2023-04-21 13:25:09 +00:00
{
2023-06-14 17:31:25 +00:00
"type" : "bundle" ,
"id" : "bundle--5e4886b7-3f14-4ab0-867f-4ea30a0a020f" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2021-05-24T10:04:03.000Z" ,
"modified" : "2021-05-24T10:04:03.000Z" ,
"name" : "laskowski-tech.com" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--5e4886b7-3f14-4ab0-867f-4ea30a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2021-05-24T10:04:03.000Z" ,
"modified" : "2021-05-24T10:04:03.000Z" ,
"name" : "IRS Doc Malware" ,
"published" : "2020-07-02T04:13:31Z" ,
"object_refs" : [
"indicator--5e4886d0-aa58-46fb-9e0d-49e10a0a020f" ,
"observed-data--5e48871a-d484-402c-af72-4ce50a0a020f" ,
"network-traffic--5e48871a-d484-402c-af72-4ce50a0a020f" ,
"ipv4-addr--5e48871a-d484-402c-af72-4ce50a0a020f" ,
"indicator--5e48880c-0c00-401e-9e4b-4b3474656a8a" ,
"indicator--5e48882f-b1c4-4e46-a8e1-4b2074656a8a" ,
"indicator--5e49291d-119c-48dd-83c5-4b5374656a8a" ,
"indicator--5e4929ef-e944-47ed-91ea-472e74656a8a" ,
"indicator--5e4ae75c-ecfc-49f8-8cf5-03f60a0a020f" ,
"indicator--5e4ae7a3-e4f8-4bb2-859f-155674656a8a" ,
"indicator--5e4ae7a3-47e4-4d8c-815b-155674656a8a" ,
"indicator--5e4ae7a3-e910-4288-9170-155674656a8a" ,
"indicator--5e4ae7a3-ef8c-49f1-8f58-155674656a8a" ,
"observed-data--5e4ae897-bb28-47fe-811d-04470a0a020f" ,
"windows-registry-key--5e4ae897-bb28-47fe-811d-04470a0a020f" ,
"observed-data--5e4aea88-9e20-4d2d-9b04-421b0a0a020f" ,
"url--5e4aea88-9e20-4d2d-9b04-421b0a0a020f" ,
"indicator--5e4afc46-fc7c-4164-819a-44c7950d210f" ,
"indicator--5e488f03-b2f8-4607-93af-4e030a0a020f" ,
"indicator--5e488f10-027c-49ed-a39f-4f3e0a0a020f" ,
"indicator--5e488f1f-6f84-4eec-8d89-4b990a0a020f" ,
"x-misp-object--5e4aea3d-a5f8-42b5-9539-457e0a0a020f"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"" ,
"misp-galaxy:mitre-attack-pattern=\"Command-Line Interface - T1059\"" ,
"misp-galaxy:mitre-attack-pattern=\"PowerShell - T1086\"" ,
"misp-galaxy:mitre-attack-pattern=\"Scripting - T1064\"" ,
"misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1060\"" ,
"misp-galaxy:mitre-attack-pattern=\"BITS Jobs - T1197\"" ,
"misp-galaxy:mitre-attack-pattern=\"Commonly Used Port - T1043\"" ,
"misp-galaxy:mitre-attack-pattern=\"Standard Cryptographic Protocol - T1032\"" ,
"maldoc"
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
2023-04-21 13:25:09 +00:00
]
2023-06-14 17:31:25 +00:00
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e4886d0-aa58-46fb-9e0d-49e10a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:23:21.000Z" ,
"modified" : "2020-02-17T19:23:21.000Z" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '199.188.200.112' AND network-traffic:dst_port = '443']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-15T00:00:00Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst|port\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Command and Control"
2023-04-21 13:25:09 +00:00
]
2023-06-14 17:31:25 +00:00
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5e48871a-d484-402c-af72-4ce50a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:22:14.000Z" ,
"modified" : "2020-02-17T19:22:14.000Z" ,
"first_observed" : "2020-02-15T00:00:00Z" ,
"last_observed" : "2020-02-15T00:00:00Z" ,
"number_observed" : 1 ,
"object_refs" : [
"network-traffic--5e48871a-d484-402c-af72-4ce50a0a020f" ,
"ipv4-addr--5e48871a-d484-402c-af72-4ce50a0a020f"
] ,
"labels" : [
"misp:type=\"ip-dst|port\"" ,
"misp:category=\"Network activity\""
2023-04-21 13:25:09 +00:00
]
2023-06-14 17:31:25 +00:00
} ,
{
"type" : "network-traffic" ,
"spec_version" : "2.1" ,
