2023-04-21 13:25:09 +00:00
{
2023-06-14 17:31:25 +00:00
"type" : "bundle" ,
"id" : "bundle--34493f6d-9441-45df-9cb4-4de473709081" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T08:28:31.000Z" ,
"modified" : "2022-07-05T08:28:31.000Z" ,
"name" : "CIRCL" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--34493f6d-9441-45df-9cb4-4de473709081" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T08:28:31.000Z" ,
"modified" : "2022-07-05T08:28:31.000Z" ,
"name" : "#StopRansomware: MedusaLocker" ,
"published" : "2022-10-25T10:48:19Z" ,
"object_refs" : [
"indicator--c98115ff-fa16-480b-aab5-94f7cd6feff6" ,
"indicator--33ed009d-9cb3-4b98-bb68-7976b1df1536" ,
"indicator--53d9f2be-dbfa-419c-a553-b80006c9cd7d" ,
"indicator--4961d7c9-4669-4556-afad-396a98d1af0e" ,
"indicator--4ab3b41b-4f44-40b3-b84c-c48bbadd4903" ,
"indicator--ad855082-779a-4638-8cf9-724471b140ed" ,
"indicator--6a6f0613-1284-4db4-bf63-353ff8bbeb15" ,
"indicator--5c19f454-be75-4f6f-874d-edc17931b5c5" ,
"indicator--bb793a7e-dc86-432b-9e98-145fff226ad9" ,
"indicator--a1f968f7-e29a-4b36-86fd-3740c71db919" ,
"indicator--bdb9b095-3dee-441f-bd0a-2bb8555b8f4f" ,
"indicator--0c778edb-d952-4e48-a55a-049893447286" ,
"indicator--0d39bcfa-b8e0-4850-b77f-ca7836958da3" ,
"indicator--64359805-055e-470e-9c03-e00e5786bbe2" ,
"indicator--d0dca853-a828-4480-bf23-24b96f2f90d2" ,
"indicator--d3204522-0b24-452e-8a3a-439533c4db9b" ,
"indicator--ab44f789-8464-4a35-92c8-6714c5f7cd19" ,
"indicator--cd58ff7e-c862-4808-83f3-5d6f66d48e93" ,
"indicator--a2d7f1a4-b93b-4e3a-810a-21f3b47695be" ,
"indicator--5c524b5d-f40b-4fb1-a603-cf0ee4fc9dd6" ,
"indicator--5bb830fd-d9ad-4d2b-a926-e097275b1d70" ,
"indicator--2c79df75-48ac-4995-86cf-46ca7d1d74c3" ,
"indicator--1c3de5f3-6aa7-4cf9-a930-3cb7eeee7add" ,
"indicator--7bfcf076-b946-4025-8d7f-632abcd6ed6c" ,
"indicator--06e0d3f6-a98e-48ca-af2d-b75a662b3349" ,
"indicator--704c6093-9063-491f-b4b5-aeae05e0db73" ,
"indicator--17ba8ed1-7980-4102-9ba6-c655372e9dab" ,
"indicator--8c00e93e-a932-475c-a44b-671dce7e6b7d" ,
"indicator--d0dd0337-6aa7-4049-acd6-85ef3dcfb6ec" ,
"indicator--d4c83f23-97d1-469c-b1c6-562024839838" ,
"indicator--44d6e0e5-0f3b-4a14-b540-d6f64d3d2647" ,
"indicator--15c2fcd2-629d-41b1-99c7-4245b238a1ba" ,
"indicator--e4570362-af05-4e6d-8588-e7be5fc5e39b" ,
"indicator--67af9843-261f-480e-8014-ac89ef9e07ed" ,
"indicator--5b9cfc17-f64b-4e34-bc44-1feb780276bf" ,
"indicator--c5ea899f-5e09-41e1-aae2-c30d1a68fed9" ,
"indicator--54c105da-bbcb-485a-95d1-9bf22d74be7a" ,
"indicator--f6aafb4e-1942-465b-bf0e-51e714232845" ,
"indicator--b35fe755-07e9-42d1-a946-26575f5e3e27" ,
"indicator--3db0cf25-9be5-43c6-a306-22b3b6744d7a" ,
"indicator--f1bf7d56-2167-492b-838d-6df4bd37e906" ,
"indicator--bb5a7749-c41f-44ad-b86f-fb383f010431" ,
"indicator--5cbe5c53-c6f0-436a-ad95-528db471c389" ,
"indicator--98ecee0e-92b0-4a74-a866-4a74624c8c00" ,
"indicator--3a879352-8790-4003-b493-968e74eb192b" ,
"indicator--45ce0956-c866-437e-916f-9ff4d2279c36" ,
"indicator--60c94b70-6aea-4481-ab03-0610ff8c6725" ,
"indicator--ae497c03-1c0a-4b6d-a374-469598af2628" ,
"indicator--07cca850-556f-44c2-a350-0a5ed617f8df" ,
"indicator--bdb2556f-698d-481c-a3a9-9acd3f929ff9" ,
"indicator--41558b31-6d45-4343-9ee4-9f6d034c7e52" ,
"indicator--0a7f65fc-36c3-4d97-ab82-0c4122e3e849" ,
"indicator--7b4d8106-1954-45a0-9d7d-02d3d7d32eac" ,
"indicator--79a0d62d-8b08-4744-8bf9-173c0dc8d2b7" ,
"indicator--712dfb1a-88d1-483b-ad51-e37944f05b25" ,
"indicator--22e9b19d-eb86-4191-9466-326966fc4ea1" ,
"indicator--345b4871-3ac0-4200-ae81-37aa75fce5a8" ,
"indicator--ff5b02aa-05b5-4c9d-9234-3b6aedb45993" ,
"indicator--06708900-d105-4965-b3b1-2fde8eb7c00a" ,
"indicator--adad2178-b001-41c7-9d8d-665338466ba1" ,
"indicator--e3f397f9-cf27-4506-a0b9-e2825170001e" ,
"indicator--134be71f-e062-4f19-9763-0aad30721923" ,
"indicator--0a7b100d-0abc-4101-a889-d3c96f296aa2" ,
"indicator--1eb5f7c3-c0de-440e-af42-a233a729b2dd" ,
"indicator--bfd0d9d5-aa65-43b8-b9d5-131182ae9b72" ,
"indicator--e3376d83-4f5a-4554-8e11-aa23fcdf7b1a" ,
"indicator--58c9bf08-3713-4cb5-8b83-8a779c21798a" ,
"indicator--888a0a2c-88dd-4b4b-a81e-8a13bb55924a" ,
"indicator--479e8bcd-e531-4f93-9848-527e2d5daff2" ,
"indicator--693aadcb-a601-461e-b510-614b25c68101" ,
"indicator--67c75f8e-5402-4265-9ff5-511f04bb7663" ,
"indicator--12355d43-008c-4ad5-9fe3-f666f4c34e7e" ,
"indicator--e86178a8-e72f-4972-b577-06dbb8756067" ,
"indicator--68caeb24-1abb-4d17-af6c-d0d4fc357a14" ,
"indicator--f87c84d1-87de-4194-832e-59252c1b6aac" ,
"indicator--cf5764cc-526c-4207-b635-c298ae5eb4dd" ,
"indicator--8899c0bb-f1c4-4274-ac97-bc2090888e04" ,
"indicator--cf93afb2-47e5-42f2-a742-c937e7976be9" ,
"indicator--e96cd637-d225-4f31-ae55-0fd7ebf72387" ,
"indicator--08716e06-ac1d-4fdd-9467-651e84a3e6a8" ,
"indicator--ba7f7120-15c8-47ba-965d-c24de237596c" ,
"indicator--21472250-40cb-4032-8146-89498d1f1473" ,
"observed-data--a611936d-86f2-4c43-893b-cef4def6ed68" ,
"file--a611936d-86f2-4c43-893b-cef4def6ed68" ,
"observed-data--612490f6-c0cb-4b85-8418-a7d2695a2e25" ,
"file--612490f6-c0cb-4b85-8418-a7d2695a2e25" ,
"observed-data--e5bf00f7-cde5-4771-8d9c-c60145e29d4a" ,
"file--e5bf00f7-cde5-4771-8d9c-c60145e29d4a" ,
"observed-data--d90bafeb-fcb8-49c0-99d7-8d9ca4b82d6e" ,
"file--d90bafeb-fcb8-49c0-99d7-8d9ca4b82d6e" ,
"observed-data--7ab046c6-1467-4888-85d8-5b9fa65fabdb" ,
"file--7ab046c6-1467-4888-85d8-5b9fa65fabdb" ,
"observed-data--7762779d-92af-4997-aabc-e3d4d53ae21b" ,
"file--7762779d-92af-4997-aabc-e3d4d53ae21b" ,
"observed-data--d0b6e769-9762-4dde-8800-5ed9c85e0f7f" ,
"file--d0b6e769-9762-4dde-8800-5ed9c85e0f7f" ,
"observed-data--6e8b7970-442d-41e0-a1b1-2b8fd9c3e32a" ,
"file--6e8b7970-442d-41e0-a1b1-2b8fd9c3e32a" ,
"observed-data--e8c99bfb-e553-425a-9760-5fc0bb6c8e4f" ,
"file--e8c99bfb-e553-425a-9760-5fc0bb6c8e4f" ,
"observed-data--1e518ccc-1b05-47f0-ae03-f418f7808e4b" ,
"file--1e518ccc-1b05-47f0-ae03-f418f7808e4b" ,
"observed-data--7b4397f5-4169-40e2-bebd-b075e1314c68" ,
"file--7b4397f5-4169-40e2-bebd-b075e1314c68" ,
"x-misp-attribute--6cf5fc69-f09f-45c6-908b-fe9dc78dbaaf" ,
"x-misp-attribute--e03b46ad-ad4b-4610-a73c-51243858e0d6" ,
"x-misp-attribute--75f8faf6-f1b1-4fd3-b365-0a07396f9fcb" ,
"x-misp-attribute--21d949a7-ce94-481f-bf25-9577e78eb5f2" ,
"x-misp-attribute--1dfdd7c2-8484-4072-b350-db4a02947152" ,
"x-misp-attribute--afea7ac1-28ec-4b95-908c-91088400557b" ,
"x-misp-attribute--dabd44a8-95a9-4d94-8d1d-18dc4a8ba58a" ,
"x-misp-attribute--296f5194-d6b7-4026-a431-c804532fce0e" ,
"x-misp-attribute--dd719fdd-1c43-4b28-aefe-c00da93ae6af" ,
"x-misp-attribute--53346bef-c79c-42c5-8b8e-7af05f2e0506" ,
"x-misp-attribute--43e5bd1f-437b-46e0-9599-b67e34fd9249" ,
"x-misp-attribute--fd604bdb-98bb-464e-80fc-8a2b9b7cca62" ,
"x-misp-attribute--7af3cba0-fdf2-4ca9-981e-d5fdccafcaaa" ,
"x-misp-attribute--aadf4226-5cac-4d18-a705-36d48bd5dbcb" ,
"x-misp-attribute--756ac5e4-684c-4861-aaf3-65aa27e8755a" ,
"x-misp-attribute--1f979729-5e8f-467c-9998-4e7e2a550ab2" ,
