2023-04-21 13:25:09 +00:00
{
2023-06-14 17:31:25 +00:00
"type" : "bundle" ,
"id" : "bundle--588b3db6-d5d4-4e46-86d6-42b9950d210f" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T15:16:08.000Z" ,
"modified" : "2017-01-27T15:16:08.000Z" ,
"name" : "CIRCL" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--588b3db6-d5d4-4e46-86d6-42b9950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T15:16:08.000Z" ,
"modified" : "2017-01-27T15:16:08.000Z" ,
"name" : "Malspam targeting github users" ,
"published" : "2017-01-27T15:16:34Z" ,
"object_refs" : [
"indicator--588b3e7d-c100-485d-b7d8-4876950d210f" ,
"indicator--588b3e7e-d0e4-4724-9d6e-484a950d210f" ,
"indicator--588b3e80-d658-4a16-a265-4dbf950d210f" ,
"x-misp-attribute--588b3eff-5b28-48b6-a288-41c1950d210f" ,
"observed-data--588b40e8-8714-4e31-84ff-4bc8950d210f" ,
"domain-name--588b40e8-8714-4e31-84ff-4bc8950d210f" ,
"x-misp-attribute--588b5654-1e48-407b-ba73-4e1f950d210f" ,
"observed-data--588b569b-534c-48ca-9d73-1a2e950d210f" ,
"email-message--588b569b-534c-48ca-9d73-1a2e950d210f" ,
"observed-data--588b56cc-0a08-4a34-b192-45a8950d210f" ,
"email-message--588b56cc-0a08-4a34-b192-45a8950d210f" ,
"file--588b56cc-0a08-4a34-b192-45a8950d210f" ,
"observed-data--588b5717-a878-4208-90b2-43f9950d210f" ,
"email-message--588b5717-a878-4208-90b2-43f9950d210f" ,
"observed-data--588b576f-efe0-4377-8fb9-4e4e950d210f" ,
"email-message--588b576f-efe0-4377-8fb9-4e4e950d210f" ,
"observed-data--588b5836-b6e8-4be5-9cb1-4b0e950d210f" ,
"network-traffic--588b5836-b6e8-4be5-9cb1-4b0e950d210f" ,
"ipv4-addr--588b5836-b6e8-4be5-9cb1-4b0e950d210f" ,
"observed-data--588b58aa-9374-4f37-a5f6-4da9950d210f" ,
"email-message--588b58aa-9374-4f37-a5f6-4da9950d210f" ,
"x-misp-attribute--588b58ed-7448-4511-8da9-48f9950d210f" ,
"indicator--588b59de-1b14-4cff-90b5-0ab5950d210f" ,
"indicator--588b59df-0b1c-4030-987e-0ab5950d210f" ,
"indicator--588b59e1-3c4c-40a6-8828-0ab5950d210f" ,
"indicator--588b5ebd-d448-48c8-ba48-4f21950d210f" ,
"indicator--588b5ebe-4340-43d3-bea0-4bfe950d210f" ,
"indicator--588b5ec0-59cc-440c-8b67-49c7950d210f" ,
"observed-data--588b641a-8b54-47fb-80d8-1a2e02de0b81" ,
"url--588b641a-8b54-47fb-80d8-1a2e02de0b81" ,
"observed-data--588b641b-72d8-4430-9107-1a2e02de0b81" ,
"url--588b641b-72d8-4430-9107-1a2e02de0b81" ,
"observed-data--588b6437-e6d4-4736-9459-452d950d210f" ,
"network-traffic--588b6437-e6d4-4736-9459-452d950d210f" ,
"ipv4-addr--588b6437-e6d4-4736-9459-452d950d210f"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"circl:incident-classification=\"malware\""
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--588b3e7d-c100-485d-b7d8-4876950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T12:35:09.000Z" ,
"modified" : "2017-01-27T12:35:09.000Z" ,
"description" : "sent by mail" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A G V k O 0 r M G P e t j A k B A J Y J A Q A g A B w A Y z F h N z M 1 Y T A y O W M 5 Z D Y 0 Z j Z k M T J m Y m V h N m R h N j I 5 Z m R V V A k A A 30 + i 1 h 9 P o t Y d X g L A A E E I Q A A A A Q h A A A A L n J b W 6 / F h g Q C P I 34 q a S j d v s 5 / 0 Y / b T v N e k 6e3 m l i c v b Y 9 j l 5 v Q J Z 9 l K j 3 P I I r / W g J s K Q T i 1 r g 3 k F R x D K k D o 1 J 0 n + g F a K e V D u t h P 7 Y d y J z A 7 k z 5 r H W e l Z S r K n + f y V f 2 P a 4 C g A C W D N T A X w R A L h w + Y i 53 q 2 F w q T 1 o 2 / C j + E F r Y C o m G e c 0 1 O a g X J E s 3 M H 0 r 269 L + V 6 t E v U 3 G M K / Y b + + G a m j q w D / r 4 l G 0 u p x D N k y l 6 Q V I a S 6 L e i L Y N I n / 63 / S I x Z V X x K D z u B N Z w n P C n 5 c E N 3 F j F G d t q q f x 5 h 0 v Y e b G D E x V y h G B S W n u 48 j w E + z t K s T p l g l 7 h G 50 V 3 E k h P Q m O z 6 q j f e B T j X k c I j t i C f O V K 7 f y V Y 3 Q p e z d B 9 R b s p h H + U f O a s j Y L G W e + M g 2 J c V Z b w v t h g C 8 K V E D G D X 1 j d Q e r + T l q g w G e V M 7 Y f D t N P P c 7 p W f 28 G h r V Y O k S C 2 a K H N v 9 y s i 7 I R m 3 p 1 Q 2 t J R W r b S f z y K 6 F M s f a F e d q r 2 O + k q J F d G 4 F 2 Z 2 J x C o E m 5 L X O 0 9 u L B b c i C l q 6 c F O J P l K P 3 m u x f 6 P Y j r Y Y e p 5 t R e l 5 m o p R n X B + N + T 1 Q M z D H W T c n H m G 4 T D T N K S 12 U O + O r G 99 r r 1 / z B m / m X h k H D 0 p W b i 6 I N g O h 8 + P N C I b 3 c P B Z B 4 V t 3 p P b N Z p h P u c F 1 L B w j / 1 k 9 H U A 0 l f H 1 B F d C i R 2 L 9 N Q Y p 135 n 0 o l B Z e + D g U M i L G K l s t r C N K p q i j h u J p 0 f