2023-04-21 13:25:09 +00:00
{
2023-06-14 17:31:25 +00:00
"type" : "bundle" ,
"id" : "bundle--5b28ffbe-0118-409f-8f26-4f0e950d210f" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2018-06-24T06:02:50.000Z" ,
"modified" : "2018-06-24T06:02:50.000Z" ,
"name" : "CIRCL" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--5b28ffbe-0118-409f-8f26-4f0e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2018-06-24T06:02:50.000Z" ,
"modified" : "2018-06-24T06:02:50.000Z" ,
"name" : "OSINT - Malware That Hit Pyeongchang Olympics Deployed in New Attacks" ,
"published" : "2018-06-24T06:03:02Z" ,
"object_refs" : [
"observed-data--5b290062-dc94-4159-8b37-4332950d210f" ,
"file--5b290062-dc94-4159-8b37-4332950d210f" ,
"artifact--5b290062-dc94-4159-8b37-4332950d210f" ,
"observed-data--5b29008f-2b3c-481f-a4ed-4f3a950d210f" ,
"url--5b29008f-2b3c-481f-a4ed-4f3a950d210f" ,
"x-misp-attribute--5b290112-f380-49b0-a09a-493d950d210f" ,
"indicator--5b29002d-92b8-468e-900d-4091950d210f" ,
"x-misp-object--2cbbe4ff-7a38-45fc-ae72-577c6b2a0edf" ,
"x-misp-object--dac822e3-0527-46dd-99a9-2a16d8310d75" ,
"relationship--63940611-2ebd-4731-b40c-fc1c878f61f0"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"circl:incident-classification=\"malware\"" ,
"osint:source-type=\"blog-post\"" ,
"misp-galaxy:tool=\"Olympic Destroyer\""
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5b290062-dc94-4159-8b37-4332950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2018-06-19T13:09:12.000Z" ,
"modified" : "2018-06-19T13:09:12.000Z" ,
"first_observed" : "2018-06-19T13:09:12Z" ,
"last_observed" : "2018-06-19T13:09:12Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--5b290062-dc94-4159-8b37-4332950d210f" ,
"artifact--5b290062-dc94-4159-8b37-4332950d210f"
] ,
"labels" : [
"misp:type=\"attachment\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--5b290062-dc94-4159-8b37-4332950d210f" ,
"name" : "DgDJaCgWAAEIA01.jpg" ,
"content_ref" : "artifact--5b290062-dc94-4159-8b37-4332950d210f"
} ,
{
"type" : "artifact" ,
"spec_version" : "2.1" ,
"id" : "artifact--5b290062-dc94-4159-8b37-4332950d210f" ,
"payload_bin" : " / 9 j / 4 A A Q S k Z J R g A B A Q A A A Q A B A A D / 2 w B D A A U D B A Q E A w U E B A Q F B Q U G B w w I B w c H B w 8 L C w k M E Q 8 S E h E P E R E T F h w X E x Q a F R E R G C E Y G h 0 d H x 8 f E x c i J C I e J B w e H x 7 / 2 w B D A Q U F B Q c G B w 4 I C A 4 e F B E U H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 4 e H h 7 / w g A R C A I 2 A 0 I D A S I A A h E B A x E B / 8 Q A H A A B A A M B A Q E B A Q A A A A A A A A A A A A M E B g U C A Q c I / 8 Q A G Q E B A A M B A Q A A A A A A A A A A A A A A A A I D B A E F / 9 o A D A M B A A I Q A x A A A A H 9 i 8 J i F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w h T C F M I U w i l h m A I Z o Z g A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A C G a G U + v g h n g n A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A I Z Y p Q C G e C c A A A A A R V M T T 6 G 2 + Z W 1 D T q L P 5 x o p V 6 U 5 l / l d N Q r n X c 7 y d N x 7 J f c n 6 d V Q 9 F 1 x v Z 1 n O + H S c W Y 6 j k S H T c 76 d B z o T r u b 8 O m 5 c p f c S 2 d A A A A A A A A B z Y D s u L E d 9 Q 5533 O q n b c e Q 6 j l