2023-04-21 13:25:09 +00:00
{
2023-06-14 17:31:25 +00:00
"type" : "bundle" ,
"id" : "bundle--58806a6c-14a4-49a9-8d6c-49e6950d210f" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:47.000Z" ,
"modified" : "2017-01-19T07:53:47.000Z" ,
"name" : "CIRCL" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--58806a6c-14a4-49a9-8d6c-49e6950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:47.000Z" ,
"modified" : "2017-01-19T07:53:47.000Z" ,
"name" : "OSINT - Uncovering the Inner Workings of EyePyramid" ,
"published" : "2017-01-19T08:07:15Z" ,
"object_refs" : [
"x-misp-attribute--58806a7b-5040-4706-8eaf-4e44950d210f" ,
"observed-data--58806a8c-4008-48f2-8de3-4842950d210f" ,
"url--58806a8c-4008-48f2-8de3-4842950d210f" ,
"x-misp-attribute--58806c1b-a244-41a1-9bbf-4532950d210f" ,
"x-misp-attribute--58806c1c-bb6c-40f4-92d0-433b950d210f" ,
"x-misp-attribute--58806c1d-49cc-4664-8c7d-428d950d210f" ,
"x-misp-attribute--58806c1e-0a40-4830-bdb0-424b950d210f" ,
"x-misp-attribute--58806c1f-b1a8-4261-b7a8-4a08950d210f" ,
"x-misp-attribute--58806c1f-95b8-4c6d-b981-4e0a950d210f" ,
"x-misp-attribute--58806c20-91b0-45df-b625-412c950d210f" ,
"x-misp-attribute--58806c21-2540-48fd-b445-40b4950d210f" ,
"x-misp-attribute--58806c22-0390-488d-bfb9-415e950d210f" ,
"x-misp-attribute--58806c23-9c98-4b91-9120-454d950d210f" ,
"x-misp-attribute--58806c24-4134-4bc3-9c5a-4fe7950d210f" ,
"x-misp-attribute--58806c57-ddb0-4a50-851d-454c950d210f" ,
"indicator--58806cb6-2af8-4192-90f9-4f10950d210f" ,
"observed-data--58806cf9-7a5c-467f-bea2-41ab950d210f" ,
"file--58806cf9-7a5c-467f-bea2-41ab950d210f" ,
"artifact--58806cf9-7a5c-467f-bea2-41ab950d210f" ,
"indicator--58806da6-5f00-4e00-871d-4cdd950d210f" ,
"observed-data--58806df2-9f50-44e7-85e2-42a5950d210f" ,
"file--58806df2-9f50-44e7-85e2-42a5950d210f" ,
"artifact--58806df2-9f50-44e7-85e2-42a5950d210f" ,
"indicator--58806e4a-0990-4e82-b7d2-4b14950d210f" ,
"indicator--58806e4b-0acc-4f4c-8073-43d1950d210f" ,
"indicator--58806e4b-25ac-4bd6-a0b9-46c8950d210f" ,
"indicator--58806e4c-3f68-409f-aa6a-4b33950d210f" ,
"indicator--58806e4d-148c-4308-b2e1-4d98950d210f" ,
"indicator--58806e4e-b3e4-4f18-9a79-4931950d210f" ,
"indicator--58806e4f-db9c-42ca-9ff4-4ff5950d210f" ,
"indicator--58806e50-a450-4989-8cc0-4f48950d210f" ,
"indicator--58806e51-89e4-463c-b283-4703950d210f" ,
"indicator--58806e51-886c-4da1-87d3-4032950d210f" ,
"indicator--58806e52-d2d0-4a2b-9cb9-428f950d210f" ,
"indicator--58806e53-07f8-4bdc-b554-46c6950d210f" ,
"indicator--58806e54-beb0-45c1-81af-4638950d210f" ,
"indicator--58806e55-0568-4c64-b4cd-4782950d210f" ,
"indicator--58806e56-72e0-4602-81cb-4356950d210f" ,
"indicator--58806e56-400c-4f3c-b727-4b4e950d210f" ,
"indicator--58806e7f-11e0-411a-adf0-497a950d210f" ,
"indicator--58806e80-ee2c-48e1-b25c-494d950d210f" ,
"indicator--58806e81-ba68-4cfb-a12c-4edc950d210f" ,
"indicator--58806e81-4664-4964-9817-4847950d210f" ,
"indicator--58806fd4-f158-41a6-bad8-46c3950d210f" ,
"indicator--58806fd5-ae40-4b64-a154-4c7b950d210f" ,
"indicator--58806fd6-af4c-4467-86bf-429d950d210f" ,
"indicator--58806fd7-424c-45a5-b1c3-4e88950d210f" ,
"indicator--58806fd7-18c0-4ca5-b2e2-4e88950d210f" ,
"indicator--58806fd8-85c4-4455-903a-47b7950d210f" ,
"indicator--58806fd9-a310-4e87-b4fb-4eaa950d210f" ,
"indicator--58806fda-01c4-473b-aaf6-4d45950d210f" ,
"indicator--58806fdb-168c-4c83-8e3c-4c92950d210f" ,
"indicator--58806fdc-a3f4-4be0-8fb3-4a8f950d210f" ,
"indicator--58806fdd-3744-4672-bd97-40df950d210f" ,
"indicator--58806fde-249c-4132-ad29-4cfe950d210f" ,
"indicator--58806fde-85e0-4f67-b8dd-4355950d210f" ,
"indicator--58806fdf-1b18-4b72-8947-4979950d210f" ,
"indicator--58806ff5-5330-4f91-8468-42f602de0b81" ,
"indicator--58806ff6-1afc-4b7c-b9c9-47de02de0b81" ,
"observed-data--58806ff6-889c-407f-b3b2-401902de0b81" ,
"url--58806ff6-889c-407f-b3b2-401902de0b81" ,
"indicator--58806ff7-2504-4521-bbb3-4a3d02de0b81" ,
"indicator--58806ff8-0868-4e2b-959a-42e402de0b81" ,
"observed-data--58806ff8-af9c-47f3-882f-4ace02de0b81" ,
"url--58806ff8-af9c-47f3-882f-4ace02de0b81" ,
"indicator--58807084-6eec-49b2-b5bb-4715950d210f" ,
"indicator--58807084-8600-417b-9bf2-47fb950d210f" ,
"indicator--58807085-f248-4cf5-9a5f-4666950d210f" ,
"indicator--58807086-775c-4aeb-a65a-4898950d210f" ,
"indicator--58807086-53a0-4a37-bf8f-4b83950d210f" ,
"indicator--58807087-4370-4e79-b2ee-4bce950d210f" ,
"indicator--58807088-8d4c-4489-9df2-4d14950d210f" ,
"indicator--58807089-4074-41eb-ad4b-4e1e950d210f" ,
"indicator--58807089-8f08-4b3b-9ac0-403c950d210f" ,
"indicator--5880708a-3e68-48f3-8aba-4df5950d210f"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"misp-galaxy:tool=\" EyePyramid Malware\""
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806a7b-5040-4706-8eaf-4e44950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:27:55.000Z" ,
"modified" : "2017-01-19T07:27:55.000Z" ,
"labels" : [
"misp:type=\"text\"" ,
"misp:category=\"External analysis\""
] ,
"x_misp_category" : "External analysis" ,
"x_misp_type" : "text" ,
