misp-circl-feed/feeds/circl/misp/e7ba6328-3c18-4578-a7c2-96a151170246.json

1181 lines
1 MiB
JSON
Raw Normal View History

2023-04-21 13:25:09 +00:00
{
2023-06-14 17:31:25 +00:00
"type": "bundle",
"id": "bundle--e7ba6328-3c18-4578-a7c2-96a151170246",
"objects": [
{
"type": "identity",
"spec_version": "2.1",
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-24T07:46:10.000Z",
"modified": "2022-08-24T07:46:10.000Z",
"name": "CIRCL",
"identity_class": "organization"
},
{
"type": "report",
"spec_version": "2.1",
"id": "report--e7ba6328-3c18-4578-a7c2-96a151170246",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-24T07:46:10.000Z",
"modified": "2022-08-24T07:46:10.000Z",
"name": "OSINT - Reservations Requested: TA558 Targets Hospitality and Travel",
"published": "2022-08-24T07:46:39Z",
"object_refs": [
"indicator--4008c754-2dc9-43e1-9270-91d20eff4eed",
"indicator--b64ed2cf-929c-454b-b78f-4394e6224d02",
"indicator--c1cf733a-b313-4eaf-a6c8-7c6943cb0cb7",
"indicator--5f91f381-5018-4ece-8714-c5262aa45d34",
"indicator--dc1cb63b-e198-4a98-a538-0db4257acfd0",
"indicator--80a5abf2-985c-427f-9303-7a576c98f5b3",
"indicator--b8c2bfbf-d9fe-4b8e-8559-9db5fde85160",
"indicator--621b1550-a05b-46fb-a8ef-24f602d8b2b2",
"indicator--dd383eb5-4b43-4e56-883c-ab6a759b82ab",
"indicator--9120e461-179d-437a-9ad7-c20c3a893619",
"indicator--368fe61d-d39d-4dd9-b1a9-51214d7d68c2",
"indicator--100cdf20-c229-43e1-a55b-5074d5cb90aa",
"indicator--628b8bd9-ea2f-4c0c-810a-35269746dfc9",
"indicator--679581be-827b-4ddd-ba3b-0582bb9fdca1",
"indicator--c92bb92b-136d-42f7-baa9-04730fb29b3e",
"indicator--e229e6bb-fb66-4682-80fe-f6988858c55b",
"indicator--40a458f9-235c-4589-858e-401a7ff8e8f0",
"indicator--3f682801-330f-4561-91e6-406ba24048e0",
"indicator--d956761d-c690-4ba0-985e-f0681df99701",
"indicator--736ae39c-2800-45cd-b998-6b1a15fb5d57",
"indicator--e20ff3b6-870b-43d0-8ba4-42e7f3859178",
"indicator--23fee22b-8f6a-4d73-b101-9097a98c87e0",
"indicator--6342d829-3ce8-48c3-b100-c5600260b82d",
"indicator--129297ea-88a4-47cd-a071-39895efede47",
"indicator--b3ed619c-782e-47ce-8ca1-5dbefad1e733",
"indicator--7a6586bf-59bd-444f-81d8-26229926b154",
"indicator--ce4d7592-d674-4d07-b393-0fa36cedfc3a",
"indicator--60860d22-7a36-48ce-ba4a-613ecb58691a",
"indicator--c2d832d4-fa8e-41f4-8234-4081996997e5",
"indicator--51a5665b-fbef-4e5c-b5e7-6ffde7bf1045",
"indicator--136f1cf5-3bd3-48c9-9b05-7493129f9134",
"indicator--6ba96613-4864-4184-aa28-54f665d2c2c5",
"indicator--20256053-3a6d-401a-802c-540740505140",
"vulnerability--ca630b95-9955-4e4b-b461-cee4a9bd7d9a",
"vulnerability--00d589c3-2ab7-4587-8f08-77dd869ca869",
"x-misp-object--ba5cbf43-23db-4b15-84f9-f6ea0376e95d",
"x-misp-object--de7a3de5-9870-48e3-9d3d-8a02af97a3c8",
"indicator--9c9a982c-a37e-4e24-85f6-0bb85d0365cf",
"indicator--8809def6-57c4-40fb-b31c-db538af6bad6",
"indicator--20c2cfc4-4abe-42e5-ac49-5759447323a8",
"indicator--dfac55b4-672a-45b3-aaa6-0e60dbdbaf96",
"indicator--ccc9024a-2748-4e43-bba0-df53f0332f5e",
"indicator--46cbebab-5fb3-4286-beac-500e45976ff0",
"indicator--3c167f94-5bac-465c-9765-b48cab0fddf5",
"indicator--aba989e1-7952-4225-8f27-be5a626323db",
"relationship--9f081c46-7aa1-4fb3-b073-051c3f79a328",
"relationship--4d1d789c-5145-48a5-80fe-f39eebc517d4",
"relationship--146c7820-bf03-45bb-b5c3-45de23506a57",
"relationship--265d7f80-e3f3-4857-9a2a-66e243922865"
],
"labels": [
"Threat-Report",
"misp:tool=\"MISP-STIX-Converter\"",
"type:OSINT",
"osint:lifetime=\"perpetual\"",
"osint:certainty=\"50\"",
"misp-galaxy:region=\"005 - South America\"",
"misp-galaxy:target-information=\"Mexico\"",
"misp-galaxy:threat-actor=\"TA558\""
],
"object_marking_refs": [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--4008c754-2dc9-43e1-9270-91d20eff4eed",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'warzonecdt.duckdns.org']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--b64ed2cf-929c-454b-b78f-4394e6224d02",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'system11.sslblindado.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c1cf733a-b313-4eaf-a6c8-7c6943cb0cb7",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'successfully.hopto.org']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5f91f381-5018-4ece-8714-c5262aa45d34",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'success20.hopto.org']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--dc1cb63b-e198-4a98-a538-0db4257acfd0",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'quedabesouro.ddns.net']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--80a5abf2-985c-427f-9303-7a576c98f5b3",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'queda212.duckdns.org']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--b8c2bfbf-d9fe-4b8e-8559-9db5fde85160",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'passagensv.sslblindado.