2023-06-14 17:31:25 +00:00
{
"type" : "bundle" ,
"id" : "bundle--5d01f1fa-cc24-4adb-b6b6-4c88950d210f" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2019-06-13T07:37:43.000Z" ,
"modified" : "2019-06-13T07:37:43.000Z" ,
"name" : "CIRCL" ,
"identity_class" : "organization"
} ,
{
"type" : "grouping" ,
"spec_version" : "2.1" ,
"id" : "grouping--5d01f1fa-cc24-4adb-b6b6-4c88950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2019-06-13T07:37:43.000Z" ,
"modified" : "2019-06-13T07:37:43.000Z" ,
"name" : "OSINT - TA505 once again launched an offensive" ,
"context" : "suspicious-activity" ,
"object_refs" : [
"observed-data--5d01f830-fcd4-4cec-9d3d-4158950d210f" ,
"file--5d01f830-fcd4-4cec-9d3d-4158950d210f" ,
"artifact--5d01f830-fcd4-4cec-9d3d-4158950d210f" ,
"x-misp-object--5d01f635-5f40-4b48-8510-4009950d210f" ,
"indicator--5d01f7ef-5530-4732-abf6-4795950d210f" ,
"relationship--0615dd96-4cd5-42f3-a31e-89429e05d729"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"misp-galaxy:threat-actor=\"TA505\"" ,
"workflow:todo=\"expansion\"" ,
"osint:source-type=\"microblog-post\"" ,
"type:OSINT" ,
"osint:lifetime=\"perpetual\"" ,
"osint:certainty=\"50\""
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5d01f830-fcd4-4cec-9d3d-4158950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2019-06-13T07:16:00.000Z" ,
"modified" : "2019-06-13T07:16:00.000Z" ,
"first_observed" : "2019-06-13T07:16:00Z" ,
"last_observed" : "2019-06-13T07:16:00Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--5d01f830-fcd4-4cec-9d3d-4158950d210f" ,
"artifact--5d01f830-fcd4-4cec-9d3d-4158950d210f"
] ,
"labels" : [
"misp:type=\"attachment\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--5d01f830-fcd4-4cec-9d3d-4158950d210f" ,
"name" : "D820AnRUcAAso9o.jpeg" ,
"content_ref" : "artifact--5d01f830-fcd4-4cec-9d3d-4158950d210f"
} ,
{
"type" : "artifact" ,
"spec_version" : "2.1" ,
"id" : "artifact--5d01f830-fcd4-4cec-9d3d-4158950d210f" ,
"payload_bin" : " / 9 j / 4 A A Q S k Z J R g A B A Q A A A Q A B A A D / 2 w B D A A g G B g c G B Q g H B w c J C Q g K D B Q N D A s L D B k S E w 8 U H R o f H h 0 a H B w g J C 4 n I C I s I x w c K D c p L D A x N D Q 0 H y c 5 P T g y P C 4 z N D L / 2 w B D A Q k J C Q w L D B g N D R g y I R w h M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j I y M j L / w g A R C A L Y B N k D A S I A A h E B A x E B / 8 Q A G w A B A A I D A Q E A A A A A A A A A A A A A A A Q F A g M G A Q f / x A A Z A Q E B A Q E B A Q A A A A A A A A A A A A A A A Q I E A w X / 2 g A M A w E A A h A D E A A A A e / R 5 C A o A A A A A A A A A A A A A A A A A A A A G u N s o u T 1 u 9 t N b + b L G m i + m O i c t v r o 8 e Y x O t Q s s W V o p p + p N 2 U 0 C u o x 5 v 0 u 5 f N 9 D m 5 j J r 2 e e s e b 6 T o z a R a 8 X O V L s L X 3 m e j M 8 Z G j F y H L o A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A B n h n u Z j r z E 0 7 q i 5 n q u z m v S r L S w 5 v o j a A r d Z b K n y L d V e F t r i a C a o 72 z Z s h F m q / C L N E l 0 A A A A A A A A A B r p 7 b T z b i 2 G n 3 F w x 2 r m P n t V r w 3 o 9 y w G j P Y N e O 4 a c 8 x h l 6 N r U N u v x p t j 5 