"id" : "network-traffic--5e48871a-d484-402c-af72-4ce50a0a020f" ,
"dst_ref" : "ipv4-addr--5e48871a-d484-402c-af72-4ce50a0a020f" ,
"dst_port" : 80 ,
"protocols" : [
"tcp"
]
} ,
{
"type" : "ipv4-addr" ,
"spec_version" : "2.1" ,
"id" : "ipv4-addr--5e48871a-d484-402c-af72-4ce50a0a020f" ,
"value" : "151.139.128.14"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e48880c-0c00-401e-9e4b-4b3474656a8a" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:23:06.000Z" ,
"modified" : "2020-02-17T19:23:06.000Z" ,
"pattern" : "[url:value = 'http://siliconmadeinhk.com/Server2_36B4.exe']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:23:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Delivery"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e48882f-b1c4-4e46-a8e1-4b2074656a8a" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:23:06.000Z" ,
"modified" : "2020-02-17T19:23:06.000Z" ,
"pattern" : "[domain-name:value = 'siliconmadeinhk.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:23:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Delivery"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e49291d-119c-48dd-83c5-4b5374656a8a" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:22:32.000Z" ,
"modified" : "2020-02-17T19:22:32.000Z" ,
"pattern" : "[domain-name:value = 'binupload.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:22:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Command and Control"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e4929ef-e944-47ed-91ea-472e74656a8a" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:22:32.000Z" ,
"modified" : "2020-02-17T19:22:32.000Z" ,
"description" : "tied to \t\r\nbinupload.com" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '199.188.200.112']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:22:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Command and Control"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e4ae75c-ecfc-49f8-8cf5-03f60a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:23:06.000Z" ,
"modified" : "2020-02-17T19:23:06.000Z" ,
"description" : "tied to siliconmadeinhk.com" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '185.222.202.237']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-16T00:00:00Z" ,
"valid_until" : "2020-02-17T00:00:00Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Delivery"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e4ae7a3-e4f8-4bb2-859f-155674656a8a" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:23:06.000Z" ,
"modified" : "2020-02-17T19:23:06.000Z" ,
"description" : "tied to siliconmadeinhk.com" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '89.208.229.55']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:23:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Delivery"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e4ae7a3-47e4-4d8c-815b-155674656a8a" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:23:06.000Z" ,
"modified" : "2020-02-17T19:23:06.000Z" ,
"description" : "tied to siliconmadeinhk.com" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '172.105.81.149']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:23:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Delivery"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e4ae7a3-e910-4288-9170-155674656a8a" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:23:06.000Z" ,
"modified" : "2020-02-17T19:23:06.000Z" ,