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--621b1550-a05b-46fb-a8ef-24f602d8b2b2",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'msin.hopto.org']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--dd383eb5-4b43-4e56-883c-ab6a759b82ab",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'microsofft.sslblindado.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--9120e461-179d-437a-9ad7-c20c3a893619",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'googledrives.ddns.net']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--368fe61d-d39d-4dd9-b1a9-51214d7d68c2",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'firefoxsystem.sytes.net']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--100cdf20-c229-43e1-a55b-5074d5cb90aa",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'cdtpitbull.hopto.org']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--628b8bd9-ea2f-4c0c-810a-35269746dfc9",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = 'cdt2021.zapto.org']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--679581be-827b-4ddd-ba3b-0582bb9fdca1",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = '4success.zapto.org']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c92bb92b-136d-42f7-baa9-04730fb29b3e",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = '3030pp.hopto.org']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e229e6bb-fb66-4682-80fe-f6988858c55b",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[domain-name:value = '111234cdt.ddns.net']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"hostname\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--40a458f9-235c-4589-858e-401a7ff8e8f0",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[email-message:from_ref.value = 'quickbooks@unimed-corporated.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"email-src\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--3f682801-330f-4561-91e6-406ba24048e0",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[email-message:from_ref.value = 'maringa.turismo@system11.com.br']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"email-src\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--d956761d-c690-4ba0-985e-f0681df99701",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[email-message:from_ref.value = 'financeiro@unimed-corporated.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"email-src\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--736ae39c-2800-45cd-b998-6b1a15fb5d57",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[email-message:from_ref.value = 'contato@155hotel.com.br']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"email-src\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e20ff3b6-870b-43d0-8ba4-42e7f3859178",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[url:value = 'http://maringareservas.com.br/seila.rtf']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--23fee22b-8f6a-4d73-b101-9097a98c87e0",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[url:value = 'http://hypemediardf.com.pl/css/css.doc']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--6342d829-3ce8-48c3-b100-c5600260b82d",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[url:value = 'http://corporated.com/tur/turismo.jpg']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--129297ea-88a4-47cd-a071-39895efede47",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[url:value = 'http://corporated.com/microsoft.txt']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--b3ed619c-782e-47ce-8ca1-5dbefad1e733",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[url:value = 'http://cdtmaster.com.br/DadosDaReserva.doc']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--7a6586bf-59bd-444f-81d8-26229926b154",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '38.132.101.45']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ce4d7592-d674-4d07-b393-0fa36cedfc3a",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[file:hashes.SHA256 = 