"x-misp-attribute--b65ba82b-36f1-4237-b170-da9c50dee3dc" ,
"x-misp-attribute--bd73085f-9605-4a38-b447-f34e04b8372a" ,
"x-misp-attribute--266f4b5e-1ab7-486d-8296-fca9d7d176a5" ,
"x-misp-attribute--381bb06f-04f0-42f9-8284-60e9ba61da6f" ,
"x-misp-attribute--3ab44efb-7487-4b85-833f-41e7351e03e1" ,
"indicator--fd141de6-e44b-426b-96f4-41b9099981b3" ,
"indicator--b10225b9-1578-47e8-81f1-b80bfe381eaa" ,
"indicator--df2dd421-1329-4b7e-b9de-93eb6b2b3c2b" ,
"indicator--c83df49e-e37b-4e6a-9951-19fc4c17c638" ,
"indicator--1fdbb119-e0d0-48f4-9c59-93f8297a4910" ,
"indicator--ca361320-8559-48db-8036-c8cc508610e3" ,
"indicator--a1540724-c8da-4131-b7a4-1995510c4c43" ,
"indicator--8a803583-a6d1-434c-90f1-3ec952fe558e" ,
"indicator--9d36edd8-2236-4956-b553-e3950cbfa4a9" ,
"indicator--be9673eb-dc13-4edf-ab0f-96a64c73e118" ,
"indicator--bb17a48c-ce0a-4cdc-8e2b-009387b7add5" ,
"indicator--5ff5592b-4f1d-4245-8ec7-af0ea19d683c" ,
"indicator--c672869e-486b-40ae-996e-8a1bf986b776" ,
"indicator--a9e0fda9-1e32-4cef-8b3d-466d51654a15" ,
"indicator--254b2b47-8712-40df-b8ec-f6140f34d140" ,
"indicator--59178c14-47de-41bc-80e2-3797d651a49f" ,
"indicator--bde85597-f1de-410d-b8a7-271f8e0f4b89" ,
"indicator--3cbfada9-55da-4fe9-8acf-7987b0ae934f" ,
"indicator--34704201-a988-4218-979a-0311b49efe49" ,
"indicator--0f267df7-a56e-48cb-959e-48e18538a218" ,
"indicator--0cbf72ae-eb07-4fda-ace9-1ce40c9d89a8" ,
"indicator--9d61fa66-4dce-4cf0-9ac7-689385585954" ,
"indicator--991ea7de-2222-4272-a317-e97ad6bd13fb" ,
"indicator--6bcc63cf-e0df-45f9-a1f0-5c94f2ad6c2b" ,
"indicator--b5d96350-0cf6-48a5-8ef0-03d26303d1a6" ,
"indicator--02ac26a2-5aea-491b-8344-7abc13dec002" ,
"indicator--56a00c45-d1bc-48e7-9c07-3ac05572a9fe" ,
"indicator--455dca2e-ac35-4510-a2a0-676ef484e431" ,
"indicator--5279ad55-77fe-4c42-a5db-25bfd83994fc" ,
"indicator--86d04351-b977-4aca-b9c4-dabdae42c5aa" ,
"indicator--e32c9026-d991-4161-9de8-d3f9b73fb0c4" ,
"indicator--9e1ac15c-56fe-49b3-b889-f69fea7a8096" ,
"indicator--15bb11c8-7ef2-4207-a542-7777bc2cb09f" ,
"indicator--9d3ce22e-70a1-4298-a721-3de55bb33f03" ,
"indicator--4cdd7f32-7a9a-4e59-9378-1a6f044522a3" ,
"indicator--118a311b-d391-4e9f-8f56-8e5a44895306" ,
"indicator--688cdd57-4ca8-4835-b385-88b788473014" ,
"indicator--506c144c-3b58-4e70-9a9d-a25791af430c" ,
"indicator--f866c7ec-03de-4b97-b15f-541e480e9372" ,
"indicator--62183cf6-8688-4102-bfa8-eaa7d4aa611c" ,
"x-misp-object--79844e5f-4db1-493a-a006-20e5e4309117"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"misp-galaxy:mitre-attack-pattern=\"External Remote Services - T1133\"" ,
"misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"" ,
"misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"" ,
"misp-galaxy:mitre-attack-pattern=\"Safe Mode Boot - T1562.009\"" ,
"misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"" ,
"misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"" ,
"type:OSINT" ,
"osint:lifetime=\"perpetual\"" ,
"osint:certainty=\"50\"" ,
"dnc:malware-type=\"Ransomware\"" ,
"enisa:nefarious-activity-abuse=\"ransomware\"" ,
"ecsirt:malicious-code=\"ransomware\"" ,
"malware_classification:malware-category=\"Ransomware\"" ,
"veris:action:malware:variety=\"Ransomware\"" ,
"Ransomware" ,
"ms-caro-malware:malware-type=\"Ransom\"" ,
"ms-caro-malware-full:malware-type=\"Ransom\"" ,
"Intel 471:GIR=\"1.2.2 - Ransomware-as-a-Service (RaaS)\"" ,
"misp-galaxy:malpedia=\"MedusaLocker\"" ,
"misp-galaxy:ransomware=\"MedusaLocker\""
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--c98115ff-fa16-480b-aab5-94f7cd6feff6" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'willyhill1960@tutanota.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--33ed009d-9cb3-4b98-bb68-7976b1df1536" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'unlockfile@cock.li']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--53d9f2be-dbfa-419c-a553-b80006c9cd7d" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'zlo@keem.ne']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--4961d7c9-4669-4556-afad-396a98d1af0e" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'unlockmeplease@airmail.cc']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--4ab3b41b-4f44-40b3-b84c-c48bbadd4903" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'zlo@keemail.me']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--ad855082-779a-4638-8cf9-724471b140ed" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'unlockmeplease@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--6a6f0613-1284-4db4-bf63-353ff8bbeb15" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'zlo@tfwno.gf']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5c19f454-be75-4f6f-874d-edc17931b5c5" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'willyhill1960@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--bb793a7e-dc86-432b-9e98-145fff226ad9" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@ypsotecs.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--a1f968f7-e29a-4b36-86fd-3740c71db919" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@imfoodst.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--bdb9b095-3dee-441f-bd0a-2bb8555b8f4f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:47.000Z" ,
"modified" : "2022-07-01T13:09:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'traceytevin@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--0c778edb-d952-4e48-a55a-049893447286" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@itwgset.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--0d39bcfa-b8e0-4850-b77f-ca7836958da3" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'unlock_file@aol.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--64359805-055e-470e-9c03-e00e5786bbe2" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@novibmaker.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--d0dca853-a828-4480-bf23-24b96f2f90d2" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'unlock_file@outlook.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--d3204522-0b24-452e-8a3a-439533c4db9b" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@securycasts.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--ab44f789-8464-4a35-92c8-6714c5f7cd19" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@exoprints.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--cd58ff7e-c862-4808-83f3-5d6f66d48e93" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'rewmiller-1974@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--a2d7f1a4-b93b-4e3a-810a-21f3b47695be" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@exorints.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5c524b5d-f40b-4fb1-a603-cf0ee4fc9dd6" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'rpd@keemail.me']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5bb830fd-d9ad-4d2b-a926-e097275b1d70" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@fanbridges.