"x_misp_value" : "Two Italians referred to as the \u00e2\u20ac\u0153Occhionero brothers\u00e2\u20ac\u009d have been arrested and accused of using malware and a carefully-prepared spear-phishing scheme to spy on high-profile politicians and businessmen. This case has been called \u00e2\u20ac\u0153EyePyramid\u00e2\u20ac\u009d, which we first discussed last week. (Conspiracy theories aside, the name came from a domain name and directory path that was found during the research.)\r\n\r\nThe court order was published by AGI, an Italian news agency, around noon on January 11. It (surprisingly) contains multiple technical details which we used to bootstrap our initial analysis. This post builds on the details of the case to provide a more complete and in-depth view of the activities of this campaign.\r\n\r\nScope of this analysis\r\n\r\nWe have analyzed nearly 250 distinct samples, with new batches of EyePryramid-related samples seen and identified daily. Right after our initial analysis, about a dozen suspicious samples were uploaded to VirusTotal and tagged as \u00e2\u20ac\u0153#eyepyramid\u00e2\u20ac\u009d. We believe that these samples are \u00e2\u20ac\u0153false flags,\u00e2\u20ac\u009d because the samples do not resemble any of the samples that we were able to definitely relate to the EyePyramid case. Although we are not able to say with 100% certainty that there are no relationships between these \u00e2\u20ac\u0153false flags\u00e2\u20ac\u009d and the original EyePyramid samples, we purposely did not focus on these uploaded samples."
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--58806a8c-4008-48f2-8de3-4842950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:28:12.000Z" ,
"modified" : "2017-01-19T07:28:12.000Z" ,
"first_observed" : "2017-01-19T07:28:12Z" ,
"last_observed" : "2017-01-19T07:28:12Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--58806a8c-4008-48f2-8de3-4842950d210f"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--58806a8c-4008-48f2-8de3-4842950d210f" ,
"value" : "http://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-inner-workings-eyepyramid"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c1b-a244-41a1-9bbf-4532950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:51.000Z" ,
"modified" : "2017-01-19T07:34:51.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\Projects\\VS2005\\ChromePass\\Release\\ChromePass.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c1c-bb6c-40f4-92d0-433b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:52.000Z" ,
"modified" : "2017-01-19T07:34:52.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\Projects\\VS2005\\MyLastSearch\\release\\MyLastSearch.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c1d-49cc-4664-8c7d-428d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:53.000Z" ,
"modified" : "2017-01-19T07:34:53.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\Projects\\VS2005\\NK2View\\Release\\NK2View.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c1e-0a40-4830-bdb0-424b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:54.000Z" ,
"modified" : "2017-01-19T07:34:54.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\Projects\\VS2005\\ProduKey\\Release\\ProduKey.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c1f-b1a8-4261-b7a8-4a08950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:55.000Z" ,
"modified" : "2017-01-19T07:34:55.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\Projects\\VS2005\\RecentFilesView\\Release\\RecentFilesView.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c1f-95b8-4c6d-b981-4e0a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:55.000Z" ,
"modified" : "2017-01-19T07:34:55.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\Projects\\VS2005\\USBDeview\\Release\\USBDeview.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c20-91b0-45df-b625-412c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:56.000Z" ,
"modified" : "2017-01-19T07:34:56.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\Projects\\VS2005\\WirelessKeyView\\Release\\WirelessKeyView.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c21-2540-48fd-b445-40b4950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:57.000Z" ,
"modified" : "2017-01-19T07:34:57.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\Projects\\VS2005\\mspass\\Release\\mspass.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c22-0390-488d-bfb9-415e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:58.000Z" ,
"modified" : "2017-01-19T07:34:58.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\Projects\\VS2005\\netpass\\Release\\netpass.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c23-9c98-4b91-9120-454d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:34:59.000Z" ,
"modified" : "2017-01-19T07:34:59.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\projects\\VS2005\\iepv\\Release\\iepv.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c24-4134-4bc3-9c5a-4fe7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:35:00.000Z" ,
"modified" : "2017-01-19T07:35:00.000Z" ,
"labels" : [
"misp:type=\"pdb\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Artifacts dropped" ,
"x_misp_comment" : "paths or library names indicating code reuse of specific components" ,
"x_misp_type" : "pdb" ,
"x_misp_value" : ":\\projects\\vs2005\\shortcutsman\\release\\shman.pdb"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--58806c57-ddb0-4a50-851d-454c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:35:51.000Z" ,
"modified" : "2017-01-19T07:35:51.000Z" ,
"labels" : [
"misp:type=\"text\"" ,
"misp:category=\"Attribution\""
] ,
"x_misp_category" : "Attribution" ,
"x_misp_comment" : "Both the 2010 and 2012 versions share the infamous MN600-D8102F401003102110C5114F1F18-0E8C MailBee license key, which was either purchased by Giulio Occhionero, or purchased using his name." ,
"x_misp_type" : "text" ,
"x_misp_value" : "MN600-D8102F401003102110C5114F1F18-0E8C"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806cb6-2af8-4192-90f9-4f10950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:37:26.000Z" ,
"modified" : "2017-01-19T07:37:26.000Z" ,
"description" : "Although used for debugging only, we found that the malware author was playing around with email-based cross-site scripting, as can be seen from the following code snippet" ,