'c2b817b02e56624c8ed7944e76a3896556dc2b7482f747f4be88f95e232f9207']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--60860d22-7a36-48ce-ba4a-613ecb58691a",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[file:hashes.SHA256 = 'b57a9f7321216c3410ebcc9d4b09e73a652dee9e750f96b2f6d7d1e39e2923d6']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c2d832d4-fa8e-41f4-8234-4081996997e5",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[file:hashes.SHA256 = '7dc70d023b2ee5a941edd925999bb6864343b11758c7dc18309416f2947ddb6e']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--51a5665b-fbef-4e5c-b5e7-6ffde7bf1045",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[file:hashes.SHA256 = '796c02729c9cd5d37976ddae205226e6339b64859e9980d56cbfc5f461d00910']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--136f1cf5-3bd3-48c9-9b05-7493129f9134",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[file:hashes.SHA256 = '2f0f99cbac828092c0ec23e12ecb44cbf53f5a671a80842a2447e6114e4f6979']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--6ba96613-4864-4184-aa28-54f665d2c2c5",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[file:hashes.SHA1 = 'c396cfb2744bf92575274b277a6c47fe9566dbff']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--20256053-3a6d-401a-802c-540740505140",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"pattern": "[file:hashes.MD5 = '070950303d80db5d2eb93e21aad77d04']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T07:27:40Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--ca630b95-9955-4e4b-b461-cee4a9bd7d9a",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"name": "CVE-2017-8570",
"labels": [
"misp:type=\"vulnerability\"",
"misp:category=\"External analysis\""
],
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2017-8570"
}
]
},
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--00d589c3-2ab7-4587-8f08-77dd869ca869",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:27:40.000Z",
"modified": "2022-08-19T07:27:40.000Z",
"name": "CVE-2017-11882",
"labels": [
"misp:type=\"vulnerability\"",
"misp:category=\"External analysis\""
],
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2017-11882"
}
]
},
{
"type": "x-misp-object",
"spec_version": "2.1",
"id": "x-misp-object--ba5cbf43-23db-4b15-84f9-f6ea0376e95d",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:08:08.000Z",
"modified": "2022-08-19T07:08:08.000Z",
"labels": [
"misp:name=\"report\"",
"misp:meta-category=\"misc\""
],
"x_misp_attributes": [
{
"type": "link",
"object_relation": "link",
"value": "https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel",
"category": "External analysis",
"uuid": "c0eaa5d0-e310-402e-90fb-61bbee5a0749"
},
{
"type": "text",
"object_relation": "summary",
"value": "Key Findings:\r\n\r\n TA558 is a likely financially motivated small crime threat actor targeting hospitality, hotel, and travel organizations.\r\n Since 2018, this group has used consistent tactics, techniques, and procedures to attempt to install a variety of malware including Loda RAT, Vjw0rm, and Revenge RAT.\r\n TA558\u2019s targeting focus is mainly on Portuguese and Spanish speakers, typically located in the Latin America region, with additional targeting observed in Western Europe and North America.\r\n TA558 increased operational tempo in 2022 to a higher average than previously observed. \r\n Like other threat actors in 2022, TA558 pivoted away from using macro-enabled documents in campaigns and adopted new tactics, techniques, and procedures.",
"category": "Other",
"uuid": "8de3129e-f920-4607-8cd2-0fe04b1a8c3b"
},
{
"type": "text",
"object_relation": "type",
"value": "Blog",
"category": "Other",
"uuid": "4b432ccd-99e2-4bf5-b619-2c4fe09068f7"
}
],
"x_misp_meta_category": "misc",
"x_misp_name": "report"
},
{
"type": "x-misp-object",
"spec_version": "2.1",
"id": "x-misp-object--de7a3de5-9870-48e3-9d3d-8a02af97a3c8",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T07:16:47.000Z",
"modified": "2022-08-19T07:16:47.000Z",
"labels": [
"misp:name=\"report\"",
"misp:meta-category=\"misc\""
],
"x_misp_attributes": [
{
"type": "link",
"object_relation": "link",
"value": "https://otx.alienvault.com/pulse/62fe1e074b82e798cd731a70/",
"category": "External analysis",
"uuid": "7d50063e-e8ec-4fbe-9bb0-625fadb0bb47"
}
],
"x_misp_meta_category": "misc",