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--2c79df75-48ac-4995-86cf-46ca7d1d74c3" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'soterissylla@wyseil.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--1c3de5f3-6aa7-4cf9-a930-3cb7eeee7add" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@faneridges.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--7bfcf076-b946-4025-8d7f-632abcd6ed6c" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'support@careersill.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--06e0d3f6-a98e-48ca-af2d-b75a662b3349" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'perfection@bestkoronavirus.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--704c6093-9063-491f-b4b5-aeae05e0db73" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'karloskolorado@tutanota.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--17ba8ed1-7980-4102-9ba6-c655372e9dab" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'pool1256@tutanota.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--8c00e93e-a932-475c-a44b-671dce7e6b7d" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'kevynchaz@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--d0dd0337-6aa7-4049-acd6-85ef3dcfb6ec" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'rapid@aaathats3as.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--d4c83f23-97d1-469c-b1c6-562024839838" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'korona@bestkoronavirus.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--44d6e0e5-0f3b-4a14-b540-d6f64d3d2647" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'rescuer@tutanota.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--15c2fcd2-629d-41b1-99c7-4245b238a1ba" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'lockperfection@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--e4570362-af05-4e6d-8588-e7be5fc5e39b" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'ithelp01@decorous.cyou']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--67af9843-261f-480e-8014-ac89ef9e07ed" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'ithelp01@wholeness.business']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5b9cfc17-f64b-4e34-bc44-1feb780276bf" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'mulierfagus@rdhos.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--c5ea899f-5e09-41e1-aae2-c30d1a68fed9" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'ithelp02@decorous.cyou']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--54c105da-bbcb-485a-95d1-9bf22d74be7a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'ithelp02@wholness.business']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--f6aafb4e-1942-465b-bf0e-51e714232845" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = '107btc@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--b35fe755-07e9-42d1-a946-26575f5e3e27" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'ithelpresotre@outlook.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--3db0cf25-9be5-43c6-a306-22b3b6744d7a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = '33btc@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--f1bf7d56-2167-492b-838d-6df4bd37e906" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'cmd@jitjat.org']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--bb5a7749-c41f-44ad-b86f-fb383f010431" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = '777decoder777@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5cbe5c53-c6f0-436a-ad95-528db471c389" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'coronaviryz@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--98ecee0e-92b0-4a74-a866-4a74624c8c00" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = '777decoder777@tfwno.gf']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--3a879352-8790-4003-b493-968e74eb192b" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'dec_helper@dremno.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--45ce0956-c866-437e-916f-9ff4d2279c36" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'andrewmiller-1974@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--60c94b70-6aea-4481-ab03-0610ff8c6725" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'dec_helper@excic.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--ae497c03-1c0a-4b6d-a374-469598af2628" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'angelomartin-1980@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--07cca850-556f-44c2-a350-0a5ed617f8df" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'dec_restore@prontonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--bdb2556f-698d-481c-a3a9-9acd3f929ff9" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'ballioverus@quocor.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--41558b31-6d45-4343-9ee4-9f6d034c7e52" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'dec_restore1@outlook.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--0a7f65fc-36c3-4d97-ab82-0c4122e3e849" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'beacon@jitjat.org']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--7b4d8106-1954-45a0-9d7d-02d3d7d32eac" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'bitcoin@sitesoutheat.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--79a0d62d-8b08-4744-8bf9-173c0dc8d2b7" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'beacon@msgsafe.io']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--712dfb1a-88d1-483b-ad51-e37944f05b25" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'briansalgado@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--22e9b19d-eb86-4191-9466-326966fc4ea1" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'best666decoder@tutanota.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--345b4871-3ac0-4200-ae81-37aa75fce5a8" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'bugervongir@outlook.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--ff5b02aa-05b5-4c9d-9234-3b6aedb45993" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'bitcoin@mobtouches.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--06708900-d105-4965-b3b1-2fde8eb7c00a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'best666decoder@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--adad2178-b001-41c7-9d8d-665338466ba1" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'encrypt2020@outlook.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--e3f397f9-cf27-4506-a0b9-e2825170001e" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'decoder83540@cock.li']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--134be71f-e062-4f19-9763-0aad30721923" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'fast-help@inbox.lv']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--0a7b100d-0abc-4101-a889-d3c96f296aa2" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'decra2019@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--1eb5f7c3-c0de-440e-af42-a233a729b2dd" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'fuc_ktheworld1448@outlook.