2023-04-21 14:44:17 +00:00
|
|
|
{
|
|
|
|
"type": "bundle",
|
|
|
|
"id": "bundle--57e634d4-4e48-4a7b-82de-46be950d210f",
|
|
|
|
"objects": [
|
|
|
|
{
|
|
|
|
"type": "identity",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:37:46.000Z",
|
|
|
|
"modified": "2018-05-15T14:37:46.000Z",
|
|
|
|
"name": "CIRCL",
|
|
|
|
"identity_class": "organization"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "report",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "report--57e634d4-4e48-4a7b-82de-46be950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:37:46.000Z",
|
|
|
|
"modified": "2018-05-15T14:37:46.000Z",
|
|
|
|
"name": "OSINT - Hunting Libyan Scorpions",
|
|
|
|
"published": "2018-05-15T14:38:05Z",
|
|
|
|
"object_refs": [
|
|
|
|
"observed-data--5afaeed5-5af0-4dd9-9744-4e46950d210f",
|
|
|
|
"url--5afaeed5-5af0-4dd9-9744-4e46950d210f",
|
|
|
|
"observed-data--5afaef73-fc68-4474-a2f7-3556950d210f",
|
|
|
|
"file--5afaef73-fc68-4474-a2f7-3556950d210f",
|
|
|
|
"artifact--5afaef73-fc68-4474-a2f7-3556950d210f",
|
|
|
|
"indicator--5afaefb2-e71c-4bde-8835-48e0950d210f",
|
|
|
|
"indicator--5afaefb2-d584-4a0d-8ee9-4ee7950d210f",
|
|
|
|
"indicator--5afaefb3-84fc-45fe-bf6b-463a950d210f",
|
|
|
|
"indicator--5afaefb3-76e0-4886-b83a-4e5f950d210f",
|
|
|
|
"indicator--5afaefb3-1448-4f67-8702-4a4d950d210f",
|
|
|
|
"indicator--5afaefb4-9288-4529-8480-461a950d210f",
|
|
|
|
"indicator--5afaefb4-d238-43d2-bde4-4146950d210f",
|
|
|
|
"indicator--5afaefb5-eb00-463a-91e0-4c37950d210f",
|
|
|
|
"indicator--5afaefb5-42a4-4a7d-a826-416f950d210f",
|
|
|
|
"indicator--5afaf007-fdcc-4753-9989-1869950d210f",
|
|
|
|
"indicator--5afaf03c-5aec-463e-9584-474d950d210f",
|
|
|
|
"indicator--5afaf05c-36d4-470e-914e-3537950d210f",
|
|
|
|
"indicator--5afaf078-7330-4b67-bbe8-3537950d210f",
|
|
|
|
"indicator--5afaf0a6-74d4-442d-b7e3-4444950d210f",
|
|
|
|
"indicator--5afaf0b7-77c4-4e09-8ef4-4d6a950d210f",
|
|
|
|
"x-misp-object--cf08eeff-6adc-4055-b07b-85e896626093",
|
|
|
|
"x-misp-object--a850600c-54f1-4a14-b31c-9593edb9fbb5",
|
|
|
|
"x-misp-object--2cbd399e-6423-4649-b234-ffcd3dca9398",
|
|
|
|
"x-misp-object--4a94a5d1-5967-4028-adf2-b900291f8b40",
|
|
|
|
"x-misp-object--f8939924-ce54-40ea-8744-9ba61335b548",
|
|
|
|
"x-misp-object--71f29082-0567-4b34-8076-6ce923945e31",
|
2023-12-14 14:30:15 +00:00
|
|
|
"relationship--90c75ce1-2afa-42e4-991d-299e1b4c0160",
|
|
|
|
"relationship--439bfef6-6573-47d9-a235-24a45067e308",
|
|
|
|
"relationship--8e7112ee-b75c-4c1f-b882-8aec1a84553e"
|
2023-04-21 14:44:17 +00:00
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"Threat-Report",
|
|
|
|
"misp:tool=\"MISP-STIX-Converter\"",
|
|
|
|
"type:OSINT"
|
|
|
|
],
|
|
|
|
"object_marking_refs": [
|
|
|
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "observed-data",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "observed-data--5afaeed5-5af0-4dd9-9744-4e46950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:29:41.000Z",
|
|
|
|
"modified": "2018-05-15T14:29:41.000Z",
|
|
|
|
"first_observed": "2018-05-15T14:29:41Z",
|
|
|
|
"last_observed": "2018-05-15T14:29:41Z",
|
|
|
|
"number_observed": 1,
|
|
|
|
"object_refs": [
|
|
|
|
"url--5afaeed5-5af0-4dd9-9744-4e46950d210f"
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"link\"",
|
|
|
|
"misp:category=\"External analysis\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "url",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "url--5afaeed5-5af0-4dd9-9744-4e46950d210f",