"x_misp_name": "report"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--9c9a982c-a37e-4e24-85f6-0bb85d0365cf",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T12:11:49.000Z",
"modified": "2022-08-19T12:11:49.000Z",
"pattern": "[email-message:subject = 'Corrigir data da reserva para o dia 03' AND email-message:body_multipart[0].body_raw_ref.name = 'Booking - Dados da Reserva.docx' AND email-message:body_multipart[0].content_disposition = 'attachment' AND email-message:body_multipart[1].body_raw_ref.payload_bin = 'iVBORw0KGgoAAAANSUhEUgAAAtQAAAKSCAYAAADyLEyBAAAYb2lDQ1BJQ0MgUHJvZmlsZQAAWIWVWQc8le3fv+6zz7HPsffeZO+9994kHOtYccxQIskqUSFKJZmVSqESkYZSRg9JEsmoFCoqI+9t1P95n+f9vO/nvT6f676+53f9rt+61v07NwBcnb6RkWEIRgDCI2KoDqYG/G7uHvzYKYAFPAAP2ICSLzk6Ut/OzgrA5Xf738vSIIA22ucyG7L+3f+/FqJ/QDQZAMgLxn7+0eRwGN8FAJVGjqTGAIAxgulC8TGRGzgYxsxU2EAYJ2/goC18dAP7beGKTR4nB0MYNwOAo/X1pQYBQN8J0/njyEGwHPp3cB8xwp8SAbP+gLEOOdjXHwAuNZhHOjx89waGKxCH+SNhnAtjNb+/yQz6b/L9/sj39Q36g7f82iw4I0p0ZJjvnv9naP7vEh4W+1uHKFxpg6lmDhv+wzEcCt1tuYFpYTwb4WdjuxFrGP+g+G/FHQAEITjWzHmLH8FNjjaE4wdYYSzn72tkCWNuGJtEhNlYbdP9Aikm5jCGVwsigRJj7rQ9NjMg2thxW+Yp6m4H2984kGqovz32si91U+8Gf2dsqLP+tvyh4ADz3/K/JQY7ucKYAACSEEdxsYExPYyZo0MdLbd4kIKJwYY2v3mosQ4b9gvDWC0gwtRgSz7SK5Bq4rDNHxke/dtfZEYwxdxmGxfHBDuZbcUHWUv23bSfHcaNARH6zr/lBES7Wf32xT/AyHjLd+SzgAjnbX+Ro5ExBg7bY+cjw+y2+VG4gDDTDbogjDmj4xy3x6K0YuDFuSUfZRUZY+e0ZSfKJ8TXwm7LHlQcsAKGwAjwg1i4+oHdIARQns02zcK/tnpMgC+ggiAQAGS2Kb9HuG72RMBPR5AIPsEoAET/GWew2RsA4mD62h/q1lMGBG72xm2OCAVTMA4HliAM/h27OSrijzYX8A6mUP6lnQzbGgbXjb5/0/RhitU2Jfa3XH6G35wYY4wRxgxjgpFAcaJ0UJooK/ipB1cFlBpK/be1/+FHT6H70G/RA+gx9MtdlDTqP2yxBmOwfJNtj/3+7jFKFJapjDJAacPSYckoVhQnkEEpwXr0UbqwZmWYarht94bv/P+Dn388+FvMt/nwcngEng2vhxf/50h6SXrlP1I2Ivr3+GzZ6vcnqoZ/ev6p3/BvcfaHW8t/ciIzkQ3Ih8h2ZBeyBdkE+JFtyGZkN/LOBv6zht5trqHf2hw27QmF5VD+pc93W+dGJKPl6uTey61u94GYgISYjQ1muDtyD5USFBzDrw/fAgH85hFkWWl+BTkFBQA27pStY+qrw+ZdAbH2/IdGPgiA6jwA+OX/0MK/AnAF3uP81v+hiXjD2wwDQPUUOZYat0VDbTzQ8GnAAO8oDsALhIA47JECUAGaQA8YAwtgC5yAO/CG4xwMr2cqiAfJIBVkgBxwFJwAJeAMOA+qwSVwDTSBFtAOHoAnoBcMgFfw+pkEH8E8WAIrEARhITqIBHFAfJAIJAUpQGqQDmQMWUEOkDvkAwVBEVAslAwdgHKgAqgEOgfVQFehm1A71AX1QS+hceg99AVaRiARtAhmBA9CFLEDoYbQR1ginBA7EUGIKEQiIh1xBFGMKEdcRDQi2hFPEAOIMcRHxCISIGmQrEgBpAxSDWmItEV6IAORVOQ+ZDayEFmOvIy8Bc/0c+QYchb5E4VBkVD8KBl4DZuhnFFkVBRqHyoXVYKqRjWiOlHPUeOoedQvNB2aGy2F1kCbo93QQeh4dAa6EF2JvoG+D++mSfQSBoNhxYhhVOHd6I4JwSRhcjGnMfWYu5g+zARmEYvFcmClsNpYW6wvNgabgT2JvYhtw/ZjJ7E/cDQ4PpwCzgTngYvApeEKcbW4Vlw/bhq3gmfEi+A18LZ4f/wefB6+An8L34OfxK8QmAhiBG2CEyGEkEooJlwm3CeMEL7S0NAI0qjT2NNQaPbTFNNcoXlEM07zk5ZIK0lrSOtFG0t7hLaK9i7tS9qvdHR0onR6dB50MXRH6Gro7tGN0v2gJ9HL0pvT+9On0JfSN9L3039mwDOIMOgzeDMkMhQyNDD0MMwy4hlFGQ0ZfRn3MZYy3mR8wbjIRGKSZ7JlCmfKZapl6mKaIWKJokRjoj8xnXieeI84QUKShEiGJDLpAKmCdJ80yYxhFmM2Zw5hzmG+xPyMeZ6FyKLE4sKSwFLKcodljBXJKspqzhrGmsd6jXWQdZmNh02fLYAti+0yWz/bd3Yudj32APZs9nr2AfZlDn4OY45QjnyOJo7XnChOSU57znjOMs77nLNczFyaXGSubK5rXMPcCG5JbgfuJO7z3N3cizy8PKY8kTwnee7xzPKy8urxhvAe523lfc9H4tPho/Ad52vj+8DPwq/PH8ZfzN/JPy/ALWAmECtwTuCZwIqgmKCzYJpgveBrIYKQmlCg0HGhDqF5YT5ha+Fk4TrhYRG8iJpIsEiRyEOR76Jioq6ih0SbRGfE2MXMxRLF6sRGxOnEdcWjxMvF/5LASKhJhEqcluiVREgqSwZLlkr2SCGkVKQoUqel+qTR0urSEdLl0i9kaGX0ZeJk6mTGZVllrWTTZJtkP+8Q3uGxI3/Hwx2/5JTlwuQq5F7JE+Ut5NPkb8l/UZBUICuUKvylSKdoopii2Ky4oCSlFKBUpjSkTFK2Vj6k3KG8pqKqQlW5rPJeVVjVR/WU6gs1ZjU7tVy1R+podQP1FPUW9Z8aKhoxGtc05jRlNEM1azVntMS0ArQqtCa0BbV9tc9pj+nw6/jonNUZ0xXQ9dUt132rJ6Tnr1epN60voR+if1H/s4GcAdXghsF3Qw3DvYZ3jZBGpkbZRs+MicbOxiXGoyaCJkEmdSbzpsqmSaZ3zdBmlmb5Zi/MeczJ5jXm8xaqFnstOi1pLR0tSyzfWklaUa1uWSOsLayPWY/YiNhE2DTZAltz22O2r+3E7KLsbttj7O3sS+2nHOQdkh0eOpIcdznWOi45GTjlOb1yFneOde5wYXDxcqlx+e5q5FrgOua2w22v2xN3TneKe7MH1sPFo9Jj0dPY84TnpJeyV4bX4E6xnQk7u7w5vcO87+xi2OW7q8EH7ePqU+uz6mvrW+676Gfud8pvnmxILiJ/9NfzP+7/PkA7oCBgOlA7sCBwJkg76FjQ+2Dd4MLgWYohpYSyEGIWcibke6htaFXoephrWH04Ltwn/GYEMSI0onM37+6E3X2RUpEZkWNRGlEnouapltTKaCh6Z3RzDDP88t4dKx57MHY8TieuNO5HvEt8QwJTQkRC9x7JPVl7phNNEi8koZLISR3JAsmpyeN79fee2wft89vXkSKUkp4yud90f3UqITU09WmaXFpB2rcDrgdupfOk70+fOGh6sC6DPoOa8eKQ5qEzmahMSuazLMWsk1m/sv2zH+fI5RTmrOaScx8flj9cfHj9SOCRZ3kqeWVHMUcjjg7m6+ZXFzAVJBZMHLM+1nic/3j28W8ndp3oKlQqPFNEKIotGiu2Km4+KXzy6MnVkuCSgVKD0vpT3KeyTn0/7X+6v0yv7PIZnjM5Z5bPUs4OnTM911guWl54HnM+7vxUhUvFwwtqF2oqOStzKteqIqrGqh2qO2tUa2pquWvz6hB1sXXvL3pd7L1kdKn5sszlc/Ws9TlXwJXYKx+u+lwdvGZ5raNBreHydZHrp26QbmQ3Qo17GuebgpvGmt2b+25a3Oy4pXnrxm3Z21UtAi2ld1ju5LUSWtNb19sS2xbvRt6dbQ9q
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T12:11:49Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "network"
}
],
"labels": [
"misp:name=\"email\"",