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--bfd0d9d5-aa65-43b8-b9d5-131182ae9b72" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'diniaminius@winrof.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--e3376d83-4f5a-4554-8e11-aa23fcdf7b1a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'fucktheworld1448@cock.li']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--58c9bf08-3713-4cb5-8b83-8a779c21798a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'dirhelp@keemail.me']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--888a0a2c-88dd-4b4b-a81e-8a13bb55924a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'gartaganisstuffback@gmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--479e8bcd-e531-4f93-9848-527e2d5daff2" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'emaila.elaich@iav.ac.ma']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--693aadcb-a601-461e-b510-614b25c68101" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'gavingonzalez@protonmail.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--67c75f8e-5402-4265-9ff5-511f04bb7663" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'emd@jitjat.org']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--12355d43-008c-4ad5-9fe3-f666f4c34e7e" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'gsupp@onionmail.org']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--e86178a8-e72f-4972-b577-06dbb8756067" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'encrypt2020@cock.li']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--68caeb24-1abb-4d17-af6c-d0d4fc357a14" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'gsupp@techmail.info']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--f87c84d1-87de-4194-832e-59252c1b6aac" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'helper@atacdi.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--cf5764cc-526c-4207-b635-c298ae5eb4dd" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'ithelp@decorous.cyou']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--8899c0bb-f1c4-4274-ac97-bc2090888e04" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'helper@buildingwin.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--cf93afb2-47e5-42f2-a742-c937e7976be9" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'ithelp@decorous.cyoum']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--e96cd637-d225-4f31-ae55-0fd7ebf72387" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'helprestore@outlook.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--08716e06-ac1d-4fdd-9467-651e84a3e6a8" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'ithelp@wholeness.business']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--ba7f7120-15c8-47ba-965d-c24de237596c" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:09:48.000Z" ,
"modified" : "2022-07-01T13:09:48.000Z" ,
"pattern" : "[email-message:from_ref.value = 'helptorestore@outlook.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:09:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--21472250-40cb-4032-8146-89498d1f1473" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-01T13:38:47.000Z" ,
"modified" : "2022-07-01T13:38:47.000Z" ,
"pattern" : "[email-message:from_ref.value = 'rescuer@cock.li']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-01T13:38:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"email-src\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--a611936d-86f2-4c43-893b-cef4def6ed68" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--a611936d-86f2-4c43-893b-cef4def6ed68"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--a611936d-86f2-4c43-893b-cef4def6ed68" ,
"name" : "how_to_ recover_data.html"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--612490f6-c0cb-4b85-8418-a7d2695a2e25" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--612490f6-c0cb-4b85-8418-a7d2695a2e25"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--612490f6-c0cb-4b85-8418-a7d2695a2e25" ,
"name" : "how_to_recover_data.html.marlock01"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--e5bf00f7-cde5-4771-8d9c-c60145e29d4a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--e5bf00f7-cde5-4771-8d9c-c60145e29d4a"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--e5bf00f7-cde5-4771-8d9c-c60145e29d4a" ,
"name" : "instructions.html"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--d90bafeb-fcb8-49c0-99d7-8d9ca4b82d6e" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--d90bafeb-fcb8-49c0-99d7-8d9ca4b82d6e"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--d90bafeb-fcb8-49c0-99d7-8d9ca4b82d6e" ,
"name" : "READINSTRUCTION.html"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--7ab046c6-1467-4888-85d8-5b9fa65fabdb" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--7ab046c6-1467-4888-85d8-5b9fa65fabdb"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--7ab046c6-1467-4888-85d8-5b9fa65fabdb" ,
"name" : "!!!HOW_TO_DECRYPT!!!"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--7762779d-92af-4997-aabc-e3d4d53ae21b" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--7762779d-92af-4997-aabc-e3d4d53ae21b"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--7762779d-92af-4997-aabc-e3d4d53ae21b" ,
"name" : "How_to_recovery.txt"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--d0b6e769-9762-4dde-8800-5ed9c85e0f7f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--d0b6e769-9762-4dde-8800-5ed9c85e0f7f"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--d0b6e769-9762-4dde-8800-5ed9c85e0f7f" ,
"name" : "readinstructions.html"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--6e8b7970-442d-41e0-a1b1-2b8fd9c3e32a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--6e8b7970-442d-41e0-a1b1-2b8fd9c3e32a"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--6e8b7970-442d-41e0-a1b1-2b8fd9c3e32a" ,
"name" : "readme_to_recover_files"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--e8c99bfb-e553-425a-9760-5fc0bb6c8e4f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--e8c99bfb-e553-425a-9760-5fc0bb6c8e4f"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--e8c99bfb-e553-425a-9760-5fc0bb6c8e4f" ,
"name" : "recovery_instructions.html"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--1e518ccc-1b05-47f0-ae03-f418f7808e4b" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--1e518ccc-1b05-47f0-ae03-f418f7808e4b"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--1e518ccc-1b05-47f0-ae03-f418f7808e4b" ,
"name" : "HOW_TO_RECOVER_DATA.html"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--7b4397f5-4169-40e2-bebd-b075e1314c68" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:03:07.000Z" ,