"pattern" : "[file:hashes.SHA256 = '21b6f2584485b8bbfffdefd45c1c72dc2133290fd8cefb235eb39cf015550316']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:37:26Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--58806cf9-7a5c-467f-bea2-41ab950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:38:33.000Z" ,
"modified" : "2017-01-19T07:38:33.000Z" ,
"first_observed" : "2017-01-19T07:38:33Z" ,
"last_observed" : "2017-01-19T07:38:33Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--58806cf9-7a5c-467f-bea2-41ab950d210f" ,
"artifact--58806cf9-7a5c-467f-bea2-41ab950d210f"
] ,
"labels" : [
"misp:type=\"attachment\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--58806cf9-7a5c-467f-bea2-41ab950d210f" ,
"name" : "EyePyramid_15-01.jpg" ,
"content_ref" : "artifact--58806cf9-7a5c-467f-bea2-41ab950d210f"
} ,
{
"type" : "artifact" ,
"spec_version" : "2.1" ,
"id" : "artifact--58806cf9-7a5c-467f-bea2-41ab950d210f" ,
"payload_bin" : " / 9 j / 4 A A Q S k Z J R g A B A g E A k A C Q A A D / 7 Q A s U G h v d G 9 z a G 9 w I D M u M A A 4 Q k l N A + 0 A A A A A A B A A k A A A A A E A A Q C Q A A A A A Q A B / + F m m m h 0 d H A 6 L y 9 u c y 5 h Z G 9 i Z S 5 j b 20 v e G F w L z E u M C 8 A P D 94 c G F j a 2 V 0 I G J l Z 2 l u P S L v u 78 i I G l k P S J X N U 0 w T X B D Z W h p S H p y Z V N 6 T l R j e m t j O W Q i P z 4 K P H g 6 e G 1 w b W V 0 Y S B 4 b W x u c z p 4 P S J h Z G 9 i Z T p u c z p t Z X R h L y I g e D p 4 b X B 0 a z 0 i Q W R v Y m U g W E 1 Q I E N v c m U g N S 4 z L W M w M T E g N j Y u M T Q 1 N j Y x L C A y M D E y L z A y L z A 2 L T E 0 O j U 2 O j I 3 I C A g I C A g I C A i P g o g I C A 8 c m R m O l J E R i B 4 b W x u c z p y Z G Y 9 I m h 0 d H A 6 L y 93 d 3 c u d z M u b 3 J n L z E 5 O T k v M D I v M j I t c m R m L X N 5 b n R h e C 1 u c y M i P g o g I C A g I C A 8 c m R m O k R l c 2 N y a X B 0 a W 9 u I H J k Z j p h Y m 91 d D 0 i I g o g I C A g I C A g I C A g I C B 4 b W x u c z p k Y z 0 i a H R 0 c D o v L 3 B 1 c m w u b 3 J n L 2 R j L 2 V s Z W 1 l b n R z L z E u M S 8 i P g o g I C A g I C A g I C A 8 Z G M 6 Z m 9 y b W F 0 P m l t Y W d l L 2 p w Z W c 8 L 2 R j O m Z v c m 1 h d D 4 K I C A g I C A g I C A g P G R j O n R p d G x l P g o g I C A g I C A g I C A g I C A 8 c m R m O k F s d D 4 K I C A g I C A g I C A g I C A g I C A g P H J k Z j p s a S B 4 b W w 6 b G F u Z z 0 i e C 1 k Z W Z h d W x 0 I j 5 k Z 20 t Y X B r L W Z p b G U 8 L 3 J k Z j p s a T 4 K I C A g I C A g I C A g I C A g P C 9 y Z G Y 6 Q W x 0 P g o g I C A g I C A g I C A 8 L 2 R j O n R p d G x l P g o g I C A g I C A 8 L 3 J k Z j p E Z X N j c m l w d G l v b j 4 K I C A g I C A g P H J k Z j p E Z X N j c m l w d G l v b i B y Z G Y 6 Y W J v d X Q 9 I i I K I C A g I C A g I C A g I C A g e G 1 s b n M 6 e G 1 w P S J o d H R w O i 8 v b n M u Y W R v Y m U u Y 29 t L 3 h h c C 8 x L j A v I g o g I C A g I C A g I C A g I C B 4 b W x u c z p 4 b X B H S W 1 n P S J o d H R w O i 8 v b n M u Y W R v Y m U u Y 29 t L 3 h h c C 8 x L j A v Z y 9 p b W c v I j 4 K I C A g I C A g I C A g P H h t c D p D c m V h d G 9 y V G 9 v b D 5 B Z G 9 i Z S B J b G x 1 c 3 R y Y X R v c i B D U z Y g K F d p b m R v d 3 M p P C 94 b X A 6 Q 3 J l Y X R v c l R v b 2 w + C i A g I C A g I C A g I D x 4 b X A 6 Q 3 J l Y X R l R G F 0 Z T 4 y M D E 3 L T A x L T E 4 V D I y O j I y O j M 5 K z A 4 O j A w P C 94 b X A 6 Q 3 J l Y X R l R G F 0 Z T 4 K I C A g I C A g I C A g P H h t c D p N b 2 R p Z n l E Y X R l P j I w M T c t M D E t M T h U M T Q 6 M j I 6 N D B a P C 94 b X A 6 T W 9 k a W Z 5 R G F 0 Z T 4 K I C A g I C A g I C A g P H h t c D p N Z X R h Z G F 0 Y U R h d G U + M j A x N y 0 w M S 0 x O F Q y M j o y M j o z O S s w O D o w M D w v e G 1 w O k 1 l d G F k Y X R h R G F 0 Z T 4 K I C A g I C A g I C A g P H h t c D p U a H V t Y m 5 h a W x z P g o g I C A g I C A g I C A g I C A 8 c m R m O k F s d D 4 K I C A g I C A g I C A g I C A g I C A g P H J k Z j p s a S B y Z G Y 6 c G F y c 2 V U e X B l P S J S Z X N v d X J j Z S I + C i A g I C A g I C A g I C A g I C A g I C A g I D x 4 b X B H S W 1 n O n d p Z H R o P j I 1 N j w v e G 1 w R 0 l t Z z p 3 a W R 0 a D 4 K I C A g I C A g I C A g I C A g I C A g I C A g P H h t c E d J b W c 6 a G V p Z 2 h 0 P j E 5 M j w v e G 1 w R 0 l t Z z p o Z W l n a H Q + C i A g I C A g I C A g I C A g I C A g I C A g I D x 4 b X B H S W 1 n O m Z v c m 1 h d D 5 K U E V H P C 94 b X B H S W 1 n O m Z v c m 1 h d D 4 K I C A g I C A g I C A g I C A g I C A g I C A g P H h t c E d J b W c 6 a W 1 h Z 2 U + L z l q L z R B Q V F T a 1 p K U m d B Q k F n R U F r Q U N R Q U F E L z d R Q X N V R 2 h 2 Z E c 5 e m F H O X d J R E 11 T U F B N F F r b E 5 B K z B B Q U F B Q U F C Q U F r Q U F B Q U F F Q S Y j e E E 7 Q V F D U U F B Q U F B U U F C L y t J T V d F b E R R M T l R V W s 5 R 1 N V e E Z B Q U V C Q U F B T V N F e H B i b T h D R U F B Q W J X N T B j b E p I U W l C W V d W b 2 d C O D R B Q W d B S i Y j e E E 7 Q U F Z Q U 1 R Q U F Z V 0 56 Y 0 U x V F J s U U F B Q U F B U 1 V W R E l I T l N S M E l B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F Q Y l d B Q U V B Q U F B Q T B 5 M U l V Q 0 F n Q U F B Q S Y j e E E 7 Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F S W T N C e W R B Q U F B V k F B Q U F B e i Y j e E E 7 W k d W e l l 3 Q U F B W V F B Q U F C c 2 Q z U n d k Q U F B Q W Z B Q U F B Q V V Z b X R 3 Z E F B Q U F n U U F B Q U F V Y 2 x o W l d n Q U F B a G d B Q U F B V V o x a F p X Z 0 F B Q W l 3 Q S Y j e E E 7 Q U F B V V l s a F p X Z 0 F B Q W t B Q U F B Q V V a R z F 1 W k F B Q U F s U U F B Q U J 3 W k c x a 1 p B Q U F B c 1 F B Q U F D S W R u V m x a Q U F B Q T B 3 Q U F B Q 0 d k b W x s Z H d B Q S Y j e E E 7 Q T l R Q U F B Q