2023-04-21 13:25:09 +00:00
|
|
|
{
|
2023-06-14 17:31:25 +00:00
|
|
|
"type": "bundle",
|
|
|
|
"id": "bundle--588a1640-bcac-4dc1-b9da-435802de0b81",
|
|
|
|
"objects": [
|
|
|
|
{
|
|
|
|
"type": "identity",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2017-01-26T16:30:29.000Z",
|
|
|
|
"modified": "2017-01-26T16:30:29.000Z",
|
|
|
|
"name": "CIRCL",
|
|
|
|
"identity_class": "organization"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "report",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "report--588a1640-bcac-4dc1-b9da-435802de0b81",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2017-01-26T16:30:29.000Z",
|
|
|
|
"modified": "2017-01-26T16:30:29.000Z",
|
|
|
|
"name": "Malware 2017-01-26 (.js in .zip) - Cerber",
|
|
|
|
"published": "2017-01-27T09:37:58Z",
|
|
|
|
"object_refs": [
|
|
|
|
"indicator--588a1688-caa4-493b-95c3-406102de0b81",
|
|
|
|
"indicator--588a1688-489c-4ca2-a4a0-446f02de0b81",
|
|
|
|
"indicator--588a1689-03dc-42d8-aa16-47f302de0b81",
|
|
|
|
"indicator--588a16c4-481c-4684-9a1f-4b1102de0b81",
|
|
|
|
"indicator--588a16c5-d85c-4db8-ac1c-468202de0b81",
|
|
|
|
"indicator--588a16c7-827c-4cc8-ad23-448702de0b81"
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"Threat-Report",
|
|
|
|
"misp:tool=\"MISP-STIX-Converter\"",
|
|
|
|
"circl:incident-classification=\"malware\""
|
|
|
|
],
|
|
|
|
"object_marking_refs": [
|
|
|
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--588a1688-caa4-493b-95c3-406102de0b81",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2017-01-26T15:32:24.000Z",
|
|
|
|
"modified": "2017-01-26T15:32:24.000Z",
|
|
|
|
"description": "download location",
|
|
|
|
"pattern": "[url:value = 'http://sonnystafgy.top/search.php']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2017-01-26T15:32:24Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Network activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"url\"",
|
|
|
|
"misp:category=\"Network activity\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--588a1688-489c-4ca2-a4a0-446f02de0b81",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2017-01-26T15:32:24.000Z",
|
|
|
|
"modified": "2017-01-26T15:32:24.000Z",
|
|
|
|
"description": "download location",
|
|
|
|
"pattern": "[domain-name:value = 'sonnystafgy.top']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2017-01-26T15:32:24Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Network activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"domain\"",
|
|
|
|
"misp:category=\"Network activity\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--588a1689-03dc-42d8-aa16-47f302de0b81",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2017-01-26T15:32:25.000Z",
|
|
|
|
"modified": "2017-01-26T15:32:25.000Z",
|
|
|
|
"description": "download location",
|
|
|
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '54.200.117.224']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2017-01-26T15:32:25Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Network activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"ip-dst\"",