"modified" : "2022-07-04T13:03:07.000Z" ,
"first_observed" : "2022-07-04T13:03:07Z" ,
"last_observed" : "2022-07-04T13:03:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--7b4397f5-4169-40e2-bebd-b075e1314c68"
] ,
"labels" : [
"misp:type=\"filename\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--7b4397f5-4169-40e2-bebd-b075e1314c68" ,
"name" : "recovery_instruction.html"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--6cf5fc69-f09f-45c6-908b-fe9dc78dbaaf" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "14oxnsSc1LZ5M2cPZeQ9rFnXqEvPCnZikc"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--e03b46ad-ad4b-4610-a73c-51243858e0d6" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1DRxUFhvJjGUdojCzMWSLmwx7Qxn79XbJq"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--75f8faf6-f1b1-4fd3-b365-0a07396f9fcb" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "18wRbb94CjyTGkUp32ZM7krCYCB9MXUq42"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--21d949a7-ce94-481f-bf25-9577e78eb5f2" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1AbRxRfP6yHePpi7jmDZkS4Mfpm1ZiatH5"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--1dfdd7c2-8484-4072-b350-db4a02947152" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1Edcufenw1BB4ni9UadJpQh9LVx9JGtKpP"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--afea7ac1-28ec-4b95-908c-91088400557b" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1DyMbw6R9PbJqfUSDcK5729xQ57yJrE8BC"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--dabd44a8-95a9-4d94-8d1d-18dc4a8ba58a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "184ZcAoxkvimvVZaj8jZFujC7EwR3BKWvf"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--296f5194-d6b7-4026-a431-c804532fce0e" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "14oH2h12LvQ7BYBufcrY5vfKoCq2hTPoev"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--dd719fdd-1c43-4b28-aefe-c00da93ae6af" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "bc1qy34v0zv6wu0cugea5xjlxagsfwgunwkzc0xcjj"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--53346bef-c79c-42c5-8b8e-7af05f2e0506" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "bc1q9jg45a039tn83jk2vhdpranty2y8tnpnrk9k5q"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--43e5bd1f-437b-46e0-9599-b67e34fd9249" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "bc1qz3lmcw4k58n79wpzm550r5pkzxc2h8rwmmu6xm"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--fd604bdb-98bb-464e-80fc-8a2b9b7cca62" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1AereQUh8yjNPs9Wzeg1Le47dsqC8NNaNM"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--7af3cba0-fdf2-4ca9-981e-d5fdccafcaaa" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1DeNHM2eTqHp5AszTsUiS4WDHWkGc5UxHf"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--aadf4226-5cac-4d18-a705-36d48bd5dbcb" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1HEDP3c3zPwiqUaYuWZ8gBFdAQQSa6sMGw"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--756ac5e4-684c-4861-aaf3-65aa27e8755a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1HdgQM9bjX7u7vWJnfErY4MWGBQJi5mVWV"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--1f979729-5e8f-467c-9998-4e7e2a550ab2" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1nycdn9ebxht4tpspu4ehpjz9ghxlzipll"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--b65ba82b-36f1-4237-b170-da9c50dee3dc" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "12xd6KrWVtgHEJHKPEfXwMVWuFK4k1FCUF"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--bd73085f-9605-4a38-b447-f34e04b8372a" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1HZHhdJ6VdwBLCFhdu7kDVZN9pb3BWeUED"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--266f4b5e-1ab7-486d-8296-fca9d7d176a5" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1PormUgPR72yv2FRKSVY27U4ekWMKobWjg"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--381bb06f-04f0-42f9-8284-60e9ba61da6f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "14cATAzXwD7CQf35n8Ea5pKJPfhM6jEHak"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--3ab44efb-7487-4b85-833f-41e7351e03e1" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-04T13:23:58.000Z" ,
"modified" : "2022-07-04T13:23:58.000Z" ,
"labels" : [
"misp:type=\"btc\"" ,
"misp:category=\"Financial fraud\"" ,
"misp:to_ids=\"True\""
] ,
"x_misp_category" : "Financial fraud" ,
"x_misp_type" : "btc" ,
"x_misp_value" : "1PopeZ4LNLanisswLndAJB1QntTF8hpLsD"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--fd141de6-e44b-426b-96f4-41b9099981b3" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/6-iSm1B1Ehljh8HYuXGym4Xyu1WdwsR2Av-6tXiw1BImsqoLh7pd207Rl6XYoln7sId']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--b10225b9-1578-47e8-81f1-b80bfe381eaa" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/8-grp514hncgblilsjtd32hg6jtbyhlocr5pqjswxfgf2oragnl3pqno6fkqcimqin']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--df2dd421-1329-4b7e-b9de-93eb6b2b3c2b" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6y4g53rxdi5.onion/21-8P4ZLCsMETPaLw9MkSlXJsNZWdHe0rxjt-XmBgZLWlm5ULGFCOJFuVdEymmxysofwu']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--c83df49e-e37b-4e6a-9951-19fc4c17c638" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/2l-8P4ZLCsMTPaLw9MkSlXJsNZWdHeOrxjtE9lck1MuXPYo29daQys6gomZZXUImN7Z']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--1fdbb119-e0d0-48f4-9c59-93f8297a4910" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/21-8P4ZLCsMTPaLw9MkSlXJsNZWdHe0rxjt-DcaE9HeHywqSHvdcIwOndCS4PuWASX8g']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--ca361320-8559-48db-8036-c8cc508610e3" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/21-8P4ZLCsMTPaLw9MkSlXJsNZWdHe0rxjt-kB4rQXGKyxGiLyw7YDsMKSBjyfdwcyxo']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--a1540724-c8da-4131-b7a4-1995510c4c43" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/21-8P4ZLCsMTPaLw9MkSlXJsNZWdHe0rxjt-bET6JbB9vEMZ7qYBPqUMCxOQExFx4iOi']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--8a803583-a6d1-434c-90f1-3ec952fe558e" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/8-MO0Q7O97Hgxvm1YbD7OMnimImZJXEWaG-RbH4TvdwVTGQB3X6VOUOP3lgO6YOJEOW']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--9d36edd8-2236-4956-b553-e3950cbfa4a9" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/8-gRp514hncgb1i1sjtD32hG6jTbUh1ocR-Uola2Fo30KTJvZX0otYZgTh5txmKwUNe']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--be9673eb-dc13-4edf-ab0f-96a64c73e118" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/21-E6UQFCEuCn4KvtAh4TonRTpyHqFo6F6L-OWQwD1w1Td7hY7IGUUjxmHMoFSQW6blg']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--bb17a48c-ce0a-4cdc-8e2b-009387b7add5" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/21-E6UQFCEuCn4KvtAh4TonRTpyHqFo6F6L-uGHwkkWCoUtBbZWN50sSS4Ds8RABkrKy']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5ff5592b-4f1d-4245-8ec7-af0ea19d683c" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/21-E6UQFCEuCn4KvtAh4TonRTpyHqFo6F6L-Tj3PRnQlpHc9OftRVDGAWUulvE80yZbc']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--c672869e-486b-40ae-996e-8a1bf986b776" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/8-Ww5sCBhsL8eM4PeAgsfgfa9lrqa81r31-tDQRZCAUe4164X532j9Ky16IBN9StWTH']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--a9e0fda9-1e32-4cef-8b3d-466d51654a15" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://gvlay6u4g53rxdi5.onion/21-wIq5kK9gGKiTmyups1U6fABj1VnXIYRB-I5xek6PG2EbWlPC7C1rXfsqJBlWlFFfY']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--254b2b47-8712-40df-b8ec-f6140f34d140" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[domain-name:value = 'qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--59178c14-47de-41bc-80e2-3797d651a49f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:22:12.000Z" ,