W t i S F Z 0 Y V F B Q U E v Z 0 F B Q U F V Y l d W a G N 3 Q U F C Q X d B Q U F B a 2 R H V m p h Q U F B Q k R B Q U F B Q U 1 j b F J T U X d B Q U J E d 0 F B Q W d N W j F S U y Y j e E E 7 U X d B Q U J E d 0 F B Q W d N W W x S U 1 F 3 Q U F C R H d B Q U F n T W R H V j R k Q U F B Q U F C R G I z Q j V j b W x u Y U h R Z 0 t H T X B J R E U 1 T 1 R n Z 1 N H V j N i R 1 Y w Z E M x U S Y j e E E 7 W V d O c l l Y S m t J R U 52 Y l h C a G J u a 0 F B R 1 J s Y z J N Q U F B Q U F B Q U F B R W 5 O U 1 I w S W d T V V Z E T m p F N U 5 q W X R N a T R 4 Q U F B Q U F B Q U F B Q U F B Q U F B U y Y j e E E 7 Y z F K S F F p Q k p S V U 0 y T V R r M k 5 p M H l M a k V B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q S Y j e E E 7 Q U F B Q U F B Q U F B Q U F B Q U Z o W l d p Q U F B Q U F B Q U F E e l V R Q U J B Q U F B Q V J i T V d G b G F J Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q l l X V m 9 n Q U F B Q S Y j e E E 7 Q U F B Q W I 2 S U F B R G o x Q U F B R G t G a F p X a U F B Q U F B Q U F B Q m l t U U F B d D R V Q U F C a m F X R m x h S U F B Q U F B Q U F B Q 1 N n Q U F B U G h B Q U F 0 c z l r W l h O a i Y j e E E 7 Q U F B Q U F B Q U F B Q l p K U l V N Z 2 F I U j B j R G 92 T D N k M 2 R 5 N X B a V 0 11 W T J n Q U F B Q U F B Q U F B Q U F B Q U F C W k p S V U 1 n Y U h S M G N E b 3 Z M M 2 Q z Z H k 1 c C Y j e E E 7 W l d N d V k y Z 0 F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F a R 1 Z 6 W X d B Q S Y j e E E 7 Q U F B Q U F B Q X V T V V Z E S U R Z e E 9 U W T J M V E l 1 T V N C R V p X W m h k V 3 g w S U Z K S F F p Q m p i M n h 2 Z F h J Z 2 M z Q m h Z M l V n T F N C e l V r Z E N B Q U F B Q U F B Q S Y j e E E 7 Q U F B Q U F B Q X V T V V Z E S U R Z e E 9 U W T J M V E l 1 T V N C R V p X W m h k V 3 g w S U Z K S F F p Q m p i M n h 2 Z F h J Z 2 M z Q m h Z M l V n T F N C e l V r Z E N B Q U F B Q U F B Q S Y j e E E 7 Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B R 1 J s Y z J N Q U F B Q U F B Q U F B T E Z K b F p t V n l a V z V q W l N C V 2 F X V j N h V z V u S U V O d m J t U n B k R 2 x 2 Y m l C c C Y j e E E 7 Y m l C S l J V T T J N V G s y T m k w e U x q R U F B Q U F B Q U F B Q U F B Q U F B Q 3 h T W l d a b G N t V n V Z M l V n V m 1 s b G Q y b H V a e U J E Y j I 1 a 2 F Y U n B i M j R n Y V c 0 Z y Y j e E E 7 U 1 V W R E 5 q R T V O a l l 0 T W k 0 e E F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F B Q U F C M m F X V j N B Q U F B Q U F B V H B Q N E F G R j h 1 Q U J E U C Y j e E E 7 R k F B R D d j d 0 F C Q k 1 M Q U F O Y 25 n Q U F B Q U Z Z V 1 Z v Z 0 F B Q U F B Q U J N Q 1 Z Z Q V V B Q U F B R m N m N T I x b F l Y T U F B Q U F B Q U F B Q U F R Q U F B Q U F B Q U F B Q S Y j e E E 7 Q U F B Q U F B Q U F B Q U F B Q U F L U E F B Q U F B b k 5 w W n l B Q U F B Q U F R M U p V S U d O M W N u W U F B Q U F B Q U F B R U F B Q U F B Q V V
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806da6-5f00-4e00-871d-4cdd950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:41:26.000Z" ,
"modified" : "2017-01-19T07:41:26.000Z" ,
"pattern" : "[file:hashes.SHA256 = 'd3ad32bcb255e56cd2a768b3cbf6bafda88233288fc6650d0dfa3810be75f74c']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:41:26Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--58806df2-9f50-44e7-85e2-42a5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:42:42.000Z" ,
"modified" : "2017-01-19T07:42:42.000Z" ,
"first_observed" : "2017-01-19T07:42:42Z" ,
"last_observed" : "2017-01-19T07:42:42Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--58806df2-9f50-44e7-85e2-42a5950d210f" ,
"artifact--58806df2-9f50-44e7-85e2-42a5950d210f"
] ,
"labels" : [
"misp:type=\"attachment\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--58806df2-9f50-44e7-85e2-42a5950d210f" ,
"name" : "Appendix_uncovering-the-inner-workings-of-eyepyramid.pdf" ,
"content_ref" : "artifact--58806df2-9f50-44e7-85e2-42a5950d210f"
} ,
{
"type" : "artifact" ,
"spec_version" : "2.1" ,
"id" : "artifact--58806df2-9f50-44e7-85e2-42a5950d210f" ,
"payload_bin" : " J V B E R i 0 x L j U N C i W 1 t b W 1 D Q o x I D A g b 2 J q D Q o 8 P C 9 U e X B l L 0 N h d G F s b 2 c v U G F n Z X M g M i A w I F I v T G F u Z y h l b i 1 V U y k g L 1 N 0 c n V j d F R y Z W V S b 290 I D Q x I D A g U i 9 N Y X J r S W 5 m b z w 8 L 0 1 h c m t l Z C B 0 c n V l P j 4 + P g 0 K Z W 5 k b 2 J q D Q o y I D A g b 2 J q D Q o 8 P C 9 U e X B l L 1 B h Z 2 V z L 0 N v d W 50 I D g v S 2 l k c 1 s g M y A w I F I g M T A g M C B S I D E 5 I D A g U i A y M y A w I F I g M j U g M C B S I D I 3 I D A g U i A y O S A w I F I g M z Y g M C B S X S A + P g 0 K Z W 5 k b 2 J q D Q o z I D A g b 2 J q D Q o 8 P C 9 U e X B l L 1 B h Z 2 U v U G F y Z W 50 I D I g M C B S L 1 J l c 291 c m N l c z w 8 L 1 h P Y m p l Y 3 Q 8 P C 9 J b W F n Z T U g N S A w I F I + P i 9 G b 250 P D w v R j E g N i A w I F I v R j I g O C A w I F I + P i 9 Q c m 9 j U 2 V 0 W y 9 Q R E Y v V G V 4 d C 9 J b W F n Z U I v S W 1 h Z 2 V D L 0 l t Y W d l S V 0 g P j 4 v T W V k a W F C b 3 h b I D A g M C A 2 M T I g N z k y X S A v Q 29 u d G V u d H M g N C A w I F I v R 3 J v d X A 8 P C 9 U e X B l L 0 d y b 3 V w L 1 M v V H J h b n N w Y X J l b m N 5 L 0 N T L 0 R l d m l j Z V J H Q j 4 + L 1 R h Y n M v U y 9 T d H J 1 Y 3 R Q Y X J l b n R z I D A + P g 0 K Z W 5 k b 2 J q D Q o 0 I D A g b 2 J q D Q o 8 P C 9 G a W x 0 Z X I v R m x h d G V E Z W N v Z G U v T G V u Z 3 R o I D c z O T 4 + D Q p z d H J l Y W 0 N C n i c l Z Z L b 9 s w D M f v A f I d e J Q O U f S 0 L K A o k L 6 G F h 3 Q d R 52 S H v w X D c x 2 t i Z 627 L t x / l J I O d x Z 6 H A I o f 4 k 9 / U