b I L v c G D 3 u k O j M + d r d T 3 l 9 b k 18 P q O T / 9 U c S y i R N f R R P h M 0 L 82 z D w D K J A + K 91 k N P r P c 0 a f H l E 3 K n e 0 u v P s K N e v u k 65 N / w 4 q b C X 7 o b i D v 73 d y 4 C H a j g 3 d u x P j P Y 65 g 8 R W r L d 2 I y 3 A K V B o m T M p n k 5 + q 5 X H 8 k t F u s l B i g g 3 k F R k z 4 z r R j a 3 s j l G D a c 0 7 u u b V L Y x M c z Z C 0 H t i T i b / W n 8 N 3 M X 51 y U p 83 P i G 60 l 0 B b H o A I x j b J t c 61 X V 7 Y h S A l b S P x c Z H + U w R 52 M b N J 833 i Z A t 4 x M a / q G H r L V h / U E E 24 S 4 T y n X b N H 9 F B m 1 r A 82 W 5 r T b 4 h p D s 5 L y W 3 T N W 39 M I n t s F S L g d A n t L 4 o b j D 5 S w 6 x i S h a X O o S m 8 q T 5 / m I N A + J b 0 7 H x E F Y t d w h X T S z p X C n m k / J W 3 u X d x 4 z t a k B h U M z / N p E n A Z + X Z K 2 I 1 k n t 4 / 6 b 43 D B Q V K E T s J 2 D z t 743 V Z h y T R Z a 6 u p D H Z i u 6717 m e J v B F u s e B 0 N l L Y g a W N w b b 2 D y Z 3 p Q Z B I 8 / 3 V c T Y 6 g k v z U 396 a F d 1 m c z s k O k J y R y 1 B z d N h B d C c e Q x S p 3 / Y e g n x + r X Z F 4 u R S Q 8 L z J I l P h c F M k v i 3 w b f B 2 t G D m l E h k f 0 F l C Y 3 f h 3 e J 4 E U Z j n 81 D T S 8 r x p T 78 z E R x d 8 L 15 v + Q 46 P D J f X Z h + k c u N f q U Z m B w P I i 0 4 V l E t P i Q S 4 S 4 m c r 4e8 T L H 5 + a G L J u J m f W y i a W X 9 j K p + S 2 f s y A a u y j v e d S S b 6 r 6 d T Y E h h 1 W p 60 Q 2 x J / Y F V e G u f P L i c J V m t 98 f c x C 8 u a d v y n c i t Y o X + o C D M n D H 16 n H J P s + A G f z Z N s y G K l h c n n q v R E s Y m K w K G c B B 3 E p N 1 y 79 k e S 1 t 2 g 8 U 9 S 22 i e d 8 u G v j I C x F u q c I P L S i j d 3 M x o Z h C Y r c 38 m g F 1 U z I A I x K v z y H S c w 5 A G v X 8 w 9 g l U w n A N c Z k l R f k B h Z E V c o M D G b o D 7 h T j h A B j t g x t U k U s Z 4 K 1 a Q T r O e 7 J I b C E f m k m l S i V g f / o e / K Y P f p 0 O J g q k H 8e9 P x + //ET0FSQ+d9We74eks9wmuxcCK0TUg1t580UZ9F3CRARIpD/MfQPEWgAT6GFy7oieNCzA8kowbX+G3mBSjGhHqsw9tV6f58T/jsMspcB48dP6aj2WIaLHi6hUfKPr3ejl+yFOAkLxkJjR/t4Z+/b2EvxswUo1xNhFNiy/RF5OOQOZ/4rjX71KSQbPJOmXXzCQiI5zi0WtMhHTDwtY7dQ69GE/hohzcU4yYnpPfCZcQ6PQ1NsMjO2nezQbw6MTHtO4Nmv16A6d467P8YyQLHhHh0tE3nA4Gg4zdStW6yNl+FshPDIZCh4jaQKlwBmfxIB4zQGNHFmkvyDl2p/DrqlDqoTCT/KheFDIM6t25vUpQJxDYNmZG3sxfWoUFjfGdotsRXXp2i64PcOD7qYhGJsxD9c6DNCyI7G52Zd+K2/LetFaGgEPEw8R3iD9dxZ2g5Vfam/6JfbLISi0XR5S7Bn2rr/SId4N94CVAYEaM3h9DBIn67Ae9iF0U26wjzIuOFuMloRJzXTAw0zqbKc8ONuZsMc0Ws52wWw5+sv8H6zzUMKtlHfFTV+ECrg+flsLW2ioWe15Q/z2VnQ4ZBMpqOVBGLxv2WBpfYiKDXCP7PKtCT+2ZLEzIfTNLOA8ByTnPoin+qNnZXIVzbLKeBTWqvqcga1Vh5ghyiW8yBMxSlO7/GOTTv1j5trU33haA670nkYiBgdWo3fCAlf5nCi+cDSj9tSnH7gPh/pCYm9c2PzFi/DvQhSp+S6h5JDrOss96+gZHF1WXJYRUgPpSFbwvV3i263xiPiSLXEsm2wmKa0+fhdu7ww0nGKXCo6vwItkroLCVe7xihOHPK+jwjBWQEw6v+MgzByuxQlER5dBcRex8Vt9/1a1aLJYWgBFsYNtExaTtpvHZQNXjACUIFF3iSFq/BaG4NHbgBasK52dFEckxY2L/JFua9ZO2ZMXVsk4WTfMG4cmhlDlRt0yNkybd98pP9o/vxmFjciie6mNnQGkvFvXz/Jec/Ywzmu8xXTtretkH/frvMlOkCm2CKqRvDw8GuN2nWj2jDRNcyZe8CXwJyjcZpzXHSfXJzYzvFP1s2Lj4dPLG0Luot8QwjnohKGvHZ49IGhgqHG3jO0eoUfnAmoJuh3VnciDhk1fVqcBBc8GXEqKPDRqP+0ZG/Zt4lwITUc9T0qInNwCV/o4NjBFK+U5hXRHhQZG19YRzfm/FtpmsAjVw7BID/sDdZu/9/wsdA5k2VgJkzIVLQLyV0VhulzWGfMB3zngJZcm4pZ9d4NJONkCYfk2ay51Yk+k0Cz9kEbTAQOmS5jlucSs9DT2uIcHi6hQDusD6C6Sc1dHlA+5+u0oM08lihaXVe4XSwyWLb5shkMsMJWnozBycolelTr2xvgVp+vJzgn5w0ZJBKwvsBM4VvokogGtKxrK7zEkRbohgKhQjBNYOGOjDCyK8aF9+QkaaNP11hFIyjd4h1gprwPWJae1WiIcpkgHJQt9q9euQFnYbWUiW8YVoaViG8OoTPwUP6gXTcRfQwnKt2uOixFClA0yQXOkZh3QwzInVM9fqntqUk5vsLHbSJidd/WJLfuiUFlqYldi+HupyrU69uDD00qDFdRQOJ+gRaG5E7zxIcpYFcYLtK2QPTkBxwLiZZjSNRMbrT+8EZRqS8CITXnGrxwJdB+XwGqkh7g1M5wn3b8yhqloI7UlbsJQNuXcmXTfGdP2S/9ZlPNOiywLuBaxZG1gWD+/LjWAUfb0b5161475s+Nr1cFE70UgiEN1/xOdn9kwcWp4s63CS83zgu9KbA83eltvbXfXg/Tm6A6rfjr5T2ebn9+nXZG/E3a46gZGi+fu3WlbtFuYtlJLTPit23y82PxG6PGg1TyOzPCQMjq8X6+eD8qFIcJhayfBhPjnJgkrmLWXxNIQWSbNBJmKDU3Egi0M5YPuJtVKWnmDHtl7Y+70ACWWKTyQvWXuDtn0rT7gafaV4CyE1URmnRR3UKCeN7CS5RqqJth2bEnqefzEvmVYwCHXvgY/3/6R5hugkFlZY7+81Veq90N4GnZuOZCRsZGmwDeIK1CRDuLx8pF2tsAGnGak+dC1hHT0fr+4Be9zxlQ8lz6rgYiU9kZ4KTHJO+RkRcx7DckmM21kTKqocIy5TjJgm8j6AkT3pNrUlVttSXSqZ2Rln4DcgVR0gcdAu7Gk5dPKbaZlP5ypRKaDveZ0EvP1/Xpr2+Xz
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-27T12:35:09Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--588b3e7e-d0e4-4724-9d6e-484a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T12:35:10.000Z" ,
"modified" : "2017-01-27T12:35:10.000Z" ,
"description" : "sent by mail" ,