"modified" : "2022-07-05T06:22:12.000Z" ,
"description" : "TOR Addresses" ,
"pattern" : "[url:value = 'http://medusacegu2ufmc3kx2kkqicrlcxdettsjcenhjena6uannk5f4ffuyd.onion/leakdata/paigesmusic-leakdata-closed-part1']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:22:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--bde85597-f1de-410d-b8a7-271f8e0f4b89" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:27:52.000Z" ,
"modified" : "2022-07-05T06:27:52.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '195.123.246.138' AND domain-name:x_misp_last_seen = '2021-11-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:27:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--3cbfada9-55da-4fe9-8acf-7987b0ae934f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:28:19.000Z" ,
"modified" : "2022-07-05T06:28:19.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '138.124.186.221' AND domain-name:x_misp_last_seen = '2021-11-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:28:19Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--34704201-a988-4218-979a-0311b49efe49" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:28:58.000Z" ,
"modified" : "2022-07-05T06:28:58.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '159.223.0.9' AND domain-name:x_misp_last_seen = '2021-11-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:28:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--0f267df7-a56e-48cb-959e-48e18538a218" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:30:05.000Z" ,
"modified" : "2022-07-05T06:30:05.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '45.146.164.141' AND domain-name:x_misp_last_seen = '2021-11-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:30:05Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--0cbf72ae-eb07-4fda-ace9-1ce40c9d89a8" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:31:07.000Z" ,
"modified" : "2022-07-05T06:31:07.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '185.220.101.35' AND domain-name:x_misp_last_seen = '2021-11-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:31:07Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--9d61fa66-4dce-4cf0-9ac7-689385585954" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:31:34.000Z" ,
"modified" : "2022-07-05T06:31:34.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '185.220.100.249' AND domain-name:x_misp_last_seen = '2021-09-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:31:34Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--991ea7de-2222-4272-a317-e97ad6bd13fb" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:31:52.000Z" ,
"modified" : "2022-07-05T06:31:52.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '50.80.219.149' AND domain-name:x_misp_last_seen = '2021-09-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:31:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--6bcc63cf-e0df-45f9-a1f0-5c94f2ad6c2b" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:32:17.000Z" ,
"modified" : "2022-07-05T06:32:17.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '185.220.101.146' AND domain-name:x_misp_last_seen = '2021-09-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:32:17Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--b5d96350-0cf6-48a5-8ef0-03d26303d1a6" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:32:39.000Z" ,
"modified" : "2022-07-05T06:32:39.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '185.220.101.252' AND domain-name:x_misp_last_seen = '2021-09-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:32:39Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--02ac26a2-5aea-491b-8344-7abc13dec002" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:32:56.000Z" ,
"modified" : "2022-07-05T06:32:56.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '179.60.150.97' AND domain-name:x_misp_last_seen = '2021-09-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:32:56Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56a00c45-d1bc-48e7-9c07-3ac05572a9fe" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:33:17.000Z" ,
"modified" : "2022-07-05T06:33:17.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '84.38.189.52' AND domain-name:x_misp_last_seen = '2021-09-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:33:17Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--455dca2e-ac35-4510-a2a0-676ef484e431" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:33:49.000Z" ,
"modified" : "2022-07-05T06:33:49.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '94.232.43.63' AND domain-name:x_misp_last_seen = '2021-07-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:33:49Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5279ad55-77fe-4c42-a5db-25bfd83994fc" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:34:18.000Z" ,
"modified" : "2022-07-05T06:34:18.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '108.11.30.103' AND domain-name:x_misp_last_seen = '2021-04-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:34:18Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--86d04351-b977-4aca-b9c4-dabdae42c5aa" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:34:32.000Z" ,
"modified" : "2022-07-05T06:34:32.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '194.61.55.94' AND domain-name:x_misp_last_seen = '2021-04-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:34:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--e32c9026-d991-4161-9de8-d3f9b73fb0c4" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:34:59.000Z" ,
"modified" : "2022-07-05T06:34:59.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '198.50.233.202' AND domain-name:x_misp_last_seen = '2021-04-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:34:59Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--9e1ac15c-56fe-49b3-b889-f69fea7a8096" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:35:40.000Z" ,
