMWJjZjVjOGZiODA4OTJhNjM3ZTFVVAUAA+Di4lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAADmemtIrHDnWBoAAAAOAAAALQAYAAAAAAABAAAApIHwBwAAMDIxMWU3YmM3ODliMWJjZjVjOGZiODA4OTJhNjM3ZTEuZmlsZW5hbWUudHh0VVQFAAPg4uJWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAIEIAAAAAA==' AND file:name = 'mail_fBmRht.js' AND file:hashes.MD5 = '0211e7bc789b1bcf5c8fb80892a637e1' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:12Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e0-e8c8-4089-a3ad-4966950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:12.000Z",
"modified": "2016-03-11T15:23:12.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'mail_fBmRht.js' AND file:hashes.SHA1 = '2798e72c275f322dabbcf232e48259ee0659f955']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:12Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e1-f398-4716-a679-4ca8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:13.000Z",
"modified": "2016-03-11T15:23:13.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'mail_fBmRht.js' AND file:hashes.SHA256 = '6c5dd37064a785f6646921103c7dbbab4ba982ed1de922c50fa768a62188e36d']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:13Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e2-b448-48b5-999c-48f7950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:14.000Z",
"modified": "2016-03-11T15:23:14.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOd6a0gy2hmahwcAACIPAAAgABwAZDFkMGRmYmQzNWRkMTMzOTZmYmFhYmExNDlmNjFkMzRVVAkAA+Li4lbi4uJWdXgLAAEEIQAAAAQhAAAAlkbbsqRG01VOMVBlRGoR3vG6Mg96Mqh5sS8DFFQMvCmmRKx8Dk+vE8Ks7hnGoZGLi4Sozn/F8mzdyajbyEa3cfOmA2Q7xyCxRdxanu4CT7fzvvicF7ogesBNxUfn9LPs8kCMpfAd26EW38Oo0VbNREIMmqP0nQ0mee4Y11oHBIg2ZfeemYx7doptSOR34JnW2VG20TSRCiwLc3z7BoWbAmSERtOwk2VvWfxP/PRGFcNBiznm/VQ+HOYikS3sRG8kqOkaBQFgZ+NTX0H1iiQru5hLbTdhwxy/do3V3oK5nI43SU3h85s8Oa2tJl5R548c1OgECL8Hv3c5LzvBDxifCNil33fPeRyQXr163YuUxra2aLqfFH+zwDb+GXExwVbWSVCqeDMClycL86dxceOSt9+V+OjgE9yzwpIrYwOsD1FONAy9UwRv7+cAujzrR7125bJlmF3jET9AycRu/GG3lHfqKFPCgCqSFl4K5oCgCPMxtAhl7UAL6ooyES34+NV9/zqZWIHVsI2jI7HjRyuVFj8D9oDjgVoSx+uzd1zwDvpGSdKZ1m39KoWRGfeiFmYDWElz7gy3GH1NlMl5Jou7H+S/xkbo85U8gsezv1kI4Xyop5apl7JzQjJZQbSZRUQo9hy2PPDZegRbM2EPbwwpj+f7+x4nCU3m3/ypsIfc8CWTlQk2ClG6X9ppIjuY8sA2hAjWuZNLYRZXs1I9f40Xmk5uH489HBvyjgAZd2w9HbD0bqS/CDydNNYw7jG2KQZXM4XXmyC/UFb6uBu78K6mYrpKnOFk4YTD54JrSfjDbC9LG8BcuBpYW6O9efsUVsJ2usSyPcprsAfB4/yQDLts58vt5LKlNtuPDv46XfkagdTXBK50+463sMeesyZZUDKdA6hmvsC97rkkJzZou/Dj9pk276SOMmizxz5nsy/ojwZ8rjtajaKDmXcIQ9Q/kcxmEaABnrSV6TaLmJ4V9K+uH+eadEBAnH1intk2BEZTbSFMrZfl2FHnnR9VWd0U1x1hBuCa/b0VilVtDYxmnmXDSzudc7JTDHf8fBf9XGy2UhLF9cYEGrzCTzqlEMYT2aTSVa3SkRjh3m7ye5PDw5Bwl4Q8Kz/rIRDDbWJK4X/2L05PtJT9ChTPBOxtULY8m2dcXLPMVlf4V9/xS6qbu4ZyGEzyY9SZZgHXGDlDDkSo/cvCPBMghZTSvHxofZr0L2Auuk39zwQegeDpYPt7iBUZrdd0OzAn9lmEJMaJ0QwP5Xfe/OdWZ3IjRLYZRUI1F4wnERfnQL9RHI9A6GiJhbXNN8bqXYyfPCxJ5k27DbfSvr4f+22UtSlt/qERPFqLHJyvZUgdRuTEBxfwex4RopMkshMj6M1CUmPQ3KVNlPCbdhdKOYn8eqFPf859F6iNs/NuKhdzUxMa97ntLWv6MWEX2ow3SuwiJaEw4k2Ma+TZ/0x7sFuZ8YeJahggp6Vfwbza6bTGmB3py5d4KtLgp3ilPxRQmyjdLrravD9UbLyeBtBSWPG6vGVtmzrhX3MoU6jBnd56vzGQdQMHcKb4SI29EN4Ou6u0zdidnTJMnp+EordOvpqi8b7HnoEVdCjcW3HDoq2Efc+B+OiRduHxrI6aNwwMs1N6RFL6DTa4WDyYs1ZRMQBBq7i7lL+gD4p34Gmh01MTS8rZYxdvd1LG0EDllhHsaoLgqC2T3nQE19XlVR4tH3ez794ZRBLfS5UnyQKOVeZFgefEoQiGx3NjbRardiOTFeJ9YqjIamGyvFWEuG5rqOJEyTO4XjwqWSzc6R03xY/Ul8oRdL3brQxAClACaqoQDyY3LcMFgMVYLdkVVlAycJrb6UNQXIbcgNdB+XcZV8ThMXTInSVb31WwQ+HDI3mBDkKKKBPvg4+4BW/Je4FOvYRJTyVHwEbb0DNcxazWw9VwOgoinyzEZNdOkGX5cFvVTDueP04Yzn+YNPECUQ27CW9PBqWvzKgKFjmwZJ7rZIirJzUra3fBW4moG6ozlwficfGCQj2PmrmQv4j67yhjupd9B38O7OrZONtvir/f5NmPTlSa59Od8GVep91MumXqkL51kNFp7hWHaCw9ShjhK5XxqdYC9QU2ViAhmgMiIh+gcs5Sh+/1KzwMurk+B+0HBg7uYpKQWgs4B+9n3TKUsVRYxE1TzqAXt30fn5qMmGXPdnJhqu3GhvptJcli+lKC/chQAmFi6BC+kNQMBwA+Lq88ekwGc2y+dxcMaM8iLuP7JkG04XpWLmU0N+EbNIftd6C61LrV6zyKs2yIEB8W+ht7ZBTvkfyHdx9T8Q0/UJiu0CiMA3FcAy+ymFW4raJLE1sIvjspGOi5MLE9OcdrFTdHopjOdJTyzPjHTxY/THf5fdtNFGDIgm/SduOrVGAJuGJRh98jTdapuXhck3G/eeRyIVSydFIq60JpLLkarllVTZPz35orO1uQqncJ705oijZKcxLdTAxPi6A4aDb4xgVVOObw0AgxCKK0HrWhyRMNiDJ6f7t1pM+F7oYR3PnTYt2qT1Idp+iLUWQpIVQCE9rm3vCjkYnPO9pncUIxxp5/U3rlQFBLBwgy2hmahwcAACIPAABQSwMECgAJAAAA53prSFxpCFUaAAAADgAAAC0AHABkMWQwZGZiZDM1ZGQxMzM5NmZiYWFiYTE0OWY2MWQzNC5maWxlbmFtZS50eHRVVAkAA+Li4lbi4uJWdXgLAAEEIQAAAAQhAAAAaWFHr8AoGiE3S+obDLbrwnxYH1MdweISQS5QSwcIXGkIVRoAAAAOAAAAUEsBAh4DFAAJAAgA53prSDLaGZqHBwAAIg8AACAAGAAAAAAAAQAAAKSBAAAAAGQxZDBkZmJkMzVkZDEzMzk2ZmJhYWJhMTQ5ZjYxZDM0VVQFAAPi4uJWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAA53prSFxpCFUaAAAADgAAAC0AGAAAAAAAAQAAAKSB8QcAAGQxZDBkZmJkMzVkZDEzMzk2ZmJhYWJhMTQ5ZjYxZDM0LmZpbGVuYW1lLnR4dFVUBQAD4uLiVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAACCCAAAAAA=' AND file:name = 'post_NAAljP.js' AND file:hashes.MD5 = 'd1d0dfbd35dd13396fbaaba149f61d34' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:14Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e2-e8c4-46c4-9832-49c3950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:14.000Z",
"modified": "2016-03-11T15:23:14.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'post_NAAljP.js' AND file:hashes.SHA1 = '0435a275bbfc149c331f4b7d9540973c633ffe25']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:14Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e3-dc10-42dc-a566-46a1950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:15.000Z",
"modified": "2016-03-11T15:23:15.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'post_NAAljP.js' AND file:hashes.SHA256 = '1a9d0655e2a4509fa89cbc842d5e0a8b472c2cf966cb619e36272fe12ea00546']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:15Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e4-e4bc-47c3-ac6f-4240950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:16.000Z",
"modified": "2016-03-11T15:23:16.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOh6a0jg1rCpoQYAAMgPAAAgABwAMDczNGJmNDU4ZDdhNTQ3NmRjZTA3YzU3NTJlNGM2MjBVVAkAA+Ti4lbk4uJWdXgLAAEEIQAAAAQhAAAAlkbbsqRG01VOMV8sVYzKmEtvxUCB18w9cDOSbZ3oRep5eJQWsQkOTFqNTS4XebIA1RBf366e8yqyE+e73jT6sdCALbYus3A66al3hhc+xythnKb9l8XxFM4twOEJuXdb6CEteCvIzYySgFPwELJPDMvEdWclvGtmQATqq7WXWCeAhD47D+W/6G8ZLy3PtlGGLWGGPqpn5gS0Qjn5KoR9qEMY4LlEB9PB2ImDZR4kveiJaCgDmcBrn9BzlkDaaxwgc75zp9DwnkJNpRszh2O+02lKeaGnnxtNzTS3h/Jklx/9as3bmCB7rpJ9yotjLdC41uqcly2YcTn4mtY/QyMePG+O9DF7vS8wvclJHtg1LgWQ/e1a7n3dm3cwc1wdU7BgHkOS9pKuDEvsnaKGoUBCNehBLZUxWWPkr91u91pv7RQs2x4JvvU3uDS685YVpVkGOLP8Ga1iAkKJUXQX7W9t1M1vlr+TZvnQ24X82DGeRNLYes1y5DKbj81GgJlFkWtcLO0+lwTLxWR+rfFDzEqzNDQt7VSih8yftX2tvEKQ+W55UvT/JwFYKjZ2sTuLLccC9WRu8NXoIH7DhjAH1doJqir1/OLW0TiystbCz8sjjzDvdKVcvHP8tK54+Auj4LTNZHlvv7Bs3g9CW0Gn+kQXKLol73hPCDd0BLSETjjkkprZ2BkfgMtMotJZ14YIJzW0On3/0paDt9cAujzIuwTrK2ZEY+LVVoCUP73MkxlezrTwJYDW7mJaxskglWmkCHQhfUwppxETHoHKFP8j2W98S8rWYEm2ppReixEEvtyMpm3B1A9zSsgENUHKLUoL9S16w4WmdMPzmD6mEkNoSNXVgYinVHUVVYa/AWIfz26wGOlEfCcPzcWWijM3yZchyQpCqbNz6vCc7PE2HLLl1keK/oq7iZ4Eg4befACkRmgb7ySeDD1WLt6qtR1LW7LIvFKGqXTQOiJviTEogDLTfx8gv4vuUHppHHmy7VUt9ZWkGM1uUAyKeWxiUTEg9LNhA/6gaozWITj3kZHYWRsVR2fcfCQQYo4wI9MCNKdthIhxFstU2/3j74aGQQjFW3S8ylh0QCFbpHrpHM5yHALOLYFQpZlN0PQfPihnskjHZ4dxD6nSBvhNKs39u2+YaRLtycd8J3QXvwHWEShskHTCqABi5zj+mf/BH9EJ387uXQXqWE+SArDmV7q2kuX/gWVYEVS0yUI4SsrJsHAkb5fCkaw4EYikZh07Vi3A8th6j4KEoxJ71BnwsmTa7H00p+d9Xj6uwJJbbtg24BwkGGdV38+979Y54qITjCkzMvQjNNhRsONLaiwC2W/MbP27hCRxSQiSD3/U4ULs+UXOU6Yn3stT8ZkAWhGV+86g/snkS8NobYgRdLYO0jc8Js/KDYVk0RW+MHry1WX6BU2uyw5xjuBo4zFeJVq09LPlVq1tXaapf1sbT3cx0mrC2gKWLijF5Jb+n6QSOzIEpyY6ArboTD7tOnKUnyWOIpG8ZmEjLbRmaBVN8g6yUK26ae/b+gYHNVJ3BAP6qrzTYEGDszCxPGPWZwqnEUyYKeeLphThXbBuo92EFAdUGxL780WhHa8EwbArufeqq+NMbkNRz34+3vtlH8iYVvvIjTE1v/VxbxJIUGokhnxiWexTrQpdsPt8VQ/J/qhbWhe7DKeV9BU5A0IG0iIqrAiKn8NRLi0GyL6ivm0MU//KoT63FBP3pPk9+rMo8X9eqPaVIH/iV8GFhR9ZiAls7qiZYYmgsyH3nK2rwXjJwqQi+vWVB7hA6s9GOTQkXxmWzUaVy8chbwEu3PkxLQ5Cw4rS07M9/ljjDexD7u/uK6XyAdSg6M8XcjDIw6NZHufpCU5czLae/Rtpx6iKyhvts1/mGMLpExnoKBPaHii1HojPZevsgQ83kDp68xLfT9VsgJ7KSrP+Q4mDq0Gp58Stgy/aah/R4czu2+rZ3w4LhJEpktfrCF9eIQ0N2Wuu27Y1jLjVByFMRmcllHpEcnmz+r/dnt1g06iT7i5bKIWHlI00nZ4sHPfvgZwre+ZAeq5PPGDj1HlokEqkh2OrY3GFKOdJ5LuXdG4MCmqpxMsNHJWn8b9pY45G/oTk6Zm8w/pDi6Lz6znZv4hb/CgtcDVeCpbYrEOKsw0NC/VqauWUT/9MB4sX9q0raqhwUfI6bqOZiiAHXBA+DVf5RwDJjKv8XL6/thbuZwiwugi/cBQxtM8OxuqzRG8SICTpCpT83NWDyv5i94V42KnpECMmYkRQSwcI4NawqaEGAADIDwAAUEsDBAoACQAAAOh6a0i2qJp6MAAAACQAAAAtABwAMDczNGJmNDU4ZDdhNTQ3NmRjZTA3YzU3NTJlNGM2MjAuZmlsZW5hbWUudHh0VVQJAAPk4uJW5OLiVnV4CwABBCEAAAAEIQAAAGlhR6/AKBohN0vlNIEYCcQaSaTgCEQQYp7M3qjJmo9JL5tZO6iCbcrDnyYgfTNbd1BLBwi2qJp6MAAAACQAAABQSwECHgMUAAkACADoemtI4NawqaEGAADIDwAAIAAYAAAAAAABAAAApIEAAAAAMDczNGJmNDU4ZDdhNTQ3NmRjZTA3YzU3NTJlNGM2MjBVVAUAA+Ti4lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAADoemtItqiaejAAAAAkAAAALQAYAAAAAAABAAAApIELBwAAMDczNGJmNDU4ZDdhNTQ3NmRjZTA3YzU3NTJlNGM2MjAuZmlsZW5hbWUudHh0VVQFAAPk4uJWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAALIHAAAAAA==' AND file:name = 'Post_Parcel_Label_id00-335062003#.js' AND file:hashes.MD5 = '0734bf458d7a5476dce07c5752e4c620' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e4-bc2c-4748-9dc5-482e950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:16.000Z",
"modified": "2016-03-11T15:23:16.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'Post_Parcel_Label_id00-335062003#.js' AND file:hashes.SHA1 = '8f14eb5933f1451418654f8e79fe1ab933c8a34c']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e5-9074-42cc-a04d-4c4b950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:17.000Z",
"modified": "2016-03-11T15:23:17.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'Post_Parcel_Label_id00-335062003#.js' AND file:hashes.SHA256 = '182a7d2e2744d6fee97a4aedba1bafbf1df9676f8d00af4841e89c665f933116']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:17Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e6-3c7c-4112-8d63-4844950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:18.000Z",