"misp:meta-category=\"network\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--8809def6-57c4-40fb-b31c-db538af6bad6",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-19T12:15:35.000Z",
"modified": "2022-08-19T12:15:35.000Z",
"pattern": "[file:hashes.SHA256 = '796c02729c9cd5d37976ddae205226e6339b64859e9980d56cbfc5f461d00910' AND file:name = 'Booking - Dados da Reserva.docx' AND file:x_misp_text = 'Author\u201d: C.D.T Original']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-19T12:15:35Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "file"
}
],
"labels": [
"misp:name=\"file\"",
"misp:meta-category=\"file\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--20c2cfc4-4abe-42e5-ac49-5759447323a8",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-22T12:27:47.000Z",
"modified": "2022-08-22T12:27:47.000Z",
"pattern": "[file:hashes.SHA256 = '7dc70d023b2ee5a941edd925999bb6864343b11758c7dc18309416f2947ddb6e' AND file:name = 'RESERVA.docx' AND file:x_misp_text = 'Attachment \u201cAuthor\u201d: msword\r\n\r\nAttachment \u201cLast Saved By\u201d: Richard']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-22T12:27:47Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "file"
}
],
"labels": [
"misp:name=\"file\"",
"misp:meta-category=\"file\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--dfac55b4-672a-45b3-aaa6-0e60dbdbaf96",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-22T12:16:11.000Z",
"modified": "2022-08-22T12:16:11.000Z",
"pattern": "[email-message:subject = 'RESERVA' AND email-message:body_multipart[0].body_raw_ref.name = 'RESERVA.docx' AND email-message:body_multipart[0].content_disposition = 'attachment' AND email-message:body_multipart[1].body_raw_ref.payload_bin = 'iVBORw0KGgoAAAANSUhEUgAAA58AAAHvCAYAAADTrGuUAAAYb2lDQ1BJQ0MgUHJvZmlsZQAAWIWVWQc8le3fv+6zz7HPsffeZO+9994kHOtYccxQIskqUSFKJZmVSqESkYZSRg9JEsmoFCoqI+9t1P95n+f9vO/nvT6f676+53f9rt+61v07NwBcnb6RkWEIRgDCI2KoDqYG/G7uHvzYKYAFPAAP2ICSLzk6Ut/OzgrA5Xf738vSIIA22ucyG7L+3f+/FqJ/QDQZAMgLxn7+0eRwGN8FAJVGjqTGAIAxgulC8TGRGzgYxsxU2EAYJ2/goC18dAP7beGKTR4nB0MYNwOAo/X1pQYBQN8J0/njyEGwHPp3cB8xwp8SAbP+gLEOOdjXHwAuNZhHOjx89waGKxCH+SNhnAtjNb+/yQz6b/L9/sj39Q36g7f82iw4I0p0ZJjvnv9naP7vEh4W+1uHKFxpg6lmDhv+wzEcCt1tuYFpYTwb4WdjuxFrGP+g+G/FHQAEITjWzHmLH8FNjjaE4wdYYSzn72tkCWNuGJtEhNlYbdP9Aikm5jCGVwsigRJj7rQ9NjMg2thxW+Yp6m4H2984kGqovz32si91U+8Gf2dsqLP+tvyh4ADz3/K/JQY7ucKYAACSEEdxsYExPYyZo0MdLbd4kIKJwYY2v3mosQ4b9gvDWC0gwtRgSz7SK5Bq4rDNHxke/dtfZEYwxdxmGxfHBDuZbcUHWUv23bSfHcaNARH6zr/lBES7Wf32xT/AyHjLd+SzgAjnbX+Ro5ExBg7bY+cjw+y2+VG4gDDTDbogjDmj4xy3x6K0YuDFuSUfZRUZY+e0ZSfKJ8TXwm7LHlQcsAKGwAjwg1i4+oHdIARQns02zcK/tnpMgC+ggiAQAGS2Kb9HuG72RMBPR5AIPsEoAET/GWew2RsA4mD62h/q1lMGBG72xm2OCAVTMA4HliAM/h27OSrijzYX8A6mUP6lnQzbGgbXjb5/0/RhitU2Jfa3XH6G35wYY4wRxgxjgpFAcaJ0UJooK/ipB1cFlBpK/be1/+FHT6H70G/RA+gx9MtdlDTqP2yxBmOwfJNtj/3+7jFKFJapjDJAacPSYckoVhQnkEEpwXr0UbqwZmWYarht94bv/P+Dn388+FvMt/nwcngEng2vhxf/50h6SXrlP1I2Ivr3+GzZ6vcnqoZ/ev6p3/BvcfaHW8t/ciIzkQ3Ih8h2ZBeyBdkE+JFtyGZkN/LOBv6zht5trqHf2hw27QmF5VD+pc93W+dGJKPl6uTey61u94GYgISYjQ1muDtyD5USFBzDrw/fAgH85hFkWWl+BTkFBQA27pStY+qrw+ZdAbH2/IdGPgiA6jwA+OX/0MK/AnAF3uP81v+hiXjD2wwDQPUUOZYat0VDbTzQ8GnAAO8oDsALhIA47JECUAGaQA8YAwtgC5yAO/CG4xwMr2cqiAfJIBVkgBxwFJwAJeAMOA+qwSVwDTSBFtAOHoAnoBcMgFfw+pkEH8E8WAIrEARhITqIBHFAfJAIJAUpQGqQDmQMWUEOkDvkAwVBEVAslAwdgHKgAqgEOgfVQFehm1A71AX1QS+hceg99AVaRiARtAhmBA9CFLEDoYbQR1ginBA7EUGIKEQiIh1xBFGMKEdcRDQi2hFPEAOIMcRHxCISIGmQrEgBpAxSDWmItEV6IAORVOQ+ZDayEFmOvIy8Bc/0c+QYchb5E4VBkVD8KBl4DZuhnFFkVBRqHyoXVYKqRjWiOlHPUeOoedQvNB2aGy2F1kCbo93QQeh4dAa6EF2JvoG+D++mSfQSBoNhxYhhVOHd6I4JwSRhcjGnMfWYu5g+zARmEYvFcmClsNpYW6wvNgabgT2JvYhtw/ZjJ7E/cDQ4PpwCzgTngYvApeEKcbW4Vlw/bhq3gmfEi+A18LZ4f/wefB6+An8L34OfxK8QmAhiBG2CEyGEkEooJlwm3CeMEL7S0NAI0qjT2NNQaPbTFNNcoXlEM07zk5ZIK0lrSOtFG0t7hLaK9i7tS9qvdHR0onR6dB50MXRH6Gro7tGN0v2gJ9HL0pvT+9On0JfSN9L3039mwDOIMOgzeDMkMhQyNDD0MMwy4hlFGQ0ZfRn3MZYy3mR8wbjIRGKSZ7JlCmfKZapl6mKaIWKJokRjoj8xnXieeI84QUKShEiGJDLpAKmCdJ80yYxhFmM2Zw5hzmG+xPyMeZ6FyKLE4sKSwFLKcodljBXJKspqzhrGmsd6jXWQdZmNh02fLYAti+0yWz/bd3Yudj32APZs9nr2AfZlDn4OY45QjnyOJo7XnChOSU57znjOMs77nLNczFyaXGSubK5rXMPcCG5JbgfuJO7z3N3cizy8PKY8kTwnee7xzPKy8urxhvAe523lfc9H4tPho/Ad52vj+8DPwq/PH8ZfzN/JPy/ALWAmECtwTuCZwIqgmKCzYJpgveBrIYKQmlCg0HGhDqF5YT5ha+Fk4TrhYRG8iJpIsEiRyEOR76Jioq6ih0SbRGfE2MXMxRLF6sRGxOnEdcWjxMvF/5LASKhJhEqcluiVREgqSwZLlkr2SCGkVKQoUqel+qTR0urSEdLl0i9kaGX0ZeJk6mTGZVllrWTTZJtkP+8Q3uGxI3/Hwx2/5JTlwuQq5F7JE+Ut5NPkb8l/UZBUICuUKvylSKdoopii2Ky4oCSlFKBUpjSkTFK2Vj6k3KG8pqKqQlW5rPJeVVjVR/WU