Q n b c c d h y p T o O U O q 4 E x 2 W d t n X c u E 7 Q A A A A A A I Z Y p Q C G e C c A A A A A 5 + T 2 e X z + v 0 r v u e e X I 9 H 7 Y r 3 d y v Y r a f E i l 9 i K O a u T f J q x I k 9 E L 77 P H y W U g + S e y h W 6 X s h T S l H 1 c F L 7 c F a D o C r H e F K a c A A A A A A A A Q e P k R 9 R W D 7 B W t E 8 V e w R e 5 K x Z + e f p 69 f I i W T n W R Y r / C n N Y 9 x s p e 4 v p 89 e Z y 1 a J V n n 0 A A A A A Q y R y A E U 8E4 A A A A B X y e s V 6 s p 0 e N X z e 23 t D q 3 + W o X / l 3 n c + p 2 v R z q 3 a 8 H J r 6 H y c q L u D m w 9 j 4 c q 3 b H I d f w c W z 1 P h w + 6 A A A A A A A A A A A A A F W P 17 K N + M e f F u s R e b c J 7 h p d M g s T V y t Y m k O f e h F C e z 4 J f t a 0 U k 1 o r / P v k 6 C v 6 P N i v Y A A A A A I Z I 5 A C K e v Y A A A A H z 6 K l s P k c r n Q 7 x z e l E V q n S 8 l K D s + C h T 7 X w o O l G V 4 r 3 o 5 r p i G r 0 o i p 56 U R S 8 X v R X g 6 s B a A A A A A A A A A A A B y a 3 b j M 9800 R y q O p j O d 86 I 4 k f e n M 10 e n G c G / 0 P h z a m g 8 H C s 9 P 6 c W T s e z N e 9 I M 190 g z F r u i D 1 K A A A A A I Z I / Z 9 f B F Y r 2 A A A A A A A A B T u V D 74 + Q E 8 U 9 c n g 91 y 3 L D W L q L y T S 1 L Z 5 Q f R J U v H y z x u y A A A A A A A A A A A A A c u P s D N W O 6 K P B 1 g z c 3 e H F 99 c Z e L W j i U d S M v L o x y u b p x n O z a A A A A A A A A A E P v x 7 A I r F e w A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A Q + / H s A i s V 7 A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A B D 68 + g C O x X s A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A E P r z 6 A I r N a y A A A A A A A A A A A A A A A A A A A H 5 N 2 D 9 B g y W d P 1 Z g P h + g M X M a 5 + V f T 9 U f k X L P 3 F + c 5 g / b X 5 J I f q 78 d s H 60 / N e C f t D 8 j 7 x v n 4 j + w l 0 A A A A A A A A A A A A A A A A A A E P r x 7 A I r N a y A A A A A A A A A A A A A A A A A A A Y z G f r c c N G P 5 f 6 O M T V / Q P R z u Z r k 8 + C u b E Y q 5 q R + f + t 8 M Z N r R g a 36 O M t V 2 Y w U m 5 G A 21 k A A A A A A A A A A A A A A A A A A A Q e / H s A i s 1 r I A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A B B 78 e j 6 + C K 1 V t A A A A A A A A A A A A A A A A A A H L r W s m d L W / l / w C g H Q g y m u M 3 U 4 u V P 3 T F a j 8 m P 2 B + R U j 9 o 4 + E t H 6 P 7 / n r 9 B N 9 y M D W P 2 T x + Z Y o / o O X 87 / Q z H z Z i Y 2 D P 886 P 6 F / P H 9 D g A A A A A A A A A A A A A A A A A E H r z 6 A I r V W 0 A A A A A A A A A A A A A A A A A A V Y e g O R 1 w R y D l 3 p g o X x V z + q F X 5 b F G e c V v N s V Y 7 w g 9 y D k W r o q w 9 A c / o A A A A A A A A A A A A A A A A A A B B 68 + g C K 1 V t A A A A A B F n j T P H s P F A 6 R X L A D m 2 C 0 A A A A g n C C c I J j 6 c 86 A A B R L x z z o A A A K 1 k H M O m A V i y A A A f D 6 o 3 g A A V i y A o 3 g A r 2 A 5 / Q A D n 9 A A A A A A g + / P o B H a q 2 g A A A A B j 9 g M T 43 I i x O 7 H 59 b 2 w / O 97 O M 1 x 96 M J B + h D A W N u M L 93 I / O + h t B m b X c G A 8 f o Q / P 8 A z + h D B 9 z Q D N y 98 c D k 7 U f n / w B 34 w U u 4 G A g / R o D j / N A P z v o 7 M f n r 9 C F P i 6 Y f n 1 z a j D U f 0 c Y H m / q H I O v h N 2 M T q r g x E e 7 H 51 D + l j F / N q P z r q b E M D