"description" : "tied to siliconmadeinhk.com" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '172.105.154.72']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:23:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Delivery"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e4ae7a3-ef8c-49f1-8f58-155674656a8a" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:23:06.000Z" ,
"modified" : "2020-02-17T19:23:06.000Z" ,
"description" : "tied to siliconmadeinhk.com" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '89.208.196.16']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:23:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Delivery"
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5e4ae897-bb28-47fe-811d-04470a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:25:56.000Z" ,
"modified" : "2020-02-17T19:25:56.000Z" ,
"first_observed" : "2020-02-17T19:25:56Z" ,
"last_observed" : "2020-02-17T19:25:56Z" ,
"number_observed" : 1 ,
"object_refs" : [
"windows-registry-key--5e4ae897-bb28-47fe-811d-04470a0a020f"
] ,
"labels" : [
"misp:type=\"regkey|value\"" ,
"misp:category=\"Artifacts dropped\"" ,
"kill-chain:Installation"
]
} ,
{
"type" : "windows-registry-key" ,
"spec_version" : "2.1" ,
"id" : "windows-registry-key--5e4ae897-bb28-47fe-811d-04470a0a020f" ,
"key" : "Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce" ,
"values" : [
{
"data" : "%USERPROFILE%\\PROTOZOA.vbs"
}
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5e4aea88-9e20-4d2d-9b04-421b0a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:33:28.000Z" ,
"modified" : "2020-02-17T19:33:28.000Z" ,
"first_observed" : "2020-02-17T19:33:28Z" ,
"last_observed" : "2020-02-17T19:33:28Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--5e4aea88-9e20-4d2d-9b04-421b0a0a020f"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--5e4aea88-9e20-4d2d-9b04-421b0a0a020f" ,
"value" : "https://laskowski-tech.com/2020/02/17/what-is-this-bad-for-sure-racoon-stealer-maybe/"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e4afc46-fc7c-4164-819a-44c7950d210f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T20:49:10.000Z" ,
"modified" : "2020-02-17T20:49:10.000Z" ,
"pattern" : "[domain-name:value = 'server237-5.web-hosting.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-15T00:00:00Z" ,
"valid_until" : "2020-02-17T00:00:00Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"hostname\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e488f03-b2f8-4607-93af-4e030a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:26:15.000Z" ,
"modified" : "2020-02-17T19:26:15.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' 9 d e c 963 d d 964716405 a d b e 9 e f 9006 d e 7 ' A N D f i l e : h a s h e s . S H A 1 = ' 452 d 0 5 a 5 a d 2 f d d 2 b 8 f 45 b 878 b 2078900 b 9 f 0 72 b 2 ' A N D f i l e : h a s h e s . S H A 256 = ' 585 f 829 c 600736 a 9613 d 0 870 c 6460068 d 9461 a 7 b e 35 c 0 7149 f e 58143 b 2 f 24 b 6 f ' A N D f i l e : n a m e = ' P R O T O Z O A . e x e ' A N D f i l e : s i z e = ' 36864 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A M 4 E U F D x O O 1 n m z I A A A C Q A A A g A B w A O W R l Y z k 2 M 2 R k O T Y 0 N z E 2 N D A 1 Y W R i Z T l l Z j k w M D Z k Z T d V V A k A A w O P S F 4 D j 0 h e d X g L A A E E I Q A A A A Q h A A A A c E 7 x t Z V Z o j Z I j q K 8 I N q N F a 7 z Q S v c r 0 Z V L 2 D V 1 p I Z X d C C d o w 35 x a W 5 q j p F w r a T o S K j Z + s f Y R X q B N z 6086 g u O g 9 N 20 q c T 6 J k 57 M r 48 w A P U a K F C g w 7 n e B J 3 G D w 4 l W N B 8 A r P m 8 u k o y S o J B a X X G 96 s M p Q w 10 w E 1 B T B a u 7 Y W p 3 D w S o C 2 D 45 K o C N a / 5 I O b x k Y b D k