i R l m N 7 B y c n 0 4 / n 1 B f D T U z i 7 O I f v 41 E g N J M K O P 6 s M 0 w Z 4 D h w H s K E M 6 G d D S F Z j U f T 61 W 8 S A 1 c F P B p P I L L j + c w n Z V V 9 h w n l c f O q i p O l u k T z K d R s X 6 c R p t 1 O r 2 L F 1 k e V 1 m R 79 Y 7 i 5 B 0 J c A x F 0 D 0 P B 6 J e m E B K g C r A 2 b x K S 5 W L w y L / c W H 8 W h O Z l S T 9 Z p O L E l z v H y i E 0 c y a s g v + g j R z X h 0 i W i P 3 x O t Z T b U T e q c Q G N u 7 Q I 0 Y i I O N E p 7 K N J K x q W G w C k W y q 3 Q W u R W Y C 9 c N u C H O K 8 w H K J Q t R R K U L w t z z G J P G M w u p 1 h / J L T i S R J 8 S M t M Y p Z v o C K K r J M 4 T q v 36 Q l 4 P 3 X o n z B d 2 / Q F d z d U t I w r X b S i 2e43 K R 3 m z J e Z f U G H T e V o W W B a 5 v 2 e q 0 P v B b m r 33 Z q t E m Y M L t k D M q D M F 0 2 Q 2 p T 5 z 8 y b v c l T D C 4 H 4 E b U q v M H O Q M E I w r o 8 l j F a c S f t / C R N 0 J 4 z m h t l B C m 0 3 R I V i o J t h D w R j F Q y C u B 6 I w v 9 B E M F 7 K B z T S g y i i G 6 K D B X j w y g 9 F S 1 N y P Q w i u q h K M X c o A o R u o f C H V P D K K a b I k K 9 b 3 n / o v Q k r g i w D o Z R 7 G H R y 1 Z h S S e Z V R g + z f a Z E 5 V Y 4 w p r / D b + 9 u a v 4 D O t 616 R x A / v Z V b R S U g 2 V A Y E r u u 5 F f a D e s b r q x + z B d 5 o k i f U b h / D 2 W u x 6 G g X h m s m W g r 6 P T p W R l L V m y M k 1 u I O c l W U V A j y E 3 u x I D E N S N n d S I M 6 B g 3 j S d d U x 32 d N q f e F s V L 5 h s + n g D R 0 s d O 4 n L o c w X 36 d s + c v W T M v F R W X p Z 8 E C u o n t 8 + 0 A h S m P f W V f 98 W k s 2 R + f Y x 1 i x 8 D S H p T B 8 l h / 0 P 4 c d 4 B n t v H d u a b c / P E t f 49 L O h E S 0 + K 4 G 9 p i F Y Z t 865 T U e M 3 h 9 L N u f g t x T W e 7 c m c S C 66 z J x l p m 1 V W 9 j e y H Y q q s P y G 1 p M C N s N C m V u Z H N 0 c m V h b Q 0 K Z W 5 k b 2 J q D Q o 1 I D A g b 2 J q D Q o 8 P C 9 U e X B l L 1 h P Y m p l Y 3 Q v U 3 V i d H l w Z S 9 J b W F n Z S 9 X a W R 0 a C A x M j c 1 L 0 h l a W d o d C A x N j U w L 0 N v b G 9 y U 3 B h Y 2 U v R G V 2 a W N l U k d C L 0 J p d H N Q Z X J D b 21 w b 25 l b n Q g O C 9 G a W x 0 Z X I v R E N U R G V j b 2 R l L 0 l u d G V y c G 9 s Y X R l I H R y d W U v T G V u Z 3 R o I D Y x N T c 5 P j 4 N C n N 0 c m V h b Q 0 K / 9 j / 4 A A Q S k Z J R g A B A Q E A l g C W A A D / 4 Q B c R X h p Z g A A T U 0 A K g A A A A g A B A M C A A I A A A A W A A A A P l E Q A A E A A A A B A Q A A A F E R A A Q A A A A B A A A X E l E S A A Q A A A A B A A A X E g A A A A B Q a G 90 b 3 N o b 3 A g S U N D I H B y b 2 Z p b G U A / + I M W E l D Q 19 Q U k 9 G S U x F A A E B A A A M S E x p b m 8 C E A A A b W 50 c l J H Q i B Y W V o g B 84 A A g A J A A Y A M Q A A Y W N z c E 1 T R l Q A A A A A S U V D I H N S R 0 I A A A A A A A A A A A A A A A E A A P b W A A E A A A A A 0 y 1 I U C A g A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A R Y 3 B y d A A A A V A A A A A z Z G V z Y w A A A Y Q A A A B s d 3 R w d A A A A f A A A A A U Y m t w d A A A A g Q A A A A U c l h Z W g A A A h g A A A A U Z 1 h Z W g A A A i w A A A A U Y l h Z W g A A A k A A A A A U Z G 1 u Z A A A A l Q A A A B w Z G 1 k Z A A A A s Q A A A C I d n V l Z A A A A 0 w A A A C G d m l l d w A A A 9 Q A A A A k b H V t a Q A A A / g A A A A U b W V h c w A A B A w A A A A k d G V j a A A A B D A A A A A M c l R S Q w A A B D w A A A g M Z 1 R S Q w A A B D w A A A g M Y l R S Q w A A B D w A A A g M d G V 4 d A A A A A B D b 3 B 5 c m l n a H Q g K G M p I D E 5 O T g g S G V 3 b G V 0 d C 1 Q Y W N r Y X J k I E N v b X B h b n k A A G R l c 2 M A A A A A A A A A E n N S R 0 I g S U V D N j E 5 N j Y t M i 4 x A A A A A A A A A A A A A A A S c 1 J H Q i B J R U M 2 M T k 2 N i 0 y L j E A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A F h Z W i A A A A A A A A D z U Q A B A A A A A R b M W F l a I A A A A A A A A A A A A A A A A A A A A A B Y W V o g A A A A A A A A b 6 I A A D j 1 A A A D k F h Z W i A A A A A A A A B i m Q A A t 4 U A A B j a W F l a I A A A A A A A A C S g A A A P h A A A t s 9 k Z X N j A A A A A A A A A B Z J R U M g a H R 0 c D o v L 3 d 3 d y 5 p Z W M u Y 2 g A A A A A A A A A A A A A A B Z J R U M g a H R 0 c D o v L 3 d 3 d y 5 p Z W M u Y 2 g A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A Z G V z Y w A A A A A A A A A u S U V D I D Y x O T Y 2 L T I u M S B E Z W Z h d W x 0 I F J H Q i B j b 2 x v d X I g c 3 B h Y 2 U g L S B z U k d C A A A A A A A A A A A A A A A u S U V D I D Y x O T Y 2 L T I u M S B E Z W Z h d W x 0 I F J H Q i B j b 2 x v d X I g c 3 B h Y 2 U g L S B z U k d C A A A A A A A A A A A A A A A A A A A A A A A A A A A A A G R l c 2 M A A A A A A A A A L F J l Z m V y Z W 5 j Z S B W a W V 3 a W 5 n I E N v b m R p d G l v b i B p b i B J R U M 2 M T k 2 N i 0 y L j E A A A A A A A A A A A A A A C x S Z W Z l c m V u Y 2 U g V m l l d 2 l u Z y B D b 25 k a X R p b 24 g a W 4 g S U V D N j E 5 N j Y t M i 4 x A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A B 2 a W V 3 A A A A A A A T p P 4 A F F 8 u A B D P F A A D 7 c w A B B M L A A N c n g A A A A F Y W V o g A A A A A A B M C V Y A U A A A A F c f 521 l Y X M A A A A A A A A A A Q A A A A A A A A A A A A A A A A A A A A A A A A K P A A A A A n N p Z y A A A A A A Q 1 J U I G N 1 c n Y A A A A A A A A E A A A A A A U A C g A P A B Q A G Q A e A C M A K A A t A D I A N w A 7 A E A A R Q B K A E 8 A V A B Z A F 4 A Y w B o A G 0 A c g B 3 A H w A g Q C G A I s A k A C V A J o A n w C k A K k A r g C y A L c A v A D B A M Y A y w D Q A N U A 2 w D g A O U A 6 w D w A P Y A + w E B A Q c B D Q E T A R k B H w E l A S s B M g E 4 A T 4 B R Q F M A V I B W Q F g A W c B b g F 1 A X w B g w G L A Z I B m g G h A a k B s Q G 5 A c E B y Q H R A d k B 4 Q H p A f I B + g I D A g w C F A I d A i Y C L w I 4 A k E C S w J U A l 0 C Z w J x A n o C h A K O A p g C o g K s A r Y C w Q L L A t U C 4 A L r A v U D A A M L A x Y D I Q M t A z g D Q w N P A 1 o D Z g N y A 34 D i g O W A 6 I D r g O 6 A 8 c D 0 w P g A + w D + Q Q G B B M E I A Q t B D s E S A R V B G M E c Q R + B I w E m g S o B L Y E x A T T B O E E 8 A T + B Q 0 F H A U r B T o F S Q V Y B W c F d w W G B Z Y F p g W 1 B c U F 1 Q X l B f Y G B g Y W B i c G N w Z I B l k G a g Z