v h x a 2 j G Q 4 v 6 S M P D v h + f R / o o z 3 Q 6 I / M + z s x i d s A A A A A E H 359 A I 7 V S 2 A A A A A U e f 0 u G X f F O M 7 V O r n D a T c y q d q f x Q L 9 T 5 y j v f e f G d P 7 y P B r u D 3 s y d 6 h L z z z V v V T p 2 + T 0 i W l S m L n N r 1 j Q 9 L g a I y H c 5 I 7 t F 6 O f P W H c 5E8 H J I 8 B 0 I 3 b r 5 + e 9 c 2 + f 72 f n n p 3 a l 8 p + Z P h D 5 l m F d 8 P N u t Y I N t i N Y X c f u M y d O X j W T p V v n C N B V c k 73 U y W p O T 2 M 13 T h 9 H j + T o e q X w 7 F F T O z Q o y G p 4 v b z R 2 O j x O 2 A A A A A Q f f g + v g j t 1 L Y A A A A A U u Y a B k 753 X A i N I z l k 7 T j 2 i 85 E B 3 m Z 9 G k Z + c 7 L h / T t s p q D 25 P L N U 4 t g 6 T K 6 o M x O a B n 6 B r 2 X 6 Z 1 X B q G p e O c d R w B 3 n C h N G w f a N G g o n V Z H r H Y c C q a l w P Z 3 G c m O 64 N Q 1 L l 9 M + u H 7 O y y e m J m Y 7 B f c 6 s d p x f p 2 X G 7 B 9 c H q F p m Z j Q O R 7 O o z H a L r L 2 j v O X 1 A A A A A C A A E d u p b A A A A A K 1 D s D h w a M c K b r j M f d N 4 M l 0 u 8 M 1 B r B y q O j G a 86 c Y 7 u d U Z j u W h k 7 u g G f 86 K M z 2 l D J 8 T 9 H G f 9 d 4 c O D R x G e l 73 s 8 c X s y G f p a 0 c i n o x n / n e 9 k H O 6 k h j 7 m k G Y l 0 Q x 93 R j k c j X D h 1 t K O F 2 J R j u x 2 R n t B 4 k M z 1 e i O Z w 9 P Y O V W 73 g z e g n G V 6 f U 9 n P 5 e k H N 5 e m H B 6 F 4 c / l 6 Q c / o A A A A A B A A C O 3 U t g A A A A F L g a r k n A t X L p w Z u v Z L m G 3 P H O R N 2 o D 5 w d B G V u Z p Y D k + N H W O k r 3 D C X d G M / q + b 0 j J 83 U x n B t X r Z y I u 76 M 3 p V s 52 a 18 Z f z W m p G R + 6 q A 63 B 79 Q z 3 n u R m f u 6 H n G d 6 / V h O T 3 O X o T g 8 z R x l D i b W k c n W c v q G T 7 v 2 U 4 s f c q H Q z m p q m Q s 9 n 0 c 7 k 7 G s Z n U R 3 C t l t n R O L 60 H g z l n t x n G 83 e o c G L S w H F a S i d b K a y k U e 5 W s g A A A A E H z 78 A P F u p b A A A A A F e v m T b M T 9 N r H k P h t G A 7 h o 2 U 651 G E t G p Z u Q 0 k m K G u n x H w 3 D F 986 s G f 5 B u p M N 1 T u z 4 L e h g r Z s m H 0 p c n x l c 3 b I 1 j b x y Y U 3 T E w m x t 4 W 8 a y P C X T Z M a N l D w B o J c k N b B B j z f M P o i z N n e M f o U G W q m 6 j x H s 3 F f N c g / R K 9 j 8 y P 0 r 3 g 7 h s G A u G z Y q 4 a m L i + D t z 5 / m G z Y 2 I 27 F 0 j e y Y n 0 b R n t C A A A A A Q f P v w A j u U 7 g A A A A A o X u C d q p W k O h D Q m J r M o 51 y X n k s l H q l X 3 P x y 948 d A q 8 z u w G f 0 z 6 R R w 0 T r R r Z B O E E d s c r q u Q d K t e E N a + E E 9 Y 9 c z p z k E V z i l 77 S m J Z u V M W r E g p 2 J A p 3 B V 9 W B S m n F P 5 d G f t 9 U U P V 0 I p R D U 6 I 4922 K M 1 g V Z J h R l s i G O 0 K U l k V o r w j k A A A A A C D 4 A E d y n c A A A A A O f l 9 x C Y q p + j D N f N N A Z v n 7 s f n / b 0 o / P J t 6 M z H q h g I P 0 Y Y N v B i 6 P 6 E O L n d 4 M F 4 / Q B + X d L c T m B t b Q Z Z q R g L W 1 G F o f p I w V 3 Y D 88 m 3 o 4 f A 3 c J w O B + i D L + 9 L A e b I A A A A A A A A A A A A A A A A A A A A A A V w A R 3 K d w A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A r n w + v g j u 0 r o A A A A B V y u w z J P 6 m E d X r 0 i L x b t H M 9 W 7 J n b s 0 Z 3 v