"pattern" : "[file:name = '2701.zip' AND file:hashes.SHA1 = '4ec4258cb17ab4e297f72d6bcb27399a3f5786e8']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-27T12:35:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--588b3e80-d658-4a16-a265-4dbf950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T12:35:12.000Z" ,
"modified" : "2017-01-27T12:35:12.000Z" ,
"description" : "sent by mail" ,
"pattern" : "[file:name = '2701.zip' AND file:hashes.SHA256 = '2690dc4ebde17e460aa9fb7c96fdaedba0702cc9737186af6efa66d1c92974ad']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-27T12:35:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--588b3eff-5b28-48b6-a288-41c1950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T12:37:19.000Z" ,
"modified" : "2017-01-27T12:37:19.000Z" ,
"labels" : [
"misp:type=\"text\"" ,
"misp:category=\"Payload delivery\""
] ,
"x_misp_category" : "Payload delivery" ,
"x_misp_comment" : "text received by mail" ,
"x_misp_type" : "text" ,
"x_misp_value" : "Hello,\r\n \r\nMy name is Adam Buchbinder, I saw your GitHub repo and i'm pretty amazed.\r\nThe point is that i have an open position in my company and looks like you\r\nare a good fit.\r\n \r\nPlease take a look into attachment to find details about company and job.\r\nDont hesitate to contact me directly via email highlighted in the document below.\r\n \r\n\r\nThanks and regards,\r\nAdam."
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b40e8-8714-4e31-84ff-4bc8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T12:45:28.000Z" ,
"modified" : "2017-01-27T12:45:28.000Z" ,
"first_observed" : "2017-01-27T12:45:28Z" ,
"last_observed" : "2017-01-27T12:45:28Z" ,
"number_observed" : 1 ,
"object_refs" : [
"domain-name--588b40e8-8714-4e31-84ff-4bc8950d210f"
] ,
"labels" : [
"misp:type=\"hostname\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "domain-name" ,
"spec_version" : "2.1" ,
"id" : "domain-name--588b40e8-8714-4e31-84ff-4bc8950d210f" ,
"value" : "gw.yugo-star.ru"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--588b5654-1e48-407b-ba73-4e1f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:16:52.000Z" ,
"modified" : "2017-01-27T14:16:52.000Z" ,
"labels" : [
"misp:type=\"email-src-display-name\"" ,
"misp:category=\"Payload delivery\""
] ,
"x_misp_category" : "Payload delivery" ,
"x_misp_comment" : "probably spoofed github user" ,
"x_misp_type" : "email-src-display-name" ,
"x_misp_value" : "alec@cpan.org"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b569b-534c-48ca-9d73-1a2e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:18:02.000Z" ,
"modified" : "2017-01-27T14:18:02.000Z" ,
"first_observed" : "2017-01-27T14:18:02Z" ,
"last_observed" : "2017-01-27T14:18:02Z" ,
"number_observed" : 1 ,
"object_refs" : [
"email-message--588b569b-534c-48ca-9d73-1a2e950d210f"
] ,
"labels" : [
"misp:type=\"email-subject\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "email-message" ,
"spec_version" : "2.1" ,
"id" : "email-message--588b569b-534c-48ca-9d73-1a2e950d210f" ,
"is_multipart" : false ,
"subject" : "Hello"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b56cc-0a08-4a34-b192-45a8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:18:52.000Z" ,
"modified" : "2017-01-27T14:18:52.000Z" ,
"first_observed" : "2017-01-27T14:18:52Z" ,
"last_observed" : "2017-01-27T14:18:52Z" ,
"number_observed" : 1 ,
"object_refs" : [
"email-message--588b56cc-0a08-4a34-b192-45a8950d210f" ,
"file--588b56cc-0a08-4a34-b192-45a8950d210f"
] ,
"labels" : [
"misp:type=\"email-attachment\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "email-message" ,
"spec_version" : "2.1" ,
"id" : "email-message--588b56cc-0a08-4a34-b192-45a8950d210f" ,
"is_multipart" : true ,
"body_multipart" : [
{
"body_raw_ref" : "file--588b56cc-0a08-4a34-b192-45a8950d210f" ,
"content_disposition" : "attachment; filename='2701.zip'"
}
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--588b56cc-0a08-4a34-b192-45a8950d210f" ,
"name" : "2701.zip"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b5717-a878-4208-90b2-43f9950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:20:07.000Z" ,
"modified" : "2017-01-27T14:20:07.000Z" ,
"first_observed" : "2017-01-27T14:20:07Z" ,
"last_observed" : "2017-01-27T14:20:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"email-message--588b5717-a878-4208-90b2-43f9950d210f"
] ,
"labels" : [
"misp:type=\"email-reply-to\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "email-message" ,