"modified" : "2022-07-05T06:35:40.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '40.92.90.105' AND domain-name:x_misp_last_seen = '2021-01-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:35:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--15bb11c8-7ef2-4207-a542-7777bc2cb09f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:36:17.000Z" ,
"modified" : "2022-07-05T06:36:17.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '188.68.216.23' AND domain-name:x_misp_last_seen = '2020-12-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:36:17Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--9d3ce22e-70a1-4298-a721-3de55bb33f03" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:36:36.000Z" ,
"modified" : "2022-07-05T06:36:36.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '87.251.75.71' AND domain-name:x_misp_last_seen = '2020-12-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:36:36Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--4cdd7f32-7a9a-4e59-9378-1a6f044522a3" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:37:09.000Z" ,
"modified" : "2022-07-05T06:37:09.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '196.240.57.20' AND domain-name:x_misp_last_seen = '2020-10-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:37:09Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--118a311b-d391-4e9f-8f56-8e5a44895306" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:37:27.000Z" ,
"modified" : "2022-07-05T06:37:27.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '198.0.198.5' AND domain-name:x_misp_last_seen = '2020-08-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:37:27Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--688cdd57-4ca8-4835-b385-88b788473014" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:42:48.000Z" ,
"modified" : "2022-07-05T06:42:48.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '194.5.220.122' AND domain-name:x_misp_last_seen = '2020-03-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:42:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--506c144c-3b58-4e70-9a9d-a25791af430c" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:44:52.000Z" ,
"modified" : "2022-07-05T06:44:52.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '194.5.250.124' AND domain-name:x_misp_last_seen = '2020-03-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:44:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--f866c7ec-03de-4b97-b15f-541e480e9372" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:45:08.000Z" ,
"modified" : "2022-07-05T06:45:08.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '194.5.220.124' AND domain-name:x_misp_last_seen = '2020-03-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:45:08Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--62183cf6-8688-4102-bfa8-eaa7d4aa611c" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T06:48:22.000Z" ,
"modified" : "2022-07-05T06:48:22.000Z" ,
"pattern" : "[domain-name:resolves_to_refs[*].value = '104.210.72.161' AND domain-name:x_misp_last_seen = '2019-11-01T00:00:00+00:00']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2022-07-05T06:48:22Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "network"
}
] ,
"labels" : [
"misp:name=\"domain-ip\"" ,
"misp:meta-category=\"network\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--79844e5f-4db1-493a-a006-20e5e4309117" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2022-07-05T08:28:31.000Z" ,
"modified" : "2022-07-05T08:28:31.000Z" ,
"labels" : [
"misp:name=\"report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_attributes" : [
{
"type" : "link" ,
"object_relation" : "link" ,
"value" : "https://www.cisa.gov/uscert/ncas/alerts/aa22-181a" ,
"category" : "External analysis" ,
"uuid" : "a6d6f274-c7e0-4fb8-8c84-e8e66680a338"
} ,
{
"type" : "link" ,
"object_relation" : "link" ,
"value" : "https://www.cisa.gov/uscert/sites/default/files/publications/AA22-181A_stopransomware_medusalocker.pdf" ,
"category" : "External analysis" ,
"uuid" : "3eceb8cf-bd52-4c01-a95f-5c1e60e75b35"
} ,
{
"type" : "text" ,
"object_relation" : "summary" ,
"value" : "The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Department of the Treasury, and the Financial Crimes Enforcement Network (FinCEN) are releasing this CSA to provide information on MedusaLocker ransomware. Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access victims\u2019 networks. The MedusaLocker actors encrypt the victim's data and leave a ransom note with communication instructions in every folder containing an encrypted file. The note directs victims to provide ransomware payments to a specific Bitcoin wallet address. MedusaLocker appears to operate as a Ransomware-as-a-Service (RaaS) model based on the observed split of ransom payments. Typical RaaS models involve the ransomware developer and various affiliates that deploy the ransomware on victim systems. MedusaLocker ransomware payments appear to be consistently split between the affiliate, who receives 55 to 60 percent of the ransom; and the developer, who receives the remainder." ,
"category" : "Other" ,
"uuid" : "c4ccb926-906e-41ff-8588-f4380fde0638"
} ,
{
"type" : "text" ,
"object_relation" : "type" ,
"value" : "Alert" ,
"category" : "Other" ,
"uuid" : "81705f55-816b-4006-92c5-fb40d55adeb6"
} ,
{
"type" : "attachment" ,
"object_relation" : "report-file" ,
"value" : "AA22-181A_stopransomware_medusalocker.pdf" ,
"category" : "External analysis" ,
"uuid" : "0ea5c6a7-d215-4c63-b8cc-7dccfad867ea" ,
"data" : " J V B E R i 0 x L j Y N J e L j z 9 M N C j E 1 N T A g M C B v Y m o N P D w v T G l u Z W F y a X p l Z C A x L 0 w g N j Q 4 N z g z L 0 8 g M T U 1 M i 9 F I D Q w N T Y 4 M C 9 O I D E x L 1 Q g N j Q 4 M j I 1 L 0 g g W y A 1 O D g g N D M 2 X T 4 + D W V u Z G 9 i a g 0 g I C A g I C A g I C A g D Q o x N T k w I D A g b 2 J q D T w 8 L 0 R l Y 29 k Z V B h c m 1 z P D w v Q 29 s d W 1 u c y A 1 L 1 B y Z W R p Y 3 R v c i A x M j 4 + L 0 Z p b H R l c i 9 G b G F 0 Z U R l Y 29 k Z S 9 J R F s 8 M k Z B M 0 Y z N U U 0 Q z U 3 M 0 M 0 Q T h C O E N F R D M x N j R F R j Y 3 N T I + P D I 4 N j U 4 Q z B B N z g 4 O U J D N D Z B Q U M z N T Z G N z F F Q k Y 2 N j M y P l 0 v S W 5 k Z X h b M T U 1 M C A 3 M l 0 v S W 5 m b y A x N T Q 5 I D A g U i 9 M Z W 5 n d G g g M T c 0 L 1 B y Z X Y g N j Q 4 M j I 2 L 1 J v b 3 Q g M T U 1 M S A w I F I v U 2 l 6 Z S A x N j I y L 1 R 5 c G U v W F J l Z i 9 X W z E g M y A x X T 4 + c 3 R y Z W F t D Q p o 3 m J i Z G A Q Y G B i Y G D 5 A C I Z V o F I J k k Q y Z E B Z u u C y S Y Q y T o L r N I d L P I S T D 4 F i 8 i D 2 V 0 g k n E R W O U E s L g T m B Q H i + u B x W V A p P U K E M n s A h Y P A 5 H 8 n 4 E k 4 + Z M E D t 3 K Y h U U g K R q l k g 8 d T / I L b e D x D p + w R s V y G I l O 0 H s 3 O B J J O C I o j N l Q w i s 4 R B Z H o k W E Q C Z E L K c