"modified": "2016-03-11T15:23:18.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOl6a0jxrpAAiAcAACIPAAAgABwAODk5YWZjM2VhODQxMDRkNzllZDk5YmVjODY0YmMwY2ZVVAkAA+bi4lbm4uJWdXgLAAEEIQAAAAQhAAAAlkbbsqRG01VOMV68h2ANtLXNlAD6YhohDxmnTN0p8l1r2FGkktpz/T1UTLenrS67KLp3ss5MZuQTEFC5jtV4ILJP1Ubyikal1+XeUKL0IPDxwbNjKgzeR1QxXYPCVZHJ0UHVB3iNEsjolshrCsfoNCd9OKucKzHHNQIwtb9OD0bVilgyjUc+YfxtDz9EPwuU4ZvRHcNtnDY7P84tHvYMoK75GP8OmxEJl42f7y9KgQ/Or73QLOSevuzLdr2Zq4qbo257tpcBGRAh5WYAdr/DA/wnIgwloeXmdkwB3abM/wSstYg9sJWc1h3bfVpPuoN8GIdmB+dGKPE57Z57hSaSp48sh/Si1zLZCNPs1RlUxgiSytuw4tEXw2wcci3Dy7Pga8PTXTgY9fxDuvTGJbMk28mvdf5d9L6ExVUAK0jB6ATQ3JJgmCVw3KdHIgLLPUIq+rzjmO2PoMCESMoM0L5npzZSwddnK5JyZT6j4jOL+tuz3BM6DRZXgEf7U6cujfrcNs6odLjYh80nfXzr87G4/CnDDDHjBaUgV+lpKYCKmmWy4FB6+W+H8sdmKdT8EbCOF4megABI5XZCPyUFBqwgmKBiUnEv26JGZJ60cg3vI/b8Zty2q/snUiCxKUdSq8EF7jD4e74WNFtlBjQruMM6LF2nWQAyjpveTdP1hdnCcL/RYY3ABvvxb7aUvFrYLD4O/lt9+j5xS2Ot225OYOsmTRcC/vcZxrarWfTW3IIT0P9rpvCTW4G5cUCJtGJ3r4vYg9lWn33ZoS9DqHA1mNH7cMmwoIy+hT4yl10A0iUvd6h9c9XLeZYBR0Z5eCoYYZiyyknZeJc0mkoLXiGrJfmt81wJItcoOX/qD5mU7QQKwbfUasNDyLOQ0gsbJAetX9J6lEb1vK0KwPC7maeNsRL3j7bNyU+zDcMiJZkHSRhAplZz5y/nIXg136U4fZkykwoM5xD1WFs2r6hoBzR8UeNPYCgmjJcgPua5+4McGofbispVWLyex+yPwi/hQ40shlcluZPITO3Ku+K02LRjQhInMBMfbkVuFwYtMsf99nwV0tkrelSvOLL2aJfgodh0XOb5X0XJKKu2e2k66dn5GoWHRRPCk8wIw/VHVj+Sia1749BLetVvQFKKqesWeBO2WzBi/i8hMjiJGi6TUXE1A4ENFQ06FnJL5xmKNjqMOGv486bn5AXp59fuSkt8CUxVOx+etyThks9xBx3a6RIjNPVFFQwzex9955N9N7TSFjBGfIOnDva9gWrC2rOal6s7Z+hhUlbr7y/9034iQdcrJgYNV9Bn/4vmcFRfy0H83kPsGWFNEByZ55eVfUUZDzsPDQkDKRlsJersmG1pYmgcCYdduV53az2tonNhDDmCKz9DyWuibD1FtYnM+Uuna9YLI6ED75N+bBWlThPKYFR7ASMEuusHNnIDehVS396HYVLk0CDBgbuQI/w+x4qX2LUk/SsuKUSLs56FKuP6q74ROY5doYCmbjup+N+HQ/2QBUr7+EW8EyJ7bVfpwUO8No1XhCbdwxT38Mff1rFTGvH4SLqSSu8ERuZi8GylMtujJXXnA8ROuYUmKOn3NqnF8pT+wEq5Mxck1nTF6VkrxGXxLyA7k8LJ5+jXwlcdT823jb7isJihpDbMgbkwq7f6KkHgHWYLXBEVY9XNZpujYQytFKXe9wgwUAE0F2WuLRaTaP7iNZhGq/bkRqpwbk9OXS11rFbipSaPUptfxbfGR1m+YJTFe7FlCFVzYhU7WtyfQZJxTA6dsdNm3+xEqVILY0mAv3jVc8ALV3OPb/8YQW/WhkdYIdtbmEvRS0p/S2Yr0rSObU2LS29uRvYmKBER9ObN2uv7hO+q72DGz16D5bYC0YgHIFp2w7297WP976eWjU5wmTgiZEgKixwGwYd8/GnLKZzjU8gbJ7EoyOEtc6KI3XBHN7QIW/XQx4DBfNbaCnvogu3Rvjv/zzSn0wEa2CkwSsD4SlvO5YvK4flIunS2BdJjDzT1UtLlKMm4pyddgp4CjPN+yG7XP1bVQpaCWD8xp9HpftDPXfO5Zc/5ifnZkfsbbEPiWcNuGYzXdgigSGjONYx5qZM5xIHdx5ttuK0jdpwzBh/mBhzWdDrW1Tud9vJoXqKBpUlnKIQnx8DFokFnb7/cmw5U2hyGCog1oMJQQ1n96jUaVH2ePrp1eljKHMXqh3JH8CGQRQHhL+AZSHjlbGRr2S9+2P/mzS+Ax7WyV6KmJ99BOCrTw5/VqOzvefJlE46d8M9jV7neaLx7nlzPHjX1Nv6jtkDEGMvkLXr6gvoCCy+vfn+KbP9GzpGtRgk6gNdDNtUQFy9keGzD+lOJuAlDqccGV/GzRwN7yCws2AbTSJB3TOf6XMgeZ4Ev7ropJtCLwnBEt0PXORLhHHXfWnSdLtDa4X9Bk1wF0qgJEVeH03yAs0zp2qOS+zxZdDy/qwEnP03Bu43M5WXBxfyrCtdE3Shvuf/Rdsklg8BkdB2ZwRSRYPEvbC360UXAI5bBRUtLoJeXkrt20I9M8iIw0GzVgD6NaxmzsCqK167CRSKkdfJbY6n4xn1QSwcI8a6QAIgHAAAiDwAAUEsDBAoACQAAAOl6a0iv38eNGgAAAA4AAAAtABwAODk5YWZjM2VhODQxMDRkNzllZDk5YmVjODY0YmMwY2YuZmlsZW5hbWUudHh0VVQJAAPm4uJW5uLiVnV4CwABBCEAAAAEIQAAAGlhR6/AKBohN0vkoglVyCgQCfb7GMhX36NBUEsHCK/fx40aAAAADgAAAFBLAQIeAxQACQAIAOl6a0jxrpAAiAcAACIPAAAgABgAAAAAAAEAAACkgQAAAAA4OTlhZmMzZWE4NDEwNGQ3OWVkOTliZWM4NjRiYzBjZlVUBQAD5uLiVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAOl6a0iv38eNGgAAAA4AAAAtABgAAAAAAAEAAACkgfIHAAA4OTlhZmMzZWE4NDEwNGQ3OWVkOTliZWM4NjRiYzBjZi5maWxlbmFtZS50eHRVVAUAA+bi4lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAgwgAAAAA' AND file:name = 'post_sfcAwT.js' AND file:hashes.MD5 = '899afc3ea84104d79ed99bec864bc0cf' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:18Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e6-6210-4141-b937-47b4950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:18.000Z",
"modified": "2016-03-11T15:23:18.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'post_sfcAwT.js' AND file:hashes.SHA1 = 'cc29b9b2400e921149f39e7730b98b564762af79']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:18Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e7-d8b8-4c6d-98e4-4ae1950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:19.000Z",
"modified": "2016-03-11T15:23:19.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'post_sfcAwT.js' AND file:hashes.SHA256 = '7ad984e6c4f170c82de77d8e0cb3026ddfb86e3d51f1d7168085ddb8ca2aac66']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:19Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e8-d23c-4199-8dfd-462e950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:20.000Z",
"modified": "2016-03-11T15:23:20.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOp6a0g5ge/PqgYAAIYPAAAgABwAODlkZTNhNWM2NGYzYzQzMjg0NjMyMTc1YTk2YTlmYzZVVAkAA+ji4lbo4uJWdXgLAAEEIQAAAAQhAAAAlkbbsqRG01VOMV2uHUQ3/Gv35SNyIE4H96fn1RMAvg4AZ3C6KTQBHNh8hBxRKLYrwtqji+RYX5QeYFXZwReYRrtMyrMxTXXXp4rgHbmlrnPsDbpI0qZ+i1qHaPL9o9exYJ3S+5VqEIR9H9YBP7Lqf9ONcQcjzDcl7GmfFqBvUJwWMcQrRf5Q/uRcMjV82u/C1lmHM1a146PNxfZK3R0r5Xf9zISW8uaQm1998V9g4XqHvzFaeTORvcyWWhvuRXLnBPsOLa4+2zCWltF9zMe0aheWos3sKVSFYWpKqIHWGxo5BqZl+/isBLhwha0tErGiGhjdKkowwWNPLxxIMDKC9lLF4XFNvpI2yYyW4839W+hy80q7h51sIlRVF+jo64jPahpaq/nN09SAlb0NdbzLkdxXB1t/slbuUA8lfh1/PffVuaruBrT7foQSE/oFj2rOXNa/C5Q9U7LiTPJ7wUQ+pqqEq+WZ61hjF8/UTKIWw4S/kCjXQQbNeLyeEfn56FxZGvuTsohgisHNVo1dREiP3/rBnVLinWoZEU8zFr1LbOJwtYIpv/qMx8WNlQHMayzfF9vEiHuc8pTCnkd9zxbHgIQqdZgN3FGBg37w0VVsMXO7f6PsjN8ybkuwBxguZj32MPYFpcSGAHCso0eWOjtfa58GO1VtToVP4xTdvmLkLsqIL4fszM+Bx8WodB/GlDaNhBJum5VYs/0tH7P7c2RDcra2Le5vpNMJcUoCOOC0mZuJpcOXLpMzLhIAbNnq8BZ7Aqhbj2QF9rc9tx9ByLsd/m1pyzUzat22IDFkGUrguqM7BAK183+rs6/vBMQNOqeI5TTD7VIAK06B6Dlri03300PRBM+cZjZtvpMsehB6s9tnOnw2UnFTLYZ7ZSdqnAiw5VvlnmYfoXtHGGbruaeD8Lo3eHPMeuj9BB0s0Xy9/w13Oor8M3Px/hRBO3QrukzBCxxchTDzss4iyrW7BquceTR5FPPSM0esQINks6fd3XOOPxcSP+3zZoSgjgwEY5FcFv8xPnkGNKbU6K/NxYNK834IqX/TOhWRggjJWtOwTdtzIeoklxD+T5uxTm1afS4NjYvZH+Txwja6H8i1LzzlfQxeJYu4Djz5xbLgUkoOh6879fCT2YDDwayEO8RNi8tCAuCpXEFrBDKW7Xw1GHbgHxWLJcvySMo3EyeUmaN2rifD6/OXsIoMDVwom5+YIV1xaeFVI7GquzAtW/MEJJMT366/iBiTCm9RES9D3xFgeWFj2sT/lTFO5ssi+5zTS0NSPKFpIXWwK28U0e9CgUWw7DUwc48KpzxAL3JFEtcfVXULmLU5r7Y5MFAOF2VOdRl+JQ7iLIfF848UnbBOOhl683BlSQYgErjHaXllHDPWbRmkAKnKbZ/J50FEUuPnZ4pIhyZ8sqRuE4KXA/vet8cpe57QUJTdXGSfzjWDvrBAlrqeJqZztYseFdXFANv7kjGMVOZQyD5b94r9Xf8XUPDuusj5cEnX8ufu0ZfA5RDlgenFct4Hdd+CmTuE857YfYkDB9twRHgDRaD0GLvlpKeKPaJgQ2inE9895vQW3wNiTmPdfQa9MNaZaVS1NsL2LH5FiGrg0z65/6Qx7GQaMu5jzvdX7YyVDVrQFEembeX7/lzn7AjzaGQtllXGSicfwhO5QDn6mbPX3CI6XGRggud6ytX4yBMssSemw1//+zryGnJPrN9mN84OQkfSpP1jtyzy5t0Q+Cvg51nVp3S5JYxYI/X3FG6IDABaVCag3VyN9tAZxbkONUGGtV2CkyEQPvzRr7nn1rHxvFmgx8CiAcoP2kC9B2inbdzmfAdBrvoufWyJJnK3zVxqRDEOR1UfJHE6UY1WmOvJDkLpCsntQZXDSZ6z7tNEiZ9OeBh4Xf1TkmuwhEOVzMaUF5TfWxNBply0jdjEwTQx0dl2rg/URqxvDKPN8PThra7IDafP8xu46dL+0JIiqjNTAHpHwYgRDxkDoUMR/h7f/CZdR4ZAaG5UhAonJZVAbHmU22gN5rFxqe+49I7NVYR1Vn+eCgyYEIyNMxwmDEnvaPYyEJ0csOkMZucWGGRMFP1L7mccIeWfLwoyzp/44akNKP1VLCauu3RrIqlEkg1OpwUpls79/UlRfnCWTctSdr65sjpu2j98vR31TovyX1HCiT8CX+SwnCQo4TVexpBlfOaU1yNSrt2IlqFq5q//dvKfRDUl9tyfNeBS/TeInokcXQHj8IYlsCkZDFaYgDsIA1YuQc34WyqiF+zh9uc2mVOzk3pQSwcIOYHvz6oGAACGDwAAUEsDBAoACQAAAOp6a0iluUKmMQAAACUAAAAtABwAODlkZTNhNWM2NGYzYzQzMjg0NjMyMTc1YTk2YTlmYzYuZmlsZW5hbWUudHh0VVQJAAPo4uJW6OLiVnV4CwABBCEAAAAEIQAAAGlhR6/AKBohN0vn6t7wC3r1o6HLbeNN1g9sxlmD3Qzxd5yF3VVyUrSVBUYg/L6qQFtQSwcIpblCpjEAAAAlAAAAUEsBAh4DFAAJAAgA6nprSDmB78+qBgAAhg8AACAAGAAAAAAAAQAAAKSBAAAAADg5ZGUzYTVjNjRmM2M0MzI4NDYzMjE3NWE5NmE5ZmM2VVQFAAPo4uJWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAA6nprSKW5QqYxAAAAJQAAAC0AGAAAAAAAAQAAAKSBFAcAADg5ZGUzYTVjNjRmM2M0MzI4NDYzMjE3NWE5NmE5ZmM2LmZpbGVuYW1lLnR4dFVUBQAD6OLiVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAAC8BwAAAAA=' AND file:name = 'Post_Shipment_Case_id00-872879018#.js' AND file:hashes.MD5 = '89de3a5c64f3c43284632175a96a9fc6' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:20Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e8-7d60-4215-bf9d-41a9950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:20.000Z",
"modified": "2016-03-11T15:23:20.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'Post_Shipment_Case_id00-872879018#.js' AND file:hashes.SHA1 = '416f03b1c838248b42c6ca09905e2c70cf6dbe8c']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:20Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2e9-f314-4fac-b5a0-4e0d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:21.000Z",
"modified": "2016-03-11T15:23:21.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'Post_Shipment_Case_id00-872879018#.js' AND file:hashes.SHA256 = '8df68a892f75722da88f2634551d8adec138b7d34a1a4ad2b992c180ef1f6307']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:21Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2ea-74e4-42be-bf82-4e3d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:22.000Z",
"modified": "2016-03-11T15:23:22.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOt6a0iPWctkvwYAAPAPAAAgABwAZWZlNzYyOTI5MzRmYmY3Y2Y1ZTVjOTVlMDgyZDM3NzJVVAkAA+ri4lbq4uJWdXgLAAEEIQAAAAQhAAAAlkbbsqRG01VOMVy/XDBTzsNEnW/Nh4P5mBBKsM6lfn+UmDqGxbtUZOule+vonNuM6S5DIFuUw2hGpZK4Fqs35MiIco3ngVFHnq6pA7vXNUQec77FP7AUHbpeRjMEDvB4dey5XTbCBN/6uPysqW84Yf/1vSI+1MwkJOLOmdsepDAGOlham2qKC/DVuo+CvDXiHba5Z3M21Jyvzsncyb9noM6EfwB3a4qDeM8oXgHHmN2F4K1uHq7JrqULlQpEspXr9zlLLpMud3BqTOrhhDLKqv+yvm1dX4Rcx13QvEcCxUssSPhZaQnmwBHTB4zjBvTmbQhL7KtK+eYumkP4n2JOUNd/SexInsVTwzCE1sKMT1Y78sioJcHqsvfs1vS2mKBRRNW5FLPCFAK4B21q6lXEA22px6+2MaZtRJtCRZVIF0V0+RwCzOuPhewZn05heRIakFljUAoX3D6PAdSHTlirXxL5U15D9v9krVXPQP6froFugK8UBP98alt+e/TjYSCUUSN2UzsZcTcAqPr7lUhfWjpiRSyXz9Yxs1AKajZB85M14jiJGBXUWp1k9GQjMNTlD6pQYF+DcomCEIsM8GPzb1wjCMW+pQoTI2TN0kK6s5qlcS8oJcyKRazopWJAE9ubKmUZl9LNe95RbuV6Zuh+w1NW3orfThlRegtlY0xtfxjF393KBSo8t6UikvPHyw3pkoP3uNEL8B6vc8WcUdRjl90Awg0smK9qchLwauNr6R8IKGsHfj1TNUHi+RJuP0KX1c0EuYRBTeiBGKQ6oDD45iDNQHJzOd8MXv/ZWWDtRx/Ov/beoqRcSzulc4+1wTK0VvMhbyoR4RGyIGPNEJdKqZSFRt/kTjAkLlFtUCfBzlp7kpwbiRdFK3MHXH5VL8E2h2eVRUREv1oJrk9KzWY0q3UU/IVSbfSIqlEeC4jWptoOwvLJsl2Upswvzu2uqF/w+FOZXfw6jjiCU23Li0/twUGI0vUXwOF2Df5+IJiynGzFeOS+1MjnIFNU+tdpKdXpQ2wAU8GXntac+EF6hrLb21AWguZXl1VoDFQuOIyYosTuAJT0oA0BpGoZFgcEBFVxIazdRMFJR0WYjONrfWCVIrXMk4weFcxkLt0KsmK1C/dxlQ2Ij8h4xPOtUBRCcVDkIHTciM2HZ/P3G7WhMZC5s6gvGyLL4GM5wZvIaw3yUyaNddsXYWXize9bpJ/M3gf9dEBmZoPlhtgRpdJuRQx97RvKIbk8O+w6WfvhZ+B1yv0feM+I4rZWiD37/I/tXCMVhlWRVVWOEq1bEGMjknOfne5lNCMZS9R2l+7BcUr/TjTzUMxilu7DYTjhaLIeJQN/4PyPmg75wmwXAajBFPET2lLPZweBt561mrEVnKPnKPeLX/i9b82B7ohy4f1x0TdiKFi2pxnCYADLmEK878CV4EDWv0ZM0G88FxBdqeiyyQhTfFdEo94bxo+pVmy8sKaxWLimFiBqVJpLu0pHPvW+2yG1+fA72IE3YT/j0WDADXXRkqwEMymQpHILklut93evIJ3Z1Ve8i4geit0tepCX7ZhatrSoq0eO6LVZk2OOm4bz6hyNEOAoNOvt3nhjLC9EIBkxeyvGPzpBKPRB+E/gqygMmR2uyoPxXhTv+wrXqjDZCPFbWneLDhRDJFD0w+P3bZziittc/BG0uA5uZuyw9AS29tOH2DK3Bbw1eRMejGsm7cEzbEBFewhjybDKHFcAn1Tzf7MmuhvT2XZ3oKuN47H9I03jVTe7lehTfyMFXucPCQAPa9lTz/g7DxrMr06epdOm1DKjS5DDCWOAvaDr1HfRHiFwKl5i945ExhdqGKMvWR4s+csV6FKIVK976sTbrZakdqZ8EFCH11lmsxZ2K1Z5HIlRZnngp6L53JxUeeYbqgelLAKfW3dG96p+q4NU/MDPbD8Ce5AOvhrlAP08URuZ37TmEb0jW7fGdyDeEATcWowaqoa24B8XyRmnP/U2B9UY6L4x7TX7yKc+cAn9v/rlYZ1PrzaYupW7slT2j6lyzCVRaPaypLMNoeKLOyeKEUHVjLpwEnAXlT72Ls2t9NLX4rTTxKh3H08vWPYJxjswCyXDOOifopdVqZ7TrrBHERX1NtJzX5eh6bau6NEzrT92IfX8U2ppnQKaJrPXeIEvjDT2Tj/A8QR6fjKajVRbP+V8GzcrimFYUvoiqx8MvGMaT048HSfm/J8ZC23S20BjfoZvG/AiuC2lMFizInGDH7J8N8DHfN1zwCoHm6Q3eyvNFYPdySCS+Jlh84dI21T1/Cxwgy3hCbQwhpVW3TpQSwcIj1nLZL8GAADwDwAAUEsDBAoACQAAAOt6a0j82IQrMQAAACUAAAAtABwAZWZlNzYyOTI5MzRmYmY3Y2Y1ZTVjOTVlMDgyZDM3NzIuZmlsZW5hbWUudHh0VVQJAAPq4uJW6uLiVnV4CwABBCEAAAAEIQAAAGlhR6/AKBohN0vmDWd/+YJgrsYo9b/cexJa2muom3/kJKz2fRMnZkSHcQAyiS5QNPtQSwcI/NiEKzEAAAAlAAAAUEsBAh4DFAAJAAgA63prSI9Zy2S/BgAA8A8AACAAGAAAAAAAAQAAAKSBAAAAAGVmZTc2MjkyOTM0ZmJmN2NmNWU1Yzk1ZTA4MmQzNzcyVVQFAAPq4uJWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAA63prSPzYhCsxAAAAJQAAAC0AGAAAAAAAAQAAAKSBKQcAAGVmZTc2MjkyOTM0ZmJmN2NmNWU1Yzk1ZTA4MmQzNzcyLmZpbGVuYW1lLnR4dFVUBQAD6uLiVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAADRBwAAAAA=' AND file:name = 'Post_Tracking_Case_id00-669928694#.js' AND file:hashes.MD5 = 'efe76292934fbf7cf5e5c95e082d3772' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:22Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2ea-fe64-4704-b7f6-40c4950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:22.000Z",