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5b29008f-2b3c-481f-a4ed-4f3a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2018-06-19T13:09:46.000Z" ,
"modified" : "2018-06-19T13:09:46.000Z" ,
"first_observed" : "2018-06-19T13:09:46Z" ,
"last_observed" : "2018-06-19T13:09:46Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--5b29008f-2b3c-481f-a4ed-4f3a950d210f"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\"" ,
"osint:source-type=\"blog-post\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--5b29008f-2b3c-481f-a4ed-4f3a950d210f" ,
"value" : "https://www.bleepingcomputer.com/news/security/malware-that-hit-pyeongchang-olympics-deployed-in-new-attacks/"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--5b290112-f380-49b0-a09a-493d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2018-06-19T13:12:02.000Z" ,
"modified" : "2018-06-19T13:12:02.000Z" ,
"labels" : [
"misp:type=\"text\"" ,
"misp:category=\"External analysis\"" ,
"osint:source-type=\"blog-post\""
] ,
"x_misp_category" : "External analysis" ,
"x_misp_type" : "text" ,
"x_misp_value" : "Olympic Destroyer, the malware that hit Pyeongchang 2018 Winter Olympics, is still alive and infecting new victims, according to a report published earlier today by Russian antivirus vendor Kaspersky Labs.\r\n\r\nThe company's security researchers say they've detected Olympic Destroyer infections across Europe in May and June 2018.\r\n\r\nNew victims include financial organizations in Russia, and biological and chemical threat prevention laboratories in Europe and Ukraine."
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5b29002d-92b8-468e-900d-4091950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2018-06-19T13:07:57.000Z" ,
"modified" : "2018-06-19T13:07:57.000Z" ,
"description" : "File Type: Microsoft Office Word" ,
"pattern" : "[file:hashes.MD5 = '0e7b32d23fbd6d62a593c234bafa2311' AND file:name = 'Spiez CONVERGENCE.doc' AND file:x_misp_state = 'Malicious']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2018-06-19T13:07:57Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--2cbbe4ff-7a38-45fc-ae72-577c6b2a0edf" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2018-06-22T08:43:10.000Z" ,
"modified" : "2018-06-22T08:43:10.000Z" ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\""
] ,
"x_misp_meta_category" : "file" ,
"x_misp_name" : "file"
} ,
{
"type" : "x-misp-object" ,
"spec_version" : "2.1" ,
"id" : "x-misp-object--dac822e3-0527-46dd-99a9-2a16d8310d75" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2018-06-22T08:43:09.000Z" ,
"modified" : "2018-06-22T08:43:09.000Z" ,
"labels" : [
"misp:name=\"virustotal-report\"" ,
"misp:meta-category=\"misc\""
] ,
"x_misp_meta_category" : "misc" ,
"x_misp_name" : "virustotal-report"
} ,
{
"type" : "relationship" ,
"spec_version" : "2.1" ,
"id" : "relationship--63940611-2ebd-4731-b40c-fc1c878f61f0" ,
"created" : "2018-06-22T08:43:10.000Z" ,
"modified" : "2018-06-22T08:43:10.000Z" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "analysed-with" ,
2023-06-14 17:31:25 +00:00
"source_ref" : "x-misp-object--2cbbe4ff-7a38-45fc-ae72-577c6b2a0edf" ,
"target_ref" : "x-misp-object--dac822e3-0527-46dd-99a9-2a16d8310d75"
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
2023-04-21 13:25:09 +00:00
]
}