H r K H 80 r c J L T A u + + U X y 7 u m m D 6 b B o 8 v 0 / B h / 128 X 3 F E T b a s d s R Q O J I b u S L 79 X s 95 Y s w V Z z z B I C 2 D Z 3 l n i w 0 D O C b 8 m n P s U 7 X I + r E 6 l 3 A a b 8 y c 3 R h U 9 W F y J l 31 z e z I t k p v 4 J o H E / m W K c o g 218 y + A b i 5 v 3 g t Q 9 c V u w x 9 M e S O 7 H m t Z m G 9 Y o o q 3 P w t u L b Z V Y g 4 H f R 0 K D 4 F S Z A c 1 i 5 i 7 e H T 4 Y h w e 1 S x C 7 G E H r V A h l M v w u B L U U C o 4 P l Z w 3 s K / d L 405 K b Z G b 7 n 7 y y L v 5 z o t s + y y w w c h O 76 B r r M m T l z K y / r F 0 I B 6 e e 2 m X 3 t 8 H z e V 0 r + t w z I 48 N Q r M S M X l F 9 Y 0 h f Y x D U F I R u R B 0 j Q Y g O K K T n c x n l q D k L y H p 3 K B V F M + Z 2 P r T u Q w s e 8 o g R 82E99 I E 3 i B u E u B M 5 D D X N 3 S D N b R P x h l n X 2 D N m M 59 p O / 0 h U T 6 H + U 4 e O V / G / F 3 X c b j 0 l L F V F Z R D j Y I Y o d h T R e y g 8 U p I H V W 6 V l 0 g B V u z u B 6 a z p 5 D k n d N v y U z S + D T A G + 5 u c L l b I N i 0 e h m y k S Q v c i W 3 g / I o G r U p L x V U 0 S 9 t A A t K + X D I S j w D 9 s 7 v K 2 Z / 9 u T 1 O I F b D e t B p s y y d l Q 7 K t R r D t 399 M r N z 2 i j w k p V e 8 h 4 P x J L C k 4 / S U a s 1 U i v v 67 e p 7 o I D Z C r A + N t 7 j n I G o L 9 v R F a 0 H 7 r w M Q 1 p F r K w W 87 H K Y y U Z p S q E c i k B O E i + / Y q f N V g 2 V W A T E M U v g f p Z t G V 9 w K Z c R l 7 f H x 5 T d V + X Z x t F P r 5 w T 1 E C W Q b u B W Y p y 9 f f 9 w r Z h K e Z U q l k q F t e y O 3 o o d 8 u 4 Z v d m I Y r b O k p o j Y v V u o L R 4 r N y I 0 k K w L e b V V b G 50 b N I p C U 0 D V q Q F O f e g Y q X 1 F h w w C Y q q 9 q q 7 j v B E U 2 I u t 6 i e + 2 R c g 6 i g Z 47 M T 9 + n w d 7 a u 1 Y F N G Q Q 0 q 5 p q R 7 c M o b f V r N B 5 a l 4 D 6 h F W 4 Q o 4 X q Q l H U b 7 g n G c b b n a b L 8 B b 0 m 3 W p B U Q J I h Z Q Z G 2 W V / a x / q g N B 7 t A I t Y K T F q 9 o s K G p L c n 9 D D D d d 8 I J Q h 2 i 73 x k X D p + J S 53 l s s W x 7 M b c m V S L t N m L K p K M 6 S g i j i s M 0 k g E c f x Q S U k G g x Q h p d 4 b u O m U T b M w o d D + O J C o 1 / s G j b e 6 l p 19 m / e s a u V o h K j x W z L K F S 0 N x i 3 D C u 1 / 1 t F Z C 1 b 6 d w Z 563 T H I K h L B H e d i 1 R z g w S H i B 9 Z 0 S Z X 0 E r u C q t t S 8 f z q M i 2 N w 3 J 0 7 u i j 98 h l x l s a r r F k U p F A k 3 e E p + q Q C T C m c L Q 9 s K y b t U 7 o g R w P N 7 h s Z A T t F v V F R F f K S Z u t e O d Z d I 1 + f I B e Z o e G r F F 1 r N / R x 96 N e W L W J S k H H Z W X b T / B l 5 / D y k S 9 T 0 l d B w a W 12 D t a c j 6 M v j N p + + q r Z B 17 j r v f 1 L Y T v a R n k Z b F b u A 4 v + Z 7 L C M d 6 z H Q B v n A c 6 g D 8 H Q P t y x h q W a C N V x g T w 4 H I 6 / 0 N g x r y 5 x h B 90 o w A 2 f N N K Z 4 h y z n 7 x Z e U v + o n x m l s t e q 4 w O W G h / v f o o Y b 4 g M 8 D A I d 0 v T g / H h c c r 7 d Q Y S + B 2 a r W 3 e x 2 x n p 5 V l J 8 n D m N x m L r J K Z 90 e A e u a 1 W g h C 2 R 8 g g 3 G L u 6 m h w 9 L B I e t r E E W 1 f J Z e i h o S / Z j F p w h p r W V g f q l e r I D O h t n 7 x F 7 v W M h 2 D + L V n c P L y W 6 V 6 I q e y 7e5 R N a l C Z z n m y I N j f 9 f T V Y C 8 c g S U X J i l 19 S u q o I X a / f P Q E f G g a D s 6 K 6 g G m R Q Q g L H E n f o E M c z G W a b G N n F i h / Y F V n y Q j 5 r P D g 15 A z 42 I 8 u o 0 0 k 3947 f 5 g g f g / J U D S 7 U j Q s B G Y h i m u O H O b O 5 Y r h 5 z h i / P 1 n W Y 0 V e 7 x C P y y m a O j D j A H 6 P F N s a S m 9 Z j A k D h b O E u H I 3 J 6 x J b y F N X q j p q b p d m E F 73 G o Q j v J G