"modified": "2016-03-11T15:23:22.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'Post_Tracking_Case_id00-669928694#.js' AND file:hashes.SHA1 = 'db717342051f4af5852b1fa289f40e4dbf724d1f']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:22Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2eb-e60c-4d85-85e6-40c2950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:23.000Z",
"modified": "2016-03-11T15:23:23.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'Post_Tracking_Case_id00-669928694#.js' AND file:hashes.SHA256 = 'abd224981a03fe7d254c7f0c4ac4411f0f23238a7c7d43fa22e650fdc09e6497']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:23Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2ec-a794-4820-b42c-4caa950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:24.000Z",
"modified": "2016-03-11T15:23:24.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAOx6a0hEFzn/fQcAALoRAAAgABwANzIzNzkxZDQ4NjNiZWE0MTRlNDMwMzVmMTk5OGNjMzhVVAkAA+zi4lbs4uJWdXgLAAEEIQAAAAQhAAAAlkbbsqRG01VOMVv80tsxuzmszK+SKgOgd+meRoMZBAk4QKNsAn2RSnXQr2aiEquFr4tqJ+lC8g5Ei7KiZ7caqrKcMOTd9t6GA+XyveHZWHjOq44L3mucgiWx1MHOr/ajGTEHEKdB6CMHSK9pPVsPKanS2pgvfhIiJJAd2wsxuTOeu9PIIc3TS3sbVUwu1HCPPzlQowHLui/lEGtMa5ossf11gYSNWFU5KODjkj5FgyrWrXdxbSB5SlG9esQlqlaF3usWuFgBeqKk2ZJvGe9oieGA1znrXkeaiQ1lb83tEVxjP9An3wl/YEAfc0AFUp+POBFCEAvtrXcSnwATPDjucKNkWjVXYpMAfdkPpRNJgHRI0LnhGleWwas45iQnbo0YoC9BO8kOhGxmMLaMydX5SXs/+hr86EckRmeWnm9ATjOq2NSBm8FlQXYyy1kWKFERs65iMMTdFF5qBFpmTv00SIjqWSU6X0D0lpC24PsC/LpEuhIzFDQqrcqb27uEiN4u+BCNQ8983LLoTRivPDQWdyENQw9BxWpFRnmE56ss06RQgDjkKSoqOy6LLNZ7X/E9ffk/fuJHzSgvYjuRt4zkscMiZhNxf3+fzPl8dv+SterhMfe6OUF6G46qeoBcpoLvPeXbnE+UoaLL3xxnLLw0D47ukXl12HsdE+ae1Kyl8p9UigjnHXehilKTgaTYdwpfeZyTDXx7oS+UhzQQTWYVSmt3rg3QqP5qgr+EETapO33g/WZsan9zq5uuzRA838tQAuEc0UAY6jufB8fofgOmr/ZohOUWt5KBFC/LjEY6LgnvlcWjbBSq8XehmVBlkOtIV6jEdr7F55hetGC39kOXcTlYBCEJYW0Co+NOBNbH05JLjd746A22ptIp2Z0oFfL0XSBzv/ltA37oG9ZkomFzJ4799YlCmRtBettyH5ZNX1EggApOFy+TKLQseVW9RGTS5UBoa1spNsjxWZCcDUTECXr3qkjCTwkOrxuLUnwk1FmktiDJEOQrFY8Gxhr4mXJVz41qkuogc0wwZXTqFlHPHWhDdxIJz/QjuCM0UDmVqty/BrBE7f414iIE08M7aOmwansKVj6U/NDGaDhRkzBvkSzqMYClzXsXg8i8BI7gPgN8NN+jn0ZMjjo3nlXI8QQVwp0rLpGNstsRdot52dRRikpN6UuZ+dqp6Pj7zBvyWFwLGrIQO5RM82eDpYXlb+I+at7AX3gnQmZD66OjznEyzJ7c9Y/0oocJY9EVr0wJ/WNRe0NZ6B4tVaQJTFUrZjh3fE5bMha4VxMXiUfOXyPz5e8RFkgofBKcb6I2TzZ7BF7ikAK/RPUuinbhDKKvPM+HMb9F2QMo947L169QNqHAOJ/M2RJ/PokY+QecjzMQ4RJuYZmKKpJS1JHa47/q+dnCevPqT406LtaHuBS+V9oXg/aHJyn5MVuO7MZ/mKyKJgaYAy37az/ELRKXeXjFPbCWhw7cZVUenHWgjC7+/on245dkKtTgqcA1lniEUAj/d2QoTWla9weMZaVtvy/x5ptDvvM9a4CEvL7niSFschS5qCbFdbttRRgWRsdM1ItzLgoKZe89ZIwbguIuDryB6z/WXPkt3J1ND8pOK5GV4WHzy3cm22omTdL+KXV1hzV8VxYfS5AiK3RZ4I2aLuaNQ8a72mg/zUJjdfIBpDLVZNecJ/L+4yE/fm8n1sR5j/s8hixt3UAM6HY0B5NVINh0J/KIMUL9awWvy3eg7pR6rg1BnWFCQtVlbvmON9Ep7eiCgMDdk0mbhHJ/leTy/nA9aynAvge66AIXs+A/UdpUSl9b6vA2t2Ynuh3NTDPMi8m574WoHRJudRjGsZ+vgVIo3fhQYSIZT3fGp2JXtncJ61g1hZC4jOZx7geYDqdYcCUoXWZrKDfC78GX2QmdJNMAqATLZtj90wj60ctUEcfKGxazB101YPwG0IRRzJ4NXGGqsVYAjxcQjGtH5LKt3NTgdg3TsjjmUnyfXbequ/mXZKDVq1As0NmvBPA187IEibVHAbSkg8Cnu3QLg2KRxiG5hUNcvr9lf/Kumv60tKASVmTHf7EykT1LYUKdxV3Xj8LSQhbBAQPG2C/2hMUsq2tpXAt/yjjJ66w8bSd1aRwhJoXwq2McADkhGPQ9g42qSC+0Ctd1/Wbbh6xGx36A8yjhqXOJWE8Zjdl3WBc0S4ZT0Vs3xqw45rDTF1NdModwUbXb7XjQSP52u/x1U1Nk1QpYxm5Z2bXgdUlyi5LFnmaB5kl7lPYWa8FUPLlvKXaRr7nYf/ufEJ2SvwDr4VtOaqs7uHRlqp3TyodmQ3uGfRzJNF980txadPuQD29G5MkdMk5CsI0PtEXbvv9tFx6QX/wpzqMijGHI3spS+4/GyyfmKN8MwBOBs1yPohqo+msijb6mXlQZUIy6Rpz0XtSg2fAkLph/ndA4ApvU8THyRJB1g0Zc2sJf/TPDz5D7++6esOyJdXyyAX9PAx9J7cle+9XjwErXzsCOm22YDJFpncFZnvQfOJPaX99Z7BxlRzLx5cj5gL6bRxAPf0+ojxuakQUYUEsHCEQXOf99BwAAuhEAAFBLAwQKAAkAAADsemtI4xm3lzEAAAAlAAAALQAcADcyMzc5MWQ0ODYzYmVhNDE0ZTQzMDM1ZjE5OThjYzM4LmZpbGVuYW1lLnR4dFVUCQAD7OLiVuzi4lZ1eAsAAQQhAAAABCEAAABpYUevwCgaITdL4ff6SQXcWDghI4TNTDdWL4Gy/bQqcdKnhMPG5I65Fkxyf73BSprBUEsHCOMZt5cxAAAAJQAAAFBLAQIeAxQACQAIAOx6a0hEFzn/fQcAALoRAAAgABgAAAAAAAEAAACkgQAAAAA3MjM3OTFkNDg2M2JlYTQxNGU0MzAzNWYxOTk4Y2MzOFVUBQAD7OLiVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAOx6a0jjGbeXMQAAACUAAAAtABgAAAAAAAEAAACkgecHAAA3MjM3OTFkNDg2M2JlYTQxNGU0MzAzNWYxOTk4Y2MzOC5maWxlbmFtZS50eHRVVAUAA+zi4lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAjwgAAAAA' AND file:name = 'Post_Tracking_Case_id00-670423294#.js' AND file:hashes.MD5 = '723791d4863bea414e43035f1998cc38' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:24Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2ed-b874-4cf2-8cb4-4f6d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:25.000Z",
"modified": "2016-03-11T15:23:25.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'Post_Tracking_Case_id00-670423294#.js' AND file:hashes.SHA1 = '0acb215872d8796c11c859c2f2cb6bfb3337bb0b']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:25Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2ed-c398-4414-aee0-40d8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:25.000Z",
"modified": "2016-03-11T15:23:25.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'Post_Tracking_Case_id00-670423294#.js' AND file:hashes.SHA256 = '11e8df42ed046221c90d81b93daeb46dd209abe35dee9048218f9f1ebd5275fd']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:25Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2ee-0d40-4330-9104-4174950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:26.000Z",
"modified": "2016-03-11T15:23:26.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAO16a0gM8oOUaAcAAAkRAAAgABwAMjJmZjUyMWI1YTg0NTFiZjE1MzBiZDBiZmQzZTdhOGJVVAkAA+7i4lbu4uJWdXgLAAEEIQAAAAQhAAAAlkbbsqRG01VOMVoO85LnJs5dk/9Fsl/2R1k+NHz4gy6XQFX9n11ZZinJNiaLUD791YX1yu2d6bd7MOn7m99k0InhsIRQvDEZGAfSA8HJrPPetJABkvXvLZkRKkz9gMhuJ+QJYfPqdQIgJO08xClGISSJOJe30JYewfKV9ZdD8E3XJ7zF2+L+5ntERRzGSBJYul0JRYo1GmOTKWiXgUZ1rexTx2YqHdWtuPgFZRkkopLQh6OAt94S0yulzoOOfk1GmuRZiBP0OUTNZ/kovlU9Fa8mnKMuTx9nemk+st0W0ppzmnljq4DW7mKtrx2VnU7bldWHDenNdkTWQRqCiavU8Qz0dMNww5UUqxWm/scLl9xCbERIN8S+6fKW7e9tdw4rpeZgJTF/2mBYAUV6KZgSRbkKE5LxvtIon0L8HEFsqvYsquuAk+85aoUuTj8vZdZY9iJ3IqM2vzJl59eihSCrTDbdj9BgzcYaHw3/ejuQ4dmJdwaOeGhXeVzC6KL74RrZofiy0z/XU48QBP4tltKw6xJSauNUD/noIOX92GWr5tfqaAa/OPgTB7jgYJVqArhbIt9nNvs7fIsDCYnTN7PK506E+ToR9MM5HheXOCriImcB0W8T8ajuvdwOk7z/0Z2/IrFei+a3DYt7HLkewXTFnhJ1zVcnuKgf0U6TrMhDH5Dw3EWEs8p1rRQ8lUZZ3iopxNUhmGPQCUHjqL8lHBzkHgsOZ6rGEOSi8tkw2qH9lSeNBuGNfwI7afbcbdXtUUF0dQFsDWkawWvlG8yi5o+IGKbUF4+GludTI63EwBhPaC+a5OJX2XN3CXBJcRpQHoAmypnn6/0Xm0aRTi6lP7aRiIdeS47cN2JMgq/SJXjAdLHgFgmETeFi47U7tlJ8eydvlmBX2KQbOZ96Spb8zJ+aalF0m/3/OypaOOC2Z47KGnetMAA51bt5nKqfIniHXlPTiSlzdexCzeKEDkcMKO5U5jUiUMnwursaQZUcOZg2Snlt8qpdCgGOeK8TYQTr3+K1AsKLKQ0BpamXn9Kd4IP9VlxNSBg4WQQYIqjvmiAsx8H/auBJNPNQGMCCcoICbJkKrUE0D5KxpUng42dawsONW+gmtNTdszBHf/prSzmIkjH0IpbQ2eklKVyuYn7f5jCo+nOgtAaLP7axAEupS0VTmMNZu7OC3QeEOAbJZE//qdexIukN1Civtma7bQoOWzYIxiOVMhDjvbmoVhjitkV3/h4Y3J3xcb3AwyKrAmOjDBaNd+NXaomLFnc1qsA7HiFcmB35XgOB5K99iy7bdfHTPyDhmTuW0ShAWJSHU2fAheE57tKii9CA44pzMCNp+dLsmjDSu4KSR1ICtnxj+DAIRok+PfWrR3ohhNaJBmwmb86JYpEgxXdPibh3F2kNiaIxgGwkOHkoeP5SAil+W48CLjKM9z9C+jvtUktYxm1/ogCUYdMuRk6D+9U+Z8lQYkoT4tNT1WvCpYvhaf3kioO19fiQw+0uB5JZh3wwzGjEsOmUHbg7QViAdcBWR/LdP7vbUCMmvok0+73wlAVc3aOIwTgpERG6jKwEPI+6XBZVsEH97TuOhJtNN4IvRfXhNLjDpPR8CMF4+qOJUx3z9T56hCv5QFrz89XbfCiXSgJjL/mErF5T0hUalPnI8BfyoPtrP3rE3V4Q0hAo/cqvPoOaHaCusvf5xRB/KpihVb77Z6lnf7w+LADFEQrE7/ESPbdQEW7rmz6t2AqDcNElV7S0cVQf7qsRfALsZNXAhyTF5aXNwHm4TCef5aROosVYXpPBRYw5lr0q0FTWcVdfHDoISYJakUcwv6q0KYp1zxDbGTNnAjvG5E8+aTTtVYYHiLjSrqwweV0bEJHlP4xMdGoLw3XJZzlUxUM6cCkQlh7MOaUgY6ji9WkrrwMZoMx647EGas0mYZYIJgE/45v858vRBfPJKPWivIMLiqvhYLrlPT3LPyMsuIcoph6rAwqTi3z4Ie3fVhtMoQXoOybpwlBJtVdq+Qzi01mPM/cwpBT9ScVVSfMmX/c4aabfbBVHm67tGNy1kjiFXlBektKbywcOVaGXGp8HgqpZnSRwSN/T6Msi4o8LE3BpAZ0YWm2DwoL885tANbiHm+kta0J97t02FMWjHePdWXXZXPGifncw+6XAmx3WWPGhY0zEe0MQ9ERDrUIx7Wjb445s8+eMLTrdA8FFkVGtx2N7ZN8+8dsPedgThUEHstAjR0JffJGX//n0fKNGUN96Rmr7dEpAV4Qi3+Oq4Mu87MAAWiCjyAqS1K4IAyB0L/7XVnZJiOPUSkbGR+pn7KnBhpf0suPCecqA2sVZuqdGPwKxN9uhWbPAnHnh/lAlnK++Xvrx0P/yN/RWH0jz4zMTAE994NZH91IDQdMhiWu9Gw/t32PBTlj1GZtid63R8wFJcLtAUFIBCK/0QYrjxhSMm2Wz/NqErRRtowufZQGB1ipnSmKrQFQLu5eOKdgLx1ca8MYMPUhWmOYqZAyeVeQI25JZNruTKz8aipq6Cx1Rue06UEsHCAzyg5RoBwAACREAAFBLAwQKAAkAAADtemtINftRExoAAAAOAAAALQAcADIyZmY1MjFiNWE4NDUxYmYxNTMwYmQwYmZkM2U3YThiLmZpbGVuYW1lLnR4dFVUCQAD7uLiVu7i4lZ1eAsAAQQhAAAABCEAAABpYUevwCgaITdL4E6hsjujfchleu1OAGCXf1BLBwg1+1ETGgAAAA4AAABQSwECHgMUAAkACADtemtIDPKDlGgHAAAJEQAAIAAYAAAAAAABAAAApIEAAAAAMjJmZjUyMWI1YTg0NTFiZjE1MzBiZDBiZmQzZTdhOGJVVAUAA+7i4lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAADtemtINftRExoAAAAOAAAALQAYAAAAAAABAAAApIHSBwAAMjJmZjUyMWI1YTg0NTFiZjE1MzBiZDBiZmQzZTdhOGIuZmlsZW5hbWUudHh0VVQFAAPu4uJWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAGMIAAAAAA==' AND file:name = 'q.076022356.js' AND file:hashes.MD5 = '22ff521b5a8451bf1530bd0bfd3e7a8b' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:26Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2ef-2ed8-49ab-8edf-4790950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:27.000Z",
"modified": "2016-03-11T15:23:27.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'q.076022356.js' AND file:hashes.SHA1 = '90af44af367c811f42755b7da1679167e5bced44']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:27Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2ef-93f0-4b5c-a152-4468950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:27.000Z",
"modified": "2016-03-11T15:23:27.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'q.076022356.js' AND file:hashes.SHA256 = 'a52738b57d91f92f70f7a24a65673182ed250de11c964383bf0c8095ff0a588a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:27Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2f0-bce4-461b-8ba4-4225950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:28.000Z",
"modified": "2016-03-11T15:23:28.000Z",