h C b O x 5 I / p 7 r w c D E y M A 2 F + x f B s Y h Q / 5 n + G P 9 G C D A A B q W H O A N C m V u Z H N 0 c m V h b Q 1 l b m R v Y m o N c 3 R h c n R 4 c m V m D Q o w D Q o l J U V P R g 0 K I C A g I C A g I A 0 K M T Y y M S A w I G 9 i a g 0 8 P C 9 D I D Q w N i 9 G a W x 0 Z X I v R m x h d G V E Z W N v Z G U v S S A 0 M j g v T G V u Z 3 R o I D M 0 M C 9 P I D M 5 M C 9 T I D I 3 N j 4 + c 3 R y Z W F t D Q p o 3 m J g Y G A C o m 8 M b A w M Q t s Y h B k Q Q J i B F S j K w s A x I Q D E 5 T E 4 c F i L i V e D s a n B b g L v B k Y b o B j j b b b 6 A 8 + u G F Y 39 I R N W a q d / I g B G Q g c k 5 l 5 T p N z k q 9 b a G S B s 0 T R M k e 30 B i B Y 3 I p I q k B z h K V E w K n O v I k P g M K s h i 2 z 2 S V D A G p B w q G A b l q l V C G x c x n j i p X U k M b e R L P q W h C 2 D M Y m J T N K j o 6 O h o Y G J X T Q Q w G B v Y K I A 9 I M D C U I z P Y y k G S j G B S 0 L 0 C r E U U r A W P X 4 A c Z Q a O o L l A W g 2 I N c C e C W M Q Z H j Y e K T B 6 o H S A S U F / i P M a o z 9 j E 8 a f B k 0 G 5 w X y C f w s z B u Y D 4 m u 5 J h N 1 D 7 y 6 s z Z m 60 c Z 6 h K m I U 0 p 3 R O f G A 4 I a X J 1 j i 7 K d x 8 Z r c m 9 l w 0 M L N V S D A 22 S X w z T G u b D A U m X g L D U E O Q O I l o N t 5 i y 7 A a T 5 G R h C d s C D 1 J y B 80E4 R B W T O E C A A Q C M I n X c D Q p l b m R z d H J l Y W 0 N Z W 5 k b 2 J q D T E 1 N T E g M C B v Y m o N P D w v T G F u Z y j + / w B F A E 4 A L Q B V A F M p L 0 1 h c m t J b m Z v P D w v T W F y a 2 V k I H R y d W U + P i 9 N Z X R h Z G F 0 Y S A 1 M y A w I F I v T 3 V 0 b G l u Z X M g N z E g M C B S L 1 B h Z 2 V M Y X l v d X Q v T 25 l Q 29 s d W 1 u L 1 B h Z 2 V z I D E 1 N D Y g M C B S L 1 N 0 c n V j d F R y Z W V S b 290 I D g 0 I D A g U i 9 U e X B l L 0 N h d G F s b 2 c + P g 1 l b m R v Y m o N M T U 1 M i A w I G 9 i a g 0 8 P C 9 B b m 5 v d H M g M T U 5 M S A w I F I v Q 29 u d G V u d H N b M T U 1 N i A w I F I g M T U 1 N y A w I F I g M T U 2 M C A w I F I g M T U 2 M y A w I F I g M T U 2 N C A w I F I g M T U 2 N S A w I F I g M T U 2 N y A w I F I g M T U 2 O S A w I F J d L 0 N y b 3 B C b 3 h b M C 4 w I D A u M C A 2 M T I u M C A 3 O T I u M F 0 v R 3 J v d X A g M T Y y M C A w I F I v T W V k a W F C b 3 h b M C 4 w I D A u M C A 2 M T I u M C A 3 O T I u M F 0 v U G F y Z W 50 I D E 1 N D c g M C B S L 1 J l c 291 c m N l c z w 8 L 0 V 4 d E d T d G F 0 Z T w 8 L 0 d T M C A x N T k 1 I D A g U j 4 + L 0 Z v b n Q 8 P C 9 D M l 8 w I D E 2 M D A g M C B S L 1 R U M C A x N j A y I D A g U i 9 U V D E g M T Y w N C A w I F I v V F Q y I D E 2 M D Y g M C B S L 1 R U M y A x N j A 4 I D A g U i 9 U V D Q g M T Y x M C A w I F I v V F Q 1 I D E 2 M T I g M C B S L 1 R U N i A x N j E 0 I D A g U i 9 U V D c g M T Y x N i A w I F I + P i 9 Q c m 9 j U 2 V 0 W y 9 Q R E Y v V G V 4 d C 9 J b W F n Z U N d L 1 h P Y m p l Y 3 Q 8 P C 9 J b T A g M T U 2 O C A w I F I v S W 0 x I D E 1 O D I g M C B S L 0 l t M i A x N T g 0 I D A g U i 9 J b T M g M T U 4 N S A w I F I v S W 0 0 I D E 1 O D c g M C B S L 0 l t N S A x N T g 5 I D A g U j 4 + P j 4 v U m 90 Y X R l I D A v U 3 R y d W N 0 U G F y Z W 50 c y A w L 1 R h Y n M v U y 9 U e X B l L 1 B h Z 2 U + P g 1 l b m R v Y m o N M T U 1 M y A w I G 9 i a g 0 8 P C 9 G a W x 0 Z X I v R m x h d G V E Z W N v Z G U v R m l y c 3 Q g M j g 3 L 0 x l b m d 0 a C A x N z k 2 L 0 4 g M z A v V H l w Z S 9 P Y m p T d G 0 + P n N 0 c m V h b Q 0 K a N 60 m W 1 T 2 z g Q g P + K P s J 0 i C V Z r 51 O 5 p J Q a O a g t I S W X p l 8 M I k B D 0 m c S U x b / v 3 t S r Y T u 3 n v 3 X i M Z W l X u 5 K e X c m B S c s I J U x a T q T E Z 0 i Y V l g Q h F u D B U k E d y K K S O a a N J H K N R l i m M C C J V Z x w h S l x G p X Y I R R Y 7 E E r y F n W I K + j V F Y g s 4 Z l 1 i S h K v Q Y E k R b o z A k i Y h s 0 7 O k F C E r s 6 S 0 E i s Y 5 Q I x k I s M S K k p F j i R B i G / U G D Z O i 3 A s e k U K 5 V E m m k x p I i o O X k N F F C o F f M Q M m i z 8 w S J U P U g P E q q R m 5 c x N D y b W f m b w g 8 g K 4 n R f K G i f c f / c u a H k b 8 B a 0 e / D e g + v m d R o H 7 X Q 2 j G f B L a H N Z v 5 y R 0 G O 9 o M P Q T e 4 j g c Z W J U N 45 w z D Z w q D Q 8 D X s P T K t E P e i / 3 G f Z 1 k U y e f a + t y S T N m s 3 C s D n U s G Y N Z W C m u G j A x B M u Z E P A 4 r J Q N r j S O 1 i 2 B 1 o W X D b A C p G 8 o a 0 x R I a s I c O Q q L C h O b d b L H d 75 C E a z c H U Z f A x n Y 2 j U d A B d x o 0 u P q U t 1 x 9 u i Q s 6 L V I N n u J g 95 l N H 8 G 0 U n s + 3 r / K z v v Z V E W B 4 P I 6 a V T r + f 6 v 0 K X k 8 n j U X c Y T 7 I k e z 0 G p x + T e T Z 7 P W o N 0 / v 4 G N y b T k f x G J p x l O j T f I A v j F I Z d L q n v R j K U l M 3 P Z 1 o + i F O H p 8 y o i k N T m M v e s I 5 D c 5 G 0 e O c i O A s n W T t d v o L J g r r C X P I Q 2 d 913 Q W j Z P R 61 H v d X y f j o 59 V T K K O d p g z g Z W f Y z G c X D 76 Z / 33 Y s 3 X v T y x j X 0 s l m c D Z 6 K u c K q W + + Q A I e 6 W T R K B q 3 J 4 y g m N O h l 8 f g r 0 d J P F I q i w 7 N k m q W z 4 F s + D k n 9 q N v R P E a R 36 z i F L z O o a v u 5 C H 1 y c T N R P f 0 J j 3 v n l 5 G 0 6 C Y 3 O D 0 F k d K a 7 Z 84 k G l A g V Q R h H 0 i y + 8 C 27 v G K d 3 E P r 9 f r N 557 J U H p R r v f N L M I x g F q F 57 j M a m n o / G a R D W P n S u Z M P p X m 0 S I O b 9 M s k A a E Y l J Q f V O l K F Q R B l x e e q c X C h 1 z m C x / y x c q f K C V d G + E w G 66 D y u K 3 Z k l U X 3 t e X f v O 1 / O b q + 9 v n O T B S 2 / M 5 q V n t r r 0 N a P l F N 4 m k 9 Z k n p T v Z 8 l s n n W e o l k x 6 u W 1 x g 0 E h 3 I R 5 T J M s s X M Q w g 7 l 5 Y n H 7 a v y u S D v W H 2 N L + D 7 I k Z F P M N b H G 4 Q k p B h o N 9 L 4 T 8 g j e 2 o A S W C 2 m U 3 O V e 7 h 0 v R m F 7 Q Q N 4 Q + Z y t 3 u H 3 U q D I L 47 A 9 Q 7 g p 0 Y M O x k o d 7 p 5 X K l X l 62 Q p R 9 Y 7037 P / 6 o Z W u U V p x s S y j d b i x H Z 9 o u T 4 k n A b X X u h B W e c 6 x b 3 f h Z a W J x u j u 78 c H N a a 7 b F h 1 V J s S N h c X W z A p m F R f 2 t o q G p o n F 91 r n v X n t I T j / 3 e E X L C e B 4 j l u 8 X I 6 u t H x o q Y S 1 U h N k S K m J 9 q F A S Q i R 5 m v y 1 K U x W r v Y + I U E r A U F L w 0 U o 0 L W B 8 L v h / x P + Q 9 E v p 69 f 3 Q x Y F X i 5 B L x W K 4 G H o y y 2 A f D W z e l 24 k 2 V + M 8 X r e + d b z l z 7 X Q 0 3 J F 6 v Z Z 6 B l v a X t i v d 2 E H 9 K V Z g b 6 s o Q + p Y y P 62 q 5 G v w C 8 e v m V 3612 N Y / V v 7 R M 1 / 5 p D L r j 4 w B I g b e c w R o t U q 1 N j y U t 1 a M D N 56 W / O g g 1 V Z a w i 207 M 1 J c X 5 g o f p D S v 4 g N e o a H 3 z b K c J u S o 2 H x P 4 q c l Z n Q F q y s H w Y K L S K / E c 3 Z D + U W X 6 i f S w v D g t F T k T y i p b i X u K v 7 E E v 8 m d 1 x 5 Z i C U
}
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "report"
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
2023-04-21 13:25:09 +00:00
]
}