v X O n b 6 H n o j z d Q 26 j N 2 t T y u 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 1 q G 3 O P t 0 3 D p z E q L e o u c e k 5 m 7 m p f P X F I Y d F z v R G 0 G j P X 6 Z 46 t h l 5 h m Z 69404 S R G 3 Z j W 2 D X s a D e A 1 + m Z r N g B i Z M M w A A A D T p m a T S 34 G t s z N C W I i W I i W I f u 3 U H n o Z S S I l i I l i I l i I l i I l 6 z Q 37 C H 6 l k R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E R L E T d t 9 A I l T b V t z b + b 0 1 F k Z D n r y r t D a C o 8 t Y 8 R 9 m W 2 u f t t 5 M d d j p l g e z 8 K h e y 8 y u T h D 12 G g 1 L D E g 6 r I Q s J q I i b h U a V l l F b J k b r G Q o A A H l D e + R F 1 z N S M c s z c L Q E C e N O r b q M M / P T K T G k k X b s 9 A N e q T 4 P Q V N t q I 80 I k u J L A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A H v n o B E x y l 3 I T Q E S R m A N K n 0 x b z e T 6 y w F A A A A A A A A A A A A A A A 0 6 d 0 Q 2 t Q 2 t P p t a v D c 1 a y S 1 e G 33 V g S G r w 3 N X h u R 8 z a 0 + m 1 G 2 G 1 p 9 N q P k b m r w 2 + 6 s C Q 1 e G 5 q 8 N z V 4 b m o b W o b W n 0 2 t P p t a f T a 0 e m 5 p 9 N r U N r V 4 b m r E 3 t X h u a v D c 0 + m 1 p 9 N q P m b W n 0 2 o 2 w 2 t P p t a f D e 1 e G 5 q 1 k l q 8 N z V g S G r w 3 N X h u R t h t a f T a 0 + m 1 p 9 N r S N z V 4 b m n w 3 t X h u a s T f u i S C S C J L i S 7 k J o A A D R 7 u G j e A A A A A A A A A A A A A A A A E W j u 6 O Z 2 e S B X y d 6 z R j J S 6 I l k T R j J L o 0 z R G S R o w l C D u k W q U O X R l 5 K V 0 Z O a y 6 M v L b e k J z m P S l 5 u N 1 p O c x 6 U v N x + s J z m P S l 5 z H p R z W X R q 5 r L o 0 c t u 6 M c 1 l 0 Y 5 T f 0 g 5 r L o x z e H T q 5 z H p U c 5 G 6 w c 5 j 0 o 5 z T 1 I 5 f b 0 a u a y 6 N H K b + k H N Z d G O U k d G O a y 6 M c x h 1 R O c x 6 U v O R e t J z m P S l 5 y P 1 Y 5 p 0 q u c d G j m c + j H N Z d H B K K R v J G y 3 l i e y h o x k i P G s R o x k j R o n C P Z R Z x O F 1 E h T c m Y O q z 2 t R Z W J N 0 S X p W P h I z i s l b v a h b p G J 7 D l 5 k f L Z 4 R N c 7 M 0 s x X y t m y I n k r O t G E n w i 792 R X b p G J q S I c Y J v l e 6 d u Z u A A A B E o 7 u k m Z Y u g A A A A A A F r V W p v A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A g z o J B A A A A A A A n Q Z x O B E l i A o A A A A A A A A A A A A A A A A A A A A E O k u 6 S Z l i 6 A A A A A A A W t V a m 8 A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A C D O g k E A A A A A A C d B n E 4 B R Y b 8 u g c + r o H P i / w D e f t 86 k j O w A A A A A A A A A A A A A A A A A I d J d 0 k z L F 0 A A A A A A A t a q 1 N 4 A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A E G d B I I A A A A A A E 6 D O J w D T W l w p x c K c X C t s g Y m T V 6 b G v I y a v D c 8 j E p H x J T H E 2 M c D a A A A A A A A A A A C J R 3 d J M y x d A A A A A A A L W q t T e A A A A A A A c / j d / w C f P M O b v + j P n K X 6 M + c j 6 N l 83 m a z 3 i J L 6 v n h Y A A A A R t h t I 5 I a d w N B v a M z Y A A A j 7 j J r 2 A A A A A A A C D O g k E A A A A A A C d B n E 4 E W i v a I 3 X E O 1 K a D f 0 B K v a K 9 G j e K d c C p 3 W G E V u i 5 z q H W 3 g r J m W A g 2 m w r P