"description": "unique .js file",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAO56a0gb3ub2KAcAAA0RAAAgABwAZjY5YTM2ZWNjYTRlYmZkNzdiMTk1ZGY1NTRjOTZmYjdVVAkAA/Di4lbw4uJWdXgLAAEEIQAAAAQhAAAAlkbbsqRG01VOMVmA7aq7SrNhDjRptHOfj+yif3i2p53o+Lcg4KXRVq5PnXXB8jymq6kbF1PMzWylcVQBzF4q3iA/W2GAcgkRlRJzyWy5sWBzEzk9E+XSescnoP6Fgw0pOIN50TKyDzzhjBt4l6hWzolnl2qIyTYQOqHOKHYoeIf27pzkgBH0su098yznkBFj/ZYYvYY9HRflR/BikU3kvDEQbPLeHphj1HxFYMWPauBMV37gcxfdKt6gioVLJd0wJJ2ioQzQEi3e+lQa/R0wkoA4qtQ05XRHWMp++5jDYthRAUUDlD8HaCfITZ3V/IfGqyqIs48Qr7j6R6cmGpF84IB0bY/P/MioIwAPS22foa5JtFVhEfGmSwf/ivCvgylQsPHMswL51bTsi392aRkEFOPSSjHy5tq0CkYJml4JRroi01jnIGXg8OkfF08+bekXyMurxpCuCbHEaTM4cu21WK7Nqonzkhssl/WcOon/bKtzti0rafr28vGXKV8KOWjq3+2dHQ1S3PWOVstWzItpg7TCF7b4qpB5Pa4hLz7kcU88LRmnodvaD/RsPf5YrfsQHIbHr6ZB1HeyOf0i/eSqvvMSsmmMCs1XsjaEAla43HG8IoZeH33XhxWnvybG5wJtFmz+W6kRzFwot/g5UcqbdK1d833A/h/iWWpOe+E7dw+opt5syauHiX36YcE++oLI8A2GvSqrxYgkH2Z6dYxUq9I49y/nU5OJowSxLb5wm12qQtELbOfp3dQq2peSYHMnb3GyHXxpHZIUgLMDperCRgLjFMLrmJC6KPFHlrebDUpBE8K1oRSo9hf4FE8zANrCnerOHn00tWHYV/9iFcop446BArCpu4/JcgdVTEEmftxplyyKX3mLH8v5tgIXc8c1cRZtwF7gz7LHYBpL4HvrIYdJyq3iQLcCyl7Nb2uRtffyUeGZpFy8PPMI78hqWYifh36zS0kGTTHZEa7nggutl7b/pzh8YZYT2brQ5uY6OHzETth+o8/7MSpVVoPdXKBDNL8orSzFRJlsw7OrqJTUMpo5FpJrb5BYxlNxueDi3UtPrUNaeSluLnDdj26jEahwwFMq2zyzkwMzAoON6LjqmNCp0kRDq9u5+58xuGuIQlr6AtgND7ZpIu9xEdk/PgwL3oktwot3uaSg5T3I/8eLJZgsqFe+BVEJ8REr3b9Fy4hA5UjmnV5c7aKiSx3AQOxEHU6Z/AP5z5s375N44rZmUxjBt8oTcCtSV7BliRKcLEgcSUngO6cnhKt3u5a0uvTV6hKpAkBISwJ4EOAxgoE4Zp9PKQPZqLJ6J6QSzJsuRQMRqBUbma0CGkKTpp9nK4xAAQcPMYAhB9WW2EeNixshhekKSVkBHwR1sHsQrvOAyktuBWAQFWw02CLnKWmPkq2okC3H9RnKaCxOGGXvJMRhhfB4EEVElH0pUoiMJ3chHqno5wnC0u9YLyR1Yf3RpquO+PpthrNoxJ6SndKjHaMs/UC3GUD6HOcxXoIBmpbrkjCSE65Dm55EF2EryAZTfO0tonZPIGj3MSrCBHX3TapGCS6ZHHo+ZASihrGnDRKtmy1Bah1Mat/LoyWFfFx30gtA9tL2//Ho4Qdf02vw0/mAha9FdHYTGaltlDKTW7Bak0ASlDByMVxUCWQSppjhRHtI1wSB/PZrNuWTrxuemObYiLITuSaypBxclLkXdsDrkUN6m+sKpp/dih5ceW/+OFTXb3WQ2sqFGdUhx1eBYL84P4loIFregU5p4ZC6vCf69N+DBVDc2lf+4vwNAvHJteXCccNS+PMnqGzwWWa40QaoGCr7YsC3rO+OgOA4T/YfRarYlHSCEFLJKaRywmJm+mdjb4L1TbvRVcBuW9mCl8bR4qhDTJdBqpIUTb6J6N9QD0u4gLF+vPJ/yNQhl43nR0nManwQodRnP2Skk/+77O82fM+zi+mjXGErGNBI4Zsu7VsL2+Ej1dci+K/jlj7XgIRp/tcpr7MXjK9ZwIMR/DS75c2GByDjEqGhCHqiekvS0WK9dAfkTLwzdsILw1C/3paTAEEYpX/Ta3aEw4YN549zVuap2XcgTM+ky7NEbAmHNKqDiEJApj9urJGbULM7zKkIhngPJdIoPCFbVkXUi6Tx4u4UeBfxOHJYGQfPiI15lRdejMEIqNuFVh2/pc0tmsx8dajLhCxbf9LUcoPJJEVaZ9wvkv/x1vnlxFiQiUSVwc1BIgl+JcN+yRQlCR1MLSJKeY0wLnrUMf85fLliBetbmDZhueS95vFqga4fN/lro8BHkc55OgxgFKn2mK8qVV3twmnJDNCEZpBW61Nc2470+Yc9lPwAXkU6mXkMA8B91HabnKcvkGo6ROBTQCoicNDqI7O0HheLlNn3fd0pJRTn2UD5tJwoBJBImotfBuEa+gT1sQdN0EF2VMdBbgfkakAi9cTKuObuDNJQSwcIG97m9igHAAANEQAAUEsDBAoACQAAAO56a0gBSdmaGgAAAA4AAAAtABwAZjY5YTM2ZWNjYTRlYmZkNzdiMTk1ZGY1NTRjOTZmYjcuZmlsZW5hbWUudHh0VVQJAAPw4uJW8OLiVnV4CwABBCEAAAAEIQAAAGlhR6/AKBohN0vjDMBqP8XhXckGDg5cQsZuUEsHCAFJ2ZoaAAAADgAAAFBLAQIeAxQACQAIAO56a0gb3ub2KAcAAA0RAAAgABgAAAAAAAEAAACkgQAAAABmNjlhMzZlY2NhNGViZmQ3N2IxOTVkZjU1NGM5NmZiN1VUBQAD8OLiVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAO56a0gBSdmaGgAAAA4AAAAtABgAAAAAAAEAAACkgZIHAABmNjlhMzZlY2NhNGViZmQ3N2IxOTVkZjU1NGM5NmZiNy5maWxlbmFtZS50eHRVVAUAA/Di4lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAIwgAAAAA' AND file:name = 'q.522501656.js' AND file:hashes.MD5 = 'f69a36ecca4ebfd77b195df554c96fb7' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:28Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2f1-4c4c-4617-918f-462e950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:29.000Z",
"modified": "2016-03-11T15:23:29.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'q.522501656.js' AND file:hashes.SHA1 = 'd532294db70ee1dabf923f1494085aac8212818c']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:29Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e2f1-ef5c-4882-bbcd-4545950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:23:29.000Z",
"modified": "2016-03-11T15:23:29.000Z",
"description": "unique .js file",
"pattern": "[file:name = 'q.522501656.js' AND file:hashes.SHA256 = 'ade66be0355a4ea01f4a84241726f337a86be41da8b86348d04e68a99da74529']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:23:29Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4de-52b0-43e6-bc64-4ed4950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:42.000Z",
"modified": "2016-03-11T15:31:42.000Z",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPV7a0hY4cbr9N0BAAA2AwAgABwAMzBjOGY3YmZhYjNmZGNkZGI3ODY1YmFlNDhjZTA4ZTFVVAkAA97k4lbe5OJWdXgLAAEEIQAAAAQhAAAA1eqEm4wVyRjcWulMWCk0axlVLPCjx5hbLqY+SezxBHshZwQSScpaAoJ08bvSYMQ1NXbzkuP9yEbrW3wLPF24kd7+LrEp6s8yn0OqBHsJQ1wJzT1kJsJGyi6ZFYn80JoCkoFS02lxbOzFH2N5PqYjnsdqkFiFr4i5x2ax8PROLadRwBAd9E+pRbIhWhYxdSiLio+jVsEPLfreOIFSBJiGFw6jqvWloY3ejZmdhRI+lxaak5jl11ag4CwbAV6MYtDhU7kIkZiCTrdrUYpZ9rk8/3XL9Ba/DP0FvDRkCVs0DbHCfdzhEel7LeY11VHFvkFfMA1RWrKFChiJXJOysdZim9TMdS9kNLetpIrQgVhlxBTbFd+R+CHdWCDJyAMEmjoUZoElrh6NP5nirsP/4hXasm9HOy4PuTT3cFbKGg+ajGr8e7VVtpXXa2RuV8ZcNz0MjIrWSQFFcNfoY28JO5PN4T0o3N8BnkDk9IUYg2swP3YptPZV1gs1GqLt9Rgh3yRA3gYHxb0Gdx37efKxm2G1w/YCbtEIE7Mrl3p/n/yosekZNLd3JBI5rJ3C75TYl32L26/wbzCL2wHkC90V97PYJCy+Uv1ilwlXM3hAje6eRQG4QGkqL+UArq2lGsKIM/izNj9e8gzavyBtrLPd5Oy0EMCKgpK3Ol6Cp0p6b0T99dN4JZpnGhSrLsOeNb2RfP5IE/O7rwabm5LX7zJTiGj1NETObM9V62Fk7q6vVq644QkNp2NKj1u8Tz+47Xh0kNECxijH08OwvhK2TPlN4FtVebGwabKrxHQeq3lSOTQ8uGMfNVqklmtwaA+fRSL2fSy8z/r049occziowo57Wtc+hLNoaU5yXAq9EcNCGoLbAVpPlbyL17NtAj8ZucRqv3UPSn7evtkdDfseTXNIcM5GUIB3dKWDvfvsxPefPerRdwOsv16Bw2wr+rhhxR0FhDb+jn9rkcT6jRnjoatUVJ/ntPIyuoZoyuXwAJa5YM73dCPODL21kz3s/CoPixcKVuDw21KaBhnmDsRoqeQgCpyN9HkXaB0KTaVXpCEAQ7yBTeoqMGRetj6mNBynEch00XDUQAonNvmgzRHOWiSu6vwJe2iMpeE8VOIemQiGXAmQBRC0wRFhCp4s493TpRkiCq1g1kNWSPdJzcCZJMiMJ/XAZw5XVvMClXfy2nOFV8QIjreXdcasyTrJMfkrOQGTWu/uCcSkvzjr3wi0v5ZI2oG1UjTESKgmVkm8mBiQGykZHynPlBdTMukFl+nFps5d7fFB314ifKNuDehXwFU7OERW3Ph4iPrsE+cm3PDvabOVaFnhpoTWhnq9DzpKYEJlc7n2WhFhKZvJauM6lb6JPXKJeAu9a5fPttKgWshwJx9XUOGAIHJtlp4fyON92CCU5Pcocowkfki+xs4cEj/juA5QVWriXnhF+rS1yWTkUbDk6sfEg/1zZefp5bIfj0SCCaO/FuXhmdJMsmEancnPJpQVwFuLiCjT6FGR86h8yxTR/kOWUBMI83aSJbM0NSnY/54edzJHUMCqyMMupzMISh2uXZIUWq1iEbC8jcuPbpo/TLPPnZVT3jF4HyKd4s6vQvDtjrVqH4fRXjwgo4RhwsdfavmcM/co+sekcry+FEStlGqLfQRWsREA6ybffdAFVyybTtKQrcVIRLv77bC8fhokG+T/eh1bCNLbjUPssWOFlrnprY/pd2LEgzCOPlSIizWVACxL+K+hQEAHwaOFyy4Aag69f9hvWrVlF8+xJRcVMbDevc9Yi07NcM1sebT67x/seCJLJLfeL1DPJoCKfGFQnBotOm90fx3KCsY2Fq2CEXXMPKTQX9iKVqi6njcwCVqNltCDUHwibfwJz66xA/TUrixnwKN5f/S8KgcaoVgdQJqytJpq+krnS3Ao/7YqC/Jrpl/7DSWlb9Wezdr65NwVF+l3qjwjZ7n9iK357kAdwWK2DKz3ASCNTklnV6vyoRNR+Mcge1iG4BJSiF17Upf9OA8NVFgsEXJs9IM7k1GILPG7y/vS9oj3yQ7WS6vFnJ9NY3uRipsGTNhd4mktiDoykJ3pLH3KpKJ7jIeGgeY9xuYqV9aW5/zvOb563M1+4YIzVcK4lRXFcMehLi7j9X2at0/TOmeROlA/OHUlIJmnQxNTPtd7dZXz4vhJWD8s0Yb2ua+0rrNomzPqJ8fFI59kyD7h57+Gng8F1p2rAnaaPn83IHtSwT6EjupzUBFg+ddnm7NLP5b4YZquMNCqQMe6FArwytRkueQ7RLeXUEJPiIAiMwzpi5eYkC9AM7AD0YMRybBsBIQzn4S5ctJkIYyboX+GvaT5m8oyP3OC/CHmnns6ExYr/6S8CpmkNHx6eDKPkRlZiaZJWHUKWs3C9Ct6+DXHyd2R8bw81Vjg2ym15/8+HnBR5qBJFT28sPJ+i8/XMedd0YGA8UTHq3oT+sLDkzzLnPZCZwBV6iTugq64NQI0SUBTcebJWusnSkT0MxGZnQEYoNk/+S7Ek2o38kim/YuAxG3b6c13/g/RrWuNIpb9kl0GXE1HiVUXYyqZNTEqPK/9EIfuKvfqsi4deYc9pFvnSkoRH+AF83xXNkzbg2Th5khoSqi4EPJx+IoLEMFPmfDHh8F8DCZcC3MLkq52/oJde0dLr+JsEbTHhKdUqpSVruCFW5IOLg0O9wKfs6COKl1Bppp5GL68h6fKZ5CgOIeCSazLI0ntzEuTdA1N8neor1/seIS0f1uF5oXpMOyQkj9cVpExBz+uBP7AcZVfJRJeA6lAGQ67hxi+Y3dv1W07Vh5N6HTVQxTYWadJKpTK20HjoTrzKFUARwwXetasn4+IVcf7nU1bH6vqSVqvCbG0yIEPBRUyewatiAxH5GgheQ3eXeplpe08yoMCgklOPaz49UyEC8IGxIry8eDZf/8tbfHQDWI7Im2b97vMRpF5YXeuQ9NYDIXp9G95MZIpe9DleSjFhUJGgIidRmntfoKsMu9IqMbcnC9h5S+yKOrsXy9lZ7mzXdj1KVHW4ZyVS9YYxjWSqHpUZ7DrOhDBMsIFLlWD7w7f5C7lIOtqWX7uHZx+9whLS3AZNF/MSC2AccGEl2FDx+wQPHqMczDVJcQFs098U3EKnPTCJn9epmTxWqT+e+PlzfngsBH4Xqv4w1BD+zEJtrAJ3y0FHMfTdlktYV9m4dYDqwNqBBwUO7q0eDTj8tTmkChJ6VSXnT75jgCTDsCc+KasmGgQeVdQenq/7vghBDar0o3oMHsFu6eWT+9TOlFD8N2NtkfztA/Jg5i+2Nc+x5Ff1qdC9weD4oT92survD1+1R+hCjbAV9H98d4XbyXzb/72ePbUEoFq7icC1h3vhs+j1RdsTgEQpPy68CE0T8KGiLQFqpHpKiiR29rdc7AyK/ZBG1etvkpfJW+5XmAlcEBySzo2HK7EXEfFPBJBt5V86DWVLhge9G+9OMoV+AGbOiD72fUGHaK8cJOEky+gGTEYICeQlEnf8U+/vc4xPi+mzzrmqb4r9guetwPTJKhNXBnOGvEYRC7C3vNHP9fnymEW/6KJbjzzI2W6mEA79Ef9Zd9r9n2NjJs0j+Mv9qfJzl60PSHy/yUt185aZ4yKP/6VHNlWtxMgc19lf9ZSYoNQD0TzZZRIQ5FlNvMEq0aqMkg/CVGh5bSNI++3sPu15qbQT/p6I4CdEglsrm6ARLgOioIFB/Yl3yEdPkjc0oDZnj9Ilzpp8rkUjzzcJPxcBrVpaMp/IkXzmIa50AKdWfN6DWhXi55YfnJxgaF5BHR2khQTvmjegGxk3PA46qoUs4ruzG8zgjns9YCuRUbhr+aE7qIiX5R2sCY2Jxg2pSNycWvCnumToiMRPs/1F5euOvvwgkIfHg8XFnmO0tiaiPkgRlCfvnSnECmTtxOf8dNbwLTnTa
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:42Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4df-20a8-4f3f-815e-44b9950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:43.000Z",
"modified": "2016-03-11T15:31:43.000Z",
"pattern": "[file:name = '08h867g5' AND file:hashes.SHA1 = '7f55862138081352125e9b60a27a06c3b39d8523']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:43Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4df-69f8-45a7-97b5-4908950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:43.000Z",
"modified": "2016-03-11T15:31:43.000Z",
"pattern": "[file:name = '08h867g5' AND file:hashes.SHA256 = 'c8747c602ae5b03174a9b5c77385438bae0d8d6704726e6fb7d1a5c4e767daf3']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:43Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e0-3314-4509-8c2c-4926950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:44.000Z",
"modified": "2016-03-11T15:31:44.000Z",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPZ7a0iL+erXVd4BAAA2AwAgABwANTYxODUyNWQwYWFmMGVlNDcxYTNiZTU4NDI2MTcyMDZVVAkAA+Dk4lbg5OJWdXgLAAEEIQAAAAQhAAAAu1bqS4fN2pFa87GxY11wfaLXAJQrIFirZuOupJxx5aUz/LcwlIzllX7UeS4umbkDoelODAyZMVMBfrBmrphjS772BRFULvTOM0Z6BEVGWgOOUhi8zQrbLn5aglUpz2UJ2ArmVt/1Lkff34fJXmy4a+8gtK2W25c995sdOPonP/TKUNW2+N2dzXzc9fyJk25MsDJsrsPT+6SXT96WqWbYCJRg8Gn66xvlOHq7FuPb5MxfkAyzYH0ZOb/iaxYxK6KgWAZ1k6zFdPo2LOVkmPkpI2w44BEQ/smIMUr1rSyBmznBd/x6ZZ6BnIm8z1ueoZLuTvVQfT35ALQ2DNF37T/6awJoaa73Tjwcgh+W4QfZDENRbvcFQ8ejusB8CRCKXjGeev5O7ioAJy3r0nTBnY44u6OOuLn27hWYu6iQqimVp3vQqWVZQC5HpE67SbfXTJRCLla5Br56KmIK0aQS2Rf2fKXnLRwJc7wf1nua+VWtwxWgcqPC/RGXmKWZY/V5uXcaJrfF9yK/vnVvVWQbDwOiHg/84nblLKaiJsokTXub8Bgz3q2VcpbL8sq1XEQcLzcpphdPj3yqbIXxujQaT8k9VIvFhFKGUUJjJQRQSCffAHq3VfEcOwvrNL2MUXuNox+p6i8lk16+kOYrPIcGU0rz1+ApU7vj9NckWyYnQBUKbIWH+P0cP6IKdOlic5aBvdT6q/g/h36lpeQnImBeIluVQGGXsCpYNHXgR1YaPUVYV6xS6UOJSIQ69kYmNrA40QC1KIOe2W9BozXhGZoB/mAbKVJlwoOHhJusjGUEvaFJEZKKk3Z7Fo3FVFvT0nbubGBzlihr4F5NM/kCRjSkCrhN8xg5qxKInRIq9X5UG5rqxGj+CO1O1UzFBprYCuWG+tyqZc+3bqEMg/UV4quoG4uG2RwVAQSoW/E+Q2XeB9gb5BihQ1/qi/L+H4YeMefCHGkUNjWatggq+bRSw0hZHANGIpPTx/IZxK2ey9Z2L5WOm5hQMoDm/TZgyMHI7zlWDuhA+85irfn+0iAHExOLEsCgH16Pd+9x4RYia21jeqVSQapPuUeQ1h5EEo07Xk6WX2Hk/8r6djxxlOVuiUfKKkvsshp8UViKLTux8jY5NAEtNIrjNuodSOgswKaZgPACDp7I5ln8ETGf+0WqS1XIR/Arz7Kd76Q1MfTZCuA1OM5JtxKWViTHwOkI7QQrssK7/b5Iu0hTX7aBNH41dg8sR0DGaslAZMfhFFRZ/555Q45/svrdUmQezCf7Xcw3ayGAPOL+GY/R6iFPLIjLgRTc9OmGO5vj7hX/+0kmoWHXykwSZAXrClA+MwInZYiMFLdfnyBBv9ynrATX/RLgZHKmRC6Us0F8teJxKPS8+99mhe3ILIq5loAtrdhKGzFB2dFhs7R3mCZiriR+6wu9EFe/GXyFybO4iw0THHr5q+z3Rfb6C26QPBVs4FczINMgl94Y8ElCp2yfhL1UG0w3pqZlq9Pm8k4zqAYl/NE5w8+R2pxKNrXDddcYkJELkv2t/gPpvUKVjHuYk1k5Oa/q7djmdcgIhXdbpZcdFWcnSCPZCCxJx2xxzT3SEWsBXlXcUla1zWuFSmoOF70YcGINQZ1gTmQlbukJLFc0aavapmnxjo3VpFlyb3sVkwl2zBTzcJoQSE6kvF8ch1Q5XRlTU52pSsW3U1IlMmZYp90BaIwS5i8EsbtXpw1xa9psTxwSMiYmelVXS9U7f9FQesjyaPFpbBEAKTydpIvMBbD4cPvhx8or3D5OlBo0NtW3JFkxj6TYzfQfFLe8Yt7ncGRYhBISDURY9++VMSR4ouFAXy4TifoVPDw94FUSXf3NDY6FHwdYmn3s+0v9zDSV8gct7fvggPW791ZDhRYpSaGkoRWE8fDpH4UIBHrgBnsbECgqzS7+u6pd8KeLwT27NqYBDO7UNL1+A4JYUU/piVhSGa+/Yni183E7R55Lx+AutskR/R4mnefNgqOHBFBhuPycMIt2eJ+9CZ6ArZ0UeLuvrle/4BbnF/8MOgrxWxdRGW4evuLazSFQa/mmuKXrSN9f2j0VBOTWD5D58Bn5T3IoOwXt80hGNnMbRBnnD1FrSxIu3I+kmVRmgAAG4gxDh8ZKHhH3i7ehoS3z7kIDjdnuOBoh7ypwaZoiZ3vvc5FpgEBd/Ba0N0i5C+3oaSjeSd8pyE4jDiUeJ5gpu6yx9bqWVWoP1ydMBQj6RYUPRYXpagITP4U3tVUbr89u3OJxGv8Z6azBUEQdBKPI8RCRALEJnVHXgUEfWY/iqFoURS/qFqKueNQX1hXYmivfA66UQ9yq84IGO7rtW/dRL70g/k3Io8SfNKvD2fkVnwlm1BpCP1RCzru/5XMkr0NIUXvSoJxeI4AQK7Dp521YVqeonOE5iQr5xxg7P2DLuz+6pmEEeetzt2lrj9v3LxpBOyPCcTeNaYmM8PXoaK49ogR2YrH+bvH/OD0uPBwep0z+4Pv9pFyZsjHBeTpP9fLsVat/NlOfH9px8TBDgB8bv8ZGx+unCJHeaRW5VTCcZaV1VJqFzNGQGa7NUGQ//jtkOI/Q1VQt5R4B5+M7YgqgxjMlEAF3gaXxByn0RKAnkNoyQhP6MdBG/ddDR9ToBwGYp23Ss8eyhCNipJD9MSEBOPIglipU75zjjfvrKXWww//rUn8ODZ6IbePK49Z/YPvuL6YaPXYP5a2w3JdmV00obIgnkNIvrPiGd8ooTLLR2hXD6A75t9/pD/S2fJR8dRvns5cUI2zy1UxpMU35kKtuLNNO/+GEzMqh1RjkrKgyQvL/feXtpXqmjJ1eIQ72s/Q1quqgwnhUubsp58+Rk3K5gRwm/rQWy9CIUfR9C2hX8SzeLNavQnoO76wZriTcrao+GzRHQbSwuPIxkJTPKcSOIC6DvmesnM/PZOkFM3OpA7SO/07ZEwxBNfM/oSV4iHf33AybURnBWNumuP0NFybwacOnrb5dK0so7CftmhRdjD+uZyxH2d9KYJNPuQ5fcGk6pSScA18L5l2VCSXWfoVZwjS0QEoEAy8WIs4vVKIyDItNHHl/NYCk0s8LCuYiOeqCQHPC4JkjwpTE/e/hCE4F0op0BBUYjJRpOGfpvQ2FuBnRlu/kJQ2/YW6ByZ+hCQ/jpQJ1Ec8Rq2dbIBHEyolG46Uwt8xHEvvJygRZKJFeDRjavPDNCUyAki7Jnw4pQZrhGANB2t8h0BOAclrg7dvRc76dZXLumjVxmqPGJ1779dZ1aDXIm5sYQzC8vyNW60PJ2l+v8sMcJH06jOWG0ZNckAcmO6p9GudStGPAIGWhfMbeeO8/V/OEK7lI+mxxFEUpK2R7uUpRgFEAVwGcfwgnGZo9oXCYRsTIsG8iq55PunXJNJ9UvNA1++cJmMZK2ULVWItQJl/ePHmErfN8ciR7LpBjLgM1Usnf5q7duHZTj+8B6xAOHnP1qflN3BfwsKgFFpcr+QfLybsjUYoLofWfwCLQEOtq43KFPqSgAgtpp3HKUCA214E4MDqlLgiYtcXpAYPwe7Gmuy72pFV2om2Jd83EVg8ahvmmRB4OEvgUAxl3nuYCNVoffvSTIIjr30s/dBNPUjkS4RTZx+jI7a4GaeQiAfw+ZaNGtsbeISAv9HxFpxyvus39XBcK9Zd9Pl8jOJTc+mzJmkIJIr5VSgK1zNZTb4PHi8n9f4Xs9rc/tXO5TZG7q+IqrUd42VJabjXv6tIQI+GL4K/yGKRnwfU0ler1sITlyom/NSrYRjdl0Lcpes7dSHt6xTqWWLyCnquO/u/twRGIWUpwsq/nFC9gyfH05lEfSYWeNiDsown+l3b3tWrYWnXzjV+PQDMQnk6Hz9G5mWrtpibFmYMcpN+WoClsVTtNHZPY5x4Zf9/haBbK2f7KDN5KHEQ9bDx5gD0JqtiwEf1eCT
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:44Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e1-f5e4-414b-9e0f-4757950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:45.000Z",
"modified": "2016-03-11T15:31:45.000Z",
"pattern": "[file:name = '32tguynjk' AND file:hashes.SHA1 = '2acd98f82297e0aba7c9cbd79554ca0dc84ebc73']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e1-a0f8-4714-a3d8-458a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:45.000Z",
"modified": "2016-03-11T15:31:45.000Z",
"pattern": "[file:name = '32tguynjk' AND file:hashes.SHA256 = 'd0228c8adbf53f5a3a846e86f36617598aab6804ac8cd73a1a0bca672e550fea']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e2-0bd8-456b-94ed-48bc950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:46.000Z",
"modified": "2016-03-11T15:31:46.000Z",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPd7a0go3O4S89QBAACAAgAgABwANWU5ZGQ2MTc2MThmMTUzZGI1MDNmOTY1YWJlYWY0NzlVVAkAA+Lk4lbi5OJWdXgLAAEEIQAAAAQhAAAAu1bqS4fN2pFa87D/a44q2VGK4efQUIEh1kRxKRTYCqR8zW2gWo/rG18eWlTra0f42EbQyqnl44V5u7KYaM+LJwjufYpeA+hrSoV8leosEkwWFsOXzNaoeLDq1Ap9rLmq33yJ5NkqGLwUX+b0Zu/CQWurYNBsUuK0ooGt0Yak7uVPKaQ7V969PYBNWHVUXzxc4ihCZ7WKQlOPlNt+95LcfCzvviBHPEJJ0iFs/c3hNiBIcWAN8VRqDu+fQf3V9xkxuGoYLRbzef8S7+H+E1r0o20Kp0KZStupL78Aj8L5NGaNyiPNo7xObnB3jrrFxZ1nOgDLBP8kx0erEXUySUBSNKqmI4vC0HPdXaT3uYjRl4Um4uo1u9cgCD4oUYNcLVLFNOldVilz7ks/sHlmQdHh7WS2h+CQC/1t9WwooMvti8+BKwtSnHu5jjjhp+/Vn84eOtHrUmxVxmlym3pLZMT0sem4Oy9mh31wDg7zJ5QLgp1/HCybkL1YEap/CV56XnzIQSEhunevAeg3x8pZl3t4VDiukD9g+TouCUJOhUWSdi6MSta86gASxOMOdGYK9631Lgsjz12UnUMoIqlPPLzmwcdNApSwfZryNFzzcSa6nRDlEgO7sFnHXzrVImV/bM/DbnGe+2ecHXB7MFphKkO+Trft9QwbCZ8Jv0RCjXvziegTuD9t0MCtr//0FNORtm0uU196EEdak8LXAEZOLraIbQ+Cj8Jltq8HomiO9lXe9CAEw8gu4USRYgL1ccVH3ubdsKujxCXAZrJVjjpS/Zlp2ALjAa7TN2zXs1dxUmgIxTaW36wy+pHaF+EkPyVvJ0IRo5xjcOmvigRy06ljISvKx2DF2ulyc6/aPQy9bcVSeSjYKrVREQTDMl8CUyKrFTP2uGph8Tekgg7B2bOv8XBkE3yyoovh8JORMsrL35OpKQgtBRhvcF+bXWYR7yIksyEWzMRL6v1X3iWp5fRn3P93AXuOz8UKWi0a7IMsphvidf1nKmigTyy2E2+bnj9PtE1ipvfuaeWtXj6PR9PxhP0tpjiHt30C8P2tygMJYQedjWPQJ5uVxTynH2bGH+qU3UtKeg2rFNjUVXSVhXedNLLBYCyLC4lMWJ/Wkw9QQXFD5acKH3Y9t45Hh6YJsCE6lgfA2k6+QmvbYDFnjRQbPxylSm6DVKO69eyovsv311LH7YcYWPYHFtR74ZUpog126mD6qBkHemz4sMiF6BfNfFVO5fNCp382YljcID8PL5pAeaRdCTL0ERb63S8xfc69VDQYlBJF63H5e+navoc8qVwAqtGm8EIvpKtqybu9DYxXNiaoLGJpvDl9oHS2vkc9HGjc/eNTYEGh9VYV1HCK6GBsBa7b2dyrwTTSVgqFwnwThATpItxNu4YG/aAyfCnNN3ZSkndrYaQif5nObqJ41OqgcP4pNh1IarzUYMSK9tYsp2Chq9RW05bnsXTgBs9vLD1Atxqm8fBRMQHptCjAehKMRFLqtG9rB4ka5tND5HVRZ6XSvwG/VE1H6Smxz2ueYKwmtE2Hz0aXtUD5Nwqc0KjUIJyfgbnYHtci81or1tCgag6mKW1tM/WbBUNf5kaIrDPBDsQ7kvBwbwiFFkIyLfVb+sj+58sCZPl1xAb/4OKjEFO/Hs6jbRvwSf3D/Y6DSwC+4N7v8BQoZXMbA+Vs0DWrUF595Vmfya0xccJofA5KnzXG3AfaOCwgEKYwpw86//iclE6kF1CtnjAyaWmF7V4yucfuEmoOBMvg9xpQmdaXyjhoZJCbVQiCkMfMmgAKbg58qRslnAClpyIauSI1shIsE6P6OCYc3c3+4U6W5as0TT6V12RS9LJfJodZN35oEsftZ3GUKsq1k4/LrkuAVo66+iYRXBU4FOr4l6/uAu8KhNUg1ktMfxSAmtHAjNSDSS0mlMoCGZOG9/1Ht3gO7FTQ8eiZgyJAWvKl3yZnw9YHw8o30it3EqVbRvWCm2ePYP0vbdq5rkJcMedzcK275m1qQXB+0tLCJLLqO9+ZFQiJ4X9UPq2z61d9diaqF5noYxmiq7Bha5P+dh7k+7wJ3N6kSEnkt7/J1UIAAl4M14e2eTbfRmr0stC4rl2BDVvbbm77cazwDx75a4jMZx5p0kxWEPgenFPIaCbH3caIElyvia8JKAjbZcp2ey9DWvn7kxPUK0L864KD2y+2hDewzM731Pjv38JRKfttvk9zKkgXz403oWMoclroIZhsm5avA/N6CxNSWTxc6vudpdrZIJwguIEoNJNpAwHtjF8yRu+2GVSN5jnI5lcKeQYN5Ctm6y0uADdZYcD4uDMXV//ZvBXAIjDdyBriCBAcFONK999DJWBEyUtsdY5Tcw/f0YSzzBd6RdtpKBzWyj/yGg7ZWZCk/gKAc6n8oAutqX/DxSuJ0Z7mIYqcEFnhAr6+3yiwB2JA1fbRjEEH1Q99ih8M5hYzMJKFJyzS75yQrPZ4JVJO7f1jpf3QGXz1NFjxytrPSIce8RcDXaYg7MNGDS5jZVmm7LO3sQ/FQpO6UQnq8Evbrlv0rOrFo8V0Jj2Z3oiR5skPEakLtaJKlwv1u7set1QWy/VFHwIjsJGDFAUfLklPeH8sWBc3LLG7gFOgmoiuswCxQzyIH46xFgeFov+9KnuNRd7Wf3B6fhSx4FgSauoirdGstTBTtw3PbYAy80vejzxCxaywd+W7itjhV75CSfn9YGZoD3FktcDqWHTdFDH7TVL6NMzcJMrzmEA3ksiFX1zQO/ss9YoUjuoUb3N2Urb584e+7jJdRCmmCubz5w8SAeD+6+y2Fbc2j6fc762MWuQGyu11/ApISowlk/2oTAQzDltc71SE1HqOPnL6JbAdezi1v+dYsCcHF0U6IkpY2yJdKFbWpbwDsyg1tpPWVsAUeC8JkSDt0DentgbsoZwX9OOu99R8v1kqObxxnU8OMkX+/VHgA/d26NrFQ9HlycNnjIFYjElpdSLHilvg3B2fLCCDqaDeFl/Zc6t1bq36JezvDzAbCCtxlfEKhTLPwLPbi1/5yh7l4nCjRE0wHpvuKZ+n/wCk8/kQsMP1t3O6DZBt6gLfYBF7933aQ9m4PTqPDKfROma38HZj1jKDW0Y9Ufa7coMNw2Kz3vPEe9I1PZbpju7yK0IbNLohk64qvXnjTL+7oCGSF0oYbivW7nvZPJcph0bsjOlV7OTfe8Kii4sm03KKzQxneV88enoaGBPTlBzbsWLAUoRhar59/bBZ7RAXksJMc8SjGIe9n0CA4DvomglRAsHxXNTNChisYzgX4t3HRCVUX5hMx/u2hTfTLbLB/ZNg3ee45SYttWacvFJkmLpLdpSls7uwMKvV7uaIeLgoZDHBEsjH1P0+b8UAN3k6UJnt+trnZVBV0MxGVxTpaPREbOTEY/eKCyo2sCWtvZ6baAmSlZsHNCDKhB2lWkfIx6kGOOm7r7QpSZMgerCO7t6CzKzTgNxIcA6Y3NUOWv7u1AHyQMjrQxajbudF7ljl5oa07vL9/prruX0kMfrkh2pqrXVAacaPTsdsx8HlwwK/sTEg2xRWc4zHxSuo28PIODADLk0shMG2eafMz7+LchAjK239qVNlQw0rNYPhsRwvw8JPGskf2fjm7kyFGCOvUsfOuBigNWbcxC2PLWymw2+D3dQLh1D7LwaA7JbjJZY52t2Emziuj2AdbIdZlozoIarqhMnjNEpYwOY/zm0MHnMNrxerWahz52ZEWQvMHbl6qHynsDnqDcnPOQVlvf49fVEYzks+2rGhTGzHeiU8N59Sdq6zeEqczoSh0ga4sNsbe1AP7YKo94eSnii15Jtzx8c58GEfrdddVlC7Wjhxa09M+Q00YXPySKGEE/2joNcg2MfcTXZ1MQtut0qWUZP79LPqbuoiF9fZUzZmUyixaLO+vn/GtFZ12Y
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:46Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e3-b330-4ab1-b91a-4ab8950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:47.000Z",
"modified": "2016-03-11T15:31:47.000Z",
"pattern": "[file:name = '69.exe' AND file:hashes.SHA1 = 'ced2758106f2f7157afad7cf4c61586dc60de694']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e3-7934-49f6-b4f8-4f37950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:47.000Z",
"modified": "2016-03-11T15:31:47.000Z",
"pattern": "[file:name = '69.exe' AND file:hashes.SHA256 = 'bee14206aa3e443af592a6946671d191f878f2cb7ca04013704b8fd4014a4c3a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e4-7940-47cd-af34-47cb950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:42:48.000Z",
"modified": "2016-03-11T15:42:48.000Z",
"description": "broken? Crashing on XP",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPh7a0iQ4UVW99EBAABOAwAgABwANjNjZTRlYmJlNTE5OGY1NzJlODRmNDVlYTRjMTJiMDdVVAkAA+Tk4lbk5OJWdXgLAAEEIQAAAAQhAAAA1eqEm4wVyRjcWuRi8w5iQZhItvfk9HkkLnu0GWup1WCrUfSVOhSLhWHucSZuNgINMlwUahoO3VHI6O0GN/+/I5BfXcDbPt/9I1q86a1fgfVxATqHUSlEKneN1BRSwKbx0tBvyvIzXgW7Jb0QcdajAN3WqO1SOZWuNNYrM41Dh4Z3BewmQIGlv3L9FaxAPG7f4WttKOPoA32IEY9VAT4lXhCkXYeBbpJWCoLYC2pdpCwRyPXGN31csQeborHrmUz2U3Q1qt+19uG9SVylmQFBaB6ZXwKkG2TYZhBGcj4qzmTFSHUAMuHuvwUWMQI5D4NiN0uyhaYHdAubf+rSY8BVML5DSyd+UYgLljbfH9notx+q5IGxIF8QcRrsj0OsMN1xTdMkKfNgwYvAOojUEY2wione1dxwuo7CMBbE3T/A+EvhKTXvls/KU0sKcmBOh6qC9uHuYLsVdisu09XhaRjyFUjWpm/iMVdw/XaStm8hC/tBcOzVx3fJAMEfvYoOXhgff0SxlL3nRGtPscepkcmyNFR104g3Y+0zswG8jNKCBjoXDp13nP2eMF4j/0lE6qIDRMjPfLWt0jN67xqEP+6F6xdrfaZjlXfBgpHdWrK5T4lThqrXn+fM0G0eefrt3QnzadzPhNMzagOWrUL+KEuL3Em9FLY1Nb7hZRs1EeSv6tergg6kaSnIvYODCUfb7R8KPEyW5Znz9mR6jpydoSPQUecTjjH3SCob83znt6cht+AiYl+iC4Z7jEgyXxc6j2ZjHqzQ3BJoE+btTkBwnW2cIWxg3NbHG8/YDj+z5xYjtit9ylxfZZncPrF1Wi+hmToYFkT+wzLP90hdoY1M+DOa471qS0vT4Cce8Bjn/EBI52qxJWjRpp3N8zvpz0fPamPL+vkOI63kEamdECdCD2Xj4jnUHfG3h+gC3wZRUOOqzk1NlnxEXAxkArvM/5fvjGuYtnOnQgoyHocWQfkVx7gdoph8fXlckJjjzqYxH/hNOK6A1OAri6R26VUtJfCB4CXPpMi1j9ll9K+Fg+GDf9S1eQz2UrxVp4AxAz57N+3kJb9f7YrAbZDzbpI5Ub0ADQIqMKgqvn6C8ur1oA2Urur2w8lIIB/0ugS+DhDsgQ+h5E+vh6XxnSn6/D3g3q6Y03TMQXbHEFaXYDONcbpgIsYojjke+hv+zEE3+oBir7lHMUdzFg4SwUTYZUBB08HmepAhuxh9uTuchUv0U2xyjpL/0JRRI1Lwko+PIBLizTAkVo6SaBsBcBCnJ19n8u3rSsh6zhlFaQACHw3z6Kc+510JZyXVUprxhIdbuTlO1Zv/AxijvKgBUh/iZNSslxnAtQ0ASpV8qFu/XFe+rndAT+SzSoAhN6RN5L0nytX1iwg89cZyTsXBvY2BCbvsFL34srevJWee6TrTonVJjF6ce2ezv8QcWoYy3KOd/x1Ml4zpHOxgA+Afm3EFuatOQiVRMifu71sf/kcmPfSOZLMM7nHD0ShfXtrObKOt1uUOVcsWzvOTFpbiYABUGK3VP7UeteR4QwSNg+849uzmf2BsObi/CPOObhoMttuLiNoFyGy1DaEwWrugRnafjPPZUz7bbzWXrWrfOaf2rS3SmQ/7+V5gbp7/uzQpm084hZD25VcMGi8WlYXUNdxR3JgV1aOFuwSnuwuiQrd2WZEOb1wOdBF8RaFp3xVD5lNOx8KJ3wuCTACFR0a8blyT/nU30rqCGxz52A7tcRaFwWM93DVz9Pw/1rMsCREXpdnGNo8qA0Hx34jrFPVyW5cPmTi44Na6rRQvmhFxNEQeKoKvapSGu+v7Xbb9j+ZjDHY0wrv+MMLsfCzqU1/2Otc0kHyzh4j4163iTJYkA1LSXkX08jh2HqCRxtmwIoOAzZSvjOQpyK8WMTaqPvcXuwdzpbdB5POZyqUAO8dLK9CF0VUhq1Axwwky6yT0FU9jxIr2BlEPvm0tATm5lSrA2yoCly88CWEeHOxD5O3Ev+9avC+gvaXAqqW3ztiQkfKQ0+/NXomId0dZw8GoMsItY/ZA32O8GLPP8m55TOHuyu4iH82dYPb+q8AIHCy5A4qrSNclQn9e5F5BL/biICiy7XeBrSxLfVKqPIowkE9ds9uH0t/WgLKTJvjaaaums6CSU0v3AlRNsqD8+mIWXzcPxyJ6X6ERq2u7+ziDc7uefC/cgZSQpT/vRmVtaQRArOAR/Gj/9cSls35ob3tTeEP0C4KcZV3UL0LBqGfnhDpl8xqqsfqtt5/+ipY1U9BBtO+VuwxxR2P4ardEI3MF5GCDH9AbuhjNF5IUHyWdZL3gGUUe0IIIedOPMOfbzFqSnLpMWdb68RXPBnEBhigbSHnI8VmhIPNZb0d7OiPlskjTLzIRhQ1wVVAaTufJ1W6PhN1zeSKk5beGUXLlJl6a7Oa4K7SDQXhIFkJQ3WHxGHXmQqz1GJF/yjGpuiLcN33HOMUKz/QAzS905miAW5WllDvE91vd26Xr4yF1NmR1EyBnI7e+t+fcOuLzkY9Gl28nQeHruddTeCnTgRfZ/U0U/gHY+wWUSvQRDzUGrqOnzx5awy2EfLbxcyRCdvNk31My5uep+bcQDZmzGl2FTBOt/Hb6NHrEkZ6/DRYdYxewBNJnj1/XgEgxIqrWfu9EKXoFbeUJrG1I7JHgLcJaQOixrDHlC/SaQQVLBeMMlE7KZBw8nLHIeJF9WMN/7W0ZKtTrT3Wewbbqqr6egMO5br7noBgdCK2wLBJeK1BbPpTy430dgLNdDw1oWxWUKPHApELymTotEsxx9OXjl52ea/0fgrOsSIJOlNTkn2vkvfZNuGUn0DMZEGKz7WE5pQELI8+6pSGjVZY5NFt70jm5zmo6noFvlHA6TWcQQD+PDsEozmmOlFWTlkeuwbjn0j0zqvJV2yqhcQePrDMB9gFwibO/v4QP3l0pwoRzbleRR2i2w2xgnKseODShQcM5E6z3DmkISEvxNC2fNymnNeEUTxMNkEZl6OrCsK1o4/zxioBbpLGHLTyXm2cJ0S7114kQYQDTO2Qpj63DTG9g+V6Sbz2AeF6R+Qh8Dk/+U4+LSvWd+DTLCoHrZ03MD8Ubl3I1IqqwLuACzDUCjq/VZSTKh5gw9GQvnTzevM5m3oh3ZG1A6Pcc8E03NwnXckfWiebHndB/HTH7e51Z6DjOdijzvyVqeeCwF6p7oltgpbNJAS3rZYjzqz4D6L96ff2TeuTWyB98N0URnC2EwU9w7ipu8j0iOz9N1EZm33lLUlzdIJYalhiptSQDqZ50vCyBf66jVfZQ0zcs9WVLGumqekZQBGFxjnKMcDKXRVnusDF0HulOvQczZcX0HEYVDYpdy9k5+8ZVVgXlVBYsr5mQWFScee7iG8LujV2fwPSd3NsvKkNX9qH9f739g/RkH41q/LfdF9G63s2fLi6o5vqtt1ulztvUsBzGkg/UvXcue4jUFKEaiO6y1jCFOWM6ZjEQKxsCmPRLcLkGj82S30sBBORSk/9xXJMeWWqynskBuuPgZrm0F35wB+Fvf7ocUO/FG6sKT4Ehp60c4nianeZ/0jQxvnkL3aur7ruvMi5bnQNP139xjn/5BwRibhzWbVu9fGH1QWDM+c8e6tYBeY40LcalJ+ZtFUzjz/BLZrlVerJP1yylqO3qRG5CfsZy9RiiU+nstfEvcSPvnhOdixhHBWdL85yULbkCfn5dCWa1xXznnaApOui90uHfz68EztrbPShU++cEnBVsmohvE5ZPY209eUGI8Cfz0jFtpcPy8lV/Ybkt5Ogdit8uumtyHE57fEQi9giugpv6Gm2PEmIIm+SdSKd9Hdtn+AzGdECOUFxzHrE/15812PmmwyZLFnwvknQdDHIlvOHo478jhgXv8qTqxwE+t6aiEJFrCH4PfP2LipcC/z0SqaR4mWMqKO