6gs1ZjU7tVy1R+podQP1FPUW9Z8aKhoxGtc05jRlNEM1azVntMS0ArQqtCa0BbV9tc9pj+nw6/jonNUZ0xXQ9dUt132rJ6Tnr1epN60voR+if1H/s4GcAdXghsF3Qw3DvYZ3jZBGpkbZRs+MicbOxiXGoyaCJkEmdSbzpsqmSaZ3zdBmlmb5Zi/MeczJ5jXm8xaqFnstOi1pLR0tSyzfWklaUa1uWSOsLayPWY/YiNhE2DTZAltz22O2r+3E7KLsbttj7O3sS+2nHOQdkh0eOpIcdznWOi45GTjlOb1yFneOde5wYXDxcqlx+e5q5FrgOua2w22v2xN3TneKe7MH1sPFo9Jj0dPY84TnpJeyV4bX4E6xnQk7u7w5vcO87+xi2OW7q8EH7ePqU+uz6mvrW+676Gfud8pvnmxILiJ/9NfzP+7/PkA7oCBgOlA7sCBwJkg76FjQ+2Dd4MLgWYohpYSyEGIWcibke6htaFXoephrWH04Ltwn/GYEMSI0onM37+6E3X2RUpEZkWNRGlEnouapltTKaCh6Z3RzDDP88t4dKx57MHY8TieuNO5HvEt8QwJTQkRC9x7JPVl7phNNEi8koZLISR3JAsmpyeN79fee2wft89vXkSKUkp4yud90f3UqITU09WmaXFpB2rcDrgdupfOk70+fOGh6sC6DPoOa8eKQ5qEzmahMSuazLMWsk1m/sv2zH+fI5RTmrOaScx8flj9cfHj9SOCRZ3kqeWVHMUcjjg7m6+ZXFzAVJBZMHLM+1nic/3j28W8ndp3oKlQqPFNEKIotGiu2Km4+KXzy6MnVkuCSgVKD0vpT3KeyTn0/7X+6v0yv7PIZnjM5Z5bPUs4OnTM911guWl54HnM+7vxUhUvFwwtqF2oqOStzKteqIqrGqh2qO2tUa2pquWvz6hB1sXXvL3pd7L1kdKn5sszlc/Ws9TlXwJXYKx+u+lwdvGZ5raNBreHydZHrp26QbmQ3Qo17GuebgpvGmt2b+25a3Oy4pXnrxm3Z21UtAi2ld1ju5LUSWtNb19sS2xbvRt6dbQ9qn+jY1fHqntu9vzrtO5/dt7z/6IHJg3sP9R+2PdJ+1NKl0XXzsd
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-22T12:16:11Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "network"
}
],
"labels": [
"misp:name=\"email\"",
"misp:meta-category=\"network\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ccc9024a-2748-4e43-bba0-df53f0332f5e",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-22T13:17:53.000Z",
"modified": "2022-08-22T13:17:53.000Z",
"pattern": "[file:hashes.SHA256 = 'c2b817b02e56624c8ed7944e76a3896556dc2b7482f747f4be88f95e232f9207' AND file:name = 'reserva.ppa']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-22T13:17:53Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "file"
}
],
"labels": [
"misp:name=\"file\"",
"misp:meta-category=\"file\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--46cbebab-5fb3-4286-beac-500e45976ff0",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-22T13:12:39.000Z",
"modified": "2022-08-22T13:12:39.000Z",
"pattern": "[email-message:from_ref.value = 'fernando1540@bol[.]com[.]br' AND email-message:from_ref.display_name = 'Oab Brasil' AND email-message:subject = 'Or\u00e7amento Conferencistas - 515449939' AND email-message:body_multipart[0].body_raw_ref.name = 'reserva.ppa' AND email-message:body_multipart[0].content_disposition = 'attachment' AND email-message:body_multipart[1].body_raw_ref.payload_bin = 'iVBORw0KGgoAAAANSUhEUgAAA7UAAAIdCAYAAADiYVoCAAAYb2lDQ1BJQ0MgUHJvZmlsZQAAWIWVWQc8le3fv+6zz7HPsffeZO+9994kHOtYccxQIskqUSFKJZmVSqESkYZSRg9JEsmoFCoqI+9t1P95n+f9vO/nvT6f676+53f9rt+61v07NwBcnb6RkWEIRgDCI2KoDqYG/G7uHvzYKYAFPAAP2ICSLzk6Ut/OzgrA5Xf738vSIIA22ucyG7L+3f+/FqJ/QDQZAMgLxn7+0eRwGN8FAJVGjqTGAIAxgulC8TGRGzgYxsxU2EAYJ2/goC18dAP7beGKTR4nB0MYNwOAo/X1pQYBQN8J0/njyEGwHPp3cB8xwp8SAbP+gLEOOdjXHwAuNZhHOjx89waGKxCH+SNhnAtjNb+/yQz6b/L9/sj39Q36g7f82iw4I0p0ZJjvnv9naP7vEh4W+1uHKFxpg6lmDhv+wzEcCt1tuYFpYTwb4WdjuxFrGP+g+G/FHQAEITjWzHmLH8FNjjaE4wdYYSzn72tkCWNuGJtEhNlYbdP9Aikm5jCGVwsigRJj7rQ9NjMg2thxW+Yp6m4H2984kGqovz32si91U+8Gf2dsqLP+tvyh4ADz3/K/JQY7ucKYAACSEEdxsYExPYyZo0MdLbd4kIKJwYY2v3mosQ4b9gvDWC0gwtRgSz7SK5Bq4rDNHxke/dtfZEYwxdxmGxfHBDuZbcUHWUv23bSfHcaNARH6zr/lBES7Wf32xT/AyHjLd+SzgAjnbX+Ro5ExBg7bY+cjw+y2+VG4gDDTDbogjDmj4xy3x6K0YuDFuSUfZRUZY+e0ZSfKJ8TXwm7LHlQcsAKGwAjwg1i4+oHdIARQns02zcK/tnpMgC+ggiAQAGS2Kb9HuG72RMBPR5AIPsEoAET/GWew2RsA4mD62h/q1lMGBG72xm2OCAVTMA4HliAM/h27OSrijzYX8A6mUP6lnQzbGgbXjb5/0/RhitU2Jfa3XH6G35wYY4wRxgxjgpFAcaJ0UJooK/ipB1cFlBpK/be1/+FHT6H70G/RA+gx9MtdlDTqP2yxBmOwfJNtj/3+7jFKFJapjDJAacPSYckoVhQnkEEpwXr0UbqwZmWYarht94bv/P+Dn388+FvMt/nwcngEng2vhxf/50h6SXrlP1I2Ivr3+GzZ6vcnqoZ/ev6p3/BvcfaHW8t/ciIzkQ3Ih8h2ZBeyBdkE+JFtyGZkN/LOBv6zht5trqHf2hw27QmF5VD+pc93W+dGJKPl6uTey61u94GYgISYjQ1muDtyD5USFBzDrw/fAgH85hFkWWl+BTkFBQA27pStY+qrw+ZdAbH2/IdGPgiA6jwA+OX/0MK/AnAF3uP81v+hiXjD2wwDQPUUOZYat0VDbTzQ8GnAAO8oDsALhIA47JECUAGaQA8YAwtgC5yAO/CG4xwMr2cqiAfJIBVkgBxwFJwAJeAMOA+qwSVwDTSBFtAOHoAnoBcMgFfw+pkEH8E8WAIrEARhITqIBHFAfJAIJAUpQGqQDmQMWUEOkDvkAwVBEVAslAwdgHKgAqgEOgfVQFehm1A71AX1QS+hceg99AVaRiARtAhmBA9CFLEDoYbQR1ginBA7EUGIKEQiIh1xBFGMKEdcRDQi2hFPEAOIMcRHxCISIGmQrEgBpAxSDWmItEV6IAORVOQ+ZDayEFmOvIy8Bc/0c+QYchb5E4VBkVD8KBl4DZuhnFFkVBRqHyoXVYKqRjWiOlHPUeOoedQvNB2aGy2F1kCbo93QQeh4dAa6EF2JvoG+D++mSfQSBoNhxYhhVOHd6I4JwSRhcjGnMfWYu5g+zARmEYvFcmClsNpYW6wvNgabgT2JvYhtw/ZjJ7E/cDQ4PpwCzgTngYvApeEKcbW4Vlw/bhq3gmfEi+A18LZ4f/wefB6+An8L34OfxK8QmAhiBG2CEyGEkEooJlwm3CeMEL7S0NAI0qjT2NNQaPbTFNNcoXlEM07zk5ZIK0lrSOtFG0t7hLaK9i7tS9qvdHR0onR6dB50MXRH6Gro7tGN0v2gJ9HL0pvT+9On0JfSN9L3039mwDOIMOgzeDMkMhQyNDD0MMwy4hlFGQ0ZfRn3MZYy3mR8wbjIRGKSZ7JlCmfKZapl6mKaIWKJokRjoj8xnXieeI84QUKShEiGJDLpAKmCdJ80yYxhFmM2Zw5hzmG+xPyMeZ6FyKLE4sKSwFLKcodljBXJKspqzhrGmsd6jXWQdZmNh02fLYAti+0yWz/bd3Yudj32APZs9nr2AfZlDn4OY45QjnyOJo7XnChOSU57znjOMs77nLNczFyaXGSubK5rXMPcCG5JbgfuJO7z3N3cizy8PKY8kTwnee7xzPKy8urxhvAe523lfc9H4tPho/Ad52vj+8DPwq/PH8ZfzN/JPy/ALWAmECtwTuCZwIqgmKCzYJpgveBrIYKQmlCg0HGhDqF5YT5ha+Fk4TrhYRG8iJpIsEiRyEOR76Jioq6ih0SbRGfE2MXMxRLF6sRGxOnEdcWjxMvF/5LASKhJhEqcluiVREgqSwZLlkr2SCGkVKQoUqel+qTR0urSEdLl0i9kaGX0ZeJk6mTGZVllrWTTZJtkP+8Q3uGxI3/Hwx2/5JTlwuQq5F7JE+Ut5NPkb8l/UZBUICuUKvylSKdoopii2Ky4oCSlFKBUpjSkTFK2Vj6k3KG8pqKqQlW5rPJeVVjVR/WU6gs1ZjU7tVy1R+podQP1FPUW9Z8aKhoxGtc05jRlNEM1azVntMS0ArQqtCa0BbV9tc9pj+nw6/jonNUZ0xXQ9dUt132rJ6Tnr1epN60voR+if1H/s4GcAdXghsF3Qw3DvYZ3jZBGpkbZRs+MicbOxiXGoyaCJkEmdSbzpsqmSaZ3zdBmlmb5Zi/MeczJ5jXm8xaqFnstOi1pLR0tSyzfWklaUa1uWSOsLayPWY/YiNhE2DTZAltz22O2r+3E7KLsbttj7O3sS+2nHOQdkh0eOpIcdznWOi45GTjlOb1yFneOde5wYXDxcqlx+e5q5FrgOua2w22v2xN3TneKe7MH1sPFo9Jj0dPY84TnpJeyV4bX4E6xnQk7u7w5vcO87+xi2OW7q8EH7ePqU+uz6mvrW+676Gfud8pvnmxILiJ/9NfzP+7/PkA7oCBgOlA7sCBwJkg76FjQ+2Dd4MLgWYohpYSyEGIWcibke6htaFXoephrWH04Ltwn/GYEMSI0onM37+6E3X2RUpEZkWNRGlEnouapltTKaCh6Z3RzDDP88t4dKx57MHY8TieuNO5HvEt8QwJTQkRC9x7JPVl7phNNEi8koZLISR3JAsmpyeN79fee2wft89vXkSKUkp4yud90f3UqITU09WmaXFpB2rcDrgdupfOk70+fOGh6sC6DPoOa8eKQ5qEzmahMSuazLMWsk1m/sv2zH+fI5RTmrOaScx8flj9cfHj9SOCRZ3kqeWVHMUcjjg7m6+ZXFzAVJBZMHLM+1nic/3j28W8ndp3oKlQqPFNEKIotGiu2Km4+KXzy6MnVkuCSgVKD0vpT3KeyTn0/7X+6v0yv7PIZnjM5Z5bPUs4OnTM911guWl54HnM+7vxUhUvFwwtqF2oqOStzKteqIqrGqh2qO2tUa2pquWvz6hB1sXXvL3pd7L1kdKn5sszlc/Ws9TlXw
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-22T13:12:39Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "network"
}
],
"labels": [
"misp:name=\"email\"",
"misp:meta-category=\"network\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--3c167f94-5bac-465c-9765-b48cab0fddf5",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-22T14:00:48.000Z",
"modified": "2022-08-22T14:00:48.000Z",
"pattern": "[email-message:from_ref.value = 'financeiro@unimed-corporated[.]com' AND email-message:from_ref.display_name = 'Financeiro UNIMED' AND email-message:additional_header_fields.reply_to = 'cdt[name]cdt@gmail[.]com' AND email-message:subject = 'Reserva' AND email-message:body_multipart[0].body_raw_ref.name = 'OficioCircularencaminhadoaoSetorFinanceiroUNIMED.docx' AND email-message:body_multipart[0].content_disposition = 'attachment' AND email-message:body_multipart[1].body_raw_ref.payload_bin = 'iVBORw0KGgoAAAANSUhEUgAABCIAAAJFCAYAAAAI8FaLAAAYb2lDQ1BJQ0MgUHJvZmlsZQAAWIWVWQc8le3fv+6zz7HPsffeZO+9994kHOtYccxQIskqUSFKJZmVSqESkYZSRg9JEsmoFCoqI+9t1P95n+f9vO/nvT6f676+53f9rt+61v07NwBcnb6RkWEIRgDCI2KoDqYG/G7uHvzYKYAFPAAP2ICSLzk6Ut/OzgrA5Xf738vSIIA22ucyG7L+3f+/FqJ/QDQZAMgLxn7+0eRwGN8FAJVGjqTGAIAxgulC8TGRGzgYxsxU2EAYJ2/goC18dAP7beGKTR4nB0MYNwOAo/X1pQYBQN8J0/njyEGwHPp3cB8xwp8SAbP+gLEOOdjXHwAuNZhHOjx89waGKxCH+SNhnAtjNb+/yQz6b/L9/sj39Q36g7f82iw4I0p0ZJjvnv9naP7vEh4W+1uHKFxpg6lmDhv+wzEcCt1tuYFpYTwb4WdjuxFrGP+g+G/FHQAEITjWzHmLH8FNjjaE4wdYYSzn72tkCWNuGJtEhNlYbdP9Aikm5jCGVwsigRJj7rQ9NjMg2thxW+Yp6m4H2984kGqovz32si91U+8Gf2dsqLP+tvyh4ADz3/K/JQY7ucKYAACSEEdxsYExPYyZo0MdLbd4kIKJwYY2v3mosQ4b9gvDWC0gwtRgSz7SK5Bq4rDNHxke/dtfZEYwxdxmGxfHBDuZbcUHWUv23bSfHcaNARH6zr/lBES7Wf32xT/AyHjLd+SzgAjnbX+Ro5ExBg7bY+cjw+y2+VG4gDDTDbogjDmj4xy3x6K0YuDFuSUfZRUZY+e0ZSfKJ8TXwm7LHlQcsAKGwAjwg1i4+oHdIARQns02zcK/tnpMgC+ggiAQAGS2Kb9HuG72RMBPR5AIPsEoAET/GWew2RsA4mD62h/q1lMGBG72xm2OCAVTMA4HliAM/h27OSrijzYX8A6mUP6lnQzbGgbXjb5/0/RhitU2Jfa3XH6G35wYY4wRxgxjgpFAcaJ0UJooK/ipB1cFlBpK/be1/+FHT6H70G/RA+gx9MtdlDTqP2yxBmOwfJNtj/3+7jFKFJapjDJAacPSYckoVhQnkEEpwXr0UbqwZmWYarht94bv/P+Dn388+FvMt/nwcngEng2vhxf/50h6SXrlP1I2Ivr3+GzZ6vcnqoZ/ev6p3/BvcfaHW8t/ciIzkQ3Ih8h2ZBeyBdkE+JFtyGZkN/LOBv6zht5trqHf2hw27QmF5VD+pc93W+dGJKPl6uTey61u94GYgISYjQ1muDtyD5USFBzDrw/fAgH85hFkWWl+BTkFBQA27pStY+qrw+ZdAbH2/IdGPgiA6jwA+OX/0MK/AnAF3uP81v+hiXjD2wwDQPUUOZYat0VDbTzQ8GnAAO8oDsALhIA47JECUAGaQA8YAwtgC5yAO/CG4xwMr2cqiAfJIBVkgBxwFJwAJeAMOA+qwSVwDTSBFtAOHoAnoBcMgFfw+pkEH8E8WAIrEARhITqIBHFAfJAIJAUpQGqQDmQMWUEOkDvkAwVBEVAslAwdgHKgAqgEOgfVQFehm1A71AX1QS+hceg99AVaRiARtAhmBA9CFLEDoYbQR1ginBA7EUGIKEQiIh1xBFGMKEdcRDQi2hFPEAOIMcRHxCISIGmQrEgBpAxSDWmItEV6IAORVOQ+ZDayEFmOvIy8Bc/0c+QYchb5E4VBkVD8KBl4DZuhnFFkVBRqHyoXVYKqRjWiOlHPUeOoedQvNB2aGy2F1kCbo93QQeh4dAa6EF2JvoG+D++mSfQSBoNhxYhhVOHd6I4JwSRhcjGnMfWYu5g+zARmEYvFcmClsNpYW6wvNgabgT2JvYhtw/ZjJ7E/cDQ4PpwCzgTngYvApeEKcbW4Vlw/bhq3gmfEi+A18LZ4f/wefB6+An8L34OfxK8QmAhiBG2CEyGEkEooJlwm3CeMEL7S0NAI0qjT2NNQaPbTFNNcoXlEM07zk5ZIK0lrSOtFG0t7hLaK9i7tS9qvdHR0onR6dB50MXRH6Gro7tGN0v2gJ9HL0pvT+9On0JfSN9L3039mwDOIMOgzeDMkMhQyNDD0MMwy4hlFGQ0ZfRn3MZYy3mR8wbjIRGKSZ7JlCmfKZapl6mKaIWKJokRjoj8xnXieeI84QUKShEiGJDLpAKmCdJ80yYxhFmM2Zw5hzmG+xPyMeZ6FyKLE4sKSwFLKcodljBXJKspqzhrGmsd6jXWQdZmNh02fLYAti+0yWz/bd3Yudj32APZs9nr2AfZlDn4OY45QjnyOJo7XnChOSU57znjOMs77nLNczFyaXGSubK5rXMPcCG5JbgfuJO7z3N3cizy8PKY8kTwnee7xzPKy8urxhvAe523lfc9H4tPho/Ad52vj+8DPwq/PH8ZfzN/JPy/ALWAmECtwTuCZwIqgmKCzYJpgveBrIYKQmlCg0HGhDqF5YT5ha+Fk4TrhYRG8iJpIsEiRyEOR76Jioq6ih0SbRGfE2MXMxRLF6sRGxOnEdcWjxMvF/5LASKhJhEqcluiVREgqSwZLlkr2SCGkVKQoUqel+qTR0urSEdLl0i9kaGX0ZeJk6mTGZVllrWTTZJtkP+8Q3uGxI3/Hwx2/5JTlwuQq5F7JE+Ut5NPkb8l/UZBUICuUKvylSKdoopii2Ky4oCSlFKBUpjSkTFK2Vj6k3KG8pqKqQlW5rPJeVVjVR/WU6gs1ZjU7tVy1R+podQP1FPUW9Z8aKhoxGtc05jRlNEM1azVntMS0ArQqtCa0BbV9tc9pj+nw6/jonNUZ0xXQ9dUt132rJ6Tnr1epN60voR+if1H/s4GcAdXghsF3Qw3DvYZ3jZBGpkbZRs+MicbOxiXGoyaCJkEmdSbzpsqmSaZ3zdBmlmb5Zi/MeczJ5jXm8xaqFnstOi1pLR0tSyzfWklaUa1uWSOsLayPWY/YiNhE2DTZAltz22O2r+3E7KLsbttj7O3sS+2nHOQdkh0eOpIcdznWOi45GTjlOb1yFneOde5wYXDxcqlx+e5q5FrgOua2w22v2xN3TneKe7MH1sPFo9Jj0dPY84TnpJeyV4bX4E6xnQk7u7w5vcO87+xi2OW7q8EH7ePqU+uz6mvrW+676Gfud8pvnmxILiJ/9NfzP+7/PkA7oCBgOlA7sCBwJkg76FjQ+2Dd4MLgWYohpYSyEGIWcibke6htaFXoephrWH04Ltwn/GYEMSI0onM37+6E3X2RUpEZkWNRGlEnouapltTKaCh6Z3RzDDP88t4dKx57MHY8TieuNO5HvEt8QwJTQkRC9x7JPVl7phNNEi8koZLISR3JAsmpyeN79fee2wft89vXkSKUkp4yud90f3UqITU09WmaXFpB2rcDrgdupfOk70+fOGh6sC6DPoOa8eKQ5qEzmahMSuazLMWsk1m/sv2zH+fI5RTmrOaScx8flj9cfHj9SOCRZ3kqeWVHMUcjjg7m6+ZXFzAVJBZMHLM+1nic/3j28W8ndp3oKlQqPFNEKIotGiu2Km4+KXzy6MnVkuCSgVKD0vpT3KeyTn0/7X+6v0yv7PIZnj
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-22T14:00:48Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "network"
}
],
"labels": [
"misp:name=\"email\"",
"misp:meta-category=\"network\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--aba989e1-7952-4225-8f27-be5a626323db",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2022-08-22T14:01:38.000Z",
"modified": "2022-08-22T14:01:38.000Z",
"pattern": "[file:hashes.SHA256 = '2f0f99cbac828092c0ec23e12ecb44cbf53f5a671a80842a2447e6114e4f6979' AND file:name = 'OficioCircularencaminhadoaoSetorFinanceiroUNIMED.docx']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-08-22T14:01:38Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "file"
}
],
"labels": [
"misp:name=\"file\"",
"misp:meta-category=\"file\"",
"misp:to_ids=\"True\""
]
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--9f081c46-7aa1-4fb3-b073-051c3f79a328",
"created": "2022-08-19T12:15:35.000Z",
"modified": "2022-08-19T12:15:35.000Z",
2023-04-21 13:25:09 +00:00
"relationship_type": "contained-within",
2023-06-14 17:31:25 +00:00
"source_ref": "indicator--8809def6-57c4-40fb-b31c-db538af6bad6",
"target_ref": "indicator--9c9a982c-a37e-4e24-85f6-0bb85d0365cf"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--4d1d789c-5145-48a5-80fe-f39eebc517d4",
"created": "2022-08-22T12:27:47.000Z",
"modified": "2022-08-22T12:27:47.000Z",
2023-04-21 13:25:09 +00:00
"relationship_type": "contained-within",
2023-06-14 17:31:25 +00:00
"source_ref": "indicator--20c2cfc4-4abe-42e5-ac49-5759447323a8",
"target_ref": "indicator--dfac55b4-672a-45b3-aaa6-0e60dbdbaf96"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--146c7820-bf03-45bb-b5c3-45de23506a57",
"created": "2022-08-22T13:17:53.000Z",
"modified": "2022-08-22T13:17:53.000Z",
2023-04-21 13:25:09 +00:00
"relationship_type": "contained-within",
2023-06-14 17:31:25 +00:00
"source_ref": "indicator--ccc9024a-2748-4e43-bba0-df53f0332f5e",
"target_ref": "indicator--46cbebab-5fb3-4286-beac-500e45976ff0"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--265d7f80-e3f3-4857-9a2a-66e243922865",
"created": "2022-08-22T14:01:38.000Z",
"modified": "2022-08-22T14:01:38.000Z",
2023-04-21 13:25:09 +00:00
"relationship_type": "contained-within",
2023-06-14 17:31:25 +00:00
"source_ref": "indicator--aba989e1-7952-4225-8f27-be5a626323db",
"target_ref": "indicator--3c167f94-5bac-465c-9765-b48cab0fddf5"
},
{
"type": "marking-definition",
"spec_version": "2.1",
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
"created": "2017-01-20T00:00:00.000Z",
"definition_type": "tlp",
"name": "TLP:WHITE",
"definition": {
"tlp": "white"
}
}
2023-04-21 13:25:09 +00:00
]
}