T 5 P m D T f s P P y j f g r h o i U 1 L P B b N s B G l + L V v u P R l x x 9 E u h M 1 l 70 n P z 3 f 7 + a I d X i F o u u A H H u + 20 r P D r m 6 M A D / 70 / c g O p l a h Z G U G P F W h v 9 K D H t 1 P K q v u j O D e m w M b v T N 7 R V T M k W R G z E l 8 B A A W d V 89 Z d C f V i a 44 D v D 0 1 o B r o a N b 4 T r v R L O s 1 t A c 70 K o E g 4 K n Y w i 2 Y N 4 V d D M A R G 7 d z 3 V k J C J T R T V P K 0 5 R c R H p B o C / X B Z v m C f o w 2 s j E 1 i i g n d P + W Q y E X R 9 j z 0 z z 5e0 a L u R D F U 8 y I F z J R G s T D F M C I s d H r u k T d s s C J y B o 8 N u h C 86 b o z u 4 c 7 K 0 8 m j J 9 K E / e p G e H U b K X 6 c V H 7 W Y A 3 J G y U a r H T 18 b j i O q j H c e / B N T L S S 1 G z q Z L f x b 6 s 1 i A 2 z H A n y q s G 0 d p u H 97 d e y v d 8 M P X k O C 7 + q q I j z n K Q A O X p Q 67 P v l 5 P h I l 5 t d n Z U q f Z k 9 C T b / Q m X d X W e S f D o 9 r 9 O s P k W O z f p u P 37 l t F Y p K J 4 E p Q s S k / y t z v C d m 1 I S l K c T V p s c v / 0 i c e 2 d x 4 Y 3 J Z n 52 m 7 x Y w C B A w a g e S q y N + X 2 A F n 8 K C M Y W u z g 2 N 79 g a r b l J Q G H 6 K o P P w v F K 4 W J 31 R Y F 9 x O f + 6 m i D y r K l 2 S W 9 Y H n S U / M S v D r I J t u 2 a v M x h c M F 5 U d C K 2 V + M e + 86 m t j M T I P Q W 8 W 1 N H X z S v 3 j / V f G a Q I O u C Q F G j J G s 3 g l o k j W + m + 3 E C Y / 9 W 11 Y l 3 G k j R U h 1 j L J J 1 y U J s b F X V 6 P X w 3 z D h F X J / Y O Q m h P q 9 S H o Z l l A K 1 G X j O m O L C b B t u s C 3 g M S g L Q D r A O u h A B q r S g a j l 73 j V / 0 m 9 K R 3 f Z 5 q K Y 1 L R 1 t 6 x z E Z h l c X F T w R f Z 3 E I 88 n 6 U y U 6 V K c 3 u d i u H L p 2 u e M 4 A 0 i k l n e g a s e W E B d l C 5 g s m 3 x 7 Q 3 i I i U T E 4 u q 4 J R r o Z o O n g h + M M k N M p 4 d Q i C j t T f 0 X y N s O E j Z y d D 897 h E 1 g 3 p e N g Y E W 4 B 9 S u u d I X R G r p w m W 6 t L x r N D / c E o v k r D 8 y x x a W O j O c 9 C x z E p X j U 0 b 8 Z J 73 w + z O A 4 b o 2 b B 9 O D i R V h E y Z x g w M H K 2 X H r A h K h J b V B 9 L L T 4 X M W H x s W a m 6 S w G U s 4 F h D X x c e d Y l u K P c v 1 x p P 6 a l g Z 0 b s C B F N q Q C I 35 m 6 a L Y g i q k 77 C q x z b t 5 j b a e a w I J n 3 a W / P 8 o T + 3 J d 5 A t u 0 G a w K F F F H N U p B 3 p f 6 p a F W t c m v s Y G j N p u Z M / z n h i L L z T F Z 5 R C E P T I x w g g w m E D y 88 S W n N X 2 s R z c g A X G 7 Y M h P 0 v r U E + i W C X m J W 9 f Q a b + d F Z N V n s A e X O 8 s n B e W + o D I / i S c H J f 3 C K k 7 h Z 0 e W g w + O x M + m a D T I O 9 s Y m L b 62 K E v + B j e D N j T 8 i h z g E w z e Z M F M / 7 N N e 0 y k c / U O E u z k 2 L 7 J n j Y T c 9 I W y H P v Q I I O N s 9 d 0 r w o s 7 B s s M A H 6 G M 2 A 2 f p U o E 9 A w Z J 2 n u X P P m B O t 2 D g 0 5 / 9 I R b + a A M D 9 J h l z q h V 4 L r f j C u 1 D S 8 K x E g 9 e i n z d J 5 o k C T U X r N z y z i p N L e 4 Q w 1 / O f D 3 V 1 / J W Q 12 u m B C g h 3 z p y + P h T P 0 p Z 131 z s U 64 e q 7 h N J U L s q s t r M q / L r F Q s V D E 3 e I n r A y u a w f C 8 R 5 Y i P 3 v 0 I O x G n i x Z C C g 8 D c f S f t B 60 X d 0 b s j 78 u S o D I I S h I s K + j M M N B D h / G W 8 o 2 Y r p 1 c i E k 7 Z 8 + l g b u X s P T d 5 m U c 36 c S K 5 N 6 K J K H T c R U f I f p J m d p 9 O z S L b 18
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:26:15Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Installation"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e488f10-027c-49ed-a39f-4f3e0a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:26:15.000Z" ,