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:42:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e5-1d54-445c-b5af-41e5950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:49.000Z",
"modified": "2016-03-11T15:31:49.000Z",
"pattern": "[file:name = '80.exe' AND file:hashes.SHA1 = 'd597de857c14af220249c2681d9e38a46ab719fa']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e6-f568-404b-937e-40ff950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:50.000Z",
"modified": "2016-03-11T15:31:50.000Z",
"pattern": "[file:name = '80.exe' AND file:hashes.SHA256 = '717ab1f2d9b2a06474b6f6dd297b253e9ae6bced85ca319574269b71a4bb2e90']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e6-5dbc-49bc-a644-449a950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:50.000Z",
"modified": "2016-03-11T15:31:50.000Z",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPl7a0gmizEgFd0BAAA2AwAgABwAYWE0NjRlYWQ4Yjc0YWU5NWYyM2Q4NTMyNDI0ZmE4N2ZVVAkAA+bk4lbm5OJWdXgLAAEEIQAAAAQhAAAA1eqEm4wVyRjcWuXaaawFM6mthCCazMDv7atjrcB+VsRXUKTNS36UQ6HqlinPu2MAyGlyId3Svd2xyL1U42pvfsORvXGZ8yTxU2Gad7YDhsxXDK+OWTWL2iuBbTBe/UKjyNkqVhY01G+2DdJjA6aW0foFq3B8JXh7EaDWrmBn5E5VbsgZ27I5dHy6JFu2OCSpPMQIJsvQGdQjie7WaJBwsvLfGLuWjii4AKC7UmHGpTFxKYxZZIBZWfZuJ7z4VBqqcHHIGjZYGc0IcAQnexPVaHEw1zqIwx8tswlwFWgjZiCuUhxIwh5n+sW/jXyTgUXw6h5hjSzEfCPhdzhrcKcQCDMXd8nqBzFdwnyGAfCMB9pSUQf/cTcxV0YO+L9sPkgxQH0HyHwNDG4cGAT7ngUAOxPJ0aNGl6D4Ay+ZwGq2ti8n8iYyw475lST2bR2TuqNgY8UTOcfFjPaypz7GEon6W/VzoyZZcwjb7/PW+yW5K67xVOSmrWMlEUiZIMd+wPvpyE3o8lwA8uzDkPl7RC6sjVTpTjZLiZvQqCOQLoPO28pJRi9c4KCOP1Zccz41RhCGM3inM8wNjtsfJEUGiQ1WPQS9igim606aVU7+H7dHK9Ftr8MlTgHV+jTzz9c+gTzaZYFMyyFGwhFRQ3gF1O+ThBZUN0wKa8Cned6Ghtii7ICCp1OEIS+nnfW6lzVjEVAENWgqEIXtNenEwPjysbyHp7mQkFImAT6+3+x019e1ePH+Y2OOT27zw9hKwqqQ7y1Cu32HjDQmETch/jZlqrNAw+VWHrrbhOVdU3sPxo/UtiBnLIV634tJPRdcR5MD0aR46X8ozKAMT4qJXGUscq0odhvw2r+465nTi+pNQsgIRSbSdAEW77qOF/MqYqN8P4AZQVIuxQNX8faBLtHwgDOp2ZGqtmdi3NFUJVshyW9/6S3+XdOD5KPon6v+BSGumg100HhzhAhfTNoPijkeqAX3tUDYDjRXqCgNXENmsABL1vmqFhtEBBZL/aM5qJOm64uq2zjznLgTyeQ3bv5dMsvqufqEcpOWGpYK050061S4Lyj2eBdc1YwxY3zpVpeB6NGs5kbK6H+Ycq8Hix+Obnwf7DemdIQiykzH+KyyZMlhTw454gvwdbpFoL0ISMxQbhHL3ty5R3XLMDVY9PQWjpKklsORcuIx+74gmpmtf/AcQSwpOYiDUR/kEMws9hq11uPTCVOaBZTcrR1t9sM+sJbpLi8HQQ3FFiQkVgg227qVr6hjsOJX9Xbz+s0SrHGnurCtepkxODW3KTwNL442VnqCsLJ0QnYuo23h3Ymt9GUT44PocscPDj5C3kKvghJzq+S/qCP8jjWIvbnTJsW6eYQypwuyvlctyRMPhhaGjxwybvUXmmrVDHHqGWKBPCExBYKHguDKwbrP28CCIX/MpX6q9wMbIrCawQ3rsL72jVa++3nuo5Qap3wbvwaD+Zv9grUlDIM4V+yVjqS8d1sIxoo+bs1RifXd+J9C8X0Wi+a3CPhwUzA9Fa4QDtDMP3g4HGJuXsWf6tRYCrvqAkEq3apaQGUi4ToP1R+/dF6RaW9DlUuPNlJFY9XwJIRpc4EhWQ4Z1T9JGGCeLmO5M2/FGio4+qkfX9sk6ce180/iy9d41aZzxDaHllKRSfTREh6DyVCet2UmAozTHTlhxngoc8gTdaluoGrrvToIdiWDzrvXofnHg6pYz8MrspmqIBopk+J1ZvvwqSkf5bc/ZKhV48CbAgjAvWc0W+SSzCbXtsjcxhbp42WZyVYV/oJEpdKYeYfh86nsLVhf+CuSYCqedDznDa/fYi2yzt6qpRDraBla+KCmPz8WQnW9BK1nH2dLNVgTxWlrYc7Ima4mG3aSdcDfZydO4Eoq3dfgw0FI1PnHEtvaKX9owEYMVrs/WRhdLl6UU222rsYOQrGKUpQcjjrk21HKMfep+p0/RZAQwvbv1ylJSvSUAHDtndL8iGJIv3w94IiFkf42MTy/5NPQSqWMGDSHjrMzDKTORT9MXa6BVnylV7+1q4OTTTBlKntfbEyeBsSu8peJ70nHMVn7Mg/TFHhcIbLnBvH9cjBaUXCNa64/4KEgcRRw5KsZepfpjYnQdgjGT54AhLl6mbpS7TeDtFrVN9U4DcomzmQ81zsCM8urG/GqDupHO0zdlSwaiiLwb1VtDdrstQ5zhUhrH6E2sSvV+lVG5+BCt7wcrNF+doJd0cUX4xjE8fq7A8wAnea45QrrbbWTd3VkX7V0RWbanNnWXAQWJhOdbPPjGjHGs0a7VxDTKhmZGx8HApMO7qsNs6UsOpEja0y6+0XRBhUhO8gv3RfqeAYyCQSOY4K5mISiQHNfl9pgc4mie8FGur0mWImItRENqHxG6ltCOBxXPy5gLyv+SeNH7hMSwoucnbyUDbtETjrfgxOePN1er9YPMshmmdueeyemUAzqZNbPwLRbrjNiD53p2GK/IIIRx1X9rw1+odXKy6H4gBBy4Voipfe5ZFl5T++3wS8kUKa4heOpJN647s2VYYHWL/GeF9SJS/6dii5bT2qv+zMo16tLxCGm1UxqSlElZ7snlYC1t/B1J/vH5YFRfkHlewJQfnvQkLsDV6wNcw1A/o3ggRjyIw7/qVVP6NJqVwXgNnibhWRm79m3zIuhzwfuUt9aed904YnrXBYY15HM9X5nYQqqebTgWrEtW7v5Rci4V5wF8lLU3isLMSUcJYHMJcb0xFJx0vRdtO6CFzdxoDGOp6X+t3IDZnM2zWStLVFnxHYrEPV0HMrUqCMTVeoBCA2B+cF07yEnLtZ9mNhHu07uMRz8/GTyVrc1ZTYa5B7A9EFd8TAslZfm4MJQ5dZPcoDYe13gV9i0QNwec6RHoz/PCp1MjOmxcdCzzzTVIWeYP0Pq7HdTG7Gchmx/ht62pmm81d4nEI9vx7zYlVQY7ay/4SQrQ5wgDzhUVXlCxmzWCyXHNBHtpD9FC/mGeNzh8q57LFctnBacNWECtoproiuT/RycsAjHWEIucTdf9XhBoIQYHOEeJX6bIZIbDw6FWyhrlpIII/5S4/S66oCXwWJ965o3GrXrwg7EEar2WbM+GyYZH7BoUBm4d35akw56INVgROh0NtHlycXh/QLYQvgDFlnIIhtbwjbOKw0io3eQbRjXhkNvO7SKqxOMuOzXkcjopEB9T8An5j+3/HZFoRqABiYVJlgZptrHS52poKZfazXO7D2I0tiAz9LqQpcnAin6+WD4Cjkew+rv3DuqaGuQTNQiY/fl0Xzo0GMbkpHRu+5QztBn6RGEEWG0/wp5fxDmDcLXUzvnu4yWPByHY86wA04J2Tj9EKbla9ped9sFOvgCv8JCx/jvy8ZoD7jE272BMuVPLVEv4Pa0Ht/3UIef16Ge8LA2CuoWXt03P7q/3zPu28Kw9zmmK9WpZ13b5105fOoCAxDT308vdFZ4jjLDA57I0d8D1AjMrT7vchJSMFS45yjgn1qrnG9aHv3qTxTX8CfG4TKEIqUsbnjQ8ks30pb2krbl/FykOHQZCMJ/A+P7N+ROKD8lidQTAF403RB84T00v1ZEjV6ewbjLejrUKMSUlkop3W/JIyCC2G5HIG0VwejibS2BWxFA/cTsWXSwQgp3Mj+Pgwu81VH+eKQxmZFaTYffJKjVLhtfwBILcRVT02+K5Vp1eCmE7/vSG0/78clzraSIlUWLoQYG6Y4zEcYANdRmDClnBx+62jkf1Dlf9OXsh7mo0x8MQBhjMjbD5wzFbn8nTkU9lNJhz2fN0ey9IZ6700Rgllzbfr6r0gcn2PdYS5yw91BGoxk6Ifsg2KpRGVOLKFC8lUIhhHXYP23MU+7vHB3TJW9DyVEbSdainsrN64PbAEskuauNhajzNXSbDZejurOUuPK3Gcc73H/2xAklopajHzJsm6
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:50Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e7-3cfc-462a-8ac2-4153950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:51.000Z",
"modified": "2016-03-11T15:31:51.000Z",
"pattern": "[file:name = '87745g' AND file:hashes.SHA1 = '711987852d293efa9cdae6326ab543cd41e26561']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:51Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e8-70c4-4cf3-a85d-4029950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:52.000Z",
"modified": "2016-03-11T15:31:52.000Z",
"pattern": "[file:name = '87745g' AND file:hashes.SHA256 = '002f8158966ab89ef6e0c33bc79708653002af90c5f7685154813b4856169b54']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:52Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e8-cda4-43ff-b0d7-4202950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:52.000Z",
"modified": "2016-03-11T15:31:52.000Z",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPp7a0iLsl5oQsYBAADoBQAgABwAYjdhZDJhYTJmYWI4YWE4ODlhZDNiOGNiNzE1ZTU0NTZVVAkAA+jk4lbo5OJWdXgLAAEEIQAAAAQhAAAA/HeveEksPN2JeHiRznWFCFZcEU8ZukJkaCQj5vnbk9aDwW5thZ6/7NCncleaWRwqR3FZ1O204x89afnXfwVOYfyv2qUIvScXapJT58M2tIT6EcnLB404NTxN1cmDXFfLBg5q55/WRYXntrx3RUTL9JpdcyPALWUwH+gMPZru/iFSUNgvqjaUiF3YZzXJKoGH1/6SomgE9dpu9bR/2yGbniFOWoDT5gSUQJGktn6ajAtOWmTo8aL4SgC7KEgXIEprDXfs49anIg2jg7NxpZgUthn2sV1XyM1oE7tNboeuuv0jdASCHyIfk83BLGUKzIpE5ICCFAVR5yua7f3U8kDaeZ4tcdeka5/7FVFcDNhUuteqi/kC5+H+4zWjb135tdkRmirlAX0qLscn/tarNTT8IwWVemohGLQQrATBh53g6DlRO4aI4dQWGCkGz+yxf24gukw9lTkh8vMEzAAIXZtRDTg1nFBgR0KEAYuR/2P+PV48vphk7wJWgXct4ledAvHVO91gHL1yTjADbGNuMcR79bSQJzVrkT5/90DwU1P3X7L3YIhuldfPzKloIvvqcmBv+9CPwU2VRedRe8ap3idw+Lg0LmTZvAeYG5OLb5AvIH3iBEZKbHyZOy6Xg6Xda6RwAIwHqRDc9GdeCDRGbFfPpLpJbuY0t2wgDC5MZaCx2DZ1QcO3W0jdikyC7eU40vsgrl2WHpLX/0MTr0XNxllgqdeCBWpD8NR5CxJmyi1aQcwwYRteOgPVE3aik0oUTuYOlk6zZrgKDpU0yQj2wq6esVFn7wxtz4C/HKvTNSCyj9Rt1sdHn4PzarFHpcgQiTMryOJ0LgWbDM6PLRyuG3lp99IN8bP6FUlNqMhcy2jRlP/sIy7z3U54rh9mkn64eXYo/A3Stw+ccbrWbpNNl3iaVxJttEyrpZ4FTIIYENiRADRm66zLo6Mlc9SdcIt88D+MqOP427PPm8iO95JqsJzL8642+DtzUHpdjvPK5pPH3tkModxv7VTw+P9Y/mMNZgk88KErBtCJ/uhx8yq+reekfOtvWIgScnQFXEvqRrloC5NT/lImfq3EGqLzYGTj3zMjcY+Zrssn8t553zbqC9U/nFSm0/A/nXBeoT0cP6fM/weeyNXphr9rI4/XDXHHlCrRXfs0VUy08q1pzZ3886R3chDK7jsvCJSMRCzfhT9JZ2iJC1XHMtd3Z92ysSlZnWdoMKSNfc26MQxGc2675uF9ngsQ14YPDGlUstpixoobGIoLNvDdtwj4Oui04FlN0YsYL2cLVRFPruzoPC2Kib4h2qo6USZKRAndiLOHJ1ekEuFW7VAw5iSr8oM+5h0KRZFLS+3v/ld857FVp7TZaJ0AHw6t1nVm6O7GQiDkgeR/P9qW+jQJvXv251QA5UVAWQ+urINRUj6w5jIF5uxqLPj24pwZBxVTtfkKxZV2CHLFJbHLJS1bFox8TGCZhvW6QclccpdbtBPefvbRDN3Ozi/euhVXrajbjUQv7Dqmfa30eYFzuqQVt23vJ4tTSPixQwSJPo7xE1zj/VJcTnQTZOST/nYgMQ22c7kJJrZOLsM+XVm6IJvP4QdOgv8ChLL0nFC2L2Bj39OJ26Fs/ssiALeZGxEN+30nziK4tvjoYG6bDTEbfdQhuNRJk76xGT4MuL38Yb5ahYaeh4xTueJxgtQxaqYigby8a2Xj/tKdiCKiXVRj3T3EWEKhYLyurO30+FhA0jIfixoWu95wjYpQHm2H2+1S2LjCmYumseT1na9J7kZ7D+YRMnPj626eIRf6eVBap14g996O4S7wt1FtnU8gDdfTKA5rW99IEdl6qXqQggBo2ovjZLvoS1yG/PR6E5TL8jF/PRE6FmmoL4jpn3l4hFFsJrVLelQE/GhGJCYN1ajJH57VXbpxvMuTM/weXYcPy+yd8VR5Tm5BgoOd8yYYI+IvQLD6kG6Ap8pW0aMWjPvdlCpC/q3W+sAioT/0wgD1KMr1ldRfHCyN2CfOd0AwZ1Lkr22p57jKiC6vEwTsYoDmelaCHepCy2bURi1V2wVe6+h3eeVkD2DoyJngBRuLIzrHK1/oY88KseW/uzof6dAHT1TORFQswElfDiXzSb8uCJzo1MdbzjbB4ABg8voBW7lZa9pY/vCBFMFQcuC22PlMoQUdT+ozAv43JvwuuZH2l7rnJXDKfuSVD/Xj5PoBMoGJG5sjfuxqaGiFPgq3/kJNOfliz2Kn9U/rXwY1Wv/Pho35Vw5SwOUEMb8181ZMyAiSm4kgDgoruPP/JTZRBVWRWTU0A7CFUgCwvnreGYi1iOAte3Ak6wPtH5pURx1q+bw+FhTJ6SiiWLB5wbSUgDq/lIa6N/9KUlcrxTqC3moLG8V5GzW6SB+o8Q/MkVybiaQF1pkwcs67RwkXx1uEy4DRQc1BkiS6gpVqP7QVbko/zvtInoODJRuBVrltywH3rHEVsULWfcRXy3Ysk9NbA7P1SXURjvPRlbDoa0Dfsc01g0Of0pVwSgOdwUtriEa3rlRTutV6IEql+pcXTmtYrs+7LWUVWYjFAGDd3Ey+sNSJtzTpWFOcBcx9xV5BjaVV471S5/XIW62w09M4Cbfo884jgOZqHeWL9SvKvbaUIE2Je/k7F4LQU7tRdVKTBlCsiTz1kBeMSmhYlj41OuP0Sue4DqrwdSsbyH1vp0yrrlyhz4ch6J4X96NH6Z03Zn0f0WJ6SUAWRWPi3fZXg6xG2uYosvaSTAL6+ANAjKxW0C5dOKs2GCspGp/eA5ZkArN61X1Z0equ5oXThnx5rb61EH6JwfybaIbfM7vnZfDkGNWH8wxcjyIC5x0cAI/BU6dzJy8mntwmwtYklFclrymVI67V0hbnynFe7QgTCny6+bw2n87rkvHNsrUfpxKH6nWN8IQHoGLdi4PyWjvJhGB7U8J4P3K2nwD0VSU8ZuS2xgTuTS+Sf2pW5LOT5ld2atsDRA7iheKGoCuUgW23d+gfb8le/u4tc4gi3naV06M2Jxf8Yvxs4FpwWVGWb/LL2p0ubo6WdeBdpBk7VnAh6zqxeArAUgrOsOj7gBVqL0C8X4Y3n0xK1Dk76Xu0yO4MLiVYt7bNNCsJWVDY2B7cTpAZ7wmWLFyhOGpDURavT6jfog6oik09T2VgPe+ripoRTSQcfF0eg0ht3WMCFn/vymH5/JfVYv2Gzk5AQJJiL9ErNnvrYrlWs2qRe72vkQavNNq6UabDtWaWPMbIMu63caPkCxvsajp42R2Ry/wbz0hnxLP1aD+kGlqKj6bGL3TpagiBcVMHllD5DvjFXi7i6c5VUXLptLZFj+XBgEVPEkOuLYYPqBfIhdTnNF2VdJQ0njwKAMB0tk6u1sFLzVFtCA975OtNEfF4/KS+BA6vpMct0oXeH1RhluASKrvflq7NQNsMYobYAdlk7sCID44i026N7e6Oqu1pU4qtsgRfRSpmTBSE94FtJRua/hyOTjraEAO6Sgpw5ONVbyZY71cxuL5Gem5x1eyG6TtsMffz6kWdKAlb5proOXuywhbN5+a79D3B738+mky6aBc6e6dkulOoFhJILZHHuxh0Z7S7kLTjGFydgMRdrHpI0kc7uYQrtb9BU3ExADiI041Si6WM5jLZkQ0baT2nQ3jVAlXCRXZbcyjeMLCWqKlW0kvpPeCt5EOKRr831N+gDZdnzLkTBlbgn1Y6wwUQ2ABQpl1x4xjzeUWlP+TALd6anQ8RENdbDHk//SjaKFZozb0g662xOhD+4JH1+QQCRqUUj/olt9SZKROOi8tA7W0WZCnEu4yotcanNOMGWILBM0X1caTh2ul6bbnAOPhhcNcnwzSDKcM2H35ypuY2Te+a3Z5uxPS7Q1zj4oDYj4oeY2h+hjALNhpGmUrV9tDEsCY2S7ms/WxvvF5N6mecSosk19NqYQ
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:52Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4e9-8c68-4618-a45e-4be4950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:53.000Z",