|
|
|
|
"value": "https://cyberkov.com/wp-content/uploads/2016/09/Hunting-Libyan-Scorpions-EN.pdf"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "observed-data",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "observed-data--5afaef73-fc68-4474-a2f7-3556950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:32:19.000Z",
|
|
|
|
"modified": "2018-05-15T14:32:19.000Z",
|
|
|
|
"first_observed": "2018-05-15T14:32:19Z",
|
|
|
|
"last_observed": "2018-05-15T14:32:19Z",
|
|
|
|
"number_observed": 1,
|
|
|
|
"object_refs": [
|
|
|
|
"file--5afaef73-fc68-4474-a2f7-3556950d210f",
|
|
|
|
"artifact--5afaef73-fc68-4474-a2f7-3556950d210f"
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"attachment\"",
|
|
|
|
"misp:category=\"External analysis\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "file",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "file--5afaef73-fc68-4474-a2f7-3556950d210f",
|
|
|
|
"name": "Hunting-Libyan-Scorpions-EN.pdf",
|
|
|
|
"content_ref": "artifact--5afaef73-fc68-4474-a2f7-3556950d210f"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "artifact",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "artifact--5afaef73-fc68-4474-a2f7-3556950d210f",
|
|
|
|
"payload_bin": "JVBERi0xLjUNCiW1tbW1DQoxIDAgb2JqDQo8PC9UeXBlL0NhdGFsb2cvUGFnZXMgMiAwIFIvTGFuZyhlbi1VUykgL1N0cnVjdFRyZWVSb290IDI0MCAwIFIvTWFya0luZm88PC9NYXJrZWQgdHJ1ZT4+L01ldGFkYXRhIDkwNiAwIFIvVmlld2VyUHJlZmVyZW5jZXMgOTA3IDAgUj4+DQplbmRvYmoNCjIgMCBvYmoNCjw8L1R5cGUvUGFnZXMvQ291bnQgMzQvS2lkc1sgMyAwIFIgMjAgMCBSIDQwIDAgUiA0NSAwIFIgNDcgMCBSIDQ5IDAgUiA1MCAwIFIgNTIgMCBSIDUzIDAgUiA1NCAwIFIgNTUgMCBSIDU2IDAgUiA1NyAwIFIgNTggMCBSIDU5IDAgUiA2MCAwIFIgNjEgMCBSIDYyIDAgUiA2MyAwIFIgNjQgMCBSIDY1IDAgUiA2NiAwIFIgNjkgMCBSIDcwIDAgUiA3MSAwIFIgNzMgMCBSIDc1IDAgUiA3NiAwIFIgNzcgMCBSIDc4IDAgUiA4MCAwIFIgODEgMCBSIDgyIDAgUiA4MyAwIFJdID4+DQplbmRvYmoNCjMgMCBvYmoNCjw8L1R5cGUvUGFnZS9QYXJlbnQgMiAwIFIvUmVzb3VyY2VzPDwvRm9udDw8L0YxIDUgMCBSL0YyIDEyIDAgUi9GMyAxNCAwIFIvRjQgMTYgMCBSPj4vRXh0R1N0YXRlPDwvR1M3IDcgMCBSL0dTOCA4IDAgUj4+L1hPYmplY3Q8PC9JbWFnZTkgOSAwIFIvSW1hZ2UxOCAxOCAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9JbWFnZUIvSW1hZ2VDL0ltYWdlSV0gPj4vQW5ub3RzWyAxMSAwIFJdIC9NZWRpYUJveFsgMCAwIDU5NS4zMiA4NDEuOTJdIC9Db250ZW50cyA0IDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAvUy9UcmFuc3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBhcmVudHMgMD4+DQplbmRvYmoNCjQgMCBvYmoNCjw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggMTM3OT4+DQpzdHJlYW0NCnicvVldT9tYEH2PlP8wj3ZXubnfH6iqtqVQWFGJXSL1gfbBCSb1lsRsYkqR+uN3xg4tje0NJGaRiGP72nPmzLlzZ26GrxdFdplMCnj5cvi6KJLJ5/QCzoej/PrTcHR3nQ5Pk2k2T4osnw/PbsYFXTpKk4t08eoVvHm7D//0e5xx+vPeCeBggmFKgteCBQmLtN/78ALm/d6bUb83PBQgBOMaRpf9Ho3mIMBocNoygVdnOObdmYPpEl8L0/LMr87e9XvnEcSfYPRHv3eAb/uz33u0dRwLB+/3Ydji8Ju8KPJZu8+HeV507LNiwZYel44+s3+PDyjHQIQKkTOGaUk28b80dvmixDRYgXI8ICj6rrgRvhWdMaXb6DTG2eB7HRMOJhTt41kyTQO8zaFyV2vJrMIhnikPQhsmFBjOjNYPXvjoge0R0M4yacEFz7Sv4sDCyvPySxmP/bt4IKNxrKJ08SUOUR4PTPQ1thHs358xOIkHKiouWC12u2I0Rj8CY10z3VjXjjOHc9NLpldC5cwGINMCFtO1C3+VYG5v44GObtkkFjy6I2Iq8uj0Sx5rJA/v021Z0Td7BtYCs/aJuNdIrD3ygwxOofCeBI5X5MNp0R3t+KCzlvH2oGfz2ESXOZH5++RunBK/qFAh7iX6gOVnIdlSotiEslGaneZiwZThAqRhxmH+kSyA8MyZH3HhdHJLR1GhQvB/Q+8/nzurKBJMWBphMbMJiYlLaOb9WhraOOiew/ALf4Ib5i0oWRI7oxtT+ihpG1EIU4zbFc6dPfgNvwVrQEqtjeEcL8L3eGAb6N0aji8X4GY4h5jvkm8IooIi4GNEE9v7eID68h9jypGglVICRfSdwMNBObeT7Kp8LMOJfy9YR4KtsmrlJMpWr1SLisVDlReAxFu5+YHM0VB6ZImjM6SgSBHWHtzSvSrprDSPn3dr73a/vnoH2hrmKyUD30Jda25+pEFcTOvpTVF6k4JJval+uJ9qMDylSfZ+//gt8O2qGEUIGyo3GZiXndUx7baEUsz4ru01ESS6I0jhGsQxr2pcwN0m0DUgcjsgGqQra8tf2BPModR4wLz36EXx6GZeZPPpTrFsQiMVrhrhqWh201QjDlwElXoqjpNsfJfM4YwSz4QSWb6gr9e4Ri07h6htOdt3o6qmLLW1suy6xC2WqFKXOI2oSfx4/jVdFtk0KTAHdyClmnkp0XnRZn5nyTTYs0y5ZntAfZGgPnZyHiXPYBurtKDafK1k2blRhZpU/yPBWEUw3kIw9WNjXNDTBRwsab5h74i66h6E4Lg+e9DSU36ogUhm10k2nVMbOEoW3cfZ+lJjzdanaZmT0fZRNv3cuXHNNWWaFuOD7u0JxYRos3e6yLHUu8T/7Cp9jtmMNb8DFRSToSF5XV7dpLgEouQSqsZ3Tu91tWP/ZEwbgE1pXHeXxmlDCquULUCY7kDI4Bj2OYor2h96KhC7LRBhaoWBcVSgSIt46sXm6OR0D1CS2Jb46DNps6CmI91RHXUYSmFEVBuMTXy4rbcr63xgp+JDVbfVNy0PsQDSEVzfjKkOuqKSKKOPCVxky5KaBZFU9nw38SBExY8h+W4LVhNWZQNNqRasm0jz2xb/2I+tk1apWeAhdFa5he7x0RZQZ/jE1u1lO0DhqfPrDOGW/R1qTa6VY455Q3uBut6Ii111vWYLm/7gWmz5jm1ZTsmv2dawa1uaFuBmW2dU3F1T/ljlVx/NxuXW2G41Vw2FIoW1RXJISU1yzHDCdmwWBaTbnN8o44e7A2CUIZMrAMJ5OvwEILCitNWPMMIa2raWWHZhmbfamfj5UwxWvdVvMaXBfwFkhZuzDQplbmRzdHJlYW0NCmVuZG9iag0KNSAwIG9iag0KPDwvVHlwZS9Gb250L1N1YnR5cGUvVHJ1ZVR5cGUvTmFtZS9GMS9CYXNlRm9udC9CQ0RFRUUrQ2FsaWJyaS9FbmNvZGluZy9XaW5BbnNpRW5jb2RpbmcvRm9udERlc2NyaXB0b3IgNiAwIFIvRmlyc3RDaGFyIDMyL0xhc3RDaGFyIDEyNC9XaWR0aHMgODc3IDAgUj4+DQplbmRvYmoNCjYgMCBvYmoNCjw8L1R5cGUvRm9udERlc2NyaXB0b3IvRm9udE5hbWUvQkNERUVFK0NhbGlicmkvRmxhZ3MgMzIvSXRhbGljQW5nbGUgMC9Bc2NlbnQgNzUwL0Rlc2NlbnQgLTI1MC9DYXBIZWlnaHQgNzUwL0F2Z1dpZHRoIDUyMS9NYXhXaWR0aCAxNzQzL0ZvbnRXZWlnaHQgNDAwL1hIZWlnaHQgMjUwL1N0ZW1WIDUyL0ZvbnRCQm94WyAtNTAzIC0yNTAgMTI0MCA3NTBdIC9Gb250RmlsZTIgODc1IDAgUj4+DQplbmRvYmoNCjcgMCBvYmoNCjw8L1R5cGUvRXh0R1N0YXRlL0JNL05vcm1hbC9jYSAxPj4NCmVuZG9iag0KOCAwIG9iag0KPDwvVHlwZS9FeHRHU3RhdGUvQk0vTm9ybWFsL0NBIDE+Pg0KZW5kb2JqDQo5IDAgb2JqDQo8PC9UeXBlL1hPYmplY3QvU3VidHlwZS9JbWFnZS9XaWR0aCAxMjIvSGVpZ2h0IDE1Mi9Db2xvclNwYWNlL0RldmljZVJHQi9CaXRzUGVyQ29tcG9uZW50IDgvSW50ZXJwb2xhdGUgZmFsc2UvU01hc2sgMTAgMCBSL0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggMjI0NDM+Pg0Kc3RyZWFtDQp4nNxdh19Ux9pml2XpvXfpbenLLogidkEFe2I0RY299xpjRdOsqKAiSu/bKAuxJGo0do2JSaQ3Ufwnvmdmzh4WxBSjN/d+8xuOZ+fMzHnnmXfeMuVoYPBfHgSG5lY
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaefb2-e71c-4bde-8835-48e0950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:33:22.000Z",
|
|
|
|
"modified": "2018-05-15T14:33:22.000Z",
|
|
|
|
"pattern": "[file:hashes.SHA256 = '9d8e5ccd4cf543b4b41e4c6a1caae1409076a26ee74c61c148dffd3ce87d7787']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:33:22Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"sha256\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaefb2-d584-4a0d-8ee9-4ee7950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:33:22.000Z",
|
|
|
|
"modified": "2018-05-15T14:33:22.000Z",
|
|
|
|
"pattern": "[file:hashes.SHA256 = '4e656834a93ce9c3df40fe9a3ee1efcccc728e7ea997dc2526b216b8fd21cbf6']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:33:22Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"sha256\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaefb3-84fc-45fe-bf6b-463a950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:33:23.000Z",
|
|
|
|
"modified": "2018-05-15T14:33:23.000Z",
|
|
|
|
"pattern": "[file:hashes.SHA256 = 'e66d795d0c832ad16381d433a13a2cb57ab097d90e9c73a1178a95132b1c0f70']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:33:23Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"sha256\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaefb3-76e0-4886-b83a-4e5f950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:33:23.000Z",