|
|
|
|
"misp:category=\"Network activity\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--588a16c4-481c-4684-9a1f-4b1102de0b81",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2017-01-26T15:33:24.000Z",
|
|
|
|
"modified": "2017-01-26T15:33:24.000Z",
|
|
|
|
"description": "downloaded malware",
|
|
|
|
"pattern": "[file:content_ref.payload_bin = 'UEsDBBQACQAIACx8OkpZeDZaTQsDAIABBQAgABwAMzVlMWIyZmNjODk0NWQ4NGMyNDBjNjZkM2IyMGMxMDhVVAkAA8QWiljEFopYdXgLAAEEIQAAAAQhAAAAnbZfsxkP81ePBeLq86LjdDKfFBa9it/2oc4CKnTwlI52y8yZd10p8nF3nINBd9cl0tfvNNYyl1Sshowxc+0GIHU9OEQ6N4CG5Jajh5cpzDk/2atFJUU+8PWT0O7d0LDgr6FuZXIRLvqsCstDO6uHU3hL3un0IyXIxNUJnfQN2X1uU+xR8Ab8ChYEpFIx9eeuPpnpYsxopSbkuMbNF4CV1OdgnCHdZiQp8REE+2/dOn2y26zyeuVvzz40sOnL9XMiApRhfEZSMK+9z3FlduFMwROHbrNZEekktnXGHdo4SjpcbXIYYjXTZaLAAQz2bmkNk0Stgo0iCCUQPH5iFv+WsWJmGEfqoKcWkPUnGE0q3vqkc0NOsYxsFiXcOM0ymNvZtnYamT6FGsuitJ9uv6xREjyU4PQIpVRQtPaCOY7HN41juvL8fXkqhSf3Ye7GKL6PUePlq5wMzSZsKYeS21rDwESEqjq0EJjJ4Y3MduaX6Y4jjNv4bDmIhW0YOdf4EHFSQyyKOczPrPk81acG/3nXB89PF2Qa95X2W5yQ9ZKPD9kzXs3PAPNZV6Y1k/zaMaPkR7OcQGoM0Hdsugu1JCzrcpno/F6KlFIz3M1eRRs9BfP5ZfmLYM5ib90/FkZwnb2tmtMmbBCGHZMZR4WWIlvy1MeYXmbwnD01C4g1RMRMvEQsfevD4muW415prl/JJFkNDfDVFZApS64NEj6WjR6+pgDk+z1oOxcDbdLWmpIrd56VHbKGpeMFFB14LGKTj8wIS9ezTOJYnF7vczqoh/VUPvV74nevqY+6NqPJnwkjthtwEuBm5l5xNc2HypYBVcbIRfJIKd16ivLQjkysC4/e/vaL2DJAEWwfGuNqY+8Ai1NsE+zBWQCeEharXSmH+Ok6go++5VDVJpi1WyiDolg97xVfKHOUFcagwRysCXxy0WrcsSyaUUExusyiAWQjs95cnxdfskPgNkRqzND1IJ13GxywnLSkE2S0rNQ1VzW8yLIuE/rqOiXSdd3xVlPZhbI4Wl6YJNcaWpn6GB55L0DFWuLg1E/SiokdYEUjBvfovla9Wwmp07YyPmild9gUb7MaUNFBraXB4NOsI4kLQ7jjW2Z+BZpzMolTU/fVSKQ7gw2a+B+1lKp8h9H5T78DlewEfR6nCm6hHKea5ilESjVbrPFsXfehzRjIpAfeNWx+TmHo8qXyIj28TsFodyhy5c57+kcXU6giF5q1+QcYE8NYLX/cVEWN4mZzIUKVgwpeUQzyRQPnw/fc6cDlM3uq/sQzevcGZempZY+xEi6RcT+RJEEHB7FljfUxILaF/f4CEgXpkb9Yq47LCJJ5s71o/dxMTh5JeutYLCnh03Pkmt6FOGD8zwZYFxRaGoWNpjU0NxaV6l125wphM65LShMP5R1uSyOIIMY4x6NAcytxDZpvad8HBWw4xdWaCn4P+iRssnBPO1B7ZQYGZ9ee7pcY3VpB/kfMDte2CLR68FxLH5yOuKDO48poMcreeJq4m9w55tCSKPeTzcYiTuegD1NAEBbYS66cSXYETqLM7zD9puNBIgtQXzpVgo7pmXts3G1m0mhcT2GSHh/TrxubR2BrjctJTHjao5I5G/7mrUIecsCDmSLqxwFtK0pZYgC6Sy/mHDC0Iwq8McdYSHzQO3ZijXXk8zw32lWdTSRGgI1XNuauj49BXe9iuMG3E+P0uv7g6Se+sTjtmvDNriPO7tYyzjds6N0OmN6eTaaFt2LU9YKEOHy9Kf1+PIi9axEH/gOTZSK0bvoWFPYdQNoXQoPKCrnGznDJd4eBanvAyyg2NC9exQSRigNf/6dsYvi88jTAyyuKQBkx3OpT0TMfCSPaFZAUqk35PDFnC9HMAGdb4PrmKzeXZ1YrcAH6toHppTwWplDoMe4nVVYu9r6lo1hfHZ90ZopjlnmGROv3r55+AZfTELAczjAqB3dj+qFhMhc/SNYv680yGBVZpHznkWYmspXYebRwIClTN0mIJTQcCSv0ODyXMpTpIx9kIugNJlphyfEX3jx7dJgfbf3wXXiYkOYwsNncBwKYIvNHLaC6/xCfWKBk4svEpreCl4e11hj6oIiLzXLCXAVQOYRVvxyOSdA36vX4lBKPSywtFpADEDrXEFtFqrsJU1Tg05WQLYspwe+wVsRj04QfPEAMOk9KmeiMVB1QBLfl7djW8qdAHqR4/m2wp5m40ChfOE5XI67HModDu0+FJB2j7oUXmHaKB0awIfSfga7IgOoFKhxb1c4P3MUPg0Eh6Z/5yxorKhDPxruOTj8P3fb8RoZwtWExJoIEt+0wxgbqBhqFx11dmhWOJPMst5sVPiLPTjpr5PLuKAN3BdK1Yh+IuLDIeoW+wz4/1WZW2/I3inLC28hXzzjVONaiwI2Q5eDH0PzuMZTH3/daqONJkXojvYRBNHaEAuXRtyiBojb5H9hkzRFsOuGBatpsglLBsT0gCluketRXRHuXn+gRR3WdVx+mNlCdc6wBAiHKaUrWzAzVjffplPqTk9TYbag2J/pnxXfCjVrjzAhQpbiKdZgrdRY2TMWxU05ijE4bIjm8lKSnixw583hzP3tQNYEokmTSfoAwWDbyltxELAP4wYNArIz0T1esLwS4v6irBqmEZLEkwJ73vo8KgF/8XdBrnTx7Siik83LPVE1apUItCYWjiJM5sDMgqZCeJ5kwA4bIYgbzFL8MX5utTXS+A/8/Cy5x2kZOAUFYf/vUqVphxVYfD4FRw4vVZN6aLbwzzAvovknl6a5I5qDLgEqEnqywj8TFKdFpEdUo5IJmrUnQ+NJGgVs6oSih1yIYe8odHXmneQn5h3jh7JhswP+LGle8LXlc+pGCh0X7f04DStNaVODBALwXUSnXTZMv7dxhOFpe5VuMV4OJWvhn9DDTzktxa8Ey/Ma1GV98AmTJJtrArzU3WEvTiJxySYRW66I1M5rLWpILbEeHEu/K/vqxbpwxcVjnIOTYz9yVRVjSR6hzDMy3splg2L4g5HZ+sbq1WDcMlMpKJTPk6Qr7MtxK0qLsLRJ+FtsbBk1OplGq+FCs3/Wkb4weKKT/MeN8YL6ML0SoxYN/yQGTHL5Gr2+du9JYpr1G+YaNp+sgExPMmZpX9p4/FSwy191PnCzjhiNcFldFw9OIFWFa0yUgNv6zbFHcGtNgxOIg8NAxhMfTvVoz2mydz4/9CGUwPnZMQ0tbNanwGJRe6rVi2tKgW5itSY+HrTc962hhi2LUidah20ovNbCQpHyyXOIHNSdkl/3/NUH3aO5PtdLCpqmhYNPLgcUN5ULKFGVYcx36HxV2HkOU6Qdp/8Y8ydT263PPXnmon2yu9Lt1vh5MyRrpDTEuon4XSSgs7p6ywjvhNjEiObZgHb2Yg1+DclAS6G7tC5nW+mtcr2F+G0AlgT6B8+QLKYG+QCjE0FdHUvU7jTiUbMbQBW94SGeg7jDErd9yWAr3LFk3W2C5rzEnTps4pm9/QGbaEn+qk5hjNHc0ACG6OgzqfOaT1FEQrP75+E0G17aRvmAWo2bXS8LxBhp4LckE+EqcgwNK0XqI51pmcURzK5r1l17fyLUJtofVb50xHNqz5cLQsLZlMtYpN4wEBXkTjxRzZCxKtN9/He+xLsev9yrCzp600vMQw+CE7KJgu5TJ1GLLPzZKJXJRbfOMM3MyYEPWsGlO8tXyC37RA1B3Ckp4WmbXonLBdBajYESMs0Hbe+kiuGoU95t78Vd1cNYj3Yp2Q3NvoR2JqfcIUGfEiqBtXXnI1glC0wtV/c7kqluBrXCTZk2H4IWzPvP2xykLX9WzjHtvI5g4N3O44tuBAKzVsmqXpwjEvprgmWB2u+TTpaBTv3/WHIYg9q4ww8rcvoYWkURh3O02xPhGcDleRlWzffVBcofvHley/KTG1WWCir0+09/dWb
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2017-01-26T15:33:24Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"malware-sample\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--588a16c5-d85c-4db8-ac1c-468202de0b81",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2017-01-26T15:33:25.000Z",
|
|
|
|
"modified": "2017-01-26T15:33:25.000Z",
|
|
|
|
"description": "downloaded malware",
|
|
|
|
"pattern": "[file:name = '1' AND file:hashes.SHA1 = 'aa9dc6afeea7d2e580ab57be53d7c5db2633e67c']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2017-01-26T15:33:25Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"filename|sha1\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--588a16c7-827c-4cc8-ad23-448702de0b81",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2017-01-26T15:33:27.000Z",
|
|
|
|
"modified": "2017-01-26T15:33:27.000Z",
|
|
|
|
"description": "downloaded malware",
|
|
|
|
"pattern": "[file:name = '1' AND file:hashes.SHA256 = '18b47db36839677a9c52150e93e76104ed0c5bd33cd12e5cce99c4727f12c6bc']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2017-01-26T15:33:27Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"filename|sha256\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "marking-definition",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
|
|
|
"created": "2017-01-20T00:00:00.000Z",
|
|
|
|
"definition_type": "tlp",
|
|
|
|
"name": "TLP:WHITE",
|
|
|
|
"definition": {
|
|
|
|
"tlp": "white"
|
|
|
|
}
|
|
|
|
}
|
2023-04-21 13:25:09 +00:00
|
|
|
]
|
|
|
|
}
|