"modified": "2016-03-11T15:31:53.000Z",
"pattern": "[file:name = 'uy78hn654e.exe' AND file:hashes.SHA1 = 'e235dd9f5b45088c378ee35b3c19fc9b981f5c36']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:53Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4ea-d720-48ef-b2a2-4f6f950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:54.000Z",
"modified": "2016-03-11T15:31:54.000Z",
"pattern": "[file:name = 'uy78hn654e.exe' AND file:hashes.SHA256 = 'a2b7ecf7285d8fb8331b543c2e521a942d3434450af828c2e3e89bb50a165830']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:54Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4eb-9d58-469b-abc6-4446950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:55.000Z",
"modified": "2016-03-11T15:31:55.000Z",
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIAPt7a0jj9AUQ4dIBAAD0BQAgABwAMTMxNzQzMTdhOWFjZDEwZjI0NGE2Yjg3NDc1YzQ4NjZVVAkAA+rk4lbq5OJWdXgLAAEEIQAAAAQhAAAAmhVjvrl2ool7LmYwVTTe9aJt4h2Ta0yt9eZF+6BB3K2dPW1bo2L7piKPxQYVexqIdWW90qyGgwprPtwp5ZZOCA7ciVc/RxfpQU75W3G5jKrZ1T39Rlk1npixAGGZprYo6YVcpi4W9W2GWlIJniF93mScDA400psU8Pzo5WuEhz4GllHkcyMrRlk3owkPgfhdKN4Wcx9SY4Mlpdla4uIGXCJ8IqrqR30TLtBMCzKWj+bk6+sUKpKC756DvedRZowVjHzFOkjhxJP1czAkwtScCqUdmYjjYq3bb1TpmxMka8XFQa3C9zkE9KXivBrTwjCeyacsmbzoudQsTgI49XRkSoP466J99mL5gLY8iXnlFhxYz1gZFYmAKKfjy0Ve0cktgNeo7M4gS3H/MiISoCv4rVuwoxD6gsSItYRLZFne90oTIYQBXgGB5BMLx4/YOHigI74g3z7FMAvMxR8iAHo/tlsMi9XqLNeh4+YP/2cjoSBK07hpkdEvxjjzMpP0yLw0LSeIKwkRKQl4GKjG+cObPNwQa1kpLnvIIws5PQ+3aSVvX+eglbuM8gwL7uP4N5L6H+m83zrCBg+uBhareJkD0Iq6huZ6bdvoglD73rd4W1CM4hHTAZj7r5h85cdAoo51pSNg5pYD9baxm/0ZIY4mnTynY+RxzUHfh/YLIiz5XY/41htPppRC332hbKxJLu1+n6vrd93Il8bSDBviEp45wwd/duhXmorqrJ2Xlux0oh2h4jc7OTmAp7qzoEyZDLizuy7eo0vvkKaMsnYoZwIqmUaOfgSC8iIC07RMfAwm6qkJODkH62s/HRlW4gFkd+oSDGxEBbQLwnQTFT04TuzlX7VwQzkN7QmNFyseZ9rRV/GNeA8Hse6CyznpEN/iQBIEWaQv3/bzb0aia2uIqcRrx91bhlLnphzg5NjA5caqrazbMLsSTbC/liDZCsb6jWWyppcLlTl13pnFo/LFNJCfisz0Wi1/bLtvlhnkgH0RH7/4RG52VHtyR+fzwO4gm4P1ddaL4DcsjvRLL9SR1dtf1NbvM4BjBBulLT6HPmASMngJcNSZRAcwKxlHUHv/TPsCB1E3wYKwkCWXUOKXbjQ7VjvotFpLXxi+Umpi9HRkFNFBDGghQPsXgijqbnRS8LPhz6uamS98gYCciri0kFiS8a9xvEZpJsLO9LeAJm6QBD9VrjIMxVVlZUD/K1XjjhEyJE1jUKf1ndJ9jFKqRG8AZp4QCdSIodWFyErT1pJ6oVW00Or8r7B/XZWtCTb5o/arxs58XCgizM8EOUOIoQ4fyJp5Wjze/I8YexF+Y2GvefpViSso/D7E1Qwu4+h4361dlJyLi1ic1NzfmKT6o+tvavUrpFAhpPqJZq0fnZ720wQ54Yzn7GTJuljarIod1LrPNYY23H/5eE2CWqRrJnqz5x+QyzQEzq30BtToSqssvX3woOo0NERla9JKYsBh6In9NAq8zWzScWWM5NpT8ZrLMtAb8C28jWmliS/4nj4t4ztRclLn1lEUQlIFAhZMheNPVNAEfyByKGt6ILuwNw/QMRtpXS/lt8UCp+vzQSFC5Fu2Obd0XHWjyVIlXnhJDfHsEW9DWva82Q6x7pWPmGlpSODRyYhHQyKUI1vCvsSlXIbAGmPM3DZ7XM1mkaaQvqmenDsywDxIR7QHbaa00WHdPnmHE0u0uovBHY1zzcf77ytA/yReq8y84iCwbd6pCVYOkmp9QhMQbc6YfQPaktu6MNlLI5tdqx3Z7WIUEkMCpsSTgpx8zb0+qLWSksFMCUoKtAcZlfCFgT1tFKWtPK0pYFQGxN7zAj6FZiGAdC4ulgBP+YYxRfq9TY4j37Rr3qYwuspWGklLN64snFCu9R2GSihrvGT0UKIG2QRE1zv5FfV4LGqcI7hn24M1RT+UM00LT5lBv+uv9LYmDbrVb+1/oN6r882Xikmpwni7wQ+X2z0u0pXGrAJ4CTjD9L+8Xe4/RwaM290AejVKD7rbJf6IMaf6Aas+heUrS15YOHTSBkaYHW01GEe4ZiCl6QtAFooTbsvWZNsoOH3hRpUC2ZlTKrrFFKwvh12JxP5rSWBhkJ3QNs6bpb+li3RQE3y6upInAtSTgvUjogmG/q6MFOWeuhArePGV2/x1fXnxNlObEK6tFrToMoH9maNxBqwxowAM+i5lc9cRlUrIvaOqlYNRScacc0/CVSuDYw/DBgkzQLwOsrJlbhaNZWTqKtPWQRBAKR+wVu/N/X7P8gJF+Dpl82tRYLGQiIgORhVe9OwElhDZLmixo+yQJNdZe2vLKvLMBOeCeKIA1I6tPYn657R58TDLcqZTibmJWKVT2Drtr88g3BlQwwTpnga6rs6HzYkNeI8ehD8d7gnC5kJHuabquzv2X4hIs3ozrmYB09VHNHPjyF1uAWNeiN/kkJwXVGI3A9n3X6vkMnl2mKVm6W8UroTcErHmWkr0ANDUfdW/DJ68ofiqWq+Ok3wF3pzQlGLZ7TrQnTp5qtYAMpYy0VaR8FP3NhMJ8WD6E0hknNsLTFeQl+EuTsoddmdsReCMVg7Szbofp4rjaTtPFwSgZi30lAtymKk9xE2ZbewTQvTXTEbsXHrViJBZ6BFY1vR0RruhzEWqkvHIyN2jhoV0XF2EQHzA98uCFLYz3gESIzxcBgINDw/iyvKy+YrM1pSTeTmApv2i4eoKkKYxsAx6VOl+5XPnt5cTp9dXhhx/aec/FtBfsGaWB+uCt+PJ65gFIEFgUhn0a5Td0ab6G9HVmLBVkv+KvQy5Pg/9rjpZvNZto85hyLamRCBhSFewjMx8ZMMafZEMf8dIpLEuE5hsNT3y+3mP1TKyjiJlTONhmfgVziNcecv7C9qYhr/Neet5RNW7pWZcWYnZGLqj1Jou6byOamaG+ti0GHJdcEvpPEVYWUMlm5I1jaPXGJWZwzdSlEpdFfeX5SoeCV0Kj9x35IOkDLL6UuGdyqmKNBHzviaCvVAwbsp3YSlXpE7qlA6Cn3apQ6cBwbA5TXsAb0K29BaXlD3XR60iBPbXzHMCHuptvrHZMHtNVW/RA0TUYx1lN6zjnTr6de0mefQC2rc9P7kCDocuZIzvtCFbCeYjm7kbx2NlXL52KJIFFTeE++Hej5V+SpskSuztzCtdbci+cykTpkY9FeyG/QQE5VM0cP1EyFt8ueq8UoNayzs6s60vquTkErJCMh/afXvBD9Tm/gCNYKZX9QyhgJXM8mjS6pEblj8boYxy0Os+8KX3DpS+zGVfDZ0/dk8gQUQnoySts/ywpldiu3syACoveB20lndsFEPDCQbcjIrD/8FK19WapjiqedcxtekAiO0o1mRU1QzJwLqzQleQACdkEf5Rfvft8t0qnHeMciAqmExq0JdVRCf4U1wQ/7JHJGPoInvM2fQxjjOf9l6f0wiUfBakKjS9ZK9ERXuNDv/1kaHwgCZiZo9dvy05ulbzTHVTIasJmnw15T76lf6iALWqXOx+xPuKCgW0AuW7X8Im84csO2KBG7eaiss6MnTa7T91klE4EEbol7Hlmj5AN66xcYYgIlrRx1F7udOAriKq6m0nvkqoHaGOFt0jAEc/KKqpkFd3uVwHHcLUqI5hzRPB4S4wObh2p28r6s4agFGFPhLusWTrC2EYbStBHrjxYK0B40LT5V9zLbpeg3/RHK2cTKPT28WDpPHjG7kJrXVxwS/O7boCfb1FanOrTb4RQpVuglY8bNRFxGE3VucvKj2s1pwE0IV+tRAnETk4WyHd7BKYW0RfLqJFckGiCiOxcyJqk33xSsHpg0NKDwrxuANjY1fdOdYgxxiyoKwhdHtjNyLBoFNltSyY0f3sLfwRsKFZFnnUuVIzTKiB/7z6O4bE0LsCuaR8wT3Pg4+q/nIpzWPg3rd/ObFCrw2e9WemhM8Wf6
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:55Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"malware-sample\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4eb-c684-47f4-b3b3-4e8d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:55.000Z",
"modified": "2016-03-11T15:31:55.000Z",
"pattern": "[file:name = 'uy78hn654e.exe.2' AND file:hashes.SHA1 = 'e25418fb175eeda2d30e8a8b981753bd8844f9b7']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:55Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e4ec-7d24-4e5d-9a92-429b950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:31:56.000Z",
"modified": "2016-03-11T15:31:56.000Z",
"pattern": "[file:name = 'uy78hn654e.exe.2' AND file:hashes.SHA256 = '7bcd80f4ba829652fcd4514585d00052ce8c8bdb48b3f7b651846de264bcba32']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:31:56Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2e6d5-0d80-4eeb-972a-4b00950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:40:05.000Z",
"modified": "2016-03-11T15:40:05.000Z",
"description": "Locky C&C",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '91.234.33.149']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:40:05Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81a-90a8-4300-b1ca-4f9402de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:30.000Z",
"modified": "2016-03-11T15:45:30.000Z",
"first_observed": "2016-03-11T15:45:30Z",
"last_observed": "2016-03-11T15:45:30Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81a-90a8-4300-b1ca-4f9402de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81a-90a8-4300-b1ca-4f9402de0b81",
"value": "https://www.virustotal.com/file/7bcd80f4ba829652fcd4514585d00052ce8c8bdb48b3f7b651846de264bcba32/analysis/1457707283/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81b-aa00-4883-98ed-40b402de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:31.000Z",
"modified": "2016-03-11T15:45:31.000Z",
"first_observed": "2016-03-11T15:45:31Z",
"last_observed": "2016-03-11T15:45:31Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81b-aa00-4883-98ed-40b402de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81b-aa00-4883-98ed-40b402de0b81",
"value": "https://www.virustotal.com/file/a2b7ecf7285d8fb8331b543c2e521a942d3434450af828c2e3e89bb50a165830/analysis/1457710845/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81b-4200-4cdd-bc5f-4cc602de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:31.000Z",
"modified": "2016-03-11T15:45:31.000Z",
"first_observed": "2016-03-11T15:45:31Z",
"last_observed": "2016-03-11T15:45:31Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81b-4200-4cdd-bc5f-4cc602de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81b-4200-4cdd-bc5f-4cc602de0b81",
"value": "https://www.virustotal.com/file/002f8158966ab89ef6e0c33bc79708653002af90c5f7685154813b4856169b54/analysis/1457707240/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81b-2068-4856-b447-42ca02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:31.000Z",
"modified": "2016-03-11T15:45:31.000Z",
"first_observed": "2016-03-11T15:45:31Z",
"last_observed": "2016-03-11T15:45:31Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81b-2068-4856-b447-42ca02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81b-2068-4856-b447-42ca02de0b81",
"value": "https://www.virustotal.com/file/717ab1f2d9b2a06474b6f6dd297b253e9ae6bced85ca319574269b71a4bb2e90/analysis/1457710513/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81c-64c0-4eaf-914f-4fde02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:32.000Z",
"modified": "2016-03-11T15:45:32.000Z",
"first_observed": "2016-03-11T15:45:32Z",
"last_observed": "2016-03-11T15:45:32Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81c-64c0-4eaf-914f-4fde02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81c-64c0-4eaf-914f-4fde02de0b81",
"value": "https://www.virustotal.com/file/bee14206aa3e443af592a6946671d191f878f2cb7ca04013704b8fd4014a4c3a/analysis/1457706127/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81c-fbd8-4201-b674-408602de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:32.000Z",
"modified": "2016-03-11T15:45:32.000Z",
"first_observed": "2016-03-11T15:45:32Z",
"last_observed": "2016-03-11T15:45:32Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81c-fbd8-4201-b674-408602de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81c-fbd8-4201-b674-408602de0b81",
"value": "https://www.virustotal.com/file/d0228c8adbf53f5a3a846e86f36617598aab6804ac8cd73a1a0bca672e550fea/analysis/1457707234/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81c-ecf8-4462-a8d1-4cd502de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:32.000Z",
"modified": "2016-03-11T15:45:32.000Z",
"first_observed": "2016-03-11T15:45:32Z",
"last_observed": "2016-03-11T15:45:32Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81c-ecf8-4462-a8d1-4cd502de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81c-ecf8-4462-a8d1-4cd502de0b81",
"value": "https://www.virustotal.com/file/c8747c602ae5b03174a9b5c77385438bae0d8d6704726e6fb7d1a5c4e767daf3/analysis/1457707231/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81c-dea8-4f73-bab3-402f02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:32.000Z",
"modified": "2016-03-11T15:45:32.000Z",
"first_observed": "2016-03-11T15:45:32Z",
"last_observed": "2016-03-11T15:45:32Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81c-dea8-4f73-bab3-402f02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81c-dea8-4f73-bab3-402f02de0b81",
"value": "https://www.virustotal.com/file/ade66be0355a4ea01f4a84241726f337a86be41da8b86348d04e68a99da74529/analysis/1457696058/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81d-2fc4-4455-b59c-47ec02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:33.000Z",
"modified": "2016-03-11T15:45:33.000Z",
"first_observed": "2016-03-11T15:45:33Z",