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e4a-0990-4e82-b7d2-4b14950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:10.000Z" ,
"modified" : "2017-01-19T07:44:10.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/jobs/44dc7eceb']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e4b-0acc-4f4c-8073-43d1950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:11.000Z" ,
"modified" : "2017-01-19T07:44:11.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/jobs/3261cc389']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:11Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e4b-25ac-4bd6-a0b9-46c8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:11.000Z" ,
"modified" : "2017-01-19T07:44:11.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/run']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:11Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e4c-3f68-409f-aa6a-4b33950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:12.000Z" ,
"modified" : "2017-01-19T07:44:12.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/ghk']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e4d-148c-4308-b2e1-4d98950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:13.000Z" ,
"modified" : "2017-01-19T07:44:13.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/co']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:13Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e4e-b3e4-4f18-9a79-4931950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:14.000Z" ,
"modified" : "2017-01-19T07:44:14.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/bin/ghk']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:14Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e4f-db9c-42ca-9ff4-4ff5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:15.000Z" ,
"modified" : "2017-01-19T07:44:15.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/obj/decepk']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:15Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e50-a450-4989-8cc0-4f48950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:16.000Z" ,
"modified" : "2017-01-19T07:44:16.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/tasks']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:16Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e51-89e4-463c-b283-4703950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:17.000Z" ,
"modified" : "2017-01-19T07:44:17.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/decepk']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:17Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e51-886c-4da1-87d3-4032950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:17.000Z" ,
"modified" : "2017-01-19T07:44:17.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/bin/run']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:17Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e52-d2d0-4a2b-9cb9-428f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:18.000Z" ,
"modified" : "2017-01-19T07:44:18.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/jobs']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:18Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e53-07f8-4bdc-b554-46c6950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:19.000Z" ,
"modified" : "2017-01-19T07:44:19.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/replace']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:19Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e54-beb0-45c1-81af-4638950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:20.000Z" ,
"modified" : "2017-01-19T07:44:20.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/fail']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:20Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e55-0568-4c64-b4cd-4782950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:21.000Z" ,
"modified" : "2017-01-19T07:44:21.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/obj']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:21Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e56-72e0-4602-81cb-4356950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:22.000Z" ,
"modified" : "2017-01-19T07:44:22.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/obj/tasks']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:22Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e56-400c-4f3c-b727-4b4e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:44:22.000Z" ,
"modified" : "2017-01-19T07:44:22.000Z" ,
"description" : "2010 sample C&C" ,
"pattern" : "[url:value = 'http://guess515.fastmail.fm/files/bin']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:44:22Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e7f-11e0-411a-adf0-497a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:45:03.000Z" ,
"modified" : "2017-01-19T07:45:03.000Z" ,
"description" : "2012 sample C&C" ,
"pattern" : "[url:value = 'ftp://ftp1.storegate.com/home/jiwoku375']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:45:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e80-ee2c-48e1-b25c-494d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:45:04.000Z" ,