"spec_version" : "2.1" ,
"id" : "email-message--588b5717-a878-4208-90b2-43f9950d210f" ,
"is_multipart" : false ,
"additional_header_fields" : {
"Reply-To" : "AdamBuchbinder@tutanota.com"
}
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b576f-efe0-4377-8fb9-4e4e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:21:34.000Z" ,
"modified" : "2017-01-27T14:21:34.000Z" ,
"first_observed" : "2017-01-27T14:21:34Z" ,
"last_observed" : "2017-01-27T14:21:34Z" ,
"number_observed" : 1 ,
"object_refs" : [
"email-message--588b576f-efe0-4377-8fb9-4e4e950d210f"
] ,
"labels" : [
"misp:type=\"email-message-id\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "email-message" ,
"spec_version" : "2.1" ,
"id" : "email-message--588b576f-efe0-4377-8fb9-4e4e950d210f" ,
"is_multipart" : false ,
"message_id" : "619BD3AF4490BE5D8184CD7A6E724E86@xpox"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b5836-b6e8-4be5-9cb1-4b0e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:24:54.000Z" ,
"modified" : "2017-01-27T14:24:54.000Z" ,
"first_observed" : "2017-01-27T14:24:54Z" ,
"last_observed" : "2017-01-27T14:24:54Z" ,
"number_observed" : 1 ,
"object_refs" : [
"network-traffic--588b5836-b6e8-4be5-9cb1-4b0e950d210f" ,
"ipv4-addr--588b5836-b6e8-4be5-9cb1-4b0e950d210f"
] ,
"labels" : [
"misp:type=\"ip-src\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "network-traffic" ,
"spec_version" : "2.1" ,
"id" : "network-traffic--588b5836-b6e8-4be5-9cb1-4b0e950d210f" ,
"src_ref" : "ipv4-addr--588b5836-b6e8-4be5-9cb1-4b0e950d210f" ,
"protocols" : [
"tcp"
]
} ,
{
"type" : "ipv4-addr" ,
"spec_version" : "2.1" ,
"id" : "ipv4-addr--588b5836-b6e8-4be5-9cb1-4b0e950d210f" ,
"value" : "185.39.170.74"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b58aa-9374-4f37-a5f6-4da9950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:26:50.000Z" ,
"modified" : "2017-01-27T14:26:50.000Z" ,
"first_observed" : "2017-01-27T14:26:50Z" ,
"last_observed" : "2017-01-27T14:26:50Z" ,
"number_observed" : 1 ,
"object_refs" : [
"email-message--588b58aa-9374-4f37-a5f6-4da9950d210f"
] ,
"labels" : [
"misp:type=\"email-x-mailer\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "email-message" ,
"spec_version" : "2.1" ,
"id" : "email-message--588b58aa-9374-4f37-a5f6-4da9950d210f" ,
"is_multipart" : false ,
"additional_header_fields" : {
"X-Mailer" : "X-Mailer: Microsoft Windows Live Mail 16.4.3528.331"
}
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--588b58ed-7448-4511-8da9-48f9950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:27:57.000Z" ,
"modified" : "2017-01-27T14:27:57.000Z" ,
"labels" : [
"misp:type=\"email-mime-boundary\"" ,
"misp:category=\"Payload delivery\""
] ,
"x_misp_category" : "Payload delivery" ,
"x_misp_type" : "email-mime-boundary" ,
"x_misp_value" : "\"----=_NextPart_001_1F9B_01D27892.CB6A37E0\""
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--588b59de-1b14-4cff-90b5-0ab5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:31:58.000Z" ,
"modified" : "2017-01-27T14:31:58.000Z" ,
"description" : "extracted from 2701.zip" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P 1 z O 0 q v 5 y p O K g 4 B A A A 4 A g A g A B w A M m Z l Y 2 J l O D g 0 O G J h Y z Q w M D F i N j k y Z j Y z Y j M z M z U 0 Z D N V V A k A A 95 Z i 1 j e W Y t Y d X g L A A E E I Q A A A A Q h A A A A 5 a B z d p 0 L b 5 S I a n i j E 7 z e c p I S Z G G H + t n b 3 G Z f l v K J x L 9 Q A N k t t j R x I r w Y n 4 r n I S s V n p I t x Z f A r B C p H d s 30 S z g + V W m J R O v f j o a 29 y 5 R p Y V Q m U o 91 H W B G w C N f q f 4 m g O + u f b N m v W 6 A i N Y w e V e d G f M y B 0 J 0 j i E I 1 x y m 4 s / E r n J t a n B N 8 s C z 9 w T 2 d g W l l q W s g r v Q U L F j 47 x z 4 w i L X S q 7 h B z Z G Y 2 y M V + K z B m L m C J 2 G 5 w 2 S n y 6 k I b m S + w R y Y E z z 0 b c z x c L t + 0 w A h X k K h J S Q D x c 9 i E r U A E E h I f + s 3 N r b W J n n / 6 I M 4 A s Y B t c H m w S C + s K N j j H h s m Y B 23 k h 7 N e 3 X X M G X t v X o B J W C W m t H 0 l u m Q j g 7 o X E 9 B k X 6 l B 1 h R U v S z l Q u I 0 p y G 8 h 6 c H f 6 w Y f j g z u V n p V W + h x o C w R e 10 Z H v v r l T L X i x R e B 2 F / O L d g K s j f 0 H h + s m 5 L 1 t Z q + 4 T W E w y n 0 M e j 9 o Q m 3 G 0 r v Z P U C V L n R A I g / y L b E X C + F / E i n n e 4 o V m Q L W / o Y e P 7 W d T G i J v x s d k 1 U H 7 B P C 0 1 y L 8 R E 7 t r r D u g j + 8 V E T O 9 R h H f h C W K J 3 H m R T L p K 8 