"last_observed": "2016-03-11T15:45:33Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81d-2fc4-4455-b59c-47ec02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81d-2fc4-4455-b59c-47ec02de0b81",
"value": "https://www.virustotal.com/file/a52738b57d91f92f70f7a24a65673182ed250de11c964383bf0c8095ff0a588a/analysis/1457700897/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81d-80a8-4b36-8ed0-426a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:33.000Z",
"modified": "2016-03-11T15:45:33.000Z",
"first_observed": "2016-03-11T15:45:33Z",
"last_observed": "2016-03-11T15:45:33Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81d-80a8-4b36-8ed0-426a02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81d-80a8-4b36-8ed0-426a02de0b81",
"value": "https://www.virustotal.com/file/11e8df42ed046221c90d81b93daeb46dd209abe35dee9048218f9f1ebd5275fd/analysis/1457708437/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81d-1500-465f-ad9c-480902de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:33.000Z",
"modified": "2016-03-11T15:45:33.000Z",
"first_observed": "2016-03-11T15:45:33Z",
"last_observed": "2016-03-11T15:45:33Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81d-1500-465f-ad9c-480902de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81d-1500-465f-ad9c-480902de0b81",
"value": "https://www.virustotal.com/file/abd224981a03fe7d254c7f0c4ac4411f0f23238a7c7d43fa22e650fdc09e6497/analysis/1457695022/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81e-acac-4460-9953-408702de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:34.000Z",
"modified": "2016-03-11T15:45:34.000Z",
"first_observed": "2016-03-11T15:45:34Z",
"last_observed": "2016-03-11T15:45:34Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81e-acac-4460-9953-408702de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81e-acac-4460-9953-408702de0b81",
"value": "https://www.virustotal.com/file/8df68a892f75722da88f2634551d8adec138b7d34a1a4ad2b992c180ef1f6307/analysis/1457696024/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81e-9090-4007-aa56-441802de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:34.000Z",
"modified": "2016-03-11T15:45:34.000Z",
"first_observed": "2016-03-11T15:45:34Z",
"last_observed": "2016-03-11T15:45:34Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81e-9090-4007-aa56-441802de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81e-9090-4007-aa56-441802de0b81",
"value": "https://www.virustotal.com/file/7ad984e6c4f170c82de77d8e0cb3026ddfb86e3d51f1d7168085ddb8ca2aac66/analysis/1457706097/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81e-c780-43b2-b23b-4f4002de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:34.000Z",
"modified": "2016-03-11T15:45:34.000Z",
"first_observed": "2016-03-11T15:45:34Z",
"last_observed": "2016-03-11T15:45:34Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81e-c780-43b2-b23b-4f4002de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81e-c780-43b2-b23b-4f4002de0b81",
"value": "https://www.virustotal.com/file/182a7d2e2744d6fee97a4aedba1bafbf1df9676f8d00af4841e89c665f933116/analysis/1457701072/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81f-73f8-46f7-a777-422602de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:35.000Z",
"modified": "2016-03-11T15:45:35.000Z",
"first_observed": "2016-03-11T15:45:35Z",
"last_observed": "2016-03-11T15:45:35Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81f-73f8-46f7-a777-422602de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81f-73f8-46f7-a777-422602de0b81",
"value": "https://www.virustotal.com/file/1a9d0655e2a4509fa89cbc842d5e0a8b472c2cf966cb619e36272fe12ea00546/analysis/1457707045/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81f-6094-404e-84ab-411702de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:35.000Z",
"modified": "2016-03-11T15:45:35.000Z",
"first_observed": "2016-03-11T15:45:35Z",
"last_observed": "2016-03-11T15:45:35Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81f-6094-404e-84ab-411702de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81f-6094-404e-84ab-411702de0b81",
"value": "https://www.virustotal.com/file/3204df9176fc0cf9e2b0a255076b125c69841673b96e2d9deab63c203b6e2977/analysis/1457708626/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81f-3584-4a61-be41-469a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:35.000Z",
"modified": "2016-03-11T15:45:35.000Z",
"first_observed": "2016-03-11T15:45:35Z",
"last_observed": "2016-03-11T15:45:35Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81f-3584-4a61-be41-469a02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81f-3584-4a61-be41-469a02de0b81",
"value": "https://www.virustotal.com/file/873fb560250755555e2530a4c9a58553b1aea9d52fc4282e5547edc20fbededa/analysis/1457706186/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e81f-7d6c-45fb-9b37-472902de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:35.000Z",
"modified": "2016-03-11T15:45:35.000Z",
"first_observed": "2016-03-11T15:45:35Z",
"last_observed": "2016-03-11T15:45:35Z",
"number_observed": 1,
"object_refs": [
"url--56e2e81f-7d6c-45fb-9b37-472902de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e81f-7d6c-45fb-9b37-472902de0b81",
"value": "https://www.virustotal.com/file/b92aa998fe6fe5667bd5418ee1f7773bc4d9634d9fcff440ab78e66d6c58d036/analysis/1457705390/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e820-1ba8-4942-a756-4be502de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:36.000Z",
"modified": "2016-03-11T15:45:36.000Z",
"first_observed": "2016-03-11T15:45:36Z",
"last_observed": "2016-03-11T15:45:36Z",
"number_observed": 1,
"object_refs": [
"url--56e2e820-1ba8-4942-a756-4be502de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e820-1ba8-4942-a756-4be502de0b81",
"value": "https://www.virustotal.com/file/1510b2e001378f1a1a7ed5582a35f89269d6d32bf8e23f13a06f3f9f131fc4a3/analysis/1457709939/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e820-da2c-468b-b1bd-410902de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:36.000Z",
"modified": "2016-03-11T15:45:36.000Z",
"first_observed": "2016-03-11T15:45:36Z",
"last_observed": "2016-03-11T15:45:36Z",
"number_observed": 1,
"object_refs": [
"url--56e2e820-da2c-468b-b1bd-410902de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e820-da2c-468b-b1bd-410902de0b81",
"value": "https://www.virustotal.com/file/a2e54950817f09e61a655f90e16a20781e138a926bf7e0557a62741840b07317/analysis/1457703268/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e820-09f0-4552-b12a-440902de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:36.000Z",
"modified": "2016-03-11T15:45:36.000Z",
"first_observed": "2016-03-11T15:45:36Z",
"last_observed": "2016-03-11T15:45:36Z",
"number_observed": 1,
"object_refs": [
"url--56e2e820-09f0-4552-b12a-440902de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e820-09f0-4552-b12a-440902de0b81",
"value": "https://www.virustotal.com/file/c33babaf1e100437a8eac1dc30be2176f3ff775ef195b7f8a16577725b6574a0/analysis/1457709938/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e821-9d78-4838-b5e6-408f02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:37.000Z",
"modified": "2016-03-11T15:45:37.000Z",
"first_observed": "2016-03-11T15:45:37Z",
"last_observed": "2016-03-11T15:45:37Z",
"number_observed": 1,
"object_refs": [
"url--56e2e821-9d78-4838-b5e6-408f02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e821-9d78-4838-b5e6-408f02de0b81",
"value": "https://www.virustotal.com/file/0a884c6fbe5314727a24b65eb1196a8d59ceae4b57ca237f4c5c974673545696/analysis/1457709938/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e821-095c-4a0b-b4ef-4f5a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:37.000Z",
"modified": "2016-03-11T15:45:37.000Z",
"first_observed": "2016-03-11T15:45:37Z",
"last_observed": "2016-03-11T15:45:37Z",
"number_observed": 1,
"object_refs": [
"url--56e2e821-095c-4a0b-b4ef-4f5a02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e821-095c-4a0b-b4ef-4f5a02de0b81",
"value": "https://www.virustotal.com/file/f365ae19431e7accfcd0d9977fb52cc288fc5f4b39c63f483105c8d5ee3cbea0/analysis/1457709938/"
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--56e2e821-9934-4c65-89a8-470802de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:45:37.000Z",
"modified": "2016-03-11T15:45:37.000Z",
"first_observed": "2016-03-11T15:45:37Z",
"last_observed": "2016-03-11T15:45:37Z",
"number_observed": 1,
"object_refs": [
"url--56e2e821-9934-4c65-89a8-470802de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--56e2e821-9934-4c65-89a8-470802de0b81",
"value": "https://www.virustotal.com/file/3f789e86a91efa6409a60728a05dedf950443f5a75d2cb658f84ca4db0ba9a4a/analysis/1457704747/"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2eb45-a1e4-44ed-81e4-40c3950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:59:01.000Z",
"modified": "2016-03-11T15:59:01.000Z",
"description": "Automatically added (via 08h867g5|7f55862138081352125e9b60a27a06c3b39d8523)",
"pattern": "[file:name = '08h867g5' AND file:hashes.MD5 = '30c8f7bfab3fdcddb7865bae48ce08e1']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:59:01Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2eb48-5f18-4a0a-b81c-6599950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:59:04.000Z",
"modified": "2016-03-11T15:59:04.000Z",
"description": "Automatically added (via 32tguynjk|2acd98f82297e0aba7c9cbd79554ca0dc84ebc73)",
"pattern": "[file:name = '32tguynjk' AND file:hashes.MD5 = '5618525d0aaf0ee471a3be5842617206']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:59:04Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2eb49-9c00-4b81-811e-4f32950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:59:05.000Z",
"modified": "2016-03-11T15:59:05.000Z",
"description": "Automatically added (via 80.exe|d597de857c14af220249c2681d9e38a46ab719fa)",
"pattern": "[file:name = '80.exe' AND file:hashes.MD5 = '63ce4ebbe5198f572e84f45ea4c12b07']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:59:05Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56e2eb4b-3ee0-4eaa-9e3f-410c950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-03-11T15:59:07.000Z",
"modified": "2016-03-11T15:59:07.000Z",
"description": "Automatically added (via uy78hn654e.exe|e235dd9f5b45088c378ee35b3c19fc9b981f5c36)",
"pattern": "[file:name = 'uy78hn654e.exe' AND file:hashes.MD5 = 'b7ad2aa2fab8aa889ad3b8cb715e5456']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-03-11T15:59:07Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"filename|md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "marking-definition",
"spec_version": "2.1",
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
"created": "2017-01-20T00:00:00.000Z",
"definition_type": "tlp",
"name": "TLP:WHITE",
"definition": {
"tlp": "white"
}
}
2023-04-21 13:25:09 +00:00
]
}