"modified" : "2017-01-19T07:45:04.000Z" ,
"description" : "2012 sample C&C" ,
"pattern" : "[url:value = 'https://webdav1.storegate.com/jiwoku375/home/jiwoku375']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:45:04Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e81-ba68-4cfb-a12c-4edc950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:45:05.000Z" ,
"modified" : "2017-01-19T07:45:05.000Z" ,
"description" : "2012 sample C&C" ,
"pattern" : "[url:value = 'http://webdav1.storegate.com/jiwoku375/home/jiwoku375']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:45:05Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806e81-4664-4964-9817-4847950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:45:05.000Z" ,
"modified" : "2017-01-19T07:45:05.000Z" ,
"description" : "2012 sample C&C" ,
"pattern" : "[url:value = 'ftp1.storegate.com/home/jiwoku375']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:45:05Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fd4-f158-41a6-bad8-46c3950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:44.000Z" ,
"modified" : "2017-01-19T07:50:44.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'https://webdav.hidrive.strato.com/users/oncole3991']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fd5-ae40-4b64-a154-4c7b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:45.000Z" ,
"modified" : "2017-01-19T07:50:45.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'http://webdav.cloudme.com/imin1399/xios']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:45Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fd6-af4c-4467-86bf-429d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:46.000Z" ,
"modified" : "2017-01-19T07:50:46.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'http://webdav1.storegate.com/oldi4006/home/oldi4006']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:46Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fd7-424c-45a5-b1c3-4e88950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:47.000Z" ,
"modified" : "2017-01-19T07:50:47.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'https://webdav1.storegate.com/oldi4006/home/oldi4006']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fd7-18c0-4ca5-b2e2-4e88950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:47.000Z" ,
"modified" : "2017-01-19T07:50:47.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'http://webdav1.storegate.com/uwiq175/home/uwiq175']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fd8-85c4-4455-903a-47b7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:48.000Z" ,
"modified" : "2017-01-19T07:50:48.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'https://webdav1.storegate.com/enzevu888/home/enzevu888']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fd9-a310-4e87-b4fb-4eaa950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:49.000Z" ,
"modified" : "2017-01-19T07:50:49.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'https://webdav1.storegate.com/ordu1337/home/ordu1337']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:49Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fda-01c4-473b-aaf6-4d45950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:50.000Z" ,
"modified" : "2017-01-19T07:50:50.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'http://webdav1.storegate.com/oqokul68646/home/oqokul68646']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fdb-168c-4c83-8e3c-4c92950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:51.000Z" ,
"modified" : "2017-01-19T07:50:51.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'http://webdav1.storegate.com/enzevu888/home/enzevu888']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:51Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fdc-a3f4-4be0-8fb3-4a8f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:52.000Z" ,
"modified" : "2017-01-19T07:50:52.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'https://webdav.cloudme.com/imin1399/xios']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fdd-3744-4672-bd97-40df950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:53.000Z" ,
"modified" : "2017-01-19T07:50:53.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'https://webdav1.storegate.com/uwiq175/home/uwiq175']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:53Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fde-249c-4132-ad29-4cfe950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:54.000Z" ,
"modified" : "2017-01-19T07:50:54.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'http://webdav.hidrive.strato.com/users/oncole3991']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:54Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fde-85e0-4f67-b8dd-4355950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:54.000Z" ,
"modified" : "2017-01-19T07:50:54.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'http://webdav1.storegate.com/ordu1337/home/ordu1337']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:54Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806fdf-1b18-4b72-8947-4979950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:50:55.000Z" ,
"modified" : "2017-01-19T07:50:55.000Z" ,
"description" : "2014 - sample C&C" ,
"pattern" : "[url:value = 'https://webdav1.storegate.com/oqokul68646/home/oqokul68646']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:50:55Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806ff5-5330-4f91-8468-42f602de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:51:17.000Z" ,
"modified" : "2017-01-19T07:51:17.000Z" ,
"description" : "Although used for debugging only, we found that the malware author was playing around with email-based cross-site scripting, as can be seen from the following code snippet - Xchecked via VT: 21b6f2584485b8bbfffdefd45c1c72dc2133290fd8cefb235eb39cf015550316" ,