P x 2 B m / p R E a m t b o x e z L M i i 3 P j A 5 T T j a 2 K P 2 X O l m M D C e z X Z C i 3 P 4 L F X a R J F T N j 3 O B i e w c E b / 8 w 7 + F 4 V d + G e W q G 3 T 8 U z g i + a p a S V N x m F 52 L w F 6 Y 8 J I p C H G c o p p 586 z J k d M q y 4 Y O s v x y O k V S g u 8 l w F W 7 g e X u m 2 t K x R A n E H M 3 L J I 6 T + J j X Z 2 J B h X 0 x f a U j y x p e A 8 S 1 P j 0 2 O X A V m 1 I / K I M T q r g 3 S k J / x x C 6 o Z b g m E a V u G T n 1 M Z S 9 j 3 z 5 p g z B z 2 V 1 G x k H t s B D a w z E t v e + r n Z y k Z E z d Y 4 b E 3 j f r 8 l 0 u 4 R M D a b S t N f 83 m x 7 R m l M 1 F 12 y G / l 6 l X Q X 6 H 0 x r C h M 4 u 8 R c r C k S T 0 m c G p m 5 v V p H B 87 Z n 49 C U p 2 z 6 C d l b J P r d R l A D W R 9 E / 7 I F x U o y w Y 3 W A h d k T + 8 i y s X i 89 y K U H s f P n d w F i P J M A B p C e J K M s p p V 5 j H i w Q K m / p c + Q / 1 Z M r Z V S + X r 1 L f P M x 6 h r o V x g W 7 o n L V T I y v R U G 9 R B E w M j t W a J V Q a x x 0 M y + Q L C 72 m m n J F 7 Q 5 y P w 1 z h F J D Y p T F L U n f D l G C B U + P 17 r n Y d O K E t a h v 8 r 8 T B c W J h c / 6 l 63 s s g w I Y h Q q z N e d 1 U r H l H x 6 V a G Q 7 T L a U l J X s 7 f e J 2 M 4 y j U 5 w B w n P q o G c q K Q c q t U O h 4 A J 6 l d 6 Q R b I 8 I B Z 1 l E U f K N P J F B e B m 8 L R B O A J v 3 u X D 11 R l d M D 0 o Q 944 / d P X d 0 j q t u f J 1 d J p o 7 f l L v c k q 7 r e q 5 W 1 O X 1 o 3 H l h e E l Z / G p C r + u 8 l g k o h p V C + 0 59 U S w a Y r 2 Q h r + F N H x D A a 2 z W X c W / e + h C s 5 p P + / O 5 T v 0 / u y i g Y D Q E 13 r D S e C n e 9 c i 9 e h y Z t S W a H A 4 H + q h h + T k 8 i t F U o F y L 8 G l X a a J e R G I s c X I U I E y h H F I t 8 m L v 3 x C a S h + 5 J Z J A D q 3 q 2 o s 1 P H E s z L u 8 j S P L X E 6 L I e 0 V U A M G 0 h q W R P N X n a d r g E C T Z A b N D G I X a m B 1 a v Y R 3 h x A v H 2 b F 7 f f 7 Z H b O a b r 0 68 L 9 B 3 s n r e U X g N v t 52 R 7 f J H 7 h b l f X d / 7 f i N Y J w e a y H K k U R d A S F s r U d n e a 3 x v J T 7 S x D l / U 7E7 K y j 0 i U t a Q o C Q 7 U 3 q S Z a l X H g N i g q G R R B H 0 c N r R 4 J l H T K M c 7 l / 4 L 7 z U 9 G D o 0 Y E M 8 D h S S S G Q t o Z 7 i m K f I / i g e H p f 6 F 0 V Z e 8 g W X K h U 3 g L Y 43 v z G R D M R 7 k o J u b e n r L 6 q 8 S X 0 w M g 2 D p w C O i p o V b 5 S A d K q 9 H N t T j s L 9 t b m 4 r i X n n g k y x 4 A c K / 2 q c 7 E a y r V H 9 e b + W j V x + Q 8 G M T w l 7 c / F 5 l 5 P t 6 q B 4 a 5 w R i q V 93 h 6 I U K i j 6 k x T m I z 1 X M 833 Z d + K v R e 5 D l j l D t y o G h g d T J I T 20 + + A r f z A o B t X K y Z 5 d Z q d + y 6 w / O 6 M v N w t k W / 7 B k C 6 k q 3 Y C T j L G g d x L V T P 4522 m 1 J T S G u s U s z B 722 k + f 5 h q c X U 40 Q j 8 q Y w N 8 P e I i s M h h D K h Y O 9 f N c N i W r P b 9 k f M o O 16 f O M 0 T S A l t X v P z G o 7 M / W o q + j V g T T y w i o 8 i 55 Q v v U f 0 m t I g W H q 1 N j P t + t 2 O W G g P G D q G K T T p m e 5 M m 1 g l G I j x b G D k e w t q 31 r s 8 x O T 53 A n 9 D E i h P F F J g T B L F M D l 45 z h e T + q i z Z 3 j 3 q F b L f A 9 s t d K Q / w B T O 2 a j 9 Q t P 6 R 19 G C q h E V w D N 7 g M + H 17 l i Y 78 K V g I O c n s j n a 99 A c W a f 5 G r C S H h 9 N o X Q 2 Y J + o Y N A C J c T e l u 99 U R X v T E J z 0 l s w b R w r y R v q 96 S M f B n A F L C Z A N b A A 65 h I P U 4 k c y 6 N w Q t K u u 33 y G B 9 I a X + 8 b p t / Y e j u / Y e 14 t g + M 4 i w 8 X S E U T 5 W Y 8 R u X b C G e i X w t f 7 V L D 15 Q V i c W W X x u 6 f a J x 84 j F d 4 Y + e 4 t M K M t H y m Z O / 1 b / Q 4 G O r 7 c 8 o E 5 V R L m D 1 Y H H G N l S Q q T f 5 C p C r j o n a q a r N 4 q 8 f T d s 1 Z q z D U Z K 7 A F g h K B 5 i 3 U h W o p L 9 l b + i u Z w 8 L G 9 X Q T y r E W z i s q d a j 1 G l / D P E F 7 k g n d H f 6 Z A p u 5 i k c 77 R 437 f u z j v I A 1 z P R M T q q Q e o S j f + 9 C P U W O + F I u W K 9 / E u n P U + K O W W k R 166 L W u u b F v B o B r u Z m O H 8 y s 7 Y m k + n Q H T 1 o 1 d B 8 A P f a i F s T y T v P m d E 2 B t I W d B h 3 q k g f P 4 B 0 n d Z / E X 879 k J G 25 U G 1 u p 9 C K e W A u R c q C N a r t F v P B x 7 V M e z g 7 i d o i C C j D A Y E h O C 4 t n G E / d w L d O R c + i q C B D h y j 9 v d 3 Y F c / N Q s 4 q c d R 6 k 3 W r 5 N n O r R d P l l F g 28 P o N c / a q O o h u M p n K C X w s M 8 z i j Z Q X 2 M U K t R q a u 5 Z N 23 Y x O w U P 636 m r f P 74 I L A l S 6 V q V g V 9 H n Y + I X M w 0 N 24 d O m U V h w X 0 