|
|
|
|
"modified": "2018-05-15T14:33:23.000Z",
|
|
|
|
"pattern": "[file:hashes.MD5 = '1738ecf69b8303934bb10170bcef8926']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:33:23Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"md5\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaefb3-1448-4f67-8702-4a4d950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:33:23.000Z",
|
|
|
|
"modified": "2018-05-15T14:33:23.000Z",
|
|
|
|
"pattern": "[file:hashes.MD5 = '93ebc337c5fe4794d33df155986a284d']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:33:23Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"md5\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaefb4-9288-4529-8480-461a950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:33:24.000Z",
|
|
|
|
"modified": "2018-05-15T14:33:24.000Z",
|
|
|
|
"pattern": "[file:hashes.MD5 = '1c8a1aa75d514d9b1c7118458e0b8a14']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:33:24Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"md5\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaefb4-d238-43d2-bde4-4146950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:33:24.000Z",
|
|
|
|
"modified": "2018-05-15T14:33:24.000Z",
|
|
|
|
"pattern": "[file:hashes.SHA1 = '41096b7f808a91ee773bbba304ea2cd0fa42519d']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:33:24Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"sha1\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaefb5-eb00-463a-91e0-4c37950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:33:25.000Z",
|
|
|
|
"modified": "2018-05-15T14:33:25.000Z",
|
|
|
|
"pattern": "[file:hashes.SHA1 = '46d832a9c1d6c34edffee361aca3de65db1b7932']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:33:25Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"sha1\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaefb5-42a4-4a7d-a826-416f950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:33:25.000Z",
|
|
|
|
"modified": "2018-05-15T14:33:25.000Z",
|
|
|
|
"pattern": "[file:hashes.SHA1 = '2e2d1315c47db73ba8facb99240ca6c085a9acbc']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:33:25Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Payload delivery"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"sha1\"",
|
|
|
|
"misp:category=\"Payload delivery\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaf007-fdcc-4753-9989-1869950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:34:47.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:47.000Z",
|
|
|
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '41.208.110.46']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:34:47Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Network activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"ip-dst\"",
|
|
|
|
"misp:category=\"Network activity\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaf03c-5aec-463e-9584-474d950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:35:40.000Z",
|
|
|
|
"modified": "2018-05-15T14:35:40.000Z",
|
|
|
|
"pattern": "[domain-name:value = 'samsung.ddns.me']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:35:40Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Network activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"hostname\"",
|
|
|
|