"modified" : "2020-02-17T19:26:15.000Z" ,
"pattern" : "[file:hashes.MD5 = '701a346228708332063529695210309a' AND file:hashes.SHA1 = '651daa1d0e25c515d8ec9e40627efa0e572de9b7' AND file:hashes.SHA256 = 'ea755fc9ed86a2a8fd8712e76e1a8ebc2d871ec143b53f4abd3ef4d9150263fa' AND file:name = 'PROTOZOA.vbs' AND file:size = '104' AND (file:content_ref.payload_bin = 'UEsDBBQACQAIANQEUFAoHxDscgAAAGgAAAAgABwANzAxYTM0NjIyODcwODMzMjA2MzUyOTY5NTIxMDMwOWFVVAkAAxCPSF4Qj0hedXgLAAEEIQAAAAQhAAAA8ZIOsoPrG3Z5XHKyWGdvFkoV6A/eOpsiE50ZIXk3a+3v2/CbxATtYK3Uu+y14Fu/YmQaYlNX40Ve2ap7va0Q37FtGNRW8s5VcoewoIi7J5i52LY26na/9UmJkUmU5a6VZroEMS5t9DK0XST9gJm0Qmd3UEsHCCgfEOxyAAAAaAAAAFBLAwQKAAkAAADUBFBQZf6gRRgAAAAMAAAALQAcADcwMWEzNDYyMjg3MDgzMzIwNjM1Mjk2OTUyMTAzMDlhLmZpbGVuYW1lLnR4dFVUCQADEI9IXhCPSF51eAsAAQQhAAAABCEAAAAshUppe3PJz0V4VKaGN7Y2Q5D+kJs0v3BQSwcIZf6gRRgAAAAMAAAAUEsBAh4DFAAJAAgA1ARQUCgfEOxyAAAAaAAAACAAGAAAAAAAAQAAAKSBAAAAADcwMWEzNDYyMjg3MDgzMzIwNjM1Mjk2OTUyMTAzMDlhVVQFAAMQj0hedXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAA1ARQUGX+oEUYAAAADAAAAC0AGAAAAAAAAQAAAKSB3AAAADcwMWEzNDYyMjg3MDgzMzIwNjM1Mjk2OTUyMTAzMDlhLmZpbGVuYW1lLnR4dFVUBQADEI9IXnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAABrAQAAAAA=' AND file:content_ref.x_misp_filename = 'PROTOZOA.vbs' AND file:content_ref.hashes.MD5 = '701a346228708332063529695210309a' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected')]" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:26:15Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Installation"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5e488f1f-6f84-4eec-8d89-4b990a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:23:06.000Z" ,
"modified" : "2020-02-17T19:23:06.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' b 102452e6 d 92 a 217995 f 4 c a 5523 d 0 b 85 ' A N D f i l e : h a s h e s . S H A 1 = ' c e 297 b 51992 a 43698 b 61467 b e b 7 b 1 b a e 55605037 ' A N D f i l e : h a s h e s . S H A 256 = ' 5 b e 14 f 4258 e d 8 d 96 d a 626 d f f 4 c 8980 f 121208 c 45595639 b a 1 f b e b 9 f 895 d e b a a 4 ' A N D f i l e : n a m e = ' I r s l e t t e r w i t h W 2 . d o c ' A N D f i l e : s i z e = ' 717585 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A N s E U F A 9 R U 3 G v b k K A B H z C g A g A B w A Y j E w M j Q 1 M m U 2 Z D k y Y T I x N z k 5 N W Y 0 Y 2E1 N T I z Z D B i O D V V V A k A A x 6 P S F 4 f j 0 h e d X g L A A E E I Q A A A A Q h A A A A 66 d n q T F t P k g w b 6 g Q d Y m a a p + A F 6 t p M f h S x D u Z X O K p v S r 9 V 0 + 6 E A I C 2 a M u C 8 c h h + Q o o E 7 F K J V 3 t 1 J g C 0 d M n F n + b M c Y K h 8 Z C C W 9 y P r q Y T i S F E V e 1 D R g 83 T n / p e n b i B m R N B z 1 / r V X P s s m F u + K u z V 76 X i 306 s X + n i L P D V Z U n f 4 K a x U 379 / R 9 U y B I G J z 4 e X j r 6 J 8 u l m i E V s o 0 f e q W W Z 80 j u J d 3 A n u / X 8 q B q f L Y e t n x p W 6 + x l V 2 N A c l l v A N b s G 0 8 K / T V I e N R q M n a M I 8 Q s D Q m Z B k u P d y N Y u I a B K O c T x 9 S I Y I I w V Z D S j q 2 h O / f 7 K z T C + q U l y k i Q Z O u Z g h 8 A 9 o Q R Z + L a w 7 z h M Q y y l U 7 Y M 78 j K H f a G P i m S b x 3 W H L 2 W 7 V 7 o L F + c / x P P e V c 8 e C o V W C A 7 Z e B m 8 B 2 z g I i t j l Z j H 78 v 2 C k L f l d Q n u 3 O G P w 8 G v F Z F 0 p 588 U 3 h D 5 g f j Y h N r G a U P r H I C r m B U t g k s k K r p O f Q w V 0 b v u X C m 8 Z K f 2 A Z m l 5 I N i 1 / b h U I 4039 M J Z s L o G k 5 I C r 2 O U R n p h Y p w 3 n s 1 c t L s b W y + J j f k d K t 8 S c N x U w e 1 L Y Q e 9 h p i v n e p v r c 6 W C Y 85 P Z 9 B K f e