r M m Z O 7 t 0 R s q 5 Z S O L Z 0 B 4 B 9 / H K 3 p n R 8 A L b P R W G k 8 m Y 3 z 0 h X n 9 T i p j J L u l 7 A j h / d I V H J P r n I 1 f d y K 7 R c p t t W r w B J V E v b K q w K X G c Y V 5 Y 5 r h 18 K l v u e s T T 8 B X 2 M j C n m 8 a w d x O t p y h Z H V L 9 P G i D a S G P C h s U q z I L F C p f s W G 7 / x U y y o Z 4 r v s 7 U i M I O 9 m 1 q Z 4 z b d g h d I T e O l 4 k 24077 b n o W I 8e4 r O t S 7 A 3 c r H Y c u / e s J + 7e7 D 4 L K C + q K S G W t S b K D 0 c T C I w F o m Z A O H V Q G P O f i v l X o 5 / 4 n M 1 Y z F N F 0 z M q 11 M z r g k T l E c I q U j H U J H v T u f n t Y A U 0 L l R 7 K / x P r R z 2 p N 54 m l O 9 T 7 t G p v R 8 w f 9 U y i q 31 V f f 2 D c 2 W C J + z 991 i N G R Z Q C N F x z j m O + S X c 9 l L b s 4 V R u t p b a i k 7 y m v e h c / 67 L 7 N 1 I d U T + u 6 I K v o F j 7 D D K W G G Z J o K N 1 R F I F k 2 Z 9 m T t 5706 / 3 A + p 3 H 88 M Y L G i o Z g 8 O V J H z 25 C q C Q D w 8 S H X g W + I B x u A t Z F / F P W b p q 7 Y y 4 D 8 T 3 Q n k A 32 e R M u P j 1 s d 28 b R B A S T L P d Q N e + y l M q o y d 8 K F 6 S V 1 k g / M H 4 V + R 3 q q T l J 2 B K T 0 G s R c / r W Z O D v / M u / E F O n V L 0 x 8 E U Y s r p T 2 R f V C T l s M V y R X 6 w l N U Z A h M c 8 j H p 21 V f r i g 419 k u J 5 O s 1 G 7 / X l K H P e g U q d r j K e 5 h l 7 l u U 7 F p 5 D f e v k W V t G p o 2 O B e H a G d t N m v z D E V Y V m d I n p i h j 5 u p R W M H s I j n r I p K y f i S x T j q z z S a E + T J O G f K J B e v 6 h Q W t S F y D j d r I 1 n 2 Q c F F 2 S l N j C N 7 e P C g E v + 4 i V P 1 O W b E / 6 n a r w 2 E i Y E q S g Y p S G K 3 v y + J v c F + 8 R j m C 8 / K j H P z h g w Q n K N b P W 7 r g u V N 7 p K a G L z Q L A L q K o 8 + 3 y P s r l I h N a b l j m n m M L v n T c z T 0 0 X Z x q N 0 v w k F E 44 l p z D g 0 R l H n 8 Y E x H r D Q D h i Y 2 s n z R m v D S 952 a + c z x 3 D m F e / p J 5 g a 6 l U h j A i Q N l Q d f n V 2 E g W Z y V O n L b Y T O 6 A G e + J 4 D J 7 W u 8 j U r O p P / V U T n q c 8 h T P I X b 8 z a I t Y l W T G b z P n K D K c c X m f h 4E5 b N 9 K + Z 3 G X b x J E a y f G N n + H f X / 5 L C V J a q d q i v Z t 3 L w h f A u O 9 K
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-27T14:31:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Artifacts dropped"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--588b59df-0b1c-4030-987e-0ab5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:31:59.000Z" ,
"modified" : "2017-01-27T14:31:59.000Z" ,
"description" : "extracted from 2701.zip" ,
"pattern" : "[file:name = '2701.doc' AND file:hashes.SHA1 = '80ac1d4ae82a4f9a3f0068c79b96483fb7a7c16d']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-27T14:31:59Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Artifacts dropped"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--588b59e1-3c4c-40a6-8828-0ab5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:32:01.000Z" ,
"modified" : "2017-01-27T14:32:01.000Z" ,
"description" : "extracted from 2701.zip" ,
"pattern" : "[file:name = '2701.doc' AND file:hashes.SHA256 = '6b9af3290723f081e090cd29113c8755696dca88f06d072dd75bf5560ca9408e']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-27T14:32:01Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Artifacts dropped"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--588b5ebd-d448-48c8-ba48-4f21950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:52:45.000Z" ,
"modified" : "2017-01-27T14:52:45.000Z" ,
"description" : "Extracted from 2701.doc" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A J d 2 O 0 q 0 l 5 P 3 C y 0 A A P e e A A A g A B w A Y T Q w Z W Z l O G E 4 N T E w Z m V j Y m M y M T J k M D g 1 M T h j Y 2 U 1 M T B V V A k A A 71 e i 1 i 9 X o t Y d X g L A A E E I Q A A A A Q h A A A A x W M J 1 S p F I 0 K W d C d Q N 3 I x F a u r f R C R Q A d c 0 Z C N y u e 1 X Y + K V W u t l W 9 K C m c Q 43 H Z v / 0 7 c A r J Y L b k Z X 5 g f D 9 k y u 6 r a c v 1 p W K n M J 2 b P O y G 2 T C K I j C 1 J u N r 18 G Y m i Q 1 q a f b d U N y 2 + r k n / E F p J v D k R M E 3 h / o h 1 n I F p e N i Q E Q T r V e N t H h n 5 h f / m i J X l 4 V z p b n r u o U A m j g R p V S + / u a y Z 4 p X B o W I B t S X 1 g a B R Y J t 1 Y p u s x a x h q h 5 S P G A e W S U b 25 D U y D N P 0 G 1 W o v t w T i 4 K t S R c j m 6 x f y X d I I o 9 S 3 I H U Y F Z 2 N y j f X 8 a d B d c a 4 L K 13 j p T X N 0 + j E I k q 0 Y I 96 g t x q o S 0 3 n x 1 + f e P