"misp:category=\"Network activity\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaf05c-36d4-470e-914e-3537950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:36:12.000Z",
|
|
|
|
"modified": "2018-05-15T14:36:12.000Z",
|
|
|
|
"pattern": "[domain-name:value = 'collge.myq-see.com']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:36:12Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Network activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"hostname\"",
|
|
|
|
"misp:category=\"Network activity\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaf078-7330-4b67-bbe8-3537950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:36:40.000Z",
|
|
|
|
"modified": "2018-05-15T14:36:40.000Z",
|
|
|
|
"pattern": "[domain-name:value = 'sara2011.no-ip.biz']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:36:40Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Network activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"hostname\"",
|
|
|
|
"misp:category=\"Network activity\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaf0a6-74d4-442d-b7e3-4444950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:37:26.000Z",
|
|
|
|
"modified": "2018-05-15T14:37:26.000Z",
|
|
|
|
"pattern": "[domain-name:value = 'winmeif.myq-see.com']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:37:26Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Network activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"hostname\"",
|
|
|
|
"misp:category=\"Network activity\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--5afaf0b7-77c4-4e09-8ef4-4d6a950d210f",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:37:43.000Z",
|
|
|
|
"modified": "2018-05-15T14:37:43.000Z",
|
|
|
|
"pattern": "[domain-name:value = 'wininit.myq-see.com']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2018-05-15T14:37:43Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "Network activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"hostname\"",
|
|
|
|
"misp:category=\"Network activity\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "x-misp-object",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "x-misp-object--cf08eeff-6adc-4055-b07b-85e896626093",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:34:29.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:29.000Z",
|
|
|
|
"labels": [
|
|
|
|
"misp:name=\"file\"",
|
|
|
|
"misp:meta-category=\"file\""
|
|
|
|
],
|
|
|
|
"x_misp_meta_category": "file",
|
|
|
|
"x_misp_name": "file"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "x-misp-object",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "x-misp-object--a850600c-54f1-4a14-b31c-9593edb9fbb5",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:34:28.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:28.000Z",
|
|
|
|
"labels": [
|
|
|
|
"misp:name=\"virustotal-report\"",
|
|
|
|
"misp:meta-category=\"misc\""
|
|
|
|
],
|
|
|
|
"x_misp_meta_category": "misc",
|
|
|
|
"x_misp_name": "virustotal-report"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "x-misp-object",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "x-misp-object--2cbd399e-6423-4649-b234-ffcd3dca9398",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:34:32.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:32.000Z",
|
|
|
|
"labels": [
|
|
|
|
"misp:name=\"file\"",
|
|
|
|
"misp:meta-category=\"file\""
|
|
|
|
],
|
|
|
|
"x_misp_meta_category": "file",