e U P x C d N b P T L S T 3 S R 3 o G + B S p 0 K B B i V 7 p Y p 2 n k p 2 L + 5 p E k / v N T C q N q X l C i a a 1 q p z 8 R R D G F G T w N 2 u Q R 4 y 5 u f d f w c g 4 Q m 64 N Q 4 G A e u U O N u r I T i z y O 8 K 4 P 9 A Z + P p 3 / u / 4 M V H q a m d T y g 6 H T E f j y 1 u k H X B q z t e t F r 26 K V X 5 a A h X r X T D A d 0 u Q J E d O 3 + 9 s 1 u d o w 0 8 G P W O m T p 0 j W x I V t o 3 l w y p N G j a d G 8 E K x / 0 4 o 8 b d G e 9 U 6 c f Q x r S p p 5 e G d 5 B H Q j h 8 K f h K 8 a 0 y a 2 o 39 K g + 8 i l Y + r q c v 6 p b i V s / I k U p 1 v l O e f A B V S Q g D X F + J E 0 t Y t 2 X w 2 c b w I 2 g X N b i J 4 Q y S E g m R 876 n O I R m j N i h 2 n E E o + q P P w h 0 f 7 c k w / 0 P h 6 A K 27 W d C Z G g Y e f z / A e N 0 N f i Z A q v u X A C X H 2 K F 9 x R N a y U 353 v r w R L M x T a K Z o 8 p V V b c 988 B U J B O 5 F 7 d C v M r A S 52 B I t I M B S 4 c G M 5 z Y 6 X b 0 b W t w Q V 3 R / J h D G w 5 Z 0 Q f G t g d 3 E C C J S O d E T + u 0 a j k z w p 5 H X P o 55 r L / V K m b 2 P 2 s x m H y M l a W L U b V N z v 15 j h m O i 8 L d v 4 k y E B t f t 8 c q V a E H p N 5 E z F b 6 + 5 J O m J t n 0 d t Y X k 59 C o q k O V J e E E 3 l 3 z v R y h J K i s g Q a D + B P 5 o / S E 5 U R V 6 n q H G 1 y o H U W N f s b s 9 q X G j U y 69 y r v k 6 / T f r k D 19 i F S I l A O j c X M h k L N f Z g N b w S R K 1 L F I x X b L e E j 7 u D e J S L w 4 T p 0 z 7 R F K t k U j Z J K D z B e p b 5 p n z T F 0 22 f 1 J G T y X 0 6 T P g e B C d p H 594 T S 7 O A U i D O l L l 6 X Z Y Y c q q w J V y / q Z k 7 V 8 m 8 X V F B Z M T U z I R i R C c G b o L v M Q Z C 1 L 8 u G J 90 p l 4 V Y d c G P 4 h H k g p h E y S + x N N k 9 q k 5 K y u a g 2 w J v y a E e + l C z e 0 b Y V u 4 D C D 8 M D 9 y Z P 3 t g M 7 f A 6 M 4 Z j b D S X d u O g L A k l x z + U j D 8 B 3 i U K C m 7 n w 37 f 3 v P 38 H 6 f a Q j z M h q n + R q S 5 R C o O d V 24 O B n m I L p P 8 S 6 M d + 0 d D a Z w N u K v 8 X a i f Y a U 7 C n c 7 c k + I y E i + i b 2 y 90 P P F v H H b x n G l T q o S J 0 R 6 A 9 n / s E p j L S Y h j 7 S M p A Q c l V w 6 b V O W A X j c K j n j W G I 4 E A e A z 8 A s Y S P x K x 0 M r t 52 t g m i b X z c q v U J x H 6 F V A C 8 j H D b u G Q o o d H i y t 1 f j f z + k 5 m I A 2 / L I S v 4 h t T z 3 m t o P x t m M f I J T R 8 a J F 0 o 3 N F 6 j c p T M + K P d G l r 6 A w v M z s I o 6 O g U 4 + c L o j s J e g W E y w g b O t H N u 7 p a r 0 2 F x h P f I v x k w o x k N y l n C U 9 T a V w M l e 9 U K M t 1 K r d j / j m I Z U + R X T 3 f T f 2 y S 5 i u 6 w 84 Y t L P g I l s / f 5 A 1 h / K 4 y x 2 W j + u j Q H c 8 J L g Z k R Z 786 A E p H 4 A M j j 1 Y c o r a 0 8 q L 826 T V f a C l 3 V R h N r V w L o s r N 8 M w 9 Q X 0 2 C a m Y z m V 6 H g t q v n m k h N T B x H l X e L p Z Y b a A P 8 k c v c y e a t E X s J 7 L A e c C C 4 t o 21 Z 9 s + 8 N v t Y O e O E X m + f t N B a R G u T c m 5 r g 5 U j v / k E 2 N G R p g Z 2 O g p 3 a r r 6 h Q E j P k o i O L a V P i s 6 g 813 u i X X b a b W j x h A e I y j j w e + I 3 N d x E 6 P U A f w o u e 8 l L j H Q 9 K v H H Z q G S h Z N P 6 r F b l J u W y O N 2 E W E q w E 1 M W 35 K l v H v p a / Y O o u 74 n X d 4 N 1 t i O L 9 b 4 a e e C 6 W 5 c N A J G S b G K k L 1 F C f O 1 B 9 V d j i T V U h Z / r O / B r k c 7 y N x + Q n 6 H P L D q G X w z S 68 V r S U k X c 4 o M R w 7 I 7 g k r J R e 1 Q i R b k V 6 c y P r N 1 h N V f K M O s T 7 V d P + z Q n S I G p n 8 n K N T U q U R 8 e B k F p H X E x W j n g e f l e / M C I c r O j A p v H l F J J t v q B c L y s Q j 93 u s s w 1 u Y J c g 2 a 1 K K F