b I e e g A A A A A A A A A B D p L u k m Z Y u g A A A A A A F r V W p v A A A A A A B H + e 97 w P D 9 U W H L 9 G v y 6 e z 6 O L l I f c S v T n + c L y j 5 P p 3 X Y 8 H 3 n d 8 h g + Y d P F 0 l D t 7 I 4 a 66 L k z u d v y f 6 o b O D 7 v 4 y W X Y d D m c h y 2 r 6 i U b q R V 8 r 31 S c l Z 2e09 p 7 n a U u y V v I e u f k c H 1 + 2 a Q b 6 F N A A A A A A A E G d B I I A A A A A A E 6 D O J w I t F e 1 x 5 Z S t B B r + j 0 l V e 0 V 6 N W 3 S a / Y W Z u y h 5 R K k 8 p 0 t k h W Z S 2 K t j 1 c Z U U i L X G q z s n K w t y o c y 5 x g x Y v N U O J V 5 q 8 q I v V V 7 V o p M y 4 R K 8 u 1 d i W Y A I N N b 1 E x L F 2 A A A A A A A t a q 1 N 4 A A A A A A I X A 99 w P B 9 d 9 C + e / Q r n m a S 1 q f H r v e u 5 H r u 35 P L 850 f O c X 1 J / e c H 3 n V w c x y V h b 9 X B 1 e Q P P R 8 z v 86 A v O A + l f N j u E 30 + d 9 l y H d l z Z Q e F P p D T H J s X 5 n I P o 0 n 5 X 3 p b 6 u d 4 s + n y / m c M + s o 0 k A A A A A A A A Q Z 0 E g g A A A A A A T o M 4 n A i x p + J u A B R X s W U P P d Y 1 a k Z 7 c Z F m n c K 1 b R q z y G v H c N P u 0 R 9 m w Q t + 4 a 2 w a v d g x x 2 D T l s G n 3 a M P c h q 2 g A B X 1 F r V M S w 2 A A A A A A A t a q 1 N 4 A A A A A A I P B d 9 w P B 9 d 9 C + e 9 P L X V M 2 J 49 V 313 J d Z 3 / H 5 j n O j 5 z i + p P 7 z g + 86 u D 5 r 0 d b p 6 u D v w A c 1 z U / M 7 f 419 l + N H 2 X 3 z 0 + P f W f k 31 k k f K P q / y g + o f O f o 3 y A 73 q d W 0 R 5 F O f N f r X x y 1 P q 3 E U G g 6 j t e D 7 w A A A A A A A A Q Z 0 E g g A A A A A A T o M 4 n A A A A A R Z Q 56 J 1 i K S 7 L A U A A A A A A A A A A A A A A C t q r e o Y l h s A A A A A A B a 1 V q b w A A A A A A Q u B + k c D x f T i j i + r O t + a e v P 3 E f j 3 p 4 T 4 B 4 d t j 3 X N d L 9 D 4 k H 5 N 9 n p O j k 9 u f k m R 9 Z q f n n h G + r w r o 8 + N f Z f k B 9 f 989 P j 31 n 5 Z 9 T J H y j 6 v 8 o P q H y X 61 y 50 E / 5 P 250 N d T X J 8 z + u f K 7 g 73 y j q D t F d Y g A A A A A A A C D O g k E A A A A A A C d B n E 4 D D V V F 2 q / U s 8 q 2 y V j 7 U R c K z K r F X S o 25 V W V W a v r z o F f i W G V X m W K s 9 L J A E 9 X C x Q s C w A A A A A A A A B W 1 V t U s S w 2 A A A A A A A t a q 1 N 4 A A A A A A E W U l 5 f R 17 x 6 e Q d e m u Q d e O R s L 5 r G O R 68 w U 0 b x p 3 A A 89 A H n o O R 64 a 9 g U N J 3 I 4 / q 9 o 0 8 t 144 W z 6 c Y 5 A A A A A A A A A g z o J B A A A A A A A n Q Z x O A 0 b x r 82 j B m G n c N f u Y 0 e S B q b R q w k D X j u G p t G G i U M M N w 1 + 5 j T n m A A A A A A A A A K 6 p u K e Y l i 7 A A A A A A A W t V a m 8 A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A C D O g k E A A A A A A C d B n E 4 H n m N V F u q P C 5 U q r p S + l y p r A k t e s k M f T 1 j m e P R 49 H j z I 8 e j x 6 P H o 8 e j x 6 P H o 8 e j x 6 P H o 8 e j x 6 P P M h X V N t U s S w 2 A A A A A A A t a q 1 N 4 A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A E G d B I I A A A A A A E 6 D O J w N d H e U u b 7 X W O r G u V n X G 71 x T 23 u a a 7 W u s l 5 u d Z 5 T z j V X Q 6 n p w f R X W d U e X R 60 q N t i W l s t + w q I P T a y t h d J H i p 6 G P I o A A A A A A A A C u q b e o Y l h s A A A A A A B a 1 V q b w A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A I M 6 C Q Q A A A A A A J 0 G c T g e e Z D F k M f f R 49 H j 0 e P R i y H n m Q x Z