|
|
|
|
"x_misp_name": "file"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "x-misp-object",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "x-misp-object--4a94a5d1-5967-4028-adf2-b900291f8b40",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:34:31.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:31.000Z",
|
|
|
|
"labels": [
|
|
|
|
"misp:name=\"virustotal-report\"",
|
|
|
|
"misp:meta-category=\"misc\""
|
|
|
|
],
|
|
|
|
"x_misp_meta_category": "misc",
|
|
|
|
"x_misp_name": "virustotal-report"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "x-misp-object",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "x-misp-object--f8939924-ce54-40ea-8744-9ba61335b548",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:34:35.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:35.000Z",
|
|
|
|
"labels": [
|
|
|
|
"misp:name=\"file\"",
|
|
|
|
"misp:meta-category=\"file\""
|
|
|
|
],
|
|
|
|
"x_misp_meta_category": "file",
|
|
|
|
"x_misp_name": "file"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "x-misp-object",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "x-misp-object--71f29082-0567-4b34-8076-6ce923945e31",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2018-05-15T14:34:33.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:33.000Z",
|
|
|
|
"labels": [
|
|
|
|
"misp:name=\"virustotal-report\"",
|
|
|
|
"misp:meta-category=\"misc\""
|
|
|
|
],
|
|
|
|
"x_misp_meta_category": "misc",
|
|
|
|
"x_misp_name": "virustotal-report"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "relationship",
|
|
|
|
"spec_version": "2.1",
|
2023-12-14 14:30:15 +00:00
|
|
|
"id": "relationship--90c75ce1-2afa-42e4-991d-299e1b4c0160",
|
2023-04-21 14:44:17 +00:00
|
|
|
"created": "2018-05-15T14:34:34.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:34.000Z",
|
|
|
|
"relationship_type": "analysed-with",
|
|
|
|
"source_ref": "x-misp-object--cf08eeff-6adc-4055-b07b-85e896626093",
|
|
|
|
"target_ref": "x-misp-object--a850600c-54f1-4a14-b31c-9593edb9fbb5"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "relationship",
|
|
|
|
"spec_version": "2.1",
|
2023-12-14 14:30:15 +00:00
|
|
|
"id": "relationship--439bfef6-6573-47d9-a235-24a45067e308",
|
2023-04-21 14:44:17 +00:00
|
|
|
"created": "2018-05-15T14:34:35.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:35.000Z",
|
|
|
|
"relationship_type": "analysed-with",
|
|
|
|
"source_ref": "x-misp-object--2cbd399e-6423-4649-b234-ffcd3dca9398",
|
|
|
|
"target_ref": "x-misp-object--4a94a5d1-5967-4028-adf2-b900291f8b40"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "relationship",
|
|
|
|
"spec_version": "2.1",
|
2023-12-14 14:30:15 +00:00
|
|
|
"id": "relationship--8e7112ee-b75c-4c1f-b882-8aec1a84553e",
|
2023-04-21 14:44:17 +00:00
|
|
|
"created": "2018-05-15T14:34:35.000Z",
|
|
|
|
"modified": "2018-05-15T14:34:35.000Z",
|
|
|
|
"relationship_type": "analysed-with",
|
|
|
|
"source_ref": "x-misp-object--f8939924-ce54-40ea-8744-9ba61335b548",
|
|
|
|
"target_ref": "x-misp-object--71f29082-0567-4b34-8076-6ce923945e31"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "marking-definition",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
|
|
|
"created": "2017-01-20T00:00:00.000Z",
|
|
|
|
"definition_type": "tlp",
|
|
|
|
"name": "TLP:WHITE",
|
|
|
|
"definition": {
|
|
|
|
"tlp": "white"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|