"pattern" : "[file:hashes.SHA1 = 'b5f08add2745bbed9ae4573fc9f16431cefa13f1']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:51:17Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806ff6-1afc-4b7c-b9c9-47de02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:51:18.000Z" ,
"modified" : "2017-01-19T07:51:18.000Z" ,
"description" : "Although used for debugging only, we found that the malware author was playing around with email-based cross-site scripting, as can be seen from the following code snippet - Xchecked via VT: 21b6f2584485b8bbfffdefd45c1c72dc2133290fd8cefb235eb39cf015550316" ,
"pattern" : "[file:hashes.MD5 = 'f3802442727c0b614482455d6ad9edc2']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:51:18Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--58806ff6-889c-407f-b3b2-401902de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:51:18.000Z" ,
"modified" : "2017-01-19T07:51:18.000Z" ,
"first_observed" : "2017-01-19T07:51:18Z" ,
"last_observed" : "2017-01-19T07:51:18Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--58806ff6-889c-407f-b3b2-401902de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--58806ff6-889c-407f-b3b2-401902de0b81" ,
"value" : "https://www.virustotal.com/file/21b6f2584485b8bbfffdefd45c1c72dc2133290fd8cefb235eb39cf015550316/analysis/1423753823/"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806ff7-2504-4521-bbb3-4a3d02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:51:19.000Z" ,
"modified" : "2017-01-19T07:51:19.000Z" ,
"description" : "- Xchecked via VT: d3ad32bcb255e56cd2a768b3cbf6bafda88233288fc6650d0dfa3810be75f74c" ,
"pattern" : "[file:hashes.SHA1 = 'b61633975206c58df648df144c78bb3e20051d93']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:51:19Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58806ff8-0868-4e2b-959a-42e402de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:51:20.000Z" ,
"modified" : "2017-01-19T07:51:20.000Z" ,
"description" : "- Xchecked via VT: d3ad32bcb255e56cd2a768b3cbf6bafda88233288fc6650d0dfa3810be75f74c" ,
"pattern" : "[file:hashes.MD5 = 'b39a673a5d2ceaa1fb5571769097ca77']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:51:20Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--58806ff8-af9c-47f3-882f-4ace02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:51:20.000Z" ,
"modified" : "2017-01-19T07:51:20.000Z" ,
"first_observed" : "2017-01-19T07:51:20Z" ,
"last_observed" : "2017-01-19T07:51:20Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--58806ff8-af9c-47f3-882f-4ace02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--58806ff8-af9c-47f3-882f-4ace02de0b81" ,
"value" : "https://www.virustotal.com/file/d3ad32bcb255e56cd2a768b3cbf6bafda88233288fc6650d0dfa3810be75f74c/analysis/1484353398/"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58807084-6eec-49b2-b5bb-4715950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:40.000Z" ,
"modified" : "2017-01-19T07:53:40.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'tip848@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58807084-8600-417b-9bf2-47fb950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:40.000Z" ,
"modified" : "2017-01-19T07:53:40.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'deliver@hostpenta.com.xml']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58807085-f248-4cf5-9a5f-4666950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:41.000Z" ,
"modified" : "2017-01-19T07:53:41.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'archive@hostpenta.com.xml']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:41Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58807086-775c-4aeb-a65a-4898950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:42.000Z" ,
"modified" : "2017-01-19T07:53:42.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'tim11235@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58807086-53a0-4a37-bf8f-4b83950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:42.000Z" ,
"modified" : "2017-01-19T07:53:42.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'guess515@fastmail.fm']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58807087-4370-4e79-b2ee-4bce950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:43.000Z" ,
"modified" : "2017-01-19T07:53:43.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'tim11235@googlemail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58807088-8d4c-4489-9df2-4d14950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:44.000Z" ,
"modified" : "2017-01-19T07:53:44.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'dude626@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58807089-4074-41eb-ad4b-4e1e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:45.000Z" ,
"modified" : "2017-01-19T07:53:45.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'octo424@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:45Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58807089-8f08-4b3b-9ac0-403c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:45.000Z" ,
"modified" : "2017-01-19T07:53:45.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'plars575@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:45Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5880708a-3e68-48f3-8aba-4df5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-19T07:53:46.000Z" ,
"modified" : "2017-01-19T07:53:46.000Z" ,
"pattern" : "[email-message:to_refs[*].value = 'purge626@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-19T07:53:46Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
2023-04-21 13:25:09 +00:00
]
}