V + F 5 A + T u c 7 T n B 4 W K L K i D Y p U e / z 7 t P Q 7 x Q Y Z 3 r 3 V / 5 C Y r x w 3 f L 0 y O z 7 a E 1 q t L I L f m e r 95 B L v v Z c M L V 8 G V 5 d g o h 92 s M 5 P 28 c T Y Y m 94 V 8 Q z Q C / Y z a o S y t v 5 w t x E b r b Y p r w A i H X 1 x X H U 5 H b + W L 0 5 u g 99 e V w y c 4 E u e s i s 8 i a b p + A / l w Z r m 58 x C 1 a A a c / F 3 v 3 w 2 H a S A D z q d 9 e I 1 b b w A s 0 k p v 6 D u X 7 D X V k B 73 Y R w 5 J 26 M k D q 0 0 k U O d 7 d b G d + c C 68 D E c k z 5 x J A z 8 y T W N p 6 v X i 5 + s E W 6 n r j F D 6 e q e s H z p 2 v k W W 0 e + M k D z V 5 C a W 1 R 0 i 9 F G K c z 6 y j M C V H K p z z c T 3 X j O v f P b s i o 3 P + A U Q I r x 6 z H q V j q e 2 X O U 0 e w S u y u 6 W P j p D P a z F g h r A Z D X 111 W X q h X Q a T + o R B 38 O A S A K 8 u B J / f T + S c L p Q 7 r H I g W o Z G n D r 66 P B F b Z M G N O S E s c H + F Q 27 l M D o q k x T g S 6 y l J k q b 9 X d / + 3 m 7 D p + N 4 / Y A D k R 2 G G E u O O 5 A G m m q T 3 K f i Z o r U T s h J E 3 e I 78 Q W 9 Z 5 Z A n f 9 q E d r D c F O f G b b c z l L Q 1 J G 8 Z E Z X k R 8 d a v x 7 e Y s E / 9 R i 6 y q V F O J G B f 4 m g s k j L y s G 2 N n p 6 Y Z n D m l J 1 h 7 p 85 a x 2 y X Q n t + u 5 Z y t w b s e r a 1 z 9 K O H a k X F Q K y 7 Q 2 I I j 5 T D n 1 C e R 2 c N y t B I v Z t R k z + 5 Z d e M x + b 7 D B m 2 I B B O 1 L l n a i h q c 764 s Q 4 z z n C / l V + i V X 7 M i 8 N C A G A J z u z L E 2 m / l X C 4 q H i r 0 3 X i 6 G 7 A L G m y 8 c 4 L K x E 76 x K V D y 85 k f s X T 0 g d p M J h K J 1 T z s E W n m K h t D n e m F 4 + j 0 p p V S s K c 9 I O q 2 N s S G 5 + x l D 6 z p v j I w x F V 0 / Y P l t v J O C B d k s 5 h G L x 7 U b 8 S x T t T P T z Y 8 b k n 5 o A n a D 2 p G E h K g 8 V P 6 j L Q 1 A l V R z a e w x f R 3 I o 8 l F D b I U 2 Q C I I N w X + 8 j L w L A W E C M U 12 v I L R f Z x D G k L l r J z D 5 W 8 T D S 6 T U W u C u F O X x o 5 d T b f T j c / e V H A 3 A 0 B r b t 0 M + i k 6 + r R j b l w e B L t N 0 H H j J x Z T q / W l o N u 55 s d 8 O P U z 3 a v x R n 9 k 4 h T D b 0 J e J b P b G I 9 T G G D w S g D 4 r 8 G 1 D o e / d V 4 m E c i 4 s v 9 p L w u I d c E 8 L r n + o F z A X g u 2 P E v p U E j r w j C i H s K B r o m E p N l P / 7 j y j L Q M n x V 2 N B k 8 S P I l g E o Z R V h L D p X s g 2 M a m W t o d H r Y 4 Z Q 4 h m t 37 L I T W o Q 717057 / 2 X u + 5 H m x X x u E e X i e y v X Z 0 9 + T E z 4 Q Q p J P q 5 W 0 3 y k V Q 28 m u g l h z A K x e S 0 8 Q 5 Z L T r M p R U X J q 3 E / h 9 s t 6 v i W E j Z 9 p k t w t B X I G Q e B q r L d u w h K a 3E5 e X Z P W T g 26 e d F I K x 1 H j 4 C r U 8 X c R 3 q 0 l m 31 v W 1 q M I 9 l m 4 n H B B E d c v N 0 N u h h 0 2 l J J P p u 5 i 6 B R F b 2 w 8 d u E y y f 7 d c q O 3 M 5 H m S h Y R j o e M u x U T u t V 7 D S + G d 41 s a 9 k F 7 Q n W h u X R U C 2 f D p d s T 8 Y X U Z m A 4 / B T U Y 4 j u u I U f f N L B a Q z I d f l S y w E N c o S W g G Q Q H U Y k D o G n L 3 B f e B 0 Z W H e + 9 e N a T v f p z H n d C F R 4 g i m 7 m J k 0 S Z f 5 f j / u v 4 / y V / Y t 3 H K s Z / b N P 0 W L u 5 g C P r E S D T v h v N v L G 0 c Y F p O / o / v l / 40 U 3 i p s I l i f q / K 3 D P p H c L P l J z 4 q N Q 2 s 9 U J m u g 2 q 9 Z 1 x G P 68 g J 48 e X F 2 v 8 Z r X h D c C g p O S i O u f X C y n u a y G x b t n / 4481 O y W x x X w 6 s w Z j b + r Y 37 O R J E h b U U T Z / E x e / j i m y + e k S w 2 G o e e B 2 E z s N 2 a H m 0 i g z J q g S 3 T Z W s U Y P S u N z 9 f R H / l 8 L Q 6 c K N q U b b v p g D e s 0 X B D q 8 a r G B 13 e j j N 0 G O g 1 / s S u B y M c / K M p i m 1 F r 5 v j d x 0 s e w K S s r F H R s Z 1 A m N / D 7 w V M U f 5 l h h K 217 R e 1 z x u 1 X v A 9 o I p A H z y / B i H f y 6 h 62 a n I u w 4 q P Z R p N i P x d h k 0 U r U M b i M J F v N V + + N R H Q c G z p T I Y S S U y y 444 T o F T 4 U L C f V l s r Z w c g l z c I X M S g L 5 O w 4 m 5 w V P L Y T O v d P 3 U V X 20 E h H l d v + C 7 i N F X 7 F c n 3 y P x R V w B E P 6 o 9 u J 1 p V H f 0 / 0 / L W l o x 52 z I t 3 I F j E 13 U p 0 6 u L u j c x 2 s + b L X c A m a 56 l M v 4 Y x k N u 9 //meoeSKdtMULh6PZIUU1r0JAQK/elb0t8ymvYp1ZyWT9FGRrhEsH1FfvZPp9PsmK/f97yxxHbj7ErnT3R/QjI2mFkPWJHXno110ufs93CYQuqspgeugUTW4rd/8JXcxjPmsE8Qs2BuzV10SYf9OMwzdSdelhODK6ojjBxx0OUAc0bOO1U5vUtgUe8YdjB9/j1KkimCSFBYv2YnoG21z+JFwNAFrCCPyjrn8XyayRcORe+D/DCIBcgzdOm1ApqMsXSubyVj61vPEMjU/LnmLLDyW2duU5nfjEJi7CA9mFEwfTEh5GQQmOhCUUEryY5D1KUJ2kmte3gveg3AcDGvMg+QJowkfnhP7TN3DhykcMDSJM5pDVvTsUDMPMyEwRjPVuY3UCdlFyzYq31p0XK/NswrkD6KRwgCIQeTDIblvUVFnfHhk0zrSOYt+8JfzzatYTX/PaW6uSm3mejCY6LOVbQrOLTxiv8A6X4l7LUIOzGQkmmLeMdVty6gLNADPS1s76k3iOGiWGks8Lv3BpnRoIVLHM/WtHPQCTfK7/LJ6aQAm4m5Vsj8Ej3jNg4nW3EiPn86gj5d5HbNZ+0TtAkZ3tZpfBplC+Is/1Iu3UchvpRZw1trPskoNDFDBv8tx4HL/P5sm8+yJPdy38QYV2dDxWDcDfTEjuzYWLuILnE6lVN87XyfKuUstsMhErAfQ38io0ekSXAFBGV4zoX8NoJWheJX1v011kc1Jh4jdzybyee5ydzh8/h/rbh3AkXJbTtKwjc+mz85AK5fS6ScMYT3rfVo+geALWJgrybIO3NczAAmbk8yo7ElfI3NjptAdYjPh3w1SpPpvSB+RVgjrlJe6MtBNa4i+7Oo26QU/aK8oHeW2YE/VQuioyi6iEuW2In2gyQcza37wOvKj06+X7o/mGMxgJzofzlAYLcWHidPPGeW8Tsobd+8mAqPVaFnvZ8wNuwDd1eMsJqmpbhFARvzSPIoYMtm09Klmur0ayk6HgP+pvZEiwDHoyR6mJgC00tdHVGwIEt/2OWFpxI3hkthRR4hSoZ79pue855Qy7WMxyblzYgjAwAI2RYw7nYmM/uTnq8VuCE9ZJbG+8xVV303/qlfMQrgijo8t+c4UXeKqGlCEzM4e+fOqF31kdusKy6RkteN0ll2S5FdYqsO7jR2jKFv48csfHtSmWLKlStjBDmeUhZPazQ+CpHnGPSbBLo1wxEtNgcPRVdumuXEcRgvvOhJ7Redcpt49cW88p/Ngx+oQeXvAb5r4bBNfjFqVyYpWTHvcMnLiSHbSG7EI3bSS06zu+NuulvrlsTTKYcJ8SiNpMzZPlm4UWFT5OeBukMdnymjRZ8A1RZWANvTTgnD4STBhHx/+pK7gq3DA6nYeqgliCAJ5riOVJDatY7NdF2VKDiKsYElOXljhsDeFdFS6hBiR3FQYPduhgIar9VcenFyIbKHz6igXje1xf2a+fp9H46+J4s26D2ofouc5/EVmNL7AcaCBFd5QJhtxrsIepLapIEIr
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-27T14:52:45Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Artifacts dropped"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--588b5ebe-4340-43d3-bea0-4bfe950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:52:46.000Z" ,
"modified" : "2017-01-27T14:52:46.000Z" ,
"description" : "Extracted from 2701.doc" ,
"pattern" : "[file:name = 'vba.txt' AND file:hashes.SHA1 = '724919041f87beeff2b68421cd2bf6b00399af2a']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-27T14:52:46Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Artifacts dropped"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--588b5ec0-59cc-440c-8b67-49c7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T14:52:48.000Z" ,
"modified" : "2017-01-27T14:52:48.000Z" ,
"description" : "Extracted from 2701.doc" ,
"pattern" : "[file:name = 'vba.txt' AND file:hashes.SHA256 = 'bae5d104f1c18d59a4a92b4d0269a85cd00c8a8e3c67a7daa15dc01ad89157bd']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2017-01-27T14:52:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Artifacts dropped"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Artifacts dropped\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b641a-8b54-47fb-80d8-1a2e02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T15:15:38.000Z" ,
"modified" : "2017-01-27T15:15:38.000Z" ,
"first_observed" : "2017-01-27T15:15:38Z" ,
"last_observed" : "2017-01-27T15:15:38Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--588b641a-8b54-47fb-80d8-1a2e02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--588b641a-8b54-47fb-80d8-1a2e02de0b81" ,
"value" : "https://www.virustotal.com/file/2690dc4ebde17e460aa9fb7c96fdaedba0702cc9737186af6efa66d1c92974ad/analysis/1485526438/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b641b-72d8-4430-9107-1a2e02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T15:15:39.000Z" ,
"modified" : "2017-01-27T15:15:39.000Z" ,
"first_observed" : "2017-01-27T15:15:39Z" ,
"last_observed" : "2017-01-27T15:15:39Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--588b641b-72d8-4430-9107-1a2e02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--588b641b-72d8-4430-9107-1a2e02de0b81" ,
"value" : "https://www.virustotal.com/file/6b9af3290723f081e090cd29113c8755696dca88f06d072dd75bf5560ca9408e/analysis/1485529768/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--588b6437-e6d4-4736-9459-452d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-27T15:16:07.000Z" ,
"modified" : "2017-01-27T15:16:07.000Z" ,
"first_observed" : "2017-01-27T15:16:07Z" ,
"last_observed" : "2017-01-27T15:16:07Z" ,
"number_observed" : 1 ,
"object_refs" : [
"network-traffic--588b6437-e6d4-4736-9459-452d950d210f" ,
"ipv4-addr--588b6437-e6d4-4736-9459-452d950d210f"
] ,
"labels" : [
"misp:type=\"ip-src\"" ,
"misp:category=\"Network activity\""
]
} ,
{
"type" : "network-traffic" ,
"spec_version" : "2.1" ,
"id" : "network-traffic--588b6437-e6d4-4736-9459-452d950d210f" ,
"src_ref" : "ipv4-addr--588b6437-e6d4-4736-9459-452d950d210f" ,
"protocols" : [
"tcp"
]
} ,
{
"type" : "ipv4-addr" ,
"spec_version" : "2.1" ,
"id" : "ipv4-addr--588b6437-e6d4-4736-9459-452d950d210f" ,
"value" : "62.213.71.141"
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
2023-04-21 13:25:09 +00:00
]
}