y U L 0 A P 0 b / F l p l q 86 j q Q M 47 V K k l O d T 17 f T R X n 9 q k Q a u p l W l K y T t H + v 70 / t h N b 11 z J 5 c h / 4 o v Y f U c u + r E H Y E O D L N K W K X 15 h 0 B M u A q 5 o L s T 9 m u c j K B z L B 7 T B B X B 1 P e R m X e N P 5 h g 87 S 8 / j b 5 m o X b t o o S h j G w A K o B e R J l w z + P Z K o B B h C 7 b V 9 j Z 34 L K j Q N b B 78 R P U l 7 X Y Z m E e 8 h i j V Y K + S S x M + s B y 2 h N 5 e v 9 u 76 a q M K V + E 5 D X k P v 68 U + T T C i w Y 4 k f e J g j 1 L k c 0 L X 0 Q 2 j G K s W Z 4 P j 6 f 2 F x 8 S W 2 D I V W T a m C 2 n h I 9 L A K R X p S A c 7 d F i l 4 W w 5 G S 0 136 w J K n 9 l o u R z e Z i J X X J T + 102 T X 19 d v D B H f E P c m s r r 3 h q G t e m y C t X p T V w 7 I c 2 B K w z Z 3 R j l Z v 1 x S C r u g / y y 8 v Q q 6 s W o J P w v i F d u k t c K K A J 4 y X 0 6 Q N C O m 3 P g e + r V l 4 F m D 8 H q 7 x / 4 A j P h a n Q t e e L T X j Q 8 f t c 93 F x p Y o X o L 2 R I R D 4 T V L o Q k n Y e Y 4 N O e G b 1E0 I 0 q j 6 d R s / k u i P 44 c Q o s D A P v z L n 7 i W c K J h P 0 P v t L T h z u + M M o L G W 7 e n E + V H D p O e y x Q J 2 F H A H K 3 N E T l C R q T Q O 9 L i p 4 D Q 1 X e k T D u M M M O V I F B 2 L l c l h X 6 a 9 V L s j o k p c m 9 H a r f 3 L X f Q S b L e J d 7 r 8 X l 6 j n s 1 s 9 e Z 4 w a A u E + p P t 9 u v 83 H x U o b r p A p s z 2 y S 8 / m I E t u 6 V D A M 7 X x q 78 e N V B v c V C G n B t S 0 4 g 3 c o N 94 e i I I H C 5 R R 9 A m 0 z T E x 7 s 4 N 1 t V T I 1 e h + 7 U Q 0 i E M C a 0 9 G y N M a g c W 7 A K E c C D m w M R p s D 9 l K l d P f I u r S W p W n 1 V I 2 q q 8 y 414 i J 7 D 5 b B C n V V H Y D H x k v S h Y q z t i U f U S 9 S f / o C g M w F k S G r P E n M P d 31 W R 49 m 85 Y I w N h e J j P g o t z B L U n h B U T Y c P 4 m A l + g a M g N j 4 / C 2 S 7 H 1 N 7 n 6 z 2 R M n h x 5 p e E o a n O 0 H 9 C I C e + e o N 57 Y 8 s 12 + Z 1 G F Z 34 K a E 6 M T t K c B B x o J h Y 1 F a C a v N J A G b H 47 / H 5 H + 3 Y e y R n Z m 7 k w 82 z + A g O E N H J E c N p b Y x L A A O Z g j b n m u A Y b 5 I m J G E O 8 H U k n j 8 y W A X u E R V t R W 7 k T P 5 a O Q 6 H b J n W l I Y u D V x x U S + h 4 t a b L 3 e t v M L U L E 4 Y g 3 E p 8 Q 3 j W l x e 94 R c t O q B d q Z J D s s U D Q + L 7 P Z q y F i 5 o s 560 T M l Z a M M + H M t h k s Y x Y s r H R 6 o q 4 Y Q l d Y i d Y g e Z R R 23 q m Q 64 a k V L V S K 4 U l / P g B J Y Q 8 l 79 e + g I V E U p 0 w E q + x W p S y b 5 q 67 q J p D C x p N O V x P 1 V N
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-02-17T19:23:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\"" ,
"kill-chain:Delivery"
]
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--5e4aea3d-a5f8-42b5-9539-457e0a0a020f" ,
"created_by_ref" : "identity--5e157d76-c92c-4acd-a54e-4a01950d210f" ,
"created" : "2020-02-17T19:32:13.000Z" ,
"modified" : "2020-02-17T19:32:13.000Z" ,
"labels" : [
"misp:name=\"virustotal-report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "link" ,
"object_relation" : "permalink" ,
"value" : "https://www.virustotal.com/gui/file/585f829c600736a9613d0870c6460068d9461a7be35c07149fe58143b2f24b6f/detection" ,
"category" : "External analysis" ,
"uuid" : "5e4aea3d-deb0-46df-9a69-41200a0a020f"
} ,
{
"type" : "text" ,
"object_relation" : "detection-ratio" ,
"value" : "7/72 initially, later 38/70" ,
"category" : "External analysis" ,
"uuid" : "5e4aea3d-2798-4a11-aed6-45810a0a020f"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "virustotal-report"
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
2023-04-21 13:25:09 +00:00
]
}