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--5d01f635-5f40-4b48-8510-4009950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2019-06-13T07:16:34.000Z" ,
"modified" : "2019-06-13T07:16:34.000Z" ,
"labels" : [
"misp:name=\"microblog\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "text" ,
"object_relation" : "post" ,
"value" : "#TA505 once again launched an offensive. This time, the bill-themed email was launched for Chinese users. This time, the Excel 4.0 macro and the back door of the same family are still used.\r\n\r\n(link: https://www.virustotal.com/gui/file/d538b3aa5da1d0e506b531fb5c1ef514f7251e7f922857b21167767b11c57ce6/detection) virustotal.com/gui/file/d538b\u2026" ,
"category" : "Other" ,
"uuid" : "5d01f635-a958-4d5a-8a9d-40b8950d210f"
} ,
{
"type" : "text" ,
"object_relation" : "type" ,
"value" : "Twitter" ,
"category" : "Other" ,
"uuid" : "5d01f635-b3ac-49cd-adc1-45d9950d210f"
} ,
{
"type" : "url" ,
"object_relation" : "url" ,
"value" : "https://mobile.twitter.com/RedDrip7/status/1138764217123655680" ,
"category" : "Network activity" ,
"to_ids" : true ,
"uuid" : "5d01f635-dc30-49c2-b45c-4383950d210f"
} ,
{
"type" : "url" ,
"object_relation" : "link" ,
"value" : "https://t.co/2RTo3djsqt?amp=1" ,
"category" : "Network activity" ,
"to_ids" : true ,
"uuid" : "5d01f635-be8c-4f63-a126-4117950d210f"
} ,
{
"type" : "url" ,
"object_relation" : "link" ,
"value" : "https://www.virustotal.com/gui/file/d538b3aa5da1d0e506b531fb5c1ef514f7251e7f922857b21167767b11c57ce6/detection" ,
"category" : "Network activity" ,
"to_ids" : true ,
"uuid" : "5d01f635-82e4-48a6-a760-41f8950d210f"
} ,
{
"type" : "text" ,
"object_relation" : "username" ,
"value" : "RedDrip7" ,
"category" : "Other" ,
"uuid" : "5d01f635-03e8-475f-b619-49a9950d210f"
} ,
{
"type" : "text" ,
"object_relation" : "state" ,
"value" : "Informative" ,
"category" : "Other" ,
"uuid" : "5d01f635-a488-49c7-81ce-4ad1950d210f"
} ,
{
"type" : "datetime" ,
"object_relation" : "creation-date" ,
"value" : "Jun 12, 2019 1:05 PM" ,
"category" : "Other" ,
"uuid" : "5d01f635-225c-4350-b0df-4984950d210f"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "microblog"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5d01f7ef-5530-4732-abf6-4795950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2019-06-13T07:14:55.000Z" ,
"modified" : "2019-06-13T07:14:55.000Z" ,
"pattern" : "[file:hashes.SHA256 = 'd538b3aa5da1d0e506b531fb5c1ef514f7251e7f922857b21167767b11c57ce6']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-06-13T07:14:55Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
"id" : "relationship--0615dd96-4cd5-42f3-a31e-89429e05d729" ,
"created" : "2019-06-13T07:16:34.000Z" ,
"modified" : "2019-06-13T07:16:34.000Z" ,
"relationship_type" : "contains" ,
"source_ref" : "x-misp-object--5d01f635-5f40-4b48-8510-4009950d210f" ,
"target_ref" : "observed-data--5d01f830-fcd